Crouching Yeti

Threat Actor Profile Updated 3 months ago
Download STIX
Preview STIX
Crouching Yeti, also known as Iron Liberty, TG-4192, Energetic Bear, and Dragonfly, is a threat actor group that has been active since at least 2010. This group primarily targets the energy sector, with a specific focus on industrial control systems (ICS). Crouching Yeti's activities are part of a broader pattern of cyber threats posed by state-sponsored actors, particularly those affiliated with Russia. From September 2020 onwards, Crouching Yeti, also identified as Berserk Bear, TeamSpy, Havex, and Koala in various reports, launched a wide-ranging campaign against numerous U.S. targets. These actions exemplify the persistent and sophisticated nature of state-sponsored cyber threats, which often aim to compromise critical infrastructure and disrupt essential services. The group’s activities were further highlighted when FSB hackers Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukov, all members of an operational unit dubbed "Dragonfly," "Berzerk Bear," "Energetic Bear," and "Crouching Yeti," were indicted. The indictment alleges that between 2012 and 2017, these individuals and their co-conspirators conducted computer intrusions, including supply chain attacks, aiming to maintain unauthorized and persistent access to the computer networks of international energy sector companies. This included oil and gas firms, nuclear power plants, and utility and power transmission companies, underscoring the Russian government's strategic interest in these sectors.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Dragonfly
1
Dragonfly is a notable threat actor known for its malicious activities in the cybersecurity landscape. This group has been particularly active in targeting the energy sector across various countries, including the United States, Switzerland, and Turkey. The tactics employed by Dragonfly often involv
Energetic Bear
1
Energetic Bear, also known as DragonFly, Crouching Yeti, and Berserk Bear, is a threat actor that has been operational since at least 2011. The group has been linked to various cyber-espionage campaigns targeting the energy sector in Europe and North America, with the primary focus on defense and av
IRON LIBERTY
1
Iron Liberty is a threat actor group that has been active since at least 2010, as per the timeline of activity observed by CTU researchers. The group specializes in cyber espionage and has been particularly focused on targeting Industrial Control Systems (ICS) companies within the energy sector. Iro
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
russian
Russia
Ics
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
Berserk Bear, Energetic BearUnspecified
1
Berserk Bear and Energetic Bear are two of the most notorious threat actors in the cybersecurity world. Berserk Bear is a group believed to be linked to the Russian government, and they are known for carrying out cyber espionage operations against various countries. Energetic Bear, on the other hand
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Crouching Yeti Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
MITRE
a year ago
Resurgent Iron Liberty Targeting Energy Sector
MITRE
a year ago
Four Russian Government Employees Charged in Two Historical Hacking
MITRE
a year ago
Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets | CISA
CERT-EU
a year ago
Ecco i russi in fuga nella lista dei maggiori ricercati dell'Fbi