Malware.View on attack.mitre.org
Industroyer is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS), specifically components used in electrical substations. Industroyer was used in the attacks on the Ukrainian power grid in December 2016. This is the first publicly known malware specifically designed to target and impact operations in the electric grid.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Industroyer has a data wiper component that enumerates keys in the Registry |
| T1016 System Network Configuration Discovery |
Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses. |
| T1018 Remote System Discovery |
Industroyer can enumerate remote computers in the compromised network. |
| T1027 Obfuscated Files or Information |
Industroyer uses heavily obfuscated code in its Windows Notepad backdoor. |
| T1041 Exfiltration Over C2 Channel |
Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request. |
| T1046 Network Service Discovery |
Industroyer uses a custom port scanner to map out a network. |
| T1071.001 Web Protocols |
Industroyer’s main backdoor connected to a remote C2 server using HTTPS. |
| T1078 Valid Accounts |
Industroyer can use supplied user credentials to execute processes and stop services. |
| T1082 System Information Discovery |
Industroyer collects the victim machine’s Windows GUID. |
| T1083 File and Directory Discovery |
Industroyer’s data wiper component enumerates specific files on all the Windows drives. |
| T1090.003 Multi-hop Proxy |
Industroyer used Tor nodes for C2. |
| T1105 Ingress Tool Transfer |
Industroyer downloads a shellcode payload from a remote C2 server and loads it into memory. |
| T1140 Deobfuscate/Decode Files or Information |
Industroyer decrypts code to connect to a remote C2 server. |
| T1485 Data Destruction |
Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files. |
| T1489 Service Stop |
Industroyer’s data wiper module writes zeros into the registry keys in |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.