logo

Dragonfly: Western energy sector targeted by sophisticated attack group

ID: 93e4e287-09bd-43f4-b0c9-685c3b1e7790

STIX ID: report--93e4e287-09bd-43f4-b0c9-685c3b1e7790

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2017-10-08

Last Modified Date: 2017-10-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec describes Dragonfly 2.0, a sophisticated, long-running APT campaign (active since at least 2011, resurging in 2015–2017) that targets the western energy sector (US, Switzerland, Turkey) using spear-phishing, watering-hole attacks, trojanized software, and credential theft to deploy backdoors (Goodor, Karagany.B, Dorshel, Heriplor); the report provides malware IOCs, evidence the attackers accessed operational systems (raising sabotage risk), and recommended protections and detections.