ATT&CKReferencesESET Industroyer

ESET Industroyer

Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples15

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareIndustroyer

Industroyer has a data wiper component that enumerates keys in the Registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services.

T1016
System Network Configuration Discovery
MalwareIndustroyer

Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses.

T1018
Remote System Discovery
MalwareIndustroyer

Industroyer can enumerate remote computers in the compromised network.

T1027
Obfuscated Files or Information
MalwareIndustroyer

Industroyer uses heavily obfuscated code in its Windows Notepad backdoor.

T1027
Obfuscated Files or Information
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor.

T1041
Exfiltration Over C2 Channel
MalwareIndustroyer

Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request.

T1046
Network Service Discovery
MalwareIndustroyer

Industroyer uses a custom port scanner to map out a network.

T1071.001
Web Protocols
MalwareIndustroyer

Industroyer’s main backdoor connected to a remote C2 server using HTTPS.

T1078
Valid Accounts
MalwareIndustroyer

Industroyer can use supplied user credentials to execute processes and stop services.

T1083
File and Directory Discovery
MalwareIndustroyer

Industroyer’s data wiper component enumerates specific files on all the Windows drives.

T1105
Ingress Tool Transfer
MalwareIndustroyer

Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.

T1140
Deobfuscate/Decode Files or Information
MalwareIndustroyer

Industroyer decrypts code to connect to a remote C2 server.

T1499.004
Application or System Exploitation
MalwareIndustroyer

Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices.

T1554
Compromise Host Software Binary
MalwareIndustroyer

Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism.

T1554
Compromise Host Software Binary
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.