ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Havex RAT

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Havex RAT

NamesHavex RAT
Oldrea
Fertger
PEACEPIPE
CategoryMalware
TypeICS malware, Reconnaissance, Backdoor
DescriptionHavex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control systems (ICS) used across numerous industries and attributed to a hacking group referred to as 'Dragonfly' and 'Energetic Bear'. Havex is estimated to have impacted thousands of infrastructure sites, a majority of which were located in Europe and the United States. Within the energy sector, Havex specifically targeted energy grid operators, major electricity generation firms, petroleum pipeline operators, and industrial equipment providers. Havex also impacted organizations in the aviation, defense, pharmaceutical, and petrochemical industries.

Once installed, Havex scanned the infected system to locate any Supervisory Control and Data Acquisition (SCADA) or ICS devices on the network and sent the data back to command and control servers. To do so, the malware leveraged the Open Platform Communications (OPC) standard, which is a universal communication protocol used by ICS components across many industries that facilitates open connectivity and vendor equipment interoperability. Havex used the Distributed Component Object Model (DCOM) to connect to OPC servers inside of an ICS network and collect information such as CLSID, server name, Program ID, OPC version, vendor information, running state, group count, and server bandwidth.

Havex was an intelligence-collection tool used for espionage and not for the disruption or destruction of industrial systems. However, the data collected by Havex would have aided efforts to design and develop attacks against specific targets or industries.
Information<https://www.fireeye.com/blog/threat-research/2014/07/havex-its-down-with-opc.html>
<https://www.f-secure.com/weblog/archives/00002718.html>
<https://en.wikipedia.org/wiki/Havex>
MITRE ATT&CK<https://attack.mitre.org/software/S0093/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat>

Last change to this tool card: 13 June 2020

Download this tool card in JSON format

All groups using tool Havex RAT

ChangedNameCountryObserved

APT groups

 Energetic Bear, DragonflyRussia2010-Oct 2020X
 Sphinx[Unknown]2014 

2 groups listed (2 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key