Skip to content
RussiaState-SponsoredActiveMITRE G0074Malpedia ↗

Berserk Bear

FSB Centre 16's energy-sector programme. Spent a decade inside Western electric utilities collecting engineering data — access, not effect.

ATTRIBUTED TORussia › FSB — Federal Security Service › Centre 16

Open MITRE Navigator layer ↗Download profile JSON
Active
2010–present
Motivation
Espionage, Pre-Positioning
Aliases
12
Exploited CVEs
4
ATT&CK techniques
11
Cited sources
11

Overview

Berserk Bear — better known in earlier reporting as Energetic Bear or Dragonfly — has pursued a single strategic objective for over a decade: durable access to the industrial control networks of Western energy utilities.

The 2013–2014 Havex campaign remains the clearest illustration of intent. The group trojanised legitimate installers on the download pages of three European ICS software vendors, so that engineers who deliberately sought out control-system software received a backdoor with it. The Havex payload then scanned for OPC servers and enumerated connected industrial devices — reconnaissance with no plausible use except operational planning against physical processes.

The 2016–2018 Dragonfly 2.0 campaign reached deeper. CISA's March 2018 alert described attackers moving from vendors and integrators into the operational networks of U.S. energy companies, and taking screenshots of human-machine interfaces showing live plant configurations. In 2020 CISA and the FBI warned that the group had compromised U.S. state, local, and aviation networks and, in at least two cases, exfiltrated data.

What distinguishes this actor is restraint. Unlike Sandworm, it has never been publicly linked to a destructive event. Every documented operation stops at collection and persistence — which is precisely what makes it strategically significant. The access is the point.

In March 2022 the U.S. Department of Justice unsealed a 2021 indictment naming three FSB Centre 16 officers for the campaign, alongside a separate indictment for the Triton attack on a Saudi petrochemical safety system.

Attribution

Down to the named unit where public evidence supports it.

RussiaFSB — Federal Security ServiceCentre 16Confirmed

Military Unit 71330, FSB 16th Centre

The U.S. Department of Justice unsealed an August 2021 indictment in March 2022 charging three FSB Centre 16 officers — Pavel Akulov, Mikhail Gavrilov, and Marat Tyukov — for the Havex and Dragonfly 2.0 campaigns against energy-sector targets in the U.S. and abroad, spanning 2012 to 2018. A separate indictment unsealed the same day charged an employee of the Russian state research institute TsNIIKhM over the Triton attack on a Saudi petrochemical safety instrumented system.

Attributing sources

Cross-vendor naming crosswalk

12 designators across 9 organisations.

3 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Dragonfly

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Ghost BlizzardFormerly BROMINE

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Berserk Bear
  • Energetic BearpartialCrowdStrike's earlier designator for the same programme

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • TEMP.Isotope

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • IRON LIBERTY

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Kaspersky GReAT

index ↗
  • Crouching Yeti

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Dragos

index ↗
  • DYMALLOY
  • ALLANITEpartialDragos assesses ALLANITE as related but distinct, focused on US/UK electric utility reconnaissance

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

Symantec (Broadcom)

index ↗
  • Dragonfly
  • Dragonfly 2.0partialThe 2015–2018 resurgence phase specifically

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • FSB Centre 16

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesGermanySwitzerlandTürkiyeUnited KingdomUkrainePoland

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Havexbackdoor

RAT distributed through trojanised ICS vendor installers, with an OPC scanning module that enumerated connected industrial devices.

Malpedia ↗
Karaganybackdoor

Modular backdoor for credential harvesting and screenshot collection on engineering workstations.

Malpedia ↗
Heriplorbackdoor

Bespoke implant considered a high-confidence clustering signal — never observed outside this actor's operations.

Shared, commodity & living-off-the-land

Goodorbackdoor

PowerShell backdoor deployed via PsExec during the Dragonfly 2.0 campaign.

SMB forced authenticationlotl

Watering-hole pages and documents referencing attacker SMB shares to harvest Net-NTLM hashes from visiting engineers.

PsExeclotl

Sysinternals remote execution used for lateral movement inside utility networks.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Berserk Bear
CVE-2020-1472KEVransomware10.01 Sep 2020Zerologon chained with VPN and Fortinet exploitation against U.S. state, local, territorial, and tribal government networks and aviation targets, per the October 2020 CISA/FBI advisory.SRCCISA / FBI
CVE-2019-19781KEVransomware9.81 Sep 2020Citrix ADC exploitation for perimeter access to targeted government and infrastructure networks.SRCCISA / FBI
CVE-2019-11510KEVransomware10.01 Sep 2020Pulse Secure arbitrary file read used to obtain plaintext VPN credentials from targeted networks.SRCCISA / FBI
CVE-2018-13379KEVransomware9.81 Aug 2020FortiOS SSL VPN path traversal used to harvest credentials for access to government networks.SRCCISA / FBI

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

5 stages · 11 techniques
  1. 03

    Credential Access

    1 technique·derived

    SMB share references in documents and web pages to capture Net-NTLM hashes.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
11 techniques across 5 tactics · 9 with actor-specific notes

Persistence

2

Credential Access

1

Discovery

2

Collection

2

Campaign timeline

  1. Havex / Dragonfly Energy Campaign

    Trojanised installers placed on the download pages of three European ICS software vendors, so engineers deliberately seeking control-system software received a backdoor with it. The Havex payload scanned for OPC servers and enumerated connected industrial devices — reconnaissance with no use except operational planning.

    EnergyCritical InfrastructureManufacturingOil & Gas

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.