Skip to main content
OT Atlas

Threats · Activity group

AZURITE

activeOT-focused accessDragosAttribution · Moderate
Last verified

Executive summary

AZURITE is a Dragos activity group reported for interest in engineering workstations and the operational data held on them — controller configuration, HMI screens, alarm lists and process documentation. The pattern is collection rather than immediate effect, but the material collected is exactly what an actor would need to build a targeted capability later.

Public reporting describes overlap with several vendor-tracked clusters. Those overlaps are analytic relationships, and are shown here as overlap rather than equivalence.

At a glance

Tracked byDragos
NexusReported by vendors as China-linked
First observed2023 (public reporting)
Last reported2024–2025 vendor reporting
ICS kill chainStage 1 — Intrusion · Stage 1 — Collection of OT information

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

AZURITE
  • Flax Typhoon
    Technical overlapModerate

    Tracked by Microsoft

  • Ethereal Panda
    Technical overlapModerate

    Tracked by CrowdStrike

  • UNC5923
    Technical overlapLow

    Tracked by Google Threat Intelligence / Mandiant

  • Raptor Train
    Reported linkLow

    Tracked by Black Lotus Labs / vendor reporting — Botnet infrastructure reporting associated with related activity.

  • Red Dev 54
    Reported linkLow

    Tracked by Vendor reporting

Relevance

Why OT defenders care

Objectives

  • Long-term access to OT-supporting infrastructure
  • Collection of engineering and process data
  • Potential capability development

Reported impacts

  • No publicly confirmed process disruption
  • Loss of sensitive engineering and process information

Observed behaviours

  • Exploitation of internet-facing applications for a foothold
  • Persistent tunnelled remote access rather than malware implants
  • Collection of PLC configuration exports, HMI screens and alarm data

Targeting

Sectors, geography and assets

Target industries

Electric powerManufacturingGovernmentTelecommunications

Target geography

Asia-PacificTaiwanUnited States

Observed assets

Engineering workstationHMIHistorianAlarm serverEdge network device

Protocols in scope

RDPSMBHTTPSSSHVendor engineering protocols

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • Web shells on internet-facing servers

Commercial tool

Not publicly established

Open-source utility

  • SoftEther VPNReported for persistent tunnelled access in associated activity.

Native OS tool

  • Native Windows remote management

ATT&CK

Technique mapping

History

Known campaigns and incidents

Reported campaigns

  • Not publicly established as named campaigns

Atlas incident case studies

Not publicly established

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Treat engineering workstations as tier-0: restrict egress, log file access, alert on archive creation
  • Detect VPN/tunnelling software installed on OT-supporting hosts
  • Alert on engineering hosts communicating with the internet at all

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.
Last verified