State-aligned OT espionage group
GRAPHITE
A Dragos-designated Stage 1 OT threat group conducting credential theft and espionage against energy, logistics and industrial organisations, with reported overlap to APT28.
- Primary focus
- Industrial-sector credential access, reconnaissance and persistent intelligence collection
- State alignment
- Russia
- Microsoft family
- Blizzard
- GRAPHITE activity cluster
- 2023
- Underlying campaign activity
- 2022
- Last reviewed
- 2026-07-16
Designations
Aliases and related groups
The same activity is tracked under several vendor names. Each designation is listed separately below.
Dragos
GRAPHITE
The primary industrial threat activity cluster described in this dossier.
SourcesDragosNote: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.
Key assessment
Key judgements
GRAPHITE is positioned in Stage 1 of the ICS Cyber Kill Chain: it steals credentials, inventories targets and maintains access, but Dragos has not reported disruptive ICS effects for this cluster.
SourcesDragosThe group has exploited high-value client vulnerabilities, used compromised Ubiquiti EdgeRouters and shifted towards legitimate internet services and code-hosting platforms after the 2024 botnet disruption.
SourcesDragosU.S. Department of JusticeMicrosoftGRAPHITE's industrial relevance is preparatory: credential capture and intelligence collection can enable later operations, but evidence should not be inflated into an unobserved process-manipulation capability.
SourcesDragosTargeting
Regions, sectors and technology
Regions
- Ukraine and Eastern EuropeSourcesDragos
- West Asia and the Middle EastSourcesDragos
- Organisations supporting UkraineSourcesDragosMITRE ATT&CK
Sectors
- Energy and electric infrastructureSourcesDragosMicrosoft
- Oil and natural gasSourcesDragos
- Logistics and transportationSourcesDragosMicrosoft
- Government and defenceSourcesMITRE ATT&CKU.S. Department of Justice
Technology
- Microsoft Outlook and Exchange environmentsSourcesDragosMicrosoft
- Ubiquiti EdgeRouter infrastructureSourcesDragosU.S. Department of Justice
- Legitimate API testing and code-hosting servicesSourcesDragos
Campaign chronology
Timeline
- 2022 onwardHigh confidence
GRAPHITE
Industrial credential-theft campaigns
Targeted spearphishing and exploitation collected credentials from energy, logistics and industrial organisations connected to the conflict in Ukraine.
Operational consequence: Persistent access and intelligence collection can expose industrial network knowledge and create options for follow-on operations.
SourcesDragosMicrosoft - Before January 2024High confidence
GRAPHITE / APT28 overlap
Compromised EdgeRouter infrastructure
Compromised Ubiquiti EdgeRouters were used to distribute malware and conceal command-and-control activity; a U.S.-led operation disrupted an APT28-operated botnet in January 2024.
Operational consequence: Third-party router infrastructure obscured attribution and separated actor traffic from direct command infrastructure.
SourcesDragosU.S. Department of Justice - 2024 onwardHigh confidence
GRAPHITE
Post-takedown legitimate-service staging
Following the router-botnet disruption, GRAPHITE shifted staging and delivery towards legitimate internet services, API testing platforms and GitHub.
Operational consequence: Abuse of trusted services reduces the value of domain-only blocking and demands behavioural monitoring.
SourcesDragos
Capabilities and malware
Capabilities and tooling
Exploit client and edge vulnerabilities
Use high-impact vulnerabilities, including no-click Outlook credential theft, to acquire access and authentication material.
SourcesDragosMicrosoftSteal credentials and conduct reconnaissance
Collect identity material and information about industrial targets without publicly observed process disruption.
SourcesDragosOperate through compromised routers and legitimate services
Relay traffic through SOHO routers and stage payloads through trusted web services.
SourcesDragosU.S. Department of JusticeTactics, techniques and procedures
Mapped ATT&CK techniques
Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.
Enterprise ATT&CK
Enterprise access and manipulation
-
T1566.001Phishing: Spearphishing AttachmentTargeted attachments and lures supported access to organisations linked to Ukraine.
High confidenceSourcesDragosMITRE ATT&CK -
T1187Forced AuthenticationCVE-2023-23397 caused Outlook clients to send Net-NTLMv2 material to actor-controlled infrastructure without user interaction.
-
T1203Exploitation for Client ExecutionClient-side vulnerabilities were used to gain code execution or credential access.
High confidenceSourcesDragos -
T1584.008Compromise Infrastructure: Network DevicesCompromised Ubiquiti EdgeRouters provided relay and concealment infrastructure.
High confidenceSourcesU.S. Department of JusticeDragos
ICS ATT&CK
ICS effects and access
-
T0865Spearphishing AttachmentIndustrial-sector spearphishing is mapped as a Stage 1 access path; no ICS process effect is asserted.
High confidenceSourcesDragos -
T0822External Remote ServicesCaptured credentials and external access services create a route towards industrial environments.
-
T0883Internet Accessible DeviceThe public record emphasises internet-facing edge infrastructure and industrial organisations rather than direct controller manipulation.
Medium confidenceSourcesDragosU.S. Department of Justice
Indicator handling
Historical indicators
No point-in-time indicators are published in this dossier. Router, hosting and legitimate-service infrastructure is shared and dynamic; hunt the access chain and credential behaviour instead of blocking broad provider ranges.
This profile intentionally prioritises sourced behaviour, access paths and operational context.
Source register
Sources
Publication and update dates preserve the point-in-time context used for this review.
- Dragosthreat group profile
GRAPHITE threat group profile
Published 4 September 2025
- MITRE ATT&CKknowledge base
APT28, Group G0007
Published 31 May 2017 ยท Updated 14 April 2025
- Microsofttechnical research
Guidance for investigating attacks using CVE-2023-23397
Published 24 March 2023
- U.S. Department of Justicegovernment disruption notice
Justice Department Disrupts Botnet Controlled by the Russian GRU
Published 15 February 2024