logo

How Adversaries Use Spear Phishing to Target Engineering Staff

ID: 0e15d042-29f1-5746-a52d-01a14fc74df6

STIX ID: report--0e15d042-29f1-5746-a52d-01a14fc74df6

Feed Name: Dragos Blog

Threat Score
75/100

Date Published: 2022-08-10

Date Updated: 2026-04-27

...
...

Engineering-focused spear-phishing and watering-hole campaigns tracked by Dragos target engineering and operations personnel to steal credentials and gain access to IT/OT environments. The report details multiple threat groups (TALONITE, ALLANITE, STIBNITE, DYMALLOY), malware components (LookBack, FlowCloud), and TTPs including malicious documents/macros, SMB/NTLM credential harvesting, watering-hole compromises, typo‑squatted and Punycode domains; it concludes with mitigations such as targeted phishing exercises, blocking outbound SMB, and hunting for 'xn--' domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.