Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files. |
| T1082 System Information Discovery |
MalwareIndustroyer | Industroyer collects the victim machine’s Windows GUID. |
| T1090.003 Multi-hop Proxy |
MalwareIndustroyer | Industroyer used Tor nodes for C2. |
| T1485 Data Destruction |
MalwareIndustroyer | Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files. |
| T1489 Service Stop |
MalwareIndustroyer | Industroyer’s data wiper module writes zeros into the registry keys in |
| T1543.003 Windows Service |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1543.003 Windows Service |
MalwareIndustroyer | Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1572 Protocol Tunneling |
MalwareIndustroyer | Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.