logo

EB - Yeti July 2014 - Public.docx

ID: 3b532516-7401-4146-a295-51bd9848918c

STIX ID: report--3b532516-7401-4146-a295-51bd9848918c

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2014-07-31

Last Modified Date: 2014-07-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Energetic Bear / Crouching Yeti is an advanced persistent threat actor active since at least 2010 that conducted large-scale surveillance campaigns against industrial, manufacturing, energy and related sectors using spearphishing, trojanized legitimate installers and waterholing (LightsOut EK). The actor deployed multiple Windows malware families (notably Havex) to harvest credentials, enumerate OPC/SCADA systems, and exfiltrate encrypted data to PHP-based C2s hosted on compromised websites, infecting roughly 2,800+ victims worldwide and demonstrating persistent, targeted operations.