National Cyber Warfare Foundation (NCWF)

Dragonfly


0 user ratings
2024-06-18 15:33:04
blscott

 - archive -- 

Dragonfly

MITRE:  G0035

Dragonfly is a cyber espionage group that has been attributed to Russia\\\\\\\'s Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.


Sure, heres an overview of the Dragonfly APT group: Dragonfly is a sophisticated and stealthy Advanced Persistent Threat (APT) group that has been active since at least 2011. The group primarily targets industrial control systems (ICS), including those used in power plants, water treatment facilities, and other critical infrastructure sectors. The Dragonfly APT is known for its advanced tactics, techniques, and procedures (TTPs) that allow it to remain undetected within targeted networks for extended periods of time. The group has been observed using a variety of tools and exploits in order to gain access to ICS systems, including spear-phishing emails, watering hole attacks, and vulnerability scanning software. Once inside the network, Dragonfly APT operators have been known to install backdoors, steal sensitive data, and modify systems.

Techniques, tactics, and practices. Dragonfly is a sophisticated and stealthy Advanced Persistent Threat (APT) group that has been active since at least 2011. The group primarily targets industrial control systems (ICS), including those used in power plants, water treatment facilities, and other critical infrastructure sectors. The Dragonfly APT is known for its advanced tactics, techniques, and procedures (TTPs) that allow it to remain undetected within targeted networks for extended periods of time. The group has been observed using a variety of tools and exploits in order to gain access to ICS systems, including spear-phishing emails, watering hole attacks, and vulnerability scanning software. Once inside the network, Dragonfly APT operators have been known to install backdoors, steal sensitive data, and modify system configurations for their own purposes. The group has also demonstrated a high degree of technical sophistication




Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
G0035
Ghost Blizzard
TEMP.Isotope
PEACEPIPE
ITG15
Crouching Yeti
TG-4192
IRON LIBERTY
Havex
Berserk Bear
ATK6
Blue Kraken
BROMINE
DYMALLOY
Fertger
Energetic Bear
Koala Team
Group 24
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.