Dragonfly
G00351 reportsAnalyst assessment — key judgments
- Signature techniques: T1053.005 (Scheduled Task), T1588.006 (Vulnerabilities), T1053 (Scheduled Task/Job).
- Primary targeting: PL.
- Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 56% of 9 observed techniques (4 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Overview
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022) Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.(Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Symantec Dragonfly Sept 2017)(Citation: Fortune Dragonfly 2.0 Sept 2017)(Citation: Gigamon Berserk Bear October 2021)(Citation: CISA AA20-296A Berserk Bear December 2020)(Citation: Symantec Dragonfly 2.0 October 2017)
ATT&CK technique matrix
- T1053.005 · Scheduled Taskconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1053 · Scheduled Task/Jobconf 601
- T1222 · File and Directory Permissions Modificationconf 601
- T1556.006 · Multi-Factor Authenticationconf 601
- T1589.001 · Credentialsconf 601
- T1485 · Data Destructionconf 601
- T1680 · Local Storage Discoveryconf 601
- T1529 · System Shutdown/Rebootconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|