logo

DHS Warns Energy Firms Of Malware Used In Targeted Attacks

ID: 0428e7ba-1b1f-5490-8462-cbb6143da920

STIX ID: report--0428e7ba-1b1f-5490-8462-cbb6143da920

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2014-07-01

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

The Department of Homeland Security’s ICS‑CERT and security firms (Symantec, F‑Secure) warned of a targeted campaign—dubbed Dragonfly/Havex—compromising industrial control systems at energy firms in the U.S. and Europe. Attackers used phishing and watering‑hole compromises of ICS vendor download sites to distribute a RAT/downloader (Havex) and secondary payloads (e.g., Karagany), conducted OPC/ICS device reconnaissance and data harvesting, and operated hundreds of C2 servers and many RAT variants to gain footholds that could enable sabotage of ICS environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.