logo

New ICS Threat Activity Group: STIBNITE

ID: a2676f9a-c3a2-5e6e-9b87-cb457ec5d775

STIX ID: report--a2676f9a-c3a2-5e6e-9b87-cb457ec5d775

Feed Name: Dragos Blog

Threat Score
75/100

Date Published: 2021-03-24

Date Updated: 2026-04-27

...
...

Dragos details STIBNITE, a threat activity group that conducted targeted intrusion campaigns in Azerbaijan (late 2019–2020) focusing on wind generation and government entities. STIBNITE uses spearphishing and credential-theft websites to deliver PoetRAT and leverages credential-harvesting tools (PypyKatz, LaZagne), DDNS/common-port C2, and infrastructure reuse; while currently IT-focused (Stage 1), stolen credentials and gathered network information could enable follow-on ICS/OT compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.