Skip to actor profile
activeTLP:CLEARHigh confidence

State-aligned OT access group

KAMACITE

A Dragos-designated access-development group that penetrates industrial organisations, steals and replays credentials, and enables follow-on ICS operations by teams such as ELECTRUM.

Primary focus
Initial access, credential capture and handoff into industrial environments
State alignment
Russia
Microsoft family
Blizzard
KAMACITE activity cluster
2014
Current expansion
2025
Last reviewed
2026-07-16

Designations

Aliases and related groups

The same activity is tracked under several vendor names. Each designation is listed separately below.

PrimaryHigh confidence

Dragos

KAMACITE

The access-development and Stage 1/early Stage 2 activity cluster profiled here.

SourcesDragosDragos

Note: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.

Key assessment

Key judgements

High confidence

KAMACITE specialises in gaining and maintaining access, capturing credentials and positioning follow-on teams. Dragos distinguishes this role from the teams that execute the final ICS-specific disruptive action.

SourcesDragosDragos
High confidence

The group's enduring tradecraft combines malicious attachments, credential replay, compromised third-party infrastructure, custom implants, criminal malware and native administrative tools.

SourcesDragosDragos
High confidence

In 2025, KAMACITE moved beyond generic perimeter reconnaissance to sequential scanning of HMIs, drives, meters and cellular gateways, behaviour Dragos assesses as mapping control loops across U.S. infrastructure.

SourcesDragosDragos

Targeting

Regions, sectors and technology

Technology

  • Enterprise email and remote-access servicesSourcesDragos
  • SOHO routers and compromised third-party serversSourcesDragosDragos
  • HMIs, variable frequency drives, meters and cellular gatewaysSourcesDragos

Campaign chronology

Timeline

  1. 2014 - 2016High confidence

    KAMACITE enabling activity

    Ukraine power access development

    Phishing, BLACKENERGY-family malware, credential theft and network penetration established access that supported the 2015 and 2016 Ukraine electric-power operations.

    Operational consequence: KAMACITE facilitated conditions for physical disruption while Dragos attributes at least the 2016 ICS execution to ELECTRUM.

    SourcesDragosDragos
  2. 2019 - 2020High confidence

    KAMACITE

    U.S. energy intrusion activity

    Persistent intrusion attempts against U.S. energy companies used compromised infrastructure, credential capture and replay.

    Operational consequence: Access into industrial organisations created options for later operational handoff even where no public disruptive event followed.

    SourcesDragos
  3. 2024High confidence

    KAMACITE

    European oil and gas conference lures

    Spearphishing themed around the Gas Infrastructure Europe conference delivered commodity and custom malware against European oil and natural gas organisations.

    Operational consequence: Credential theft and endpoint access increased supply-chain and IT-to-OT pivot risk.

    SourcesDragos
  4. 2025High confidence

    KAMACITE

    U.S. control-loop mapping

    Dragos observed four months of sequential scanning across exposed HMIs, variable frequency drives, meters and cellular gateways in U.S. infrastructure.

    Operational consequence: The sequence could reveal process relationships and operational dependencies useful for later disruption.

    SourcesDragosDragos

Capabilities and malware

Capabilities and tooling

High confidenceKAMACITE

Phish and replay captured credentials

Use malicious attachments and legitimate external services to gain access, then reuse captured credentials for remote entry and movement.

SourcesDragosDragos
High confidenceKAMACITE

Develop and modify malware

Deploy custom implants and adapt criminal malware while blending them with native tools and administration frameworks.

SourcesDragosDragos
High confidenceKAMACITE-to-ELECTRUM handoff

Enable follow-on ICS operators

Maintain access and transfer operational control to teams such as ELECTRUM for ICS-specific effects.

SourcesDragosDragos
High confidenceKAMACITE

Map exposed control-loop components

Scan industrial device classes in deliberate sequence to understand process relationships.

SourcesDragos

KAMACITE

High confidence

BLACKENERGY2 / BLACKENERGY3 / GREYENERGY

Historical malware families associated with access, credential collection and network penetration supporting Ukraine power operations.

SourcesDragos

KAMACITE

High confidence

Kapeka

A backdoor used in 2024 activity against European oil and natural gas organisations.

SourcesDragos

KAMACITE

High confidence

LummaStealer and custom Windows implants

Rented commodity infrastructure and custom payloads used in conference-themed access campaigns.

SourcesDragos

Tactics, techniques and procedures

Mapped ATT&CK techniques

Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.

Enterprise ATT&CK

Enterprise access and manipulation

Download Navigator layer

ICS ATT&CK

ICS effects and access

Download Navigator layer
  • T0865Spearphishing Attachment
    Initial AccessKAMACITE

    Targeted attachments established enterprise footholds that could be developed towards ICS networks.

    High confidenceSourcesDragos
  • T0859Valid Accounts
    Persistence / Lateral MovementKAMACITE

    Credential replay enabled remote entry and maintained access around industrial environments.

    High confidenceSourcesDragos
  • T0886Remote Services
    Lateral MovementKAMACITE

    Legitimate remote access and administration paths supported movement towards control networks.

    Medium confidenceSourcesDragos
  • T0867Lateral Tool Transfer
    Lateral MovementKAMACITE

    Custom malware, criminal tools and native utilities were transferred during access development.

    Medium confidenceSourcesDragos
  • T0883Internet Accessible Device
    Initial AccessKAMACITE

    Sequential scanning targeted exposed HMIs, drives, meters and cellular gateways during 2025.

    High confidenceSourcesDragos

Indicator handling

Historical indicators

Historical, not current infrastructure.

No historical infrastructure is reproduced here. KAMACITE routinely uses compromised third-party servers, Tor relays and criminal hosting, so isolated IP matches have low durability without authentication and execution context.

No point-in-time indicators published.

This profile intentionally prioritises sourced behaviour, access paths and operational context.

Source register

Sources

Publication and update dates preserve the point-in-time context used for this review.

  1. Dragosthreat group profile

    KAMACITE threat group profile

    Published 4 September 2025

  2. Dragosthreat research

    New ICS Threat Activity Group: KAMACITE

    Published 25 February 2021

  3. Dragosannual threat report

    2025 OT Cybersecurity Report: A Year in Review

    Published 25 February 2025

  4. Dragosannual threat report

    Dragos 2026 OT Cybersecurity Year in Review

    Published 9 March 2026

  5. Dragossector threat research

    Electric Grid Cybersecurity: 2026 OT Threat Insights

    Published 14 April 2026

  6. Dragosincident retrospective

    10 Years Since the First Ukraine Power Grid Attack

    Published 22 December 2025

  7. MITRE ATT&CKknowledge base

    Sandworm Team, Group G0034

    Published 31 May 2017 ยท Updated 4 December 2024