Campaign Proprietary 2013-06-01 · 326 days ·Backdoor, Data Theft, Remote Access

Dragonfly Havex ICS vendor compromises

Dragonfly/Energetic Bear compromised industrial software vendors and placed Havex malware in official downloads. The linked attacks preserve the separate MESA Imaging, eWON, and MB Connect Line distribution paths.

Story

Dragonfly, also tracked as Energetic Bear, turned industrial software distribution into an espionage path. During the Havex phase, the operators compromised ICS and SCADA vendor sites and made trusted downloads carry remote-access malware.

The vendor compromises were not interchangeable. MESA Imaging supplied industrial camera software, eWON supplied remote-access tooling, and MB Connect Line supplied router and maintenance utilities. Each download looked like legitimate support software for engineers working near operational environments.

Havex gave the operators remote access and reconnaissance capability, including an OPC-scanning component used to look for industrial control systems after infection. That made the trojanized installer more than a foothold; it was a way to map what kind of plant or energy environment the victim might be connected to.

The campaign matters because each vendor served a different operational niche, but the actor, malware family, infrastructure, and industrial targeting were shared. Vendor records remain separate so responders can search concrete products, versions, hashes, and download windows.

Linked Attacks

2014

Top vector Distribution Top payload point Distribution
2 entries 0 open source 2 proprietary
April 1 entry
January 1 entry

2013

Top vector Distribution Top payload point Distribution
1 entries 0 open source 1 proprietary
June 1 entry

Campaign Context

Actor
FSB Center 16 (Dragonfly/Energetic Bear)
Attribution
State
Cause
Unknown

Affected Packages

Notes

  • The DOJ indictment describes more than 17,000 infected devices across the broader operation; linked attack records do not assign that whole count to any single vendor.

External References

Source record: proprietary/campaigns/dragonfly-havex-ics-2014/meta.yaml