A threat intelligence report from Symantec documented the resurgence of Dragonfly — also known as Energetic Bear and Berserk Bear — which re-emerged in a "Dragonfly 2.0" campaign targeting energy sector organizations in the United States, Turkey, and Switzerland beginning in December 2015, with a marked escalation through 2017. The group, active since at least 2011, appears to have moved beyond an exploratory intelligence-gathering phase into a stage where it may have obtained access to operational technology (OT) systems sufficient to cause physical disruption should it choose to act.
Multi-Vector Campaign: Phishing, Watering Holes, and Trojanized Software
Dragonfly 2.0 employs three distinct initial access vectors in parallel. Spear-phishing campaigns began in December 2015 with emails disguised as New Year's Eve party invitations to energy sector targets; subsequent emails in 2016–2017 contained highly specific energy industry content and used the Phishery toolkit (available on GitHub since late 2016) to steal credentials via template injection attacks. Simultaneously, the group compromised websites likely to be visited by energy sector professionals to conduct watering hole attacks, harvesting network credentials for use in follow-on targeted intrusions. In a third vector, Dragonfly used the evasion framework Shellter to develop Trojanized versions of standard Windows applications, delivering the Backdoor.Dorshel implant. Files masquerading as Flash player updates also delivered the Trojan.Karagany.B backdoor through social engineering.
Custom Malware Arsenal With Exclusive Energy Sector DNA
Dragonfly's toolset includes both custom-developed and publicly available components. The backdoors Backdoor.Goodor (providing remote access via PowerShell), Backdoor.Dorshel, and Trojan.Karagany.B provide persistent access to victim environments. Most significantly, Trojan.Heriplor — a backdoor used exclusively by Dragonfly — has never been observed in campaigns by any other threat group, has never appeared on underground markets, and has been deployed solely against energy sector targets since at least 2011. Its continued use in Dragonfly 2.0 provides the strongest technical evidence linking the two campaign phases to a single persistent threat actor. Trojan.Karagany.B is an evolution of the earlier Karagany backdoor, sharing command structures and encryption approaches, though the original version's underground market appearance means its use is not exclusively attributable to Dragonfly.
OT Access and Potential for Sabotage
The most operationally significant evidence from the Dragonfly 2.0 campaign is the group's use of screen capture with a systematic naming convention: [machine description and location].[organization name], with the string "cntrl" appearing in many machine descriptions — suggesting the compromised machines have access to control systems. This intelligence-collection behavior mirrors the pre-sabotage reconnaissance phases observed in Stuxnet and Shamoon operations, where credential and network intelligence gathered during an initial phase was subsequently weaponized for destructive effect. Symantec assesses that Dragonfly may now have the capability to disrupt or seize control of targeted energy operations, though whether or not it will exercise that capability remains unclear.
Attribution Complications
Dragonfly's use of publicly available tools — PowerShell, PsExec, Bitsadmin, the Phishery toolkit, and code from CodeProject — alongside the absence of zero-day exploits may be deliberate misattribution efforts rather than resource constraints. Code strings in malware samples appeared in both Russian and French, suggesting at least one language may be a false flag. Symantec declines to definitively attribute the group's national origin given the conflicting evidence.