Skip to main content
OT Atlas

Threats · Activity group

GANANITE

activeIT access with OT relevanceDragosAttribution · Low
Last verified

Executive summary

GANANITE is a more recently named Dragos activity group reported against critical infrastructure and government organisations in Central Asia and South Asia, focused on espionage and access. Public technical detail is limited.

At a glance

Tracked byDragos
NexusNot publicly established
First observed2024 (public reporting)
Last reportedNot publicly established
ICS kill chainStage 1 — Reconnaissance · Stage 1 — Intrusion

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

No publicly associated names established for this cluster.

Relevance

Why OT defenders care

Objectives

  • Espionage against critical infrastructure and government organisations

Reported impacts

Not publicly established

Observed behaviours

Not publicly established

Targeting

Sectors, geography and assets

Target industries

GovernmentElectric powerManufacturing

Target geography

Central AsiaSouth Asia

Observed assets

Corporate IT supporting OT

Protocols in scope

Not publicly established

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

Not publicly established

Commercial tool

Not publicly established

Open-source utility

Not publicly established

Native OS tool

Not publicly established

ATT&CK

Technique mapping

ATT&CK Enterprise

ATT&CK for ICS

Not publicly established

History

Known campaigns and incidents

Reported campaigns

Not publicly established

Atlas incident case studies

Not publicly established

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Phishing-resistant MFA
  • Segmentation of OT-supporting IT

Hunt for this activity

No group-specific hunts mapped yet — start with the core hunt packs.

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.
Last verified