Initial Access
4 techniques·derived
Trojanised installers on three European ICS vendor download pages. Watering holes on energy-sector trade publications and vendor sites. Pivoting from integrators and suppliers into utility operational networks.
FSB Centre 16's energy-sector programme. Spent a decade inside Western electric utilities collecting engineering data — access, not effect.
ATTRIBUTED TORussia › FSB — Federal Security Service › Centre 16
Berserk Bear — better known in earlier reporting as Energetic Bear or Dragonfly — has pursued a single strategic objective for over a decade: durable access to the industrial control networks of Western energy utilities.
The 2013–2014 Havex campaign remains the clearest illustration of intent. The group trojanised legitimate installers on the download pages of three European ICS software vendors, so that engineers who deliberately sought out control-system software received a backdoor with it. The Havex payload then scanned for OPC servers and enumerated connected industrial devices — reconnaissance with no plausible use except operational planning against physical processes.
The 2016–2018 Dragonfly 2.0 campaign reached deeper. CISA's March 2018 alert described attackers moving from vendors and integrators into the operational networks of U.S. energy companies, and taking screenshots of human-machine interfaces showing live plant configurations. In 2020 CISA and the FBI warned that the group had compromised U.S. state, local, and aviation networks and, in at least two cases, exfiltrated data.
What distinguishes this actor is restraint. Unlike Sandworm, it has never been publicly linked to a destructive event. Every documented operation stops at collection and persistence — which is precisely what makes it strategically significant. The access is the point.
In March 2022 the U.S. Department of Justice unsealed a 2021 indictment naming three FSB Centre 16 officers for the campaign, alongside a separate indictment for the Triton attack on a Saudi petrochemical safety system.
Down to the named unit where public evidence supports it.
Military Unit 71330, FSB 16th Centre
The U.S. Department of Justice unsealed an August 2021 indictment in March 2022 charging three FSB Centre 16 officers — Pavel Akulov, Mikhail Gavrilov, and Marat Tyukov — for the Havex and Dragonfly 2.0 campaigns against energy-sector targets in the U.S. and abroad, spanning 2012 to 2018. A separate indictment unsealed the same day charged an employee of the Russian state research institute TsNIIKhM over the Triton attack on a Saudi petrochemical safety instrumented system.
Attributing sources
12 designators across 9 organisations.
3 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
RAT distributed through trojanised ICS vendor installers, with an OPC scanning module that enumerated connected industrial devices.
Malpedia ↗Modular backdoor for credential harvesting and screenshot collection on engineering workstations.
Malpedia ↗Bespoke implant considered a high-confidence clustering signal — never observed outside this actor's operations.
Shared, commodity & living-off-the-land
PowerShell backdoor deployed via PsExec during the Dragonfly 2.0 campaign.
Watering-hole pages and documents referencing attacker SMB shares to harvest Net-NTLM hashes from visiting engineers.
Sysinternals remote execution used for lateral movement inside utility networks.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Berserk Bear | ||
|---|---|---|---|---|
| CVE-2020-1472KEVransomware | 10.0 | Windows NetlogonMicrosoft | 1 Sep 2020 | Zerologon chained with VPN and Fortinet exploitation against U.S. state, local, territorial, and tribal government networks and aviation targets, per the October 2020 CISA/FBI advisory.SRCCISA / FBI ↗ |
| CVE-2019-19781KEVransomware | 9.8 | Citrix ADC / GatewayCitrix | 1 Sep 2020 | Citrix ADC exploitation for perimeter access to targeted government and infrastructure networks.SRCCISA / FBI ↗ |
| CVE-2019-11510KEVransomware | 10.0 | Pulse Connect SecureIvanti / Pulse Secure | 1 Sep 2020 | Pulse Secure arbitrary file read used to obtain plaintext VPN credentials from targeted networks.SRCCISA / FBI ↗ |
| CVE-2018-13379KEVransomware | 9.8 | FortiOS SSL VPNFortinet | 1 Aug 2020 | FortiOS SSL VPN path traversal used to harvest credentials for access to government networks.SRCCISA / FBI ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
4 techniques·derived
Trojanised installers on three European ICS vendor download pages. Watering holes on energy-sector trade publications and vendor sites. Pivoting from integrators and suppliers into utility operational networks.
2 techniques·derived
Long-term persistence via legitimate credentials rather than malware.
1 technique·derived
SMB share references in documents and web pages to capture Net-NTLM hashes.
2 techniques·derived
OPC and ICS protocol enumeration via the Havex scanning module. ICS technique — mapping control network topology.
2 techniques·derived
HMI screenshots documenting live plant configurations. Engineering diagrams, network topologies, and control-system documentation.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Long-term persistence via legitimate credentials rather than malware
SMB share references in documents and web pages to capture Net-NTLM hashes
OPC and ICS protocol enumeration via the Havex scanning module
ICS technique — mapping control network topology
HMI screenshots documenting live plant configurations
Engineering diagrams, network topologies, and control-system documentation
Trojanised installers placed on the download pages of three European ICS software vendors, so engineers deliberately seeking control-system software received a backdoor with it. The Havex payload scanned for OPC servers and enumerated connected industrial devices — reconnaissance with no use except operational planning.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both attributed to FSB Centre 16 / Military Unit 71330 by U.S. indictment.
Both pursue energy-sector access. Berserk Bear stops at collection; Sandworm executes destructive effects.
No connection between the actors, but strategically analogous: long-dwell pre-positioning in critical infrastructure with no collection payoff evident.
Curated links to the reports that established what is known about this group.