APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
TEMP.Isotope (aka BERSERK BEAR, Dragonfly 2.0) · APT Atlas
Actors
/
Nation-state / APT
/
Europe
TEMP.Isotope
G0035
APT
RU · Russia
AKA
BERSERK BEAR · Dragonfly 2.0 · Dragonfly · Havex
CrowdStrike
:
ENERGETIC BEAR
Kaspersky
:
Crouching Yeti
Microsoft
:
Ghost Blizzard
MITRE
:
G0035
Secureworks
:
IRON LIBERTY
Targets
25
Sectors
18
Threat types
2
GIRs covered
0/480
Active since
2017
Pin to atlas
Watch
Share
Export
Also tracked as
6 vendor names · 4 other aliases
Open Rosetta Stone
CrowdStrike
ENERGETIC BEAR
Kaspersky
Crouching Yeti
Mandiant
TEMP.Isotope
Microsoft
Ghost Blizzard
MITRE
G0035
Secureworks
IRON LIBERTY
UNATTRIBUTED ALIASES
BERSERK BEAR
Dragonfly 2.0
Dragonfly
Havex
Victimology
Geographic footprint · 25 countries
Region filter
Export
origin · Russia
targeted countries · 25
ASIA ·
14
United Arab Emirates
·
Afghanistan
·
Armenia
·
Bahrain
·
Indonesia
·
Israel
·
Iraq
·
Iran
·
Jordan
·
Malaysia
·
Oman
·
Türkiye
·
Uzbekistan
·
Yemen
EUROPE ·
6
Belgium
·
Germany
·
Finland
·
France
·
Netherlands
·
Ukraine
AMERICAS ·
3
Colombia
·
Ecuador
·
Paraguay
AFRICA ·
1
Algeria
OCEANIA ·
1
New Zealand
Sectors targeted
18 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Aviation
22 actors
Financial Services
74 actors
Technology
60 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Media & Journalism
49 actors
Transportation
31 actors
Hospitality
33 actors
Legal & Professional
18 actors
Industrials / Engineering
29 actors
Dissidents (as targets)
16 actors
Maritime
24 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
DIS · Disinformation
ESP · Espionage
MITRE ATT&CK · 38 techniques
Resource Development
· 1
T1583.003
Virtual Private Server
Initial Access
· 4
T1189
Drive-by Compromise
T1190
Exploit Public-Facing Application
T1195.002
Compromise Software Supply Chain
T1566.001
Spearphishing Attachment
Execution
· 6
T1053.005
Scheduled Task
Persistence
· 1
Credential Access
· 5
T1003.002
Security Account Manager
T1003.003
NTDS
Discovery
· 6
T1012
Query Registry
T1016
System Network Configuration Discovery
Lateral Movement
· 2
T1021.001
Remote Desktop Protocol
Collection
· 4
T1005
Data from Local System
T1113
Screen Capture
T1114.002
Remote Email Collection
T1560
Archive Collected Data
Command And Control
· 2
T1071.002
File Transfer Protocols
Defense Impairment
· 2
T1112
Modify Registry
Stealth
· 5
T1036.010
Masquerade Account Name
T1070.004
File Deletion
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
38 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.006
Python
T1203
Exploitation for Client Execution
T1547.001
Registry Run Keys / Startup Folder
T1003.004
LSA Secrets
T1110
Brute Force
T1187
Forced Authentication
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1083
File and Directory Discovery
T1135
Network Share Discovery
T1210
Exploitation of Remote Services
T1105
Ingress Tool Transfer
T1686
Disable or Modify System Firewall
T1078
Valid Accounts
T1221
Template Injection
T1564.002
Hidden Users