Full Disclosure of Havex Trojans - NETRESEC Blog
ID: 1923a9f2-bdff-4915-9ce1-5030ed446a69
STIX ID: report--1923a9f2-bdff-4915-9ce1-5030ed446a69
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2014-10-27
Last Modified Date: 2014-10-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report discloses investigation results into the Havex backdoor (used by the Dragonfly/Energetic Bear APT), documenting multiple instances where legitimate ICS vendor installers (MESA Imaging, eWON, MB Connect Line) were trojanized; it includes product names, filenames, MD5/SHA256 hashes, exposure windows, and concludes the actor focused on European industrial control system suppliers through supply‑chain compromise.
