Skip to main content
OT Atlas

Threats · Activity group

GRAPHITE

activeIT access with OT relevanceDragosAttribution · Moderate
Last verified

Executive summary

GRAPHITE is a Dragos activity group targeting energy, oil and gas, logistics and government organisations, with public reporting describing technical overlap with the actor widely tracked as APT28. The overlap is technical and analytic — it is not presented here as a direct alias.

Tradecraft reported for this cluster centres on phishing, credential theft and exploitation of known vulnerabilities in perimeter and email infrastructure.

At a glance

Tracked byDragos
NexusAssociated reporting describes Russian state-sponsored activity
First observed2022 (public reporting)
Last reported2024–2025
ICS kill chainStage 1 — Reconnaissance · Stage 1 — Intrusion

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

GRAPHITE
  • APT28
    Technical overlapModerate

    Tracked by MITRE ATT&CK / multiple vendors — Technical overlap reported; not stated as identical.

  • Forest Blizzard
    Reported linkLow

    Tracked by Microsoft

Relevance

Why OT defenders care

Objectives

  • Access to energy and logistics organisations
  • Credential theft
  • Intelligence collection

Reported impacts

  • No publicly confirmed OT process effects

Observed behaviours

  • Spearphishing with credential harvesting
  • Exploitation of known perimeter vulnerabilities
  • Reuse of valid accounts

Targeting

Sectors, geography and assets

Target industries

Electric powerOil and gasLogisticsGovernment

Target geography

Eastern EuropeMiddle EastUnited States

Observed assets

Corporate IT supporting OTEmail infrastructureRemote access gateway

Protocols in scope

SMTPHTTPSSMB

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • Credential phishing kits

Commercial tool

Not publicly established

Open-source utility

Not publicly established

Native OS tool

  • Living-off-the-land Windows tooling

ATT&CK

Technique mapping

ATT&CK Enterprise

ATT&CK for ICS

History

Known campaigns and incidents

Reported campaigns

  • Not publicly established as named campaigns under the GRAPHITE label

Atlas incident case studies

Not publicly established

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Phishing-resistant MFA
  • Perimeter patch discipline
  • Detection of anomalous mailbox and VPN authentication

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.
Last verified