Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-02

Static Tundra

Also known as:DragonflyEnergetic BearBerserk BearBlue KrakenCrouching YetiGhost BlizzardBROMINEDYMALLOYTEMP.IsotopeIRON LIBERTYHavex GroupFSB Center 16

As of 2026-09-09, Static Tundra is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 12 threats spanning ics scada, vulnerability, nation state. Also known as Dragonfly, Energetic Bear, Berserk Bear, Blue Kraken. ATT&CK coverage spans 161 techniques across 26 tactics in 12 of 12 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application).

Tracked threats
127 critical · 5 high
First seen
2026-02-02
Last seen
2026-09-09
ATT&CK techniques
161across 12 of 12 threats
Related CVEs
3Referenced by its activity
Attribution
RussiaNation or origin
Nation: Russia · 12 tracked threat(s) · Categories: ICS_SCADA, VULNERABILITY, NATION_STATE, CAMPAIGN, APT

Activity timeline

Static Tundra appears in 12 tracked threats between and ; the busiest month was 2026-07 with 6 reports.

ATT&CK techniques observed

161 techniques observed across 12 of 12 tracked threats · Impact (15), Collection (12), Defense Impairment (12), Discovery (10), Credential Access (9), Initial Access (ICS) (9)
  • T1059 Command and Scripting Interpreter — Executionobserved in 9 of 12 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 9 of 12 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 9 of 12 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 8 of 12 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 8 of 12 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 7 of 12 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 7 of 12 tracked threats
  • T1136 Create Account — Persistenceobserved in 7 of 12 tracked threats
  • T1485 Data Destruction — Impactobserved in 7 of 12 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 7 of 12 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 6 of 12 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 6 of 12 tracked threats
  • T1110 Brute Force — Credential Accessobserved in 6 of 12 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 6 of 12 tracked threats
  • T1040 Network Sniffing — Credential Accessobserved in 5 of 12 tracked threats

Tracked threats

Related CVEs

3 CVEs referenced by tracked Static Tundra activity