Campaign, Dec 2016 to Dec 2016.View on attack.mitre.org
2016 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid. This campaign was the second major public attack conducted against Ukraine by Sandworm Team.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials. |
| T1018 Remote System Discovery |
During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD. |
| T1021.002 SMB/Windows Admin Shares |
During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares. |
| T1027 Obfuscated Files or Information |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor. |
| T1027.002 Software Packing |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz. |
| T1036.005 Match Legitimate Resource Name or Location |
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files. |
| T1036.008 Masquerade File Type |
During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as `.txt` files. |
| T1036.010 Masquerade Account Name |
During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). |
| T1047 Windows Management Instrumentation |
During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys. |
| T1059.001 PowerShell |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.003 Windows Command Shell |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL. |
| T1059.005 Visual Basic |
During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. |
| T1098 Account Manipulation |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network. |
| T1110 Brute Force |
During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts. |
| T1136 Create Account |
During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.