Threats · Activity group
AZURITE
Executive summary
AZURITE is a Dragos activity group reported for interest in engineering workstations and the operational data held on them — controller configuration, HMI screens, alarm lists and process documentation. The pattern is collection rather than immediate effect, but the material collected is exactly what an actor would need to build a targeted capability later.
Public reporting describes overlap with several vendor-tracked clusters. Those overlaps are analytic relationships, and are shown here as overlap rather than equivalence.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- Flax TyphoonTechnical overlapModerate
Tracked by Microsoft
- Ethereal PandaTechnical overlapModerate
Tracked by CrowdStrike
- UNC5923Technical overlapLow
Tracked by Google Threat Intelligence / Mandiant
- Raptor TrainReported linkLow
Tracked by Black Lotus Labs / vendor reporting — Botnet infrastructure reporting associated with related activity.
- Red Dev 54Reported linkLow
Tracked by Vendor reporting
Relevance
Why OT defenders care
Objectives
- Long-term access to OT-supporting infrastructure
- Collection of engineering and process data
- Potential capability development
Reported impacts
- No publicly confirmed process disruption
- Loss of sensitive engineering and process information
Observed behaviours
- Exploitation of internet-facing applications for a foothold
- Persistent tunnelled remote access rather than malware implants
- Collection of PLC configuration exports, HMI screens and alarm data
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- Web shells on internet-facing servers
Commercial tool
Not publicly established
Open-source utility
- SoftEther VPNReported for persistent tunnelled access in associated activity.
Native OS tool
- Native Windows remote management
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- Not publicly established as named campaigns
Atlas incident case studies
Not publicly established
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Treat engineering workstations as tier-0: restrict egress, log file access, alert on archive creation
- Detect VPN/tunnelling software installed on OT-supporting hosts
- Alert on engineering hosts communicating with the internet at all
Hunt for this activity
- Unexpected engineering workstation peerAn engineering workstation is communicating with a system outside its normal peer set.
- Engineering workstation communicating externallyAn engineering workstation has direct or proxied internet egress.
- Living-off-the-land behaviourBuilt-in operating system tooling is being used for discovery, credential access or movement outside normal administration.
- Long-lived, low-volume connectionsA session has stayed open for an unusually long time while transferring very little data.
- Historian communicating with an unknown internet hostA process historian is exchanging data with an external destination that is not an approved service.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)
- ATT&CKMITRE ATT&CKGroups (opens in a new tab)