Energetic Bear/Crouching Yeti: attacks on servers - Securelist
ID: ba34d00b-99ad-442f-b8da-874d756da41e
STIX ID: report--ba34d00b-99ad-442f-b8da-874d756da41e
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2018-04-24
Last Modified Date: 2018-04-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
Kaspersky Lab ICS CERT documents Energetic Bear/Crouching Yeti activity against internet-facing servers (2016–early 2017), describing waterhole infections that exfiltrate SMB/NTLM credentials, deployment of obfuscated PHP web shells and a modified sshd backdoor, use of open-source scanning/exploitation tools and SQL injection activity, and provides indicators of compromise (file paths, hashes, logs, YARA rule and detection scripts) to help defenders identify and remediate affected hosts.
