ENERGETIC BEAR
A Russian group that collects intelligence on the energy industry.
Russian state-sponsored cyber espionage group primarily targeting the energy sector.
ENERGETIC BEAR (also known as BERSERK BEAR or Dragonfly) is a Russian nation-state cyber espionage group. The group primarily targets the energy, government, and private sectors across multiple countries including the US, Germany, Turkey, and China. They utilize spearphishing attachments (T1566.001) for initial access, web shells (T1505.003) for persistence, and deploy custom malware like Backdoor.Oldrea (S0093) and Trojan.Karagany (S0094), alongside tools such as Mimikatz (S0002) for credential theft. Defenders should monitor for network discovery activities (T1016), lateral movement via RDP (T1021.001), and FTP-based C2 (T1071.002), while tracking the use of post-exploitation tools like Impacket (S0357) and CrackMapExec (S0488).
A Russian group that collects intelligence on the energy industry.
Monitor network traffic and open sources to track business relationships.
Monitor server logins and network activity to detect unauthorized acquisition of Server resources.
Analyze email content and attachment behavior to detect suspicious email attachments.
Monitor user activity and software exploitation to detect execution of malicious files.
Monitor account creation and web server activity to detect Local Account creation and Web Shell access.
Analyze user account activity and authentication logs to detect Hidden Users and Valid Accounts.
Monitor authentication logs and suspicious processes to detect Password Cracking activity.
Analyze network queries and system logs to detect System Network Configuration Discovery.
Monitor Remote Desktop activity and network traffic to detect RDP connections.
Monitor user activity and file system to detect Screen Capture and Archive Collected Data.
Analyze network traffic and file system to detect File Transfer Protocols.
Monitor Windows Event Logs and system logs to detect clearing of Windows Event Logs.
The group primarily uses spearphishing attachments (T1566.001) for initial access.
In addition to Backdoor.Oldrea (S0093), ENERGETIC BEAR also uses Trojan.Karagany (S0094).
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.