EB - Yeti July 2014 - Public.docx
ID: 3b532516-7401-4146-a295-51bd9848918c
STIX ID: report--3b532516-7401-4146-a295-51bd9848918c
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2014-07-31
Last Modified Date: 2014-07-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Energetic Bear / Crouching Yeti is an advanced persistent threat actor active since at least 2010 that conducted large-scale surveillance campaigns against industrial, manufacturing, energy and related sectors using spearphishing, trojanized legitimate installers and waterholing (LightsOut EK). The actor deployed multiple Windows malware families (notably Havex) to harvest credentials, enumerate OPC/SCADA systems, and exfiltrate encrypted data to PHP-based C2s hosted on compromised websites, infecting roughly 2,800+ victims worldwide and demonstrating persistent, targeted operations.
