ATT&CKGroupsDragonfly

Dragonfly

G0035

Threat group.View on attack.mitre.org

About this group

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.

Techniques used56

Procedure examples56

TechniqueProcedure example
T1003.002
Security Account Manager

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.003
NTDS

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

T1003.004
LSA Secrets

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1005
Data from Local System

Dragonfly has collected data from local victim systems.

T1012
Query Registry

Dragonfly has queried the Registry to identify victim information.

T1016
System Network Configuration Discovery

Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.

T1018
Remote System Discovery

Dragonfly has likely obtained a list of hosts in the victim environment.

T1021.001
Remote Desktop Protocol

Dragonfly has moved laterally via RDP.

T1033
System Owner/User Discovery

Dragonfly used the command query user on victim hosts.

T1036.010
Masquerade Account Name

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.

T1053.005
Scheduled Task

Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files.

T1059
Command and Scripting Interpreter

Dragonfly has used the command line for execution.

T1059.001
PowerShell

Dragonfly has used PowerShell scripts for execution.

T1059.003
Windows Command Shell

Dragonfly has used various types of scripting to perform operations, including batch scripts.

T1059.006
Python

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

View all 56 procedure examples

Software10

Campaigns0

None recorded.

References9

  1. CISA AA20-296A Berserk Bear December 2020 Open source
    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.
  2. DOJ Russia Targeting Critical Infrastructure March 2022 Open source
    Department of Justice. (2022, March 24). Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide. Retrieved April 5, 2022.
  3. Fortune Dragonfly 2.0 Sept 2017 Open source
    Hackett, R. (2017, September 6). Hackers Have Penetrated Energy Grid, Symantec Warns. Retrieved June 6, 2018.
  4. Gigamon Berserk Bear October 2021 Open source
    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.
  5. Secureworks IRON LIBERTY July 2019 Open source
    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.
  6. Symantec Dragonfly Open source
    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.
  7. Symantec Dragonfly 2.0 October 2017 Open source
    Symantec. (2017, October 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved April 19, 2022.
  8. Symantec Dragonfly Sept 2017 Open source
    Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.
  9. UK GOV FSB Factsheet April 2022 Open source
    UK Gov. (2022, April 5). Russia's FSB malign activity: factsheet. Retrieved April 5, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.