logo

Full Disclosure of Havex Trojans - NETRESEC Blog

ID: 1923a9f2-bdff-4915-9ce1-5030ed446a69

STIX ID: report--1923a9f2-bdff-4915-9ce1-5030ed446a69

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2014-10-27

Last Modified Date: 2014-10-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report discloses investigation results into the Havex backdoor (used by the Dragonfly/Energetic Bear APT), documenting multiple instances where legitimate ICS vendor installers (MESA Imaging, eWON, MB Connect Line) were trojanized; it includes product names, filenames, MD5/SHA256 hashes, exposure windows, and concludes the actor focused on European industrial control system suppliers through supply‑chain compromise.