Skip to main content
OT Atlas

Threats · Activity group

ALLANITE

activeOT-focused accessDragosAttribution · Low
Last verified

Executive summary

ALLANITE is reported for access operations against electric utilities in the United States and United Kingdom, including collection of information from business and operations networks. Public reporting emphasises reconnaissance and access rather than demonstrated ICS effects.

At a glance

Tracked byDragos
NexusNot conclusively established in public government attribution
First observed2017 (public reporting)
Last reportedContinued Dragos tracking
ICS kill chainStage 1 — Reconnaissance · Stage 1 — Intrusion

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

ALLANITE
  • Palmetto Fusion / Dragonfly-adjacent reporting
    Technical overlapLow

    Tracked by Multiple sources — Reporting describes similarity to Dragonfly-related activity; sources do not universally equate them.

Relevance

Why OT defenders care

Objectives

  • Access to electric utility networks
  • Collection of HMI screenshots and network information

Reported impacts

  • No publicly confirmed process disruption

Observed behaviours

  • Watering-hole and phishing access
  • Screenshot capture of operator interfaces
  • Network enumeration

Targeting

Sectors, geography and assets

Target industries

Electric power

Target geography

United StatesUnited Kingdom

Observed assets

HMIEngineering workstationBusiness network hosts supporting OT

Protocols in scope

SMBHTTPRDP

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • Credential harvesting via watering holes and phishing

Commercial tool

Not publicly established

Open-source utility

Not publicly established

Native OS tool

Not publicly established

ATT&CK

Technique mapping

ATT&CK Enterprise

ATT&CK for ICS

History

Known campaigns and incidents

Reported campaigns

Not publicly established

Atlas incident case studies

Not publicly established

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Detect screenshot/collection tooling on HMI-adjacent hosts
  • Boundary monitoring
  • Credential hygiene

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.
Last verified