logo

ENERGETIC_BEAR__2020__Resurgent_Iron_Liberty_Targeting_Energy_Sector.pdf

ID: 902d1462-d5ca-4f3c-87cc-d6b0a7671fb2

STIX ID: report--902d1462-d5ca-4f3c-87cc-d6b0a7671fb2

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2020-01-14

Last Modified Date: 2020-01-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Resurgent IRON LIBERTY (aka Dragonfly/Energetic Bear) is presented as a likely Russian government–linked APT targeting the energy sector and ICS from 2010–2018; the report documents the CASTLE campaign and describes techniques including spearphishing, strategic web compromises, SMB template-injection credential harvesting, use of trojanized installers, and deployment of custom malware (Karagany, MCMD/Havex) to conduct espionage and pre-position for potential sabotage.