Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure

Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on (TL-2026-0004) is a critical-severity advanced persistent threat campaign scored CVSS 9.1, first published 2026-02-02. It is attributed to Static Tundra (Russia) with high confidence, affects Hitachi Energy RTU560 Remote Terminal Units, references 1 CVE (CVE-2024-2617), maps to 61 MITRE ATT&CK techniques (T0800, T0827, T0831), and is covered by 15 detection rules and 71 indicators of compromise.

Key facts for TL-2026-0004

Threat ID
TL-2026-0004
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-02-02
Last reviewed
2026-02-02
Attribution
Static Tundra
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
DESTRUCTION
Target sectors
Energy, Government, Critical Infrastructure, Aviation, ICS/SCADA, Defense, Water
Target regions
Poland, Europe, North America, Turkey
Detection rules
15
Indicators of compromise
71

Malware and tooling in Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

Malware and tooling: DorShel backdoor — Dragonfly/DYMALLOY Phase 2 commodity malware, DynoWiper — ICS/SCADA destructive wiper (OPC/Modbus/IEC 61850/IEC 104), DynoWiper — destructive ICS wiper targeting OPC/Modbus/IEC 61850/IEC 104, DynoWiper — destructive ICS/SCADA wiper targeting OPC, Modbus, IEC 61850, IEC 104, Goodor backdoor — Dragonfly/DYMALLOY Phase 2 commodity malware, Goodor/DorShel/Karagany backdoor suite, Goodor/DorShel/Karagany backdoor suite — Phase 2 ICS access, Havex RAT + OPC scanner — Phase 1 ICS reconnaissance, Havex RAT with OPC scanner module, Havex RAT — OPC scanner for ICS reconnaissance, Karagany backdoor — Dragonfly/DYMALLOY Phase 2 commodity malware, CrackMapExec — network enumeration and credential exploitation

Static Tundra (Dragonfly/Energetic Bear/Berserk Bear/DYMALLOY/TEMP.Isotope/Crouching Yeti/IRON LIBERTY/Ghost Blizzard/BROMINE — MITRE G0035) is a Russian state-sponsored APT group conducting sustained cyber operations against Industrial Control System (ICS) networks, energy infrastructure, and government targets since 2011. In the 2025-2026 campaign designated 'Static Tundra,' the group has escalated operations against Polish energy grid infrastructure, deploying DynoWiper — a destructive wiper malware purpose-built for ICS/SCADA environments that targets Supervisory Control and Data Acquisition (SCADA) systems, Human-Machine Interfaces (HMIs), and Programmable Logic Controllers (PLCs). The campaign represents a deliberate escalation from intelligence gathering (pre-positioning) to destructive capability deployment against NATO-allied critical infrastructure. Dragonfly's 15-year operational history spans three documented phases: Phase 1 (2011-2014, 'Dragonfly 1.0') targeting energy companies in US, Spain, France, Italy, Germany, Turkey, and Poland via supply chain compromise of ICS vendor websites; Phase 2 (2015-2018, 'Dragonfly 2.0'/DYMALLOY) penetrating ICS networks in Turkey, Europe, and North America with credential theft, Goodor/DorShel/Karagany backdoors, and Mimikatz; Phase 3 (2020-present) targeting US state/local government, aviation, energy, and now Polish grid infrastructure with increased destructive intent. CISA AA20-296A confirmed Russian state attribution. The Static Tundra campaign against Poland is assessed as both a MILITARY PREPARATION ACTIVITY and a COERCIVE SIGNALING OPERATION — demonstrating capability to disrupt a NATO frontline state's energy infrastructure during a period of heightened geopolitical tension. Absorbs duplicates TL-2026-0014, TL-2026-0037, TL-2026-0053.

How Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on works

The Static Tundra campaign represents the convergence of 15 years of Russian state-sponsored ICS targeting with the current geopolitical reality of NATO's Eastern European defense posture. This is not a new group — it is the MOST PERSISTENT state-sponsored ICS threat actor in documented history, now deploying DESTRUCTIVE capabilities against a NATO ally.

**The Threat Actor — Dragonfly (MITRE G0035):**

Dragonfly is one of the most extensively documented state-sponsored threat groups operating globally: - **Aliases**: Energetic Bear, Berserk Bear, TEMP.Isotope, DYMALLOY (Dragos), Crouching Yeti, IRON LIBERTY (SecureWorks), Ghost Blizzard (Microsoft), BROMINE, TG-4192, TeamSpy, Koala, Havex - **Attribution**: Russian state-sponsored (FBI/CISA joint assessment, CISA AA20-296A) - **Active since**: 2011 (15-year operational history) - **Primary targets**: Energy sector (power generation, transmission, distribution), ICS/SCADA systems, government networks, aviation - **Target regions**: US, Europe (Poland, Turkey, Germany, France, Spain, Italy, UK), North America - **Motivation**: Intelligence gathering, pre-positioning for disruption/destruction, coercive signaling

**Phase 1 — Dragonfly 1.0 (2011-2014):**

Initial operations focused on ICS reconnaissance and intelligence gathering: - Supply chain compromise: infected ICS vendor update websites (trojanized legitimate ICS software downloads) - Deployed Havex RAT — specifically designed to scan for OPC (OLE for Process Control) servers on victim networks - OPC scanning = mapping ICS/SCADA architecture without active exploitation of control systems - Targeted energy companies in US, Western and Eastern Europe - Primarily intelligence gathering: understanding ICS architectures, identifying HMI workstations, mapping SCADA networks

**Phase 2 — Dragonfly 2.0 / DYMALLOY (2015-2018):**

Escalated to direct network penetration and credential theft: - Spearphishing campaigns targeting energy sector employees - Watering hole attacks on industrial-related websites - Deployed Goodor, DorShel, and Karagany backdoors (commodity malware assembled as unique toolkit) - Used Mimikatz, CrackMapExec, PsExec, SecretsDump for credential harvesting - Successfully penetrated ICS networks in Turkey, Europe, and North America - Stole confidential ICS documentation including SCADA configurations and network diagrams - US-CERT TA18-074A (March 2018): attributed to Russian government actors - Accessed SCADA/HMI screens — demonstrated ability to interact with control systems - Key evidence: screenshots of HMI interfaces taken by operators indicated CAPABILITY to manipulate industrial processes

**Phase 3 — Current Operations (2020-2026):**

- CISA AA20-296A (October 2020): Dragonfly targeting US SLTT government and aviation networks - Exploited CVE-2019-19781 (Citrix), CVE-2020-0688 (Exchange), CVE-2018-13379 (Fortinet), CVE-2020-1472 (Zerologon) - Compromised O365 accounts, exfiltrated data from government servers - Used Turkish IP addresses and registered look-alike domains (microsoftonline[.]host) - 2025-2026 Static Tundra campaign: ESCALATION to Polish energy infrastructure with DynoWiper deployment

**DynoWiper — Destructive ICS Malware:**

DynoWiper represents Dragonfly's evolution from reconnaissance/pre-positioning to DESTRUCTIVE CAPABILITY: - Purpose-built wiper targeting ICS/SCADA environments - Designed to corrupt or destroy SCADA configurations, HMI databases, and PLC programming - Targets specific ICS protocols (OPC, Modbus, IEC 61850, IEC 104) - Can wipe historian databases — destroying operational records needed for forensics and recovery - Can corrupt PLC firmware — requiring physical replacement of industrial controllers - Includes time-delay and condition-triggered execution — allowing pre-positioning before activation - Parallels to previous ICS wipers: Industroyer/CrashOverride (2016, Ukraine), Industroyer2 (2022, Ukraine), Triton/TRISIS (2017, Saudi Arabia)

**The Polish Energy Grid Target:**

Poland's selection as target is STRATEGICALLY SIGNIFICANT: - NATO frontline state bordering Ukraine, Belarus, Russia (Kaliningrad) - Major transit hub for energy supplies to Western Europe - Host to US military installations and NATO Enhanced Forward Presence - Energy infrastructure includes: power generation (coal, gas, renewable), transmission grid (400kV, 220kV), distribution networks, gas pipelines - ICS vendors in Polish grid include Siemens, ABB, GE, Schneider Electric — all with documented vulnerabilities - Disrupting Polish energy during winter = humanitarian impact + military logistics disruption

**Geopolitical Context:**

The campaign operates at the intersection of cyber and kinetic military capability: - Energy grid disruption degrades military logistics (base operations, communications, transportation) - Demonstrates Russian capability to impose costs on NATO allies supporting Ukraine - Coercive signaling: 'We CAN disrupt your critical infrastructure if you escalate' - Pre-positioning: destructive malware deployed but not necessarily activated — a latent threat - Historical precedent: Russia's BlackEnergy (2015) and Industroyer (2016, 2022) attacks on Ukrainian power grid caused real blackouts

**Absorbs Duplicates:** - TL-2026-0014: Earlier reporting on Dragonfly energy sector targeting - TL-2026-0037: DynoWiper analysis and ICS protocol targeting - TL-2026-0053: Polish energy infrastructure vulnerability assessment

MITRE ATT&CK techniques used in TL-2026-0004

inhibit-response-function

T0800 Activate Firmware Update Mode

impact

T0827 Loss of Control; T0831 Manipulation of Control; T0880 Loss of Safety; T1485 Data Destruction; T1489 Service Stop; T1490 Inhibit System Recovery; T1495 Firmware Corruption; T1529 System Shutdown/Reboot; T1561 Disk Wipe

credential-access

T1003 OS Credential Dumping; T1003.001 LSASS Memory; T1110 Brute Force; T1187 Forced Authentication; T1558 Steal or Forge Kerberos Tickets

collection

T1005 Data from Local System; T1074 Data Staged; T1113 Screen Capture; T1114 Email Collection; T1213.002 Sharepoint; T1560 Archive Collected Data

lateral-movement

T1021 Remote Services; T1021.002 SMB/Windows Admin Shares; T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer

defense-evasion

T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1078.001 Default Accounts; T1078.002 Domain Accounts; T1564 Hide Artifacts

exfiltration

T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery

execution

T1053.005 Scheduled Task; T1059 Command and Scripting Interpreter; T1059.001 PowerShell

command-and-control

T1090.002 External Proxy; T1095 Non-Application Layer Protocol

persistence

T1098 Account Manipulation; T1133 External Remote Services; T1136 Create Account; T1547 Boot or Logon Autostart Execution

initial-access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

defense-impairment

T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools

resource-development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1591 Gather Victim Org Information; T1595 Active Scanning

Affected products and versions in Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

  • Hitachi Energy — RTU560 Remote Terminal Units
    Vulnerable versions: RTU500 series with outdated firmware (CVE-2024-2617)
    Fixed in: Updated firmware per Hitachi advisory 8DBD000236
  • Hitachi Energy — Relion Protection and Control Relays
    Vulnerable versions: All versions with default FTP/credentials enabled
    Fixed in: Credential rotation + FTP disabled
  • Mikronika — RTUs and HMI Computers
    Vulnerable versions: All versions with default credentials
    Fixed in: Credential rotation
  • Moxa — NPort Serial Device Servers
    Vulnerable versions: All versions with exposed web interfaces and default credentials
    Fixed in: Web interface secured + credentials rotated
  • Fortinet — FortiGate
    Vulnerable versions: Versions with SSL-VPN exposed without MFA
    Fixed in: Patched + MFA enforced

Remediation for Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

Patches

  • Hitachi Energy RTU500 series: Update firmware to address CVE-2024-2617
  • Fortinet FortiGate: Apply latest firmware patches and enforce MFA
  • Mikronika HMI/RTU: Apply vendor security hardening guides

Immediate actions

  • Deploy behavioral ransomware/wiper protection (canary file monitoring) on all ICS endpoints
  • Enable MFA on all VPN and remote access solutions
  • Audit FortiGate and edge device configurations for unauthorized accounts
  • Reset all default credentials on industrial devices (RTUs, HMIs, serial servers, relays)
  • Isolate OT networks from IT with strict segmentation

Workarounds

  • Disable default FTP accounts on Hitachi Relion relays
  • Disable exposed web interfaces on Moxa NPort serial servers
  • Segment SCADA/OT networks behind dedicated firewalls
  • Implement canary file deployment on all Windows-based OT workstations

Longer-term hardening

  • Implement network monitoring for mass file operations (GetLogicalDrives + SetFileAttributesW patterns)
  • Deploy OT-specific threat detection platforms (Dragos, Claroty)
  • Establish offline/air-gapped backup strategy for critical OT data
  • Review and harden all industrial device firmware against CVE-2024-2617
  • Implement NIS2 directive compliance

CVEs associated with Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

CVE-2024-2617

Weaknesses (CWE) in Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

CWE-358, CWE-798, CWE-287, CWE-1188, CWE-521

Timeline of Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

  • Dragonfly (Energetic Bear) begins operations targeting Western energy companies. Initial operations focus on supply chain compromise — trojanizing ICS vendor software update websites to deliver Havex RAT. Havex specifically scans for OPC servers, mapping ICS/SCADA architectures without active exploitation. Targets include energy companies in US, Spain, France, Italy, Germany, Turkey, and Poland. Source: Symantec, MITRE G0035.
  • Symantec publishes 'Dragonfly: Western Energy Sector Targeted by Sophisticated Attack Group' — first major public disclosure of Dragonfly operations. Documents supply chain compromise, Havex RAT, and OPC scanning. Reveals targeting of energy companies across multiple Western nations. Establishes Dragonfly as a persistent, sophisticated ICS-focused threat actor. Source: https://docs.broadcom.com/doc/dragonfly_threat_against_western_energy_suppliers
  • BlackEnergy malware causes first-ever confirmed cyber-induced power outage in Ukraine — 230,000 customers lose power for 1-6 hours. Attributed to Sandworm (GRU Unit 74455). While Sandworm is a DIFFERENT Russian unit than Dragonfly (FSB-linked), the Ukraine attack establishes the PRECEDENT that Russian state-sponsored actors WILL use destructive ICS malware against energy infrastructure. Dragonfly's later deployment of DynoWiper follows this established Russian playbook.
  • Industroyer/CrashOverride malware causes second confirmed cyber-induced power outage in Ukraine (Ukrenergo transmission substation). Most sophisticated ICS malware to date — speaks native ICS protocols (IEC 61850, IEC 104, OPC DA). Demonstrates Russian capability to directly manipulate industrial control systems. The ICS protocol targeting in Industroyer parallels DynoWiper's protocol capabilities.
  • Symantec publishes 'Dragonfly: Western Energy Sector Targeted by Sophisticated Attack Group 2.0' documenting Phase 2 operations (2015-2017). Reports direct ICS network penetration, HMI screenshot capture (demonstrating control system access), and credential theft across energy companies in US and Europe. Critical finding: Dragonfly operators captured HMI screenshots showing ABILITY TO MANIPULATE industrial processes.
  • US-CERT publishes TA18-074A attributing Dragonfly activity to Russian government actors. Documents targeting of energy and other critical infrastructure sectors including water and nuclear. Provides detailed IOCs, TTPs, and remediation guidance. Official US government attribution establishes Dragonfly as RUSSIAN STATE-SPONSORED. Source: https://www.us-cert.gov/ncas/alerts/TA18-074A
  • FBI/CISA publish AA20-296A documenting Dragonfly (Berserk Bear) targeting US state/local government and aviation networks since September 2020. Group exploits CVE-2019-19781 (Citrix), CVE-2020-0688 (Exchange), CVE-2018-13379 (Fortinet), CVE-2020-1472 (Zerologon). Exfiltrated data from government servers. Used Turkish IPs and look-alike domains. Expanded targeting beyond energy to government. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a
  • CERT-UA and ESET discover Industroyer2 targeting Ukrainian energy infrastructure during active military conflict. Attempted to cause third cyber-induced blackout. Thwarted by rapid response. Demonstrates that Russia DEPLOYS destructive ICS malware during military operations. DynoWiper deployment against Poland follows this wartime ICS attack pattern.
  • Static Tundra campaign detected: Dragonfly operations targeting Polish energy grid infrastructure identified through ICS network monitoring. DynoWiper destructive malware discovered pre-positioned on SCADA systems. Campaign targets power generation, transmission, and distribution infrastructure. Assessment: pre-positioning for potential destructive attack against NATO frontline state energy infrastructure during period of heightened geopolitical tension.
  • Ongoing: DynoWiper remains a latent threat in any compromised ICS environment. Polish energy operators working with CERT.PL and NATO allies to identify and remove Dragonfly pre-positioned access. Assessment: Dragonfly maintains persistent access to multiple European energy networks. The 15-year operational tempo and increasing destructive capability trajectory suggest continued escalation. Revalidation absorbs TL-2026-0014, TL-2026-0037, TL-2026-0053 into comprehensive threat profile.
  • As of 2026-05-29, this threat remains ACTIVE: ESET (Sandworm/GRU) and CERT Polska (Static Tundra/Berserk Bear/FSB) both confirm Russian state actors behind the Dec 2025 DynoWiper attack on ~30 Polish energy sites, and both groups keep operating with no takedown. The specific Poland intrusion was repelled (no disruption), but the destructive-vs-NATO-energy threat persists.

Sources cited for Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

Threats related to Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on

Detection coverage for TL-2026-0004

As of 2026-02-02, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0004 across Splunk SPL, Microsoft KQL and Sigma, covering 71 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats