Skip to content

RAT

Havex RAT

Havex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control systems (ICS) used across numerous industries and attributed t

Havex RAT is a Windows rat operated by Energetic Bear.

Background

Havex is a remote access trojan (RAT) uncovered in 2013 during a broad espionage operation aimed at industrial control systems (ICS) spanning many sectors, attributed to a group tracked as "Dragonfly" and "Energetic Bear". The campaign is believed to have reached thousands of infrastructure sites, mostly in Europe and the United States. In the energy space, Havex zeroed in on grid operators, large electricity generators, petroleum pipeline operators, and industrial equipment suppliers, and it also struck aviation, defense, pharmaceutical, and petrochemical organizations.

After installation, Havex surveyed the compromised host for any Supervisory Control and Data Acquisition (SCADA) or ICS devices on the network and relayed the findings to its command and control servers. It accomplished this through the Open Platform Communications (OPC) standard, a widely used ICS communication protocol that enables open connectivity and cross-vendor interoperability. Using the Distributed Component Object Model (DCOM), Havex reached OPC servers within an ICS network to gather details such as CLSID, server name, Program ID, OPC version, vendor information, running state, group count, and server bandwidth.

Havex served as an intelligence-gathering tool for espionage rather than for disrupting or destroying industrial systems. Even so, the information it collected could have supported the planning and development of attacks against particular targets or industries.


Source: Malpedia (Fraunhofer FKIE).