Threats · Activity group
DYMALLOY
Executive summary
DYMALLOY is reported for deep and long-lived access into electric utilities, oil and gas, and advanced industrial organisations, including access to operator interfaces. Public reporting describes overlap with the widely reported Dragonfly / Energetic Bear activity.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- Dragonfly / Berserk Bear / Energetic BearTechnical overlapModerate
Tracked by Multiple vendors
Relevance
Why OT defenders care
Objectives
- Long-term access to energy sector networks
- Collection of operational information including HMI imagery
Reported impacts
- Access to operator interfaces reported; no confirmed manipulation of the process
Observed behaviours
- Supply-chain and watering-hole access
- SMB credential capture
- Screenshot collection from operator interfaces
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- Credential harvesting and remote access tooling
Commercial tool
Not publicly established
Open-source utility
Not publicly established
Native OS tool
- Native Windows administration tooling
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- Reported energy-sector intrusion campaigns described in US government advisories on Dragonfly-related activity
Atlas incident case studies
Not publicly established
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Block outbound SMB and monitor forced authentication attempts
- Harden HMI access and log sessions
- Vendor and supply-chain access review
Hunt for this activity
- New IT-to-OT communication pathA corporate system has begun communicating with an OT asset over a path that is not in the approved conduit list.
- Unexpected engineering workstation peerAn engineering workstation is communicating with a system outside its normal peer set.
- Abnormal RDP usageRDP is being used along a path or at a time that does not match administrative practice.
- Historian communicating with an unknown internet hostA process historian is exchanging data with an external destination that is not an approved service.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)
- ATT&CKMITRE ATT&CKGroups (opens in a new tab)