← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Cyberattack by Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
The Governmental Computer Emergency Response Team of Ukraine CERT-UA has taken urgent measures to respond to an information security incident related to a targeted attack on Ukraine's energy facility.
The idea of the attackers involved the decommissioning of several infrastructural elements of the object of attack, namely:
high-voltage electrical substations - using the malicious program INDUSTROYER2; moreover, each executable file contained a statically specified set of unique parameters for the respective substations (file compilation date: 23.03.2022);
electronic computers (computers) running the Windows operating system (user computers, servers, as well as automated workstations ACS TP) - using malicious software-destructor CADDYWIPER; in this case, the decryption and launch of the latter involves the use of the ARGUEPATCH loader and the TAILJUMP silkcode;
server equipment running Linux operating systems - using malicious destructive scripts ORCSHRED, SOLOSHRED, AWFULSHRED;
active network equipment.
MITRE ATT&CK & Malware Families
Indicators of Compromise (7 / 21 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 1724a0a3c9c73f4d8891f988b5035effce8d897ed42336a92e2c9bc7d9ee7f5a | — | 2022-04-12 | |
| FileHash-SHA256 | 43d07f28b7b699f43abd4f695596c15a90d772bfbd6029c8ee7bc5859c2b0861 | — | 2022-04-12 | |
| FileHash-SHA256 | 7062403bccacc7c0b84d27987b204777f6078319c3f4caa361581825c1a94e87 | — | 2022-04-12 | |
| FileHash-SHA256 | 87ca2b130a8ec91d0c9c0366b419a0fce3cb6a935523d900918e634564b88028 | — | 2022-04-12 | |
| FileHash-SHA256 | bcdf0bd8142a4828c61e775686c9892d89893ed0f5093bdc70bde3e48d04ab99 | — | 2022-04-12 | |
| FileHash-SHA256 | cda9310715b7a12f47b7c134260d5ff9200c147fc1d05f030e507e57e3582327 | — | 2022-04-12 | |
| FileHash-SHA256 | fc0e6f2effbfa287217b8930ab55b7a77bb86dbd923c0e8150551627138c9caa | — | 2022-04-12 |
References (2)