Industrial Control Vendors Identified In Dragonfly Attack
ID: 26e23a0c-ebdd-5169-b85e-694d17ce5d0e
STIX ID: report--26e23a0c-ebdd-5169-b85e-694d17ce5d0e
Feed Name: Security Ledger
Symantec, F-Secure and DHS/ICS-CERT reported a targeted campaign dubbed Dragonfly/Havex that compromised industrial control system software vendor websites to distribute a RAT/downloader (Havex) and additional payloads (e.g., Karagany), targeting energy-sector organizations across multiple countries; vendors eWon and MB Connect Line were named as compromised, with evidence of watering-hole and supply-chain tactics, credential theft risk, and mitigation steps taken by affected vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
