← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Cyberattack by Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
The Governmental Computer Emergency Response Team of Ukraine CERT-UA has taken urgent measures to respond to an information security incident related to a targeted attack on Ukraine's energy facility.
The idea of the attackers involved the decommissioning of several infrastructural elements of the object of attack, namely:
high-voltage electrical substations - using the malicious program INDUSTROYER2; moreover, each executable file contained a statically specified set of unique parameters for the respective substations (file compilation date: 23.03.2022);
electronic computers (computers) running the Windows operating system (user computers, servers, as well as automated workstations ACS TP) - using malicious software-destructor CADDYWIPER; in this case, the decryption and launch of the latter involves the use of the ARGUEPATCH loader and the TAILJUMP silkcode;
server equipment running Linux operating systems - using malicious destructive scripts ORCSHRED, SOLOSHRED, AWFULSHRED;
active network equipment.
MITRE ATT&CK & Malware Families
Indicators of Compromise (7 / 21 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 0090cb4de31d2d3bca55fd4a36859921b5fc5dae | — | 2022-04-12 | |
| FileHash-SHA1 | 3cdbc19bc4f12d8d00b81380f7a2504d08074c15 | — | 2022-04-12 | |
| FileHash-SHA1 | 6fa04992c0624c7aa3ca80da6a30e6de91226a16 | — | 2022-04-12 | |
| FileHash-SHA1 | 8fc7646fa14667d07e3110fe754f61a78cfde6bc | — | 2022-04-12 | |
| FileHash-SHA1 | 9ce1491ce69809f92ae1fe8d4c0783bd1d11fbe7 | — | 2022-04-12 | |
| FileHash-SHA1 | d27d0b9bb57b2bab881e0efb97c740b7e81405df | — | 2022-04-12 | |
| FileHash-SHA1 | fd9c17c35a68fc505235e20c6e50c622aed8dea0 | — | 2022-04-12 |
References (2)