ENERGETIC_BEAR__2020__Resurgent_Iron_Liberty_Targeting_Energy_Sector.pdf
ID: 902d1462-d5ca-4f3c-87cc-d6b0a7671fb2
STIX ID: report--902d1462-d5ca-4f3c-87cc-d6b0a7671fb2
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2020-01-14
Last Modified Date: 2020-01-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Resurgent IRON LIBERTY (aka Dragonfly/Energetic Bear) is presented as a likely Russian government–linked APT targeting the energy sector and ICS from 2010–2018; the report documents the CASTLE campaign and describes techniques including spearphishing, strategic web compromises, SMB template-injection credential harvesting, use of trojanized installers, and deployment of custom malware (Karagany, MCMD/Havex) to conduct espionage and pre-position for potential sabotage.
