Dragonfly: Western energy sector targeted by sophisticated attack group
ID: 93e4e287-09bd-43f4-b0c9-685c3b1e7790
STIX ID: report--93e4e287-09bd-43f4-b0c9-685c3b1e7790
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2017-10-08
Last Modified Date: 2017-10-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec describes Dragonfly 2.0, a sophisticated, long-running APT campaign (active since at least 2011, resurging in 2015–2017) that targets the western energy sector (US, Switzerland, Turkey) using spear-phishing, watering-hole attacks, trojanized software, and credential theft to deploy backdoors (Goodor, Karagany.B, Dorshel, Heriplor); the report provides malware IOCs, evidence the attackers accessed operational systems (raising sabotage risk), and recommended protections and detections.
