{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "berserk-bear",
    "slug": "berserk-bear",
    "name": "Berserk Bear",
    "shortName": "Berserk Bear",
    "country": "Russia",
    "countryCode": "RU",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2010",
    "prominence": 80,
    "mitreGroupId": "G0074",
    "malpediaSlug": "energetic_bear",
    "tagline": "FSB Centre 16's energy-sector programme. Spent a decade inside Western electric utilities collecting engineering data — access, not effect.",
    "bio": "Berserk Bear — better known in earlier reporting as Energetic Bear or Dragonfly — has pursued a single strategic objective for over a decade: durable access to the industrial control networks of Western energy utilities.\n\nThe 2013–2014 Havex campaign remains the clearest illustration of intent. The group trojanised legitimate installers on the download pages of three European ICS software vendors, so that engineers who deliberately sought out control-system software received a backdoor with it. The Havex payload then scanned for OPC servers and enumerated connected industrial devices — reconnaissance with no plausible use except operational planning against physical processes.\n\nThe 2016–2018 Dragonfly 2.0 campaign reached deeper. CISA's March 2018 alert described attackers moving from vendors and integrators into the operational networks of U.S. energy companies, and taking screenshots of human-machine interfaces showing live plant configurations. In 2020 CISA and the FBI warned that the group had compromised U.S. state, local, and aviation networks and, in at least two cases, exfiltrated data.\n\nWhat distinguishes this actor is restraint. Unlike Sandworm, it has never been publicly linked to a destructive event. Every documented operation stops at collection and persistence — which is precisely what makes it strategically significant. The access is the point.\n\nIn March 2022 the U.S. Department of Justice unsealed a 2021 indictment naming three FSB Centre 16 officers for the campaign, alongside a separate indictment for the Triton attack on a Saudi petrochemical safety system.",
    "attribution": {
      "sponsor": "Russia",
      "service": "FSB — Federal Security Service",
      "unit": "Centre 16",
      "unitDetail": "Military Unit 71330, FSB 16th Centre",
      "confidence": "confirmed",
      "summary": "The U.S. Department of Justice unsealed an August 2021 indictment in March 2022 charging three FSB Centre 16 officers — Pavel Akulov, Mikhail Gavrilov, and Marat Tyukov — for the Havex and Dragonfly 2.0 campaigns against energy-sector targets in the U.S. and abroad, spanning 2012 to 2018. A separate indictment unsealed the same day charged an employee of the Russian state research institute TsNIIKhM over the Triton attack on a Saudi petrochemical safety instrumented system.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure",
          "url": "https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical",
          "date": "2022-03-24"
        },
        {
          "org": "CISA / FBI",
          "title": "Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors (TA18-074A)",
          "url": "https://www.cisa.gov/news-events/alerts/2018/03/15/russian-government-cyber-activity-targeting-energy-and-other-critical",
          "date": "2018-03-15"
        },
        {
          "org": "CISA / FBI",
          "title": "Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets (AA20-296A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a",
          "date": "2020-10-22"
        }
      ]
    },
    "motivations": [
      "espionage",
      "pre-positioning"
    ],
    "targetSectors": [
      "Energy",
      "Critical Infrastructure",
      "ICS / SCADA",
      "Nuclear",
      "Oil & Gas",
      "Water & Wastewater",
      "Government",
      "Manufacturing",
      "Aerospace",
      "Transportation"
    ],
    "targetCountries": [
      "United States",
      "Germany",
      "Switzerland",
      "Türkiye",
      "United Kingdom",
      "Ukraine",
      "Poland"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Dragonfly",
        "url": "https://attack.mitre.org/groups/G0074/",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "Berserk Bear",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "Energetic Bear",
        "correlation": "partial",
        "note": "CrowdStrike's earlier designator for the same programme"
      },
      {
        "org": "microsoft",
        "name": "Ghost Blizzard",
        "correlation": "exact",
        "note": "Formerly BROMINE"
      },
      {
        "org": "symantec",
        "name": "Dragonfly",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Dragonfly 2.0",
        "correlation": "partial",
        "note": "The 2015–2018 resurgence phase specifically"
      },
      {
        "org": "kaspersky",
        "name": "Crouching Yeti",
        "correlation": "exact"
      },
      {
        "org": "dragos",
        "name": "DYMALLOY",
        "correlation": "exact"
      },
      {
        "org": "dragos",
        "name": "ALLANITE",
        "correlation": "partial",
        "note": "Dragos assesses ALLANITE as related but distinct, focused on US/UK electric utility reconnaissance"
      },
      {
        "org": "secureworks",
        "name": "IRON LIBERTY",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "TEMP.Isotope",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "FSB Centre 16",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Havex",
        "type": "backdoor",
        "custom": true,
        "description": "RAT distributed through trojanised ICS vendor installers, with an OPC scanning module that enumerated connected industrial devices.",
        "malpediaSlug": "win.havex_rat"
      },
      {
        "name": "Karagany",
        "type": "backdoor",
        "custom": true,
        "description": "Modular backdoor for credential harvesting and screenshot collection on engineering workstations.",
        "malpediaSlug": "win.karagany"
      },
      {
        "name": "Heriplor",
        "type": "backdoor",
        "custom": true,
        "description": "Bespoke implant considered a high-confidence clustering signal — never observed outside this actor's operations."
      },
      {
        "name": "Goodor",
        "type": "backdoor",
        "custom": false,
        "description": "PowerShell backdoor deployed via PsExec during the Dragonfly 2.0 campaign."
      },
      {
        "name": "SMB forced authentication",
        "type": "lotl",
        "custom": false,
        "description": "Watering-hole pages and documents referencing attacker SMB shares to harvest Net-NTLM hashes from visiting engineers."
      },
      {
        "name": "PsExec",
        "type": "lotl",
        "custom": false,
        "description": "Sysinternals remote execution used for lateral movement inside utility networks."
      }
    ],
    "techniques": [
      {
        "tCode": "T1195.002",
        "name": "Supply Chain Compromise: Compromise Software Supply Chain",
        "tactic": "Initial Access",
        "note": "Trojanised installers on three European ICS vendor download pages"
      },
      {
        "tCode": "T1189",
        "name": "Drive-by Compromise",
        "tactic": "Initial Access",
        "note": "Watering holes on energy-sector trade publications and vendor sites"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1187",
        "name": "Forced Authentication",
        "tactic": "Credential Access",
        "note": "SMB share references in documents and web pages to capture Net-NTLM hashes"
      },
      {
        "tCode": "T1199",
        "name": "Trusted Relationship",
        "tactic": "Initial Access",
        "note": "Pivoting from integrators and suppliers into utility operational networks"
      },
      {
        "tCode": "T1046",
        "name": "Network Service Discovery",
        "tactic": "Discovery",
        "note": "OPC and ICS protocol enumeration via the Havex scanning module"
      },
      {
        "tCode": "T1113",
        "name": "Screen Capture",
        "tactic": "Collection",
        "note": "HMI screenshots documenting live plant configurations"
      },
      {
        "tCode": "T1005",
        "name": "Data from Local System",
        "tactic": "Collection",
        "note": "Engineering diagrams, network topologies, and control-system documentation"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Persistence",
        "note": "Long-term persistence via legitimate credentials rather than malware"
      },
      {
        "tCode": "T1505.003",
        "name": "Server Software Component: Web Shell",
        "tactic": "Persistence"
      },
      {
        "tCode": "T0840",
        "name": "Network Connection Enumeration",
        "tactic": "Discovery",
        "note": "ICS technique — mapping control network topology"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2020-1472",
        "firstExploited": "2020-09-01",
        "usage": "Zerologon chained with VPN and Fortinet exploitation against U.S. state, local, territorial, and tribal government networks and aviation targets, per the October 2020 CISA/FBI advisory.",
        "source": {
          "org": "CISA / FBI",
          "title": "Russian State-Sponsored APT Actor Compromises U.S. Government Targets (AA20-296A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a",
          "date": "2020-10-22"
        }
      },
      {
        "cveId": "CVE-2018-13379",
        "firstExploited": "2020-08-01",
        "usage": "FortiOS SSL VPN path traversal used to harvest credentials for access to government networks.",
        "source": {
          "org": "CISA / FBI",
          "title": "Russian State-Sponsored APT Actor Compromises U.S. Government Targets (AA20-296A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a",
          "date": "2020-10-22"
        }
      },
      {
        "cveId": "CVE-2019-19781",
        "firstExploited": "2020-09-01",
        "usage": "Citrix ADC exploitation for perimeter access to targeted government and infrastructure networks.",
        "source": {
          "org": "CISA / FBI",
          "title": "Russian State-Sponsored APT Actor Compromises U.S. Government Targets (AA20-296A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a",
          "date": "2020-10-22"
        }
      },
      {
        "cveId": "CVE-2019-11510",
        "firstExploited": "2020-09-01",
        "usage": "Pulse Secure arbitrary file read used to obtain plaintext VPN credentials from targeted networks.",
        "source": {
          "org": "CISA / FBI",
          "title": "Russian State-Sponsored APT Actor Compromises U.S. Government Targets (AA20-296A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a",
          "date": "2020-10-22"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "turla",
        "type": "same-sponsor",
        "confidence": "confirmed",
        "note": "Both attributed to FSB Centre 16 / Military Unit 71330 by U.S. indictment."
      },
      {
        "relatedActorId": "sandworm",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Both pursue energy-sector access. Berserk Bear stops at collection; Sandworm executes destructive effects."
      },
      {
        "relatedActorId": "volt-typhoon",
        "type": "operational-overlap",
        "confidence": "low",
        "note": "No connection between the actors, but strategically analogous: long-dwell pre-positioning in critical infrastructure with no collection payoff evident."
      }
    ],
    "reports": [
      {
        "org": "Symantec",
        "title": "Dragonfly: Western Energy Sector Targeted by Sophisticated Attack Group",
        "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/dragonfly-energy-sector-cyber-attacks",
        "date": "2017-09-06"
      },
      {
        "org": "CISA / FBI",
        "title": "Alert TA18-074A: Russian Government Cyber Activity Targeting Energy Sectors",
        "url": "https://www.cisa.gov/news-events/alerts/2018/03/15/russian-government-cyber-activity-targeting-energy-and-other-critical",
        "date": "2018-03-15"
      },
      {
        "org": "Kaspersky GReAT",
        "title": "Energetic Bear / Crouching Yeti: Attackers Targeting Multiple Industrial Sectors",
        "url": "https://securelist.com/energetic-bear-crouching-yeti/85345/",
        "date": "2018-04-23"
      },
      {
        "org": "U.S. Department of Justice",
        "title": "Indictment: US v. Akulov, Gavrilov, Tyukov (FSB Centre 16)",
        "url": "https://www.justice.gov/opa/press-release/file/1486006/download",
        "date": "2022-03-24"
      }
    ],
    "campaigns": [
      {
        "id": "havex-dragonfly",
        "actorId": "berserk-bear",
        "name": "Havex / Dragonfly Energy Campaign",
        "date": "2013-06-01",
        "endDate": "2014-07-01",
        "significance": "major",
        "targetSectors": [
          "Energy",
          "Critical Infrastructure",
          "Manufacturing",
          "Oil & Gas"
        ],
        "targetCountries": [
          "United States",
          "Germany",
          "Switzerland",
          "Türkiye"
        ],
        "cveIds": [],
        "summary": "Trojanised installers placed on the download pages of three European ICS software vendors, so engineers deliberately seeking control-system software received a backdoor with it. The Havex payload scanned for OPC servers and enumerated connected industrial devices — reconnaissance with no use except operational planning.",
        "sources": [
          {
            "org": "Symantec",
            "title": "Dragonfly: Western Energy Sector Targeted by Sophisticated Attack Group",
            "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/dragonfly-energy-sector-cyber-attacks",
            "date": "2017-09-06"
          },
          {
            "org": "U.S. Department of Justice",
            "title": "Four Russian Government Employees Charged in Two Historical Hacking Campaigns",
            "url": "https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical",
            "date": "2022-03-24"
          }
        ]
      }
    ],
    "flag": "🇷🇺",
    "profile": "/apt/berserk-bear/"
  }
}