Dragonfly

APT / StateG0035
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)56
SourceMITRE ATT&CK
State sponsor: Russian FederationAttribution confidence: 75%Target categories: Private sector, Government
Targeted regions: United States · Germany · Turkey · China · Spain · France · Ireland · Japan · Italy · Poland
Also known as:TEMP.IsotopeDYMALLOYBerserk BearTG-4192Crouching YetiIRON LIBERTYEnergetic BearGhost BlizzardBROMINE

Vexday analysis

Dragonfly é um grupo de espionagem cibernética atribuído ao Centro 16 do Serviço Federal de Segurança da Rússia (FSB), ativo desde pelo menos 2010. Seus alvos incluem empresas de defesa e aviação, entidades governamentais, organizações ligadas a sistemas de controle industrial e setores de infraestrutura crítica ao redor do mundo, com ataques conduzidos por meio de comprometimento de cadeias de suprimento, spearphishing e drive-by compromise. O grupo é rastreado pelo MITRE ATT&CK sob o identificador G0035, com 56 técnicas documentadas e 8 CVEs atribuídas à sua atuação, sendo também conhecido pelos aliases TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti e IRON LIBERTY.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity86
Impact: High
T1189T1053.005T1098.007T1003.002T1012T1021.001ENTRYInitial accessDrive-byCompromiseEXECExecutionScheduled TaskPERSPersistenceAdditional Localor Domain GroupsCREDCredential accessSecurity AccountManagerDISCDiscoveryQuery RegistryLATLateral movementRemote DesktopProtocolCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Dragonfly uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →