logo

New ICS Threat Activity Group: TALONITE

ID: da6df16b-d9e3-5624-adf6-cedb34fcbf97

STIX ID: report--da6df16b-d9e3-5624-adf6-cedb34fcbf97

Feed Name: Dragos Blog

Threat Score
85/100

Date Published: 2021-04-26

Date Updated: 2026-04-27

...
...

Dragos details TALONITE, an ICS-focused threat activity group that began targeting U.S. electric utilities in 2019 using engineering-themed spearphishing and custom RATs (LookBack and FlowCloud). The report describes TALONITE’s tactics (credential capture, persistence via modified legitimate binaries, abuse of certutil.exe and renamed Microsoft utilities), shared infrastructure and domain masquerading, notes behavioral overlap with APT10, and states there is no observed disruptive control-system attack while assessing the group as a serious, well-resourced threat to the electric sector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.