Cyber Threat Report: 'Dragonfly: Cyberespionage Attacks Against Energy Suppliers'

Report Author Symantec
Publication Date 2014-07-07
Original Reporting Source
Related Intrusion Sets Dragonfly
Identified CVEs CVE-2012-4792 , CVE-2013-1347 , CVE-2012-1723 , CVE-2013-2465
Victim Sectors Energy, Aerospace, Defense

This report by Symantec details activities of the cyberespionage group known as Dragonfly. The reporting covers a campaign which initially focused on defense and aviation in the US and Canada before shifting to target energy firms in the US and Europe in early 2013. Dragonfly employed various tactics including spam campaigns and watering hole attacks to ultimately compromise industrial control system (ICS) software updates. Symantec name the custom malware used by the group Backdoor.Oldrea and Trojan.Karagany. The attackers could have potentially caused damage or disruption to the energy supply in affected countries. The report includes a technical appendix with indicators of compromise (IoCs) and detailed analysis.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph