PULSE NAME
Cyberattack by Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
WHITE Sandworm Team AlienVault 2022-04-12 Modified: 2022-05-12
21
IOCs
MEDIUM VOLUME
The Governmental Computer Emergency Response Team of Ukraine CERT-UA has taken urgent measures to respond to an information security incident related to a targeted attack on Ukraine's energy facility. The idea of ​​the attackers involved the decommissioning of several infrastructural elements of the object of attack, namely: high-voltage electrical substations - using the malicious program INDUSTROYER2; moreover, each executable file contained a statically specified set of unique parameters for the respective substations (file compilation date: 23.03.2022); electronic computers (computers) running the Windows operating system (user computers, servers, as well as automated workstations ACS TP) - using malicious software-destructor CADDYWIPER; in this case, the decryption and launch of the latter involves the use of the ARGUEPATCH loader and the TAILJUMP silkcode; server equipment running Linux operating systems - using malicious destructive scripts ORCSHRED, SOLOSHRED, AWFULSHRED; active network equipment.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Caddywiper Industroyer - S0604
Indicators of Compromise (7 / 21 total)
All FileHash-MD5 FileHash-SHA256 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 1724a0a3c9c73f4d8891f988b5035effce8d897ed42336a92e2c9bc7d9ee7f5a 2022-04-12
FileHash-SHA256 43d07f28b7b699f43abd4f695596c15a90d772bfbd6029c8ee7bc5859c2b0861 2022-04-12
FileHash-SHA256 7062403bccacc7c0b84d27987b204777f6078319c3f4caa361581825c1a94e87 2022-04-12
FileHash-SHA256 87ca2b130a8ec91d0c9c0366b419a0fce3cb6a935523d900918e634564b88028 2022-04-12
FileHash-SHA256 bcdf0bd8142a4828c61e775686c9892d89893ed0f5093bdc70bde3e48d04ab99 2022-04-12
FileHash-SHA256 cda9310715b7a12f47b7c134260d5ff9200c147fc1d05f030e507e57e3582327 2022-04-12
FileHash-SHA256 fc0e6f2effbfa287217b8930ab55b7a77bb86dbd923c0e8150551627138c9caa 2022-04-12