ATT&CKReferencesDragos Crashoverride 2017

Dragos Crashoverride 2017

Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.

T1082
System Information Discovery
MalwareIndustroyer

Industroyer collects the victim machine’s Windows GUID.

T1090.003
Multi-hop Proxy
MalwareIndustroyer

Industroyer used Tor nodes for C2.

T1485
Data Destruction
MalwareIndustroyer

Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files.

T1489
Service Stop
MalwareIndustroyer

Industroyer’s data wiper module writes zeros into the registry keys in SYSTEM\CurrentControlSet\Services to render a system inoperable.

T1543.003
Windows Service
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.

T1543.003
Windows Service
MalwareIndustroyer

Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary.

T1572
Protocol Tunneling
MalwareIndustroyer

Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.