US-CERT. (2016, February 25). ICS Alert (IR-ALERT-H-16-056-01) Cyber-Attack Against Ukrainian Critical Infrastructure. Retrieved June 10, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupSandworm Team | Sandworm Team have used previously acquired legitimate credentials prior to attacks. |
| T1219 Remote Access Tools |
GroupSandworm Team | Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers. |
| T1485 Data Destruction |
GroupSandworm Team | Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes. |
| T1561.002 Disk Structure Wipe |
GroupSandworm Team | Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record. |
| T1566.001 Spearphishing Attachment |
GroupSandworm Team | Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.