New ICS Threat Activity Group: STIBNITE
ID: a2676f9a-c3a2-5e6e-9b87-cb457ec5d775
STIX ID: report--a2676f9a-c3a2-5e6e-9b87-cb457ec5d775
Feed Name: Dragos Blog
Dragos details STIBNITE, a threat activity group that conducted targeted intrusion campaigns in Azerbaijan (late 2019–2020) focusing on wind generation and government entities. STIBNITE uses spearphishing and credential-theft websites to deliver PoetRAT and leverages credential-harvesting tools (PypyKatz, LaZagne), DDNS/common-port C2, and infrastructure reuse; while currently IT-focused (Stage 1), stolen credentials and gathered network information could enable follow-on ICS/OT compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
