Dragonfly
MITREUnknown
Unknown
Unknown
[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022) Active since at least 2010, [Dragonfly](https://attack.mitre.org/groups/G0035) has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.(Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Symantec Dragonfly Sept 2017)(Citation: Fortune Dragonfly 2.0 Sept 2017)(Citation: Gigamon Berserk Bear October 2021)(Citation: CISA AA20-296A Berserk Bear December 2020)(Citation: Symantec Dragonfly 2.0 October 2017)
Techniques Used (56)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1003.002 | Security Account Manager | - |
| T1003.003 | NTDS | - |
| T1003.004 | LSA Secrets | - |
| T1005 | Data from Local System | - |
| T1012 | Query Registry | - |
| T1016 | System Network Configuration Discovery | - |
| T1018 | Remote System Discovery | - |
| T1021.001 | Remote Desktop Protocol | - |
| T1033 | System Owner/User Discovery | - |
| T1036.010 | Masquerade Account Name | - |
| T1053.005 | Scheduled Task | - |
| T1059 | Command and Scripting Interpreter | - |
| T1059.001 | PowerShell | - |
| T1059.003 | Windows Command Shell | - |
| T1059.006 | Python | - |
Aliases (954)
Related Malware (10)
Metadata
| ID: | 870 |
| Created: | 13/01/2026 17:48 |
| Updated: | 07/03/2026 16:00 |