ATT&CKReferencesUS-CERT Ukraine Feb 2016

US-CERT Ukraine Feb 2016

US-CERT. (2016, February 25). ICS Alert (IR-ALERT-H-16-056-01) Cyber-Attack Against Ukrainian Critical Infrastructure. Retrieved June 10, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupSandworm Team

Sandworm Team have used previously acquired legitimate credentials prior to attacks.

T1219
Remote Access Tools
GroupSandworm Team

Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers.

T1485
Data Destruction
GroupSandworm Team

Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes.

T1561.002
Disk Structure Wipe
GroupSandworm Team

Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.

T1566.001
Spearphishing Attachment
GroupSandworm Team

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.