{"id":45868,"date":"2022-03-24T23:19:50","date_gmt":"2022-03-24T23:19:50","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/russian-state-sponsored-hackers-behind-epic-trisis-attack-indicted-for-targeting-energy-firms"},"modified":"2022-03-24T23:19:50","modified_gmt":"2022-03-24T23:19:50","slug":"russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/","title":{"rendered":"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The US government today unsealed two blockbuster indictments handed down in 2021 charging four Russian nationals working for that nation&#8217;s government with allegedly perpetrating two major industrial system cyberattack campaigns that targeted the global energy sector between 2012 and 2018.<\/p>\n<p>In a <a href=\"https:\/\/www.justice.gov\/opa\/press-release\/file\/1486831\/download\" target=\"_blank\" rel=\"noopener\">now-unsealed June 2021 indictment<\/a>, the US Department of Justice charged Evgeny Viktorovich Gladkikh, a Russian Ministry of Defense research institute employee, and two co-conspirators for their role in the <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/triton-trisis-attack-was-more-widespread-than-publicly-known\" target=\"_blank\" rel=\"noopener\">infamous Triton\/Trisis malware tools used in a 2017 attack<\/a> that shut down Schneider Electric&#8217;s safety instrumentation system at a petrochemical plant in Saudi Arabia. The defendants also were charged with trying to breach a US critical infrastructure management firm.<\/p>\n<p>Triton was one of the first known industrial cyberattacks meant to inflict major physical and potentially life-threatening damage on a industrial plant: The malware was intended to sabotage and fool the Schneider safety system so it would be unable to detect unsafe conditions of its ICS equipment.<\/p>\n<p>Gladkikh, 36, a computer programmer, and his co-conspirators created and dropped the Triton malware in an oil refinery in Saudi Arabia. The malware instead triggered emergency shutdowns at the refinery. The defendants then repeatedly tried to break into the network of a US company that owns similar refineries, but failed, the indictment said.<\/p>\n<p>Gladkikh was charged with conspiracy, damage, and computer fraud crimes, which could bring a total maximum sentence of 45 years in prison.<\/p>\n<p><strong>Dragonfly<\/strong><br \/>The <a href=\"https:\/\/www.justice.gov\/opa\/press-release\/file\/1486836\/download\" target=\"_blank\" rel=\"noopener\">second unsealed indictment<\/a> is from August 2021, which charges Russian Federal Security Service officers Pavel Aleksandrovich Akulov, 36; Mikhail Mikhailovich Gavrilov, 42; and Marat Valeryevich Tyukov, 39, for a long-running cyberattack campaign against the energy sector, known as the <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/destructive-and-false-flag-cyberattacks-to-escalate\" target=\"_blank\" rel=\"noopener\">Dragonfly or Havex attacks<\/a>.<\/p>\n<p>Charges against the FSB hackers include computer fraud and abuse, wire fraud, aggravated identity theft, and inflicting damage to the property of an energy facility.<\/p>\n<p>From 2012 to 2017, Akulov, Gavrilov, Tyukov, and others allegedly waged multi-phase cyberattacks to gain a foothold in the networks of oil and gas, nuclear power, and utility and power transmission companies by first infiltrating and compromising the networks of ICS\/SCADA manufacturers and software suppliers, then injecting the Havex malware into legitimate software updates that energy sector organizations installed in their industrial networks. Overall, they installed the backdoor malware on 17,000 devices in the US and in other nations, including on ICS controllers used in energy plants.<\/p>\n<p>The defendants then kicked off Dragonfly 2.0, where they allegedly used spear-phishing, watering hole attacks, and other methods to target engineers and energy sector entities who use and work with ICS\/SCADA equipment, hitting more than 500 organizations worldwide, including targeting US Nuclear Regulatory Commission. They got as far as the enterprise network of the nuclear power plant operator Wolf Creek Nuclear Operating Corporation in Burlington, Kansas, but not to its industrial network.<\/p>\n<p>Akulov, Gavrilov, and Tyukov each face multiple charges associated with computer fraud and wire fraud; Akulov and Gavrilov also face charges related to computer damages.<\/p>\n<p>But unless the defendants in these two cases leave Russia and step onto US soil \u2014 or visit another country that has an extradition agreement with the US \u2014 chances of their arrests are slim.<\/p>\n<p>John Hultquist, vice president of intelligence analysis at Mandiant, called the indictments &#8220;a warning shot&#8221; aimed at key Russian state-sponsored hacking groups that wage damaging cyberattacks. &#8220;These actions are personal and are meant to signal to anyone working for these programs that they won&#8217;t be able to leave Russia anytime soon,&#8221; he said in a statement.<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/russian-state-sponsored-hackers-behind-epic-trisis-attack-indicted-for-targeting-energy-firms\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Four Russian government employees were charged by the DoJ for attack campaigns targeting hundreds of energy sector companies and organizations in 135 countries, including the US.Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/russian-state-sponsored-hackers-behind-epic-trisis-attack-indicted-for-targeting-energy-firms\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-45868","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-24T23:19:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Russian Nationals Indicted for Epic Triton\\\/Trisis and Dragonfly Cyberattacks on Energy Firms\",\"datePublished\":\"2022-03-24T23:19:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/\"},\"wordCount\":581,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt62afc6c29d861ce3\\\/623cf77fca8e810d8620b8b9\\\/oilrefinery.jpeg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/\",\"name\":\"Russian Nationals Indicted for Epic Triton\\\/Trisis and Dragonfly Cyberattacks on Energy Firms 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt62afc6c29d861ce3\\\/623cf77fca8e810d8620b8b9\\\/oilrefinery.jpeg\",\"datePublished\":\"2022-03-24T23:19:50+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt62afc6c29d861ce3\\\/623cf77fca8e810d8620b8b9\\\/oilrefinery.jpeg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt62afc6c29d861ce3\\\/623cf77fca8e810d8620b8b9\\\/oilrefinery.jpeg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Russian Nationals Indicted for Epic Triton\\\/Trisis and Dragonfly Cyberattacks on Energy Firms\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/","og_locale":"en_US","og_type":"article","og_title":"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-03-24T23:19:50+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms","datePublished":"2022-03-24T23:19:50+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/"},"wordCount":581,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/","url":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/","name":"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg","datePublished":"2022-03-24T23:19:50+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt62afc6c29d861ce3\/623cf77fca8e810d8620b8b9\/oilrefinery.jpeg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/russian-nationals-indicted-for-epic-triton-trisis-and-dragonfly-cyberattacks-on-energy-firms\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Russian Nationals Indicted for Epic Triton\/Trisis and Dragonfly Cyberattacks on Energy Firms"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45868","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=45868"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45868\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=45868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=45868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=45868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}