State-aligned OT access group
KAMACITE
A Dragos-designated access-development group that penetrates industrial organisations, steals and replays credentials, and enables follow-on ICS operations by teams such as ELECTRUM.
- Primary focus
- Initial access, credential capture and handoff into industrial environments
- State alignment
- Russia
- Microsoft family
- Blizzard
- KAMACITE activity cluster
- 2014
- Current expansion
- 2025
- Last reviewed
- 2026-07-16
Designations
Aliases and related groups
The same activity is tracked under several vendor names. Each designation is listed separately below.
Dragos
KAMACITE
The access-development and Stage 1/early Stage 2 activity cluster profiled here.
SourcesDragosDragosNote: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.
Key assessment
Key judgements
KAMACITE specialises in gaining and maintaining access, capturing credentials and positioning follow-on teams. Dragos distinguishes this role from the teams that execute the final ICS-specific disruptive action.
SourcesDragosDragosThe group's enduring tradecraft combines malicious attachments, credential replay, compromised third-party infrastructure, custom implants, criminal malware and native administrative tools.
SourcesDragosDragosIn 2025, KAMACITE moved beyond generic perimeter reconnaissance to sequential scanning of HMIs, drives, meters and cellular gateways, behaviour Dragos assesses as mapping control loops across U.S. infrastructure.
SourcesDragosDragosTargeting
Regions, sectors and technology
Regions
Sectors
Technology
Campaign chronology
Timeline
- 2014 - 2016High confidence
KAMACITE enabling activity
Ukraine power access development
Phishing, BLACKENERGY-family malware, credential theft and network penetration established access that supported the 2015 and 2016 Ukraine electric-power operations.
Operational consequence: KAMACITE facilitated conditions for physical disruption while Dragos attributes at least the 2016 ICS execution to ELECTRUM.
SourcesDragosDragos - 2019 - 2020High confidence
KAMACITE
U.S. energy intrusion activity
Persistent intrusion attempts against U.S. energy companies used compromised infrastructure, credential capture and replay.
Operational consequence: Access into industrial organisations created options for later operational handoff even where no public disruptive event followed.
SourcesDragos - 2024High confidence
KAMACITE
European oil and gas conference lures
Spearphishing themed around the Gas Infrastructure Europe conference delivered commodity and custom malware against European oil and natural gas organisations.
Operational consequence: Credential theft and endpoint access increased supply-chain and IT-to-OT pivot risk.
SourcesDragos - 2025High confidence
KAMACITE
U.S. control-loop mapping
Dragos observed four months of sequential scanning across exposed HMIs, variable frequency drives, meters and cellular gateways in U.S. infrastructure.
Operational consequence: The sequence could reveal process relationships and operational dependencies useful for later disruption.
SourcesDragosDragos
Capabilities and malware
Capabilities and tooling
Phish and replay captured credentials
Use malicious attachments and legitimate external services to gain access, then reuse captured credentials for remote entry and movement.
SourcesDragosDragosDevelop and modify malware
Deploy custom implants and adapt criminal malware while blending them with native tools and administration frameworks.
SourcesDragosDragosEnable follow-on ICS operators
Maintain access and transfer operational control to teams such as ELECTRUM for ICS-specific effects.
SourcesDragosDragosMap exposed control-loop components
Scan industrial device classes in deliberate sequence to understand process relationships.
SourcesDragosKAMACITE
High confidenceBLACKENERGY2 / BLACKENERGY3 / GREYENERGY
Historical malware families associated with access, credential collection and network penetration supporting Ukraine power operations.
SourcesDragosKAMACITE
High confidenceKapeka
A backdoor used in 2024 activity against European oil and natural gas organisations.
SourcesDragosKAMACITE
High confidenceLummaStealer and custom Windows implants
Rented commodity infrastructure and custom payloads used in conference-themed access campaigns.
SourcesDragosTactics, techniques and procedures
Mapped ATT&CK techniques
Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.
Enterprise ATT&CK
Enterprise access and manipulation
-
T1566.001Phishing: Spearphishing AttachmentMalicious attachments and conference-themed lures delivered custom and commodity malware.
-
T1078Valid AccountsCaptured credentials were replayed through legitimate external services and remote access paths.
High confidenceSourcesDragos -
T1003OS Credential DumpingDragos assesses with moderate confidence that KAMACITE uses tools such as Mimikatz to capture credentials.
Medium confidenceSourcesDragos -
T1021.002Remote Services: SMB/Windows Admin SharesAdministrative frameworks such as PsExec supported remote execution and movement.
Medium confidenceSourcesDragos
ICS ATT&CK
ICS effects and access
-
T0865Spearphishing AttachmentTargeted attachments established enterprise footholds that could be developed towards ICS networks.
High confidenceSourcesDragos -
T0859Valid AccountsCredential replay enabled remote entry and maintained access around industrial environments.
High confidenceSourcesDragos -
T0886Remote ServicesLegitimate remote access and administration paths supported movement towards control networks.
Medium confidenceSourcesDragos -
T0867Lateral Tool TransferCustom malware, criminal tools and native utilities were transferred during access development.
Medium confidenceSourcesDragos -
T0883Internet Accessible DeviceSequential scanning targeted exposed HMIs, drives, meters and cellular gateways during 2025.
High confidenceSourcesDragos
Indicator handling
Historical indicators
No historical infrastructure is reproduced here. KAMACITE routinely uses compromised third-party servers, Tor relays and criminal hosting, so isolated IP matches have low durability without authentication and execution context.
This profile intentionally prioritises sourced behaviour, access paths and operational context.
Source register
Sources
Publication and update dates preserve the point-in-time context used for this review.
- Dragosthreat group profile
KAMACITE threat group profile
Published 4 September 2025
- Dragosthreat research
New ICS Threat Activity Group: KAMACITE
Published 25 February 2021
- Dragosannual threat report
2025 OT Cybersecurity Report: A Year in Review
Published 25 February 2025
- Dragosannual threat report
Dragos 2026 OT Cybersecurity Year in Review
Published 9 March 2026
- Dragossector threat research
Electric Grid Cybersecurity: 2026 OT Threat Insights
Published 14 April 2026
- Dragosincident retrospective
10 Years Since the First Ukraine Power Grid Attack
Published 22 December 2025
- MITRE ATT&CKknowledge base
Sandworm Team, Group G0034
Published 31 May 2017 ยท Updated 4 December 2024