Skip to actor profile
activeTLP:CLEARHigh confidence

State-aligned OT espionage group

GRAPHITE

A Dragos-designated Stage 1 OT threat group conducting credential theft and espionage against energy, logistics and industrial organisations, with reported overlap to APT28.

Primary focus
Industrial-sector credential access, reconnaissance and persistent intelligence collection
State alignment
Russia
Microsoft family
Blizzard
GRAPHITE activity cluster
2023
Underlying campaign activity
2022
Last reviewed
2026-07-16

Designations

Aliases and related groups

The same activity is tracked under several vendor names. Each designation is listed separately below.

PrimaryHigh confidence

Dragos

GRAPHITE

The primary industrial threat activity cluster described in this dossier.

SourcesDragos

Note: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.

Key assessment

Key judgements

High confidence

GRAPHITE is positioned in Stage 1 of the ICS Cyber Kill Chain: it steals credentials, inventories targets and maintains access, but Dragos has not reported disruptive ICS effects for this cluster.

SourcesDragos
High confidence

The group has exploited high-value client vulnerabilities, used compromised Ubiquiti EdgeRouters and shifted towards legitimate internet services and code-hosting platforms after the 2024 botnet disruption.

SourcesDragosU.S. Department of JusticeMicrosoft
High confidence

GRAPHITE's industrial relevance is preparatory: credential capture and intelligence collection can enable later operations, but evidence should not be inflated into an unobserved process-manipulation capability.

SourcesDragos

Targeting

Regions, sectors and technology

Campaign chronology

Timeline

  1. 2022 onwardHigh confidence

    GRAPHITE

    Industrial credential-theft campaigns

    Targeted spearphishing and exploitation collected credentials from energy, logistics and industrial organisations connected to the conflict in Ukraine.

    Operational consequence: Persistent access and intelligence collection can expose industrial network knowledge and create options for follow-on operations.

    SourcesDragosMicrosoft
  2. Before January 2024High confidence

    GRAPHITE / APT28 overlap

    Compromised EdgeRouter infrastructure

    Compromised Ubiquiti EdgeRouters were used to distribute malware and conceal command-and-control activity; a U.S.-led operation disrupted an APT28-operated botnet in January 2024.

    Operational consequence: Third-party router infrastructure obscured attribution and separated actor traffic from direct command infrastructure.

    SourcesDragosU.S. Department of Justice
  3. 2024 onwardHigh confidence

    GRAPHITE

    Post-takedown legitimate-service staging

    Following the router-botnet disruption, GRAPHITE shifted staging and delivery towards legitimate internet services, API testing platforms and GitHub.

    Operational consequence: Abuse of trusted services reduces the value of domain-only blocking and demands behavioural monitoring.

    SourcesDragos

Capabilities and malware

Capabilities and tooling

High confidenceGRAPHITE / APT28 overlap

Exploit client and edge vulnerabilities

Use high-impact vulnerabilities, including no-click Outlook credential theft, to acquire access and authentication material.

SourcesDragosMicrosoft
High confidenceGRAPHITE

Steal credentials and conduct reconnaissance

Collect identity material and information about industrial targets without publicly observed process disruption.

SourcesDragos
High confidenceGRAPHITE / APT28 overlap

Operate through compromised routers and legitimate services

Relay traffic through SOHO routers and stage payloads through trusted web services.

SourcesDragosU.S. Department of Justice

GRAPHITE

High confidence

OCEANMAP

One of several custom capabilities Dragos associates with GRAPHITE operations.

SourcesDragos

GRAPHITE

High confidence

HEADLACE / MASEPIE / STEELHOOK

Custom payload families named by Dragos in the public GRAPHITE capability set.

SourcesDragos

Tactics, techniques and procedures

Mapped ATT&CK techniques

Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.

Enterprise ATT&CK

Enterprise access and manipulation

Download Navigator layer

ICS ATT&CK

ICS effects and access

Download Navigator layer

Indicator handling

Historical indicators

Historical, not current infrastructure.

No point-in-time indicators are published in this dossier. Router, hosting and legitimate-service infrastructure is shared and dynamic; hunt the access chain and credential behaviour instead of blocking broad provider ranges.

No point-in-time indicators published.

This profile intentionally prioritises sourced behaviour, access paths and operational context.

Source register

Sources

Publication and update dates preserve the point-in-time context used for this review.

  1. Dragosthreat group profile

    GRAPHITE threat group profile

    Published 4 September 2025

  2. MITRE ATT&CKknowledge base

    APT28, Group G0007

    Published 31 May 2017 ยท Updated 14 April 2025

  3. Microsofttechnical research

    Guidance for investigating attacks using CVE-2023-23397

    Published 24 March 2023

  4. U.S. Department of Justicegovernment disruption notice

    Justice Department Disrupts Botnet Controlled by the Russian GRU

    Published 15 February 2024