Energetic Bear

Threat Actor updated 4 months ago (2024-05-04T19:13:07.542Z)
Download STIX
Preview STIX
Energetic Bear, also known as DragonFly, Crouching Yeti, and Berserk Bear, is a threat actor that has been operational since at least 2011. The group has been linked to various cyber-espionage campaigns targeting the energy sector in Europe and North America, with the primary focus on defense and aviation companies in the US and Canada. Their preferred malware tool is Backdoor.Oldrea, also known as Havex or the Energetic Bear Remote Access Trojan (RAT). Karagany, another modular RAT, is also associated with this threat group. The group is tied to Center 16, an operational unit of FSB hackers including Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukov. Between 2012 and 2017, these individuals, along with their co-conspirators, engaged in computer intrusions, including supply chain attacks, to maintain unauthorized and persistent access to the computer networks of international energy sector companies. These activities were conducted in furtherance of the Russian government's efforts to infiltrate oil and gas firms, nuclear power plants, and utility and power transmission companies. To prevent becoming victims of such attacks, companies are advised to implement safeguards against domain impersonation, install robust email security protocols like DMARC, SPF, and DKIM, enable Enhanced Safe Browsing for Chrome, ensure all devices are updated, and vet any previously unknown entity claiming to be a colleague or field expert. Despite some disputes over attribution, there is consensus that Energetic Bear represents a significant threat to global critical infrastructure, with links to other notorious cyber espionage activities such as Turla and Gamaredon.
Description last updated: 2024-05-04T16:34:58.405Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Dragonfly
2
Dragonfly is a notable threat actor known for its malicious activities in the cybersecurity landscape. This group has been particularly active in targeting the energy sector across various countries, including the United States, Switzerland, and Turkey. The tactics employed by Dragonfly often involv
Turla
2
Turla, a threat actor linked to Russia, is known for its sophisticated cyber-espionage activities. It has been associated with numerous high-profile attacks, employing innovative techniques and malware to infiltrate targets and execute actions with malicious intent. According to MITRE ATT&CK and MIT
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Russia
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Energetic Bear Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
6 months ago
Operational Technology Threats - ReliaQuest
DARKReading
8 months ago
Google: Russia's ColdRiver APT Unleashes Custom 'Spica' Malware
CERT-EU
9 months ago
UK government takes steps to thwart Russia's FSB hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
9 months ago
Russia's FSB Hacking UK Politicians NCSC | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
CERT-EU
a year ago
The Urgency for Robust Utility Cybersecurity
CERT-EU
a year ago
The Fiji Times » Cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
MITRE
2 years ago
Four Russian Government Employees Charged in Two Historical Hacking
MITRE
2 years ago
Hackers Have Penetrated Energy Grid, Symantec Warns
MITRE
2 years ago
Updated Karagany Malware Targets Energy Sector
MITRE
2 years ago
Endpoint Protection - Symantec Enterprise