Campaign · Proprietary · · 326 days

Dragonfly Havex ICS vendor compromises

Dragonfly/Energetic Bear compromised industrial software vendors and placed Havex malware in official downloads. The linked attacks preserve the separate MESA Imaging, eWON, and MB Connect Line distribution paths.

Draws together 3 incidents across 6 packages

Dragonfly, also tracked as Energetic Bear, turned industrial software distribution into an espionage path. During the Havex phase, the operators compromised ICS and SCADA vendor sites and made trusted downloads carry remote-access malware.

The vendor compromises were not interchangeable. MESA Imaging supplied industrial camera software, eWON supplied remote-access tooling, and MB Connect Line supplied router and maintenance utilities. Each download looked like legitimate support software for engineers working near operational environments.

Havex gave the operators remote access and reconnaissance capability, including an OPC-scanning component used to look for industrial control systems after infection. That made the trojanized installer more than a foothold; it was a way to map what kind of plant or energy environment the victim might be connected to.

The campaign matters because each vendor served a different operational niche, but the actor, malware family, infrastructure, and industrial targeting were shared. Vendor records remain separate so responders can search concrete products, versions, hashes, and download windows.

Notes

  • The DOJ indictment describes more than 17,000 infected devices across the broader operation; linked attack records do not assign that whole count to any single vendor.

Incidents in this campaign

  1. MESA Imaging software delivered Havex
  2. eWON VPN installer delivered Havex
  3. MB Connect Line delivered Havex

Appendix · Affected packages

Swiss Ranger libMesaSR driver 2013-06-01 to 2013-07-31
1.0.14.706
Talk2M eCatcher 2014-01-01 to 2014-01-31
4.0.0.13073
eGrabIt 2014-01-01 to 2014-01-31
3.0.0.82
mbCONFTOOL 2014-04-16 to 2014-04-23
1.0.1
mbCHECK Europe 2014-04-16 to 2014-04-23
1.1.1
VCOM 2014-04-16 to 2014-04-23

Samples and hashes sit on each incident page, linked above

References

  1. Full Disclosure of Havex Trojansnetresec.com
  2. Havex Hunts For ICS/SCADA Systemsf-secure.com
  3. Wikipedia: Havexen.wikipedia.org
  4. ICS Alert ICS-ALERT-14-176-02A: Ongoing Sophisticated Malware Campaign Compromising ICScisa.gov
  5. ICS Advisory ICSA-14-178-01: ICS Focused Malwarecisa.gov
  6. Dragonfly: Cyberespionage Attacks Against Energy Suppliersweb.archive.org
  7. US reveals Russian supply-chain attack on energy sectortheregister.com
  8. Indictment: United States v. Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov, and Marat Valeryevich Tyukovjustice.gov
  9. Motives Behind Havex ICS Malware Campaign Remain a Mysterythreatpost.com
  10. Industrial Control Vendors Identified In Dragonfly Attacksecurityledger.com

Source record: proprietary/campaigns/dragonfly-havex-ics-2014/meta.yaml