Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0035
MITRE ATT&CK Group

Dragonfly (G0035)

TEMP.IsotopeDYMALLOYBerserk BearTG-4192Crouching YetiIRON LIBERTYEnergetic BearGhost BlizzardBROMINE
ShareXLinkedInRedditHN

[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022) Active since at least 2010, [Dragonfly](https://attack.mitre.org/groups/G0035) has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.(Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Symantec Dragonfly Sept 2017)(Citation: Fortune Dragonfly 2.0 Sept 2017)(Citation: Gigamon Berserk Bear October 2021)(Citation: CISA AA20-296A Berserk Bear December 2020)(Citation: Symantec Dragonfly 2.0 October 2017)

▪Techniques used (58)

T1560Archive Collected DataT1113Screen CaptureT1564.002Hidden UsersT1505.003Web ShellT1204.002Malicious FileT1591.002Business RelationshipsT1078Valid AccountsT1016System Network Configuration DiscoveryT1584.004ServerT1083File and Directory DiscoveryT1136.001Local AccountT1221Template InjectionT1203Exploitation for Client ExecutionT1110.002Password CrackingT1608.004Drive-by TargetT1012Query RegistryT1566.001Spearphishing AttachmentT1189Drive-by CompromiseT1583.001DomainsT1003.002Security Account ManagerT1598.002Spearphishing AttachmentT1005Data from Local SystemT1070.004File DeletionT1059Command and Scripting InterpreterT1685.005Clear Windows Event LogsT1686Disable or Modify System FirewallT1112Modify RegistryT1588.002ToolT1195.002Compromise Software Supply ChainT1036.010Masquerade Account NameT1003.003NTDST1098.007Additional Local or Domain GroupsT1583.003Virtual Private ServerT1059.003Windows Command ShellT1071.002File Transfer ProtocolsT1598.003Spearphishing LinkT1053.005Scheduled TaskT1069.002Domain GroupsT1114.002Remote Email CollectionT1595.002Vulnerability ScanningT1547.001Registry Run Keys / Startup FolderT1105Ingress Tool TransferT1133External Remote ServicesT1003.004LSA SecretsT1190Exploit Public-Facing ApplicationT1135Network Share DiscoveryT1110Brute ForceT1021.001Remote Desktop ProtocolT1187Forced AuthenticationT1033System Owner/User DiscoveryT1074.001Local Data StagingT1059.001PowerShellT1210Exploitation of Remote ServicesT1059.006PythonT1018Remote System DiscoveryT1087.002Domain AccountT0817Drive-by CompromiseT0862Supply Chain Compromise

▪Software used (10)

S0500MCMDtoolS0039NettoolS0357ImpackettoolS0488CrackMapExectoolS0075RegtoolS0093Backdoor.OldreamalwareS0002MimikatztoolS0029PsExectoolS0094Trojan.KaraganymalwareS0108netshtool
G0035on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.