Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
Dragonfly
Also tracked as BROMINE · Berserk Bear · Crouching Yeti · DYMALLOY · Energetic Bear · Ghost Blizzard · IRON LIBERTY · TEMP.Isotope · TG-4192
[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB Factsheet April 2022) Active since at least 2010, [Dragonfly](https://attack.mitre.org/groups/G0035) has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.(Citation: Symantec Dragonfly)(Citation: Secureworks IRON LIBERTY July 2019)(Citation: Symantec Dragonfly Sept 2017)(Citation: Fortune Dragonfly 2.0 Sept 2017)(Citation: Gigamon Berserk Bear October 2021)(Citation: CISA AA20-296A Berserk Bear December 2020)(Citation: Symantec Dragonfly 2.0 October 2017)
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0035- ATT&CK record
- G0035
- Record version
- 4.0
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 03
- Mapped events
- 12
- Evidence gates
- 15
- Defensive analytics
- 05
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps Dragonfly to T1591.002 Gather Victim Org Information: Business Relationships. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/1
Failed gates
0/1
Pending
1/1
Coverage gaps
0/1
- 1
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
Technique context retained
T1591.002 is highlighted below. Public group behavior remains separate from synthetic replay evidence.
PATH 01
T1070.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Dragonfly to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E14 to E28
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E1413:00Build interpositionFile integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
BLD-WIN-03
- E1615:00Build interpositionFile integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
BLD-WIN-03
- E2824:30InvestigationFile integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
BLD-WIN-03
PATH 02
T1195.002
Compromise Software Supply Chain
Initial Access · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Dragonfly to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E08 to E29
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0807:00Build accessCI orchestrator
The adversary waits for a legitimate build
Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.
- E1110:00Build interpositionEndpoint telemetry
The helper observes the compiler invocation
The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.
BLD-WIN-03
- E11A10:30Build interpositionCI orchestrator
Selectivity check — correct product and expected source version
Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.
BLD-WIN-03
- E1514:00Build interpositionCI orchestrator
Produced binary hash differs from the reproducible reference
Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.
BLD-WIN-03
- E1716:00Trusted releaseCI orchestrator
Trusted release — the ordinary workflow accepts the artifact
Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.
- E2019:00Trusted releaseRelease system
Provenance record lacks the compile-input attestation
The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.
- E2422:30Downstream signalEndpoint telemetry
Marker string observed in the released artifact inventory
Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.
- E2925:00InvestigationRelease system
Provenance gap documented as the failed boundary
Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.
PATH 03
T1591.002
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Dragonfly to T1591.002 Gather Victim Org Information: Business Relationships. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E03 to E03
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0302:00ReconnaissanceEgress proxy
Release cadence is public
Published release notes disclose a predictable weekly gateway-agent release and the name of the build toolchain. Public information alone narrows where trust is concentrated.