ATT&CKSoftwareIndustroyer

Industroyer

S0604

Malware.View on attack.mitre.org

About this malware

Industroyer is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS), specifically components used in electrical substations. Industroyer was used in the attacks on the Ukrainian power grid in December 2016. This is the first publicly known malware specifically designed to target and impact operations in the electric grid.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1012
Query Registry

Industroyer has a data wiper component that enumerates keys in the Registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services.

T1016
System Network Configuration Discovery

Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses.

T1018
Remote System Discovery

Industroyer can enumerate remote computers in the compromised network.

T1027
Obfuscated Files or Information

Industroyer uses heavily obfuscated code in its Windows Notepad backdoor.

T1041
Exfiltration Over C2 Channel

Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request.

T1046
Network Service Discovery

Industroyer uses a custom port scanner to map out a network.

T1071.001
Web Protocols

Industroyer’s main backdoor connected to a remote C2 server using HTTPS.

T1078
Valid Accounts

Industroyer can use supplied user credentials to execute processes and stop services.

T1082
System Information Discovery

Industroyer collects the victim machine’s Windows GUID.

T1083
File and Directory Discovery

Industroyer’s data wiper component enumerates specific files on all the Windows drives.

T1090.003
Multi-hop Proxy

Industroyer used Tor nodes for C2.

T1105
Ingress Tool Transfer

Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory.

T1140
Deobfuscate/Decode Files or Information

Industroyer decrypts code to connect to a remote C2 server.

T1485
Data Destruction

Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files.

T1489
Service Stop

Industroyer’s data wiper module writes zeros into the registry keys in SYSTEM\CurrentControlSet\Services to render a system inoperable.

View all 19 procedure examples

Groups that use it1

Campaigns1

References3

  1. Dragos Crashoverride 2017 Open source
    Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020.
  2. Dragos Crashoverride 2018 Open source
    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.
  3. ESET Industroyer Open source
    Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.