Cyber Threat Report: 'Dragonfly: Cyberespionage Attacks Against Energy Suppliers'
Report Author | Symantec |
---|---|
Publication Date | 2014-07-07 |
Original Reporting | Source |
Related Intrusion Sets | Dragonfly |
Identified CVEs | CVE-2012-4792 , CVE-2013-1347 , CVE-2012-1723 , CVE-2013-2465 |
Victim Sectors | Energy, Aerospace, Defense |
This report by Symantec details activities of the cyberespionage group known as Dragonfly. The reporting covers a campaign which initially focused on defense and aviation in the US and Canada before shifting to target energy firms in the US and Europe in early 2013. Dragonfly employed various tactics including spam campaigns and watering hole attacks to ultimately compromise industrial control system (ICS) software updates. Symantec name the custom malware used by the group Backdoor.Oldrea and Trojan.Karagany. The attackers could have potentially caused damage or disruption to the energy supply in affected countries. The report includes a technical appendix with indicators of compromise (IoCs) and detailed analysis.
Cyber Threat Graph Context
Explore how this report relates to the wider threat graph