Research any topic before you write.

Find related topics. | Discover entities. | See connections. | Build a topical map.

Havex: Description, Discovery & Exploit Kits

Havex malware, also known as Backdoor.Oldrea, is a Remote Access Trojan (RAT) employed by the Russian attributed APT group "Energetic Bear" or "Dragonfly". Havex was discovered in 2013 and is one of five known ICS tailored malware developed in the past decade. These malwares include Stuxnet, BlackEnergy, Industroyer/CRASHOVERRIDE, and TRITON/TRISIS.…

Language: English [EN]
Use the mouse wheel or two fingers (on touchscreens) to zoom in and out of the map.
100%
More settings
100% 100% 100% 100% 100%

Havex topic overview

The analysis highlights Description, Discovery and Exploit Kits as prominent areas in the source structure around Havex.

Related topics
17
Source areas
4
Connected nodes
21
Extracted relationships
70
Concept neighborhoods
9
Bridge connections
21

What this topic covers Research coverage

Source areas are shown by the number of related topics found in each part of the analysis. Use smaller areas too: they can reveal specialized angles and content gaps.

Overview · 8 topics
Description · 4 topics
Discovery · 3 topics
Exploit Kits · 2 topics

Smaller areas are not necessarily less important. They contain fewer connections in this analysis and can be useful for finding specialized angles or coverage gaps.

Key facts & relationships

High-confidence facts extracted from structured source data. Use them as anchors for further research.

Author
Energetic Bear
Alias
Oldrea
Platforms
Windows, Linux, iOS, Android
Ports used
44818, 105 and 502
Technical name
BKDR_HAVEX.[letter] (Trend Micro) · Backdoor:Win32/Havex.[letter] Microsoft · Backdoor:W32/Havex (F-Secure)
Type
RAT

Explore all related topics Closing gaps

Browse the complete topic structure, not only the most central items. Less prominent entities and concepts can reveal missing angles, specialized context and useful research gaps. Each item opens a new analysis centered on that subject.

Overview

Discovery

Description

Exploit Kits

Advanced semantic analysis

Deeper signals for content research, entity SEO and topical coverage. The plain-language headings explain what each technical view is useful for.

How Havex connects Entity context

The extracted context around Havex shows recurring relationship patterns in the source. For example, Havex → By, DCOM-based, Distributed Component Object Model, Dragonfly, Havex RAT, ICS, ICS/SCADA, In, Karagany, Known, MB Connect Line, MESA Imaging, OPC, OPC Unified Architecture, Open Platform Communications, PHP, RAT, Researchers, Rockwell Automation, SANS Another extracted example is Havex → Corrupted, Hello, Java, Karagany, LightsOut, Once, OS, The, The Hello, The LightsOut, URL. Use these groups to spot repeated connection types before inspecting the individual relationships.

Havex

Top relations

related to Description · 31
Havex → By, DCOM-based, Distributed Component Object Model, Dragonfly, Havex RAT, ICS, ICS/SCADA, In, Karagany, Known, MB Connect Line, MESA Imaging, OPC, OPC Unified Architecture, Open Platform Communications, PHP, RAT, Researchers, Rockwell Automation, SANS
related to Website Redirect Injection · 11
Havex → Corrupted, Hello, Java, Karagany, LightsOut, Once, OS, The, The Hello, The LightsOut, URL
related to Affected Regions & Victims · 10
Havex → Canadian, Cybersecurity, Dragos, Europe, Researchers, Symantec, The Dragonfly, Through, United States, US
related to Discovery · 7
Havex → F-Secure, ICS, ICS-CERT, OPC, Symantec, The Havex, The ICS-CERT Alert
Technical name · 3
Havex → Backdoor:W32/Havex (F-Secure), Backdoor:Win32/Havex.[letter] Microsoft, BKDR_HAVEX.[letter] (Trend Micro)
Alias · 1
Havex → Oldrea
Author · 1
Havex → Energetic Bear
Platforms · 1
Havex → Windows, Linux, iOS, Android
Ports used · 1
Havex → 44818, 105 and 502
Type · 1
Havex → RAT

Important terminology

Use these terms to understand the vocabulary surrounding the topic, not as a checklist for keyword stuffing.

Important terminology

malware campaign ics exploit opc researchers websites rat victims energetic bear systems also known used backdoor information industrial devices victim

Havex relationships Subject–Predicate–Object triples

TTTA extracted 70 structured relationships around Havex. Examples in this analysis include Havex → Alias → Oldrea and Havex → Author → Energetic Bear. The table shows each extracted connection, where it came from and its confidence.

SubjectPredicateObjectConfidenceSrc
HavexAliasOldrea1.00infobox
HavexAuthorEnergetic Bear1.00infobox
HavexPlatformsWindows, Linux, iOS, Android1.00infobox
HavexPorts used44818, 105 and 5021.00infobox
HavexTechnical nameBKDR_HAVEX.[letter] (Trend Micro)1.00infobox
HavexTechnical nameBackdoor:Win32/Havex.[letter] Microsoft1.00infobox
HavexTechnical nameBackdoor:W32/Havex (F-Secure)1.00infobox
HavexTypeRAT1.00infobox
HavexWritten inPHP1.00infobox
Siemensinstance ofResearchers at SANS noted these ports are common to ICS/SCADA companies0.80text
Rockwell Automationinstance ofResearchers at SANS noted these ports are common to ICS/SCADA companies0.80text
Havexrelated to Affected Regions & VictimsThe Dragonfly0.60section

Related concept clusters Concept neighborhoods

The concept neighborhoods around Havex bring nearby vocabulary together. In this analysis, examples include Malware, Systems and Websites. Use the clusters to find adjacent concepts and terminology that may deserve separate research.

  • Havex
    • Malware
    • Systems
    • Websites
    • Also
    • Rat
    • Used
    • Ics
    • Campaign
    • Aviation
    • Backdoor
    • Bear
    • Defense
  • havex
    • Malware
    • Systems
    • Websites
    • Also
    • Rat
    • Used
    • Ics
    • Campaign
    • Aviation
    • Backdoor
    • Bear
    • Defense
  • energetic bear
    • Bear
    • Energetic
    • Oldrea
    • Rat
    • F-secure
    • Aviation
    • Defense
    • Dragonfly
    • Energy
    • Known
    • Ports
    • Sectors
  • remote access trojan
    • Also
    • Victim
    • Oldrea
    • Backdoor
    • Bear
    • Dragonfly
    • Energetic
    • Known
    • Target
    • Information
    • Kit
    • Rat
  • exploit kits
    • Kit
    • Information
    • Target
    • Karagany
    • Used
    • F-secure
    • Oldrea
    • Havex
    • Ports
    • Written
    • Rat
    • Victim
  • ics
    • Malware
    • Industrial
    • Systems
    • Known
    • Network
    • Ports
    • Target
    • Targeting
    • Written
    • Information
    • Vendor
    • Victim
  • ics/scada
    • Malware
    • Industrial
    • Systems
    • Known
    • Network
    • Ports
    • Target
    • Targeting
    • Written
    • Information
    • Vendor
    • Victim
  • opc
    • Module
    • Scanning
    • Network
    • Devices
    • Ports
    • Target
    • Targeting
    • Used
    • Victim
    • Systems
    • Researchers

Connections between topic areas Semantic bridges

For Havex, one of the stronger structural bridges in this analysis connects Havex with Overview. Bridges highlight paths between different parts of the map and can reveal research angles that are easy to miss in a flat list.

Min side: 3
HavexOverview · splits 13 ⟂ 9
HavexDescription · splits 17 ⟂ 5
HavexDiscovery · splits 18 ⟂ 4
HavexExploit Kits · splits 19 ⟂ 3

Map overview Semantic statistics

Havex

Nodes22
Edges21
Triples70
Avg. degree1.91
Density0.090909
Components1

Source & methodology

TTTA analyzes the structure around Havex to surface related topics, entities, relationships, concept neighborhoods and bridge connections. Use the map to explore areas such as Description, Discovery & Exploit Kits, including less central topics that may reveal useful research gaps. Automatically extracted connections are research leads rather than rewritten encyclopedia content.

Source: Wikipedia — Havex · EN edition · Analysis: TopicsToTalkAbout

For writers, content strategists, SEOs, marketers and creators — from quick topic research to advanced semantic analysis.