Cyber Resilience

Threat actor · all actors

DragonflyG0035 state

🇷🇺 RU · FSB

aka Dragonfly, TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear, Ghost Blizzard, BROMINE, ALLANITE, CASTLE, Group 24, Havex, Koala Team, G0035, ATK6, ITG15, Blue Kraken, Palmetto Fusion

Last updated: 2026-08-20

0attributed CVEs
82ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

Adversaries abusing ICS (based on Dragos Inc adversary list). ALLANITE accesses business and industrial control (ICS) networks, conducts reconnaissance, and gathers intelligence in United States and United Kingdom electric utility sectors. Dragos assesses with moderate confidence that ALLANITE operators continue to maintain ICS network access to: (1) understand the operational environment necessary to develop disruptive capabilities, (2) have ready access from which to disrupt electric utilities. ALLANITE uses email phishing campaigns and compromised websites called watering holes to steal credentials and gain access to target networks, including collecting and distributing screenshots of industrial control systems. ALLANITE operations limit themselves to information gathering and have not demonstrated any disruptive or damaging capabilities. ALLANITE conducts malware-less operations primarily leveraging legitimate and available tools in the Windows operating system.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0035

Microsoftweather-system names

Ghost Blizzard

CrowdStrikenation-animal names

Berserk BearEnergetic Bear

MandiantTEMP temporary cluster

TEMP.Isotope

Secureworkscolour-metal names

IRON LIBERTY

DragosICS mineral names

DYMALLOYALLANITE

Unclassifiedno scheme matched

DragonflyTG-4192Crouching YetiBROMINECASTLEGroup 24HavexKoala TeamATK6ITG15Blue KrakenPalmetto Fusion

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 82 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-453 / 8265%
CM-650 / 8261%
CM-240 / 8249%
AC-335 / 8243%
AC-634 / 8241%
AC-232 / 8239%
CA-731 / 8238%
CM-731 / 8238%
SI-331 / 8238%
IA-226 / 8232%
SI-726 / 8232%
AC-525 / 8230%
AC-423 / 8228%
SC-723 / 8228%
CM-522 / 8227%

Co-occurring actors

None.

Similar actors

Similar TTPs