PULSE NAME
Cyberattack by Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
WHITE Sandworm Team AlienVault 2022-04-12 Modified: 2022-05-12
21
IOCs
MEDIUM VOLUME
The Governmental Computer Emergency Response Team of Ukraine CERT-UA has taken urgent measures to respond to an information security incident related to a targeted attack on Ukraine's energy facility. The idea of ​​the attackers involved the decommissioning of several infrastructural elements of the object of attack, namely: high-voltage electrical substations - using the malicious program INDUSTROYER2; moreover, each executable file contained a statically specified set of unique parameters for the respective substations (file compilation date: 23.03.2022); electronic computers (computers) running the Windows operating system (user computers, servers, as well as automated workstations ACS TP) - using malicious software-destructor CADDYWIPER; in this case, the decryption and launch of the latter involves the use of the ARGUEPATCH loader and the TAILJUMP silkcode; server equipment running Linux operating systems - using malicious destructive scripts ORCSHRED, SOLOSHRED, AWFULSHRED; active network equipment.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Caddywiper Industroyer - S0604
Indicators of Compromise (7 / 21 total)
All FileHash-MD5 FileHash-SHA256 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1938380a81a23b8b1100de8403b583a7 2022-04-12
FileHash-MD5 3229e8c4150b5e43f836643ec9428865 2022-04-12
FileHash-MD5 73561d9a331c1d8a334ec48dfd94db99 2022-04-12
FileHash-MD5 97ad7f3ed815c0528b070941be903d07 2022-04-12
FileHash-MD5 9ec8468dd4a81b0b35c499b31e67375e 2022-04-12
FileHash-MD5 b63b9929b8f214c4e8dcff7956c87277 2022-04-12
FileHash-MD5 fbe32784c073e341fc57d175a913905c 2022-04-12