Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareIndustroyer | Industroyer has a data wiper component that enumerates keys in the Registry |
| T1016 System Network Configuration Discovery |
MalwareIndustroyer | Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses. |
| T1018 Remote System Discovery |
MalwareIndustroyer | Industroyer can enumerate remote computers in the compromised network. |
| T1027 Obfuscated Files or Information |
MalwareIndustroyer | Industroyer uses heavily obfuscated code in its Windows Notepad backdoor. |
| T1027 Obfuscated Files or Information |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor. |
| T1041 Exfiltration Over C2 Channel |
MalwareIndustroyer | Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request. |
| T1046 Network Service Discovery |
MalwareIndustroyer | Industroyer uses a custom port scanner to map out a network. |
| T1071.001 Web Protocols |
MalwareIndustroyer | Industroyer’s main backdoor connected to a remote C2 server using HTTPS. |
| T1078 Valid Accounts |
MalwareIndustroyer | Industroyer can use supplied user credentials to execute processes and stop services. |
| T1083 File and Directory Discovery |
MalwareIndustroyer | Industroyer’s data wiper component enumerates specific files on all the Windows drives. |
| T1105 Ingress Tool Transfer |
MalwareIndustroyer | Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareIndustroyer | Industroyer decrypts code to connect to a remote C2 server. |
| T1499.004 Application or System Exploitation |
MalwareIndustroyer | Industroyer uses a custom DoS tool that leverages CVE-2015-5374 and targets hardcoded IP addresses of Siemens SIPROTEC devices. |
| T1554 Compromise Host Software Binary |
MalwareIndustroyer | Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism. |
| T1554 Compromise Host Software Binary |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.