# Static Tundra

> As of 2026-09-09, Static Tundra is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 12 threats spanning ics scada, vulnerability, nation state. Also known as Dragonfly, Energetic Bear, Berserk Bear, Blue Kraken. ATT&CK coverage spans 161 techniques across 26 tactics in 12 of 12 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application).

- **Nation:** Russia
- **Tracked threats:** 12
- **Categories:** ICS_SCADA, VULNERABILITY, NATION_STATE, CAMPAIGN, APT
- **Also known as:** Dragonfly, Energetic Bear, Berserk Bear, Blue Kraken, Crouching Yeti, Ghost Blizzard, BROMINE, DYMALLOY, TEMP.Isotope, IRON LIBERTY, Havex Group, FSB Center 16
- **As of:** 2026-09-09

## ATT&CK techniques observed

161 techniques observed across 12 of 12 tracked threats. Tactics: Impact (15), Collection (12), Defense Impairment (12), Discovery (10), Credential Access (9), Initial Access (ICS) (9).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 9 of 12 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 9 of 12 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 9 of 12 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 8 of 12 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 8 of 12 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 7 of 12 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 7 of 12 tracked threats
- [T1136](https://intel.threadlinqs.com/technique/T1136) Create Account — Persistence — observed in 7 of 12 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 7 of 12 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 7 of 12 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 6 of 12 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 6 of 12 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 6 of 12 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 6 of 12 tracked threats
- [T1040](https://intel.threadlinqs.com/technique/T1040) Network Sniffing — Credential Access — observed in 5 of 12 tracked threats

## Tracked threats

- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry](https://intel.threadlinqs.com/threat/TL-2026-2420) — HIGH
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2317) — HIGH
- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers](https://intel.threadlinqs.com/threat/TL-2026-1312) — CRITICAL
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack](https://intel.threadlinqs.com/threat/TL-2026-1283) — HIGH
- [Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1282) — CRITICAL
- [NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171](https://intel.threadlinqs.com/threat/TL-2026-1279) — CRITICAL
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory](https://intel.threadlinqs.com/threat/TL-2026-1277) — HIGH
- [CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-1272) — HIGH
- [Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities](https://intel.threadlinqs.com/threat/TL-2026-0053) — CRITICAL
- [Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms](https://intel.threadlinqs.com/threat/TL-2026-0037) — CRITICAL
- [Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper](https://intel.threadlinqs.com/threat/TL-2026-0014) — CRITICAL
- [Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0004) — CRITICAL

## Related CVEs

3 CVEs referenced by tracked Static Tundra activity.

- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Static%20Tundra
