ATT&CKCampaigns2016 Ukraine Electric Power Attack

2016 Ukraine Electric Power Attack

C0025

Campaign, Dec 2016 to Dec 2016.View on attack.mitre.org

About this campaign

2016 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid. This campaign was the second major public attack conducted against Ukraine by Sandworm Team.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1003.001
LSASS Memory

During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials.

T1018
Remote System Discovery

During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD.

T1021.002
SMB/Windows Admin Shares

During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares.

T1027
Obfuscated Files or Information

During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor.

T1027.002
Software Packing

During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz.

T1036.005
Match Legitimate Resource Name or Location

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1036.008
Masquerade File Type

During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files.

T1036.010
Masquerade Account Name

During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System).

T1047
Windows Management Instrumentation

During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys.

T1059.001
PowerShell

During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1059.003
Windows Command Shell

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL.

T1059.005
Visual Basic

During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server.

T1098
Account Manipulation

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network.

T1110
Brute Force

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts.

T1136
Create Account

During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`.

View all 21 procedure examples

Attributed groups1

Software1

References2

  1. Dragos Crashoverride 2018 Open source
    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.
  2. ESET Industroyer Open source
    Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.