logo

New ICS Threat Activity Group: KAMACITE

ID: 29482764-246a-5cd8-9202-3b80c1d0ad02

STIX ID: report--29482764-246a-5cd8-9202-3b80c1d0ad02

Feed Name: Dragos Blog

Threat Score
90/100

Date Published: 2021-03-02

Date Updated: 2026-04-27

...
...

**KAMACITE (Dragos)** — This Dragos intelligence brief profiles KAMACITE, a long-running ICS/OT-focused activity group active since at least 2014 that leverages phishing, credential theft, compromised third-party infrastructure, and custom malware (BLACKENERGY2/3, GREYENERGY, CRASHOVERRIDE/EXARAMEL) to gain and maintain access to electric, oil & gas, and manufacturing networks; the group has enabled or facilitated disruptive events (including the 2015 and 2016 Ukraine power outages) and remains an ongoing high-risk actor with recommended mitigations such as MFA, logging/monitoring of remote access, and blocking anomalous IP-based communications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.