Industroyer2
MITRE ATT&CK: S1072 View on attack.mitre.org
Aliases: Industroyer2
- First seen
- 2022-03-23 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- field-controller/rtu/plc/ied, engineering-workstation
- Profile updated
- 2026-07-07 12:44:01
Targeted industries: energy-and-utilities
Targeted regions: country_code:ua
Context
Industroyer2 is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol. It is similar to the IEC-104 module found in Industroyer. Security researchers assess that Industroyer2 was designed to cause impact to high-voltage electrical substations. The initial Industroyer2 sample was compiled on 03/23/2022 and scheduled to execute on 04/08/2022, however it was discovered before deploying, resulting in no impact.
Detection coverage
- 1 YARA rules
- 6 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Brute Force I/O (attack-pattern)
- Service Stop (attack-pattern)
- Modify Parameter (attack-pattern)
- Remote System Information Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- Monitor Process State (attack-pattern)
- Command Message (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
Detection rules
- MALPEDIA_Win_Industroyer2_Auto (yara-rule)
Reports & references
- services.google.com — Google Fog Of War Research Report (report)
- services.google.com — Apt44 Unearthing Sandworm (report)
- Microsoft — Analysis Resources Cyber Threat Activity Ukraine (report)
- Mandiant — Gru Disruptive Playbook (report)
- dragos.com — 2022 Ics Ot Threat Landscape Recap What To Watch For This Year (report)
- cybersecurity.att.com — Analysis On Recent Wiper Attacks Examples And How They Wiper Malware Works (report)
- trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
- youtube.com — Watch (report)
- mandiant.widen.net — M Trends 2023 (report)
- ESET — Industroyer2 Industroyer Reloaded (report)
- twitter.com — 1513870210398363651 (report)
- CERT-UA — 39518 (report)
- Microsoft — Re4Vwwd (report)
- blog.eset.ie — Industroyer2 Industroyer Reloaded (report)
- Microsoft — A Year Of Russian Hybrid Warfare In Ukraine Ms Threat Intelligence 1 (report)
- sos-vo.org — Hotsos2024 Taleoftwoindustroyers (report)
- zambo99.github.io — S&P2024 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Industroyer2 (report)
- nozominetworks.com — Industroyer2 Nozomi Networks Labs Analyzes The Iec 104 Payload (report)
- blog.scadafence.com — Industroyer2 Attack (report)
- Mandiant — Industroyer V2 Old Malware New Tricks (report)
- nozominetworks.com — Nozomi Networks Wp Industroyer2 (report)
- ntop.org — How Ntopng Monitors Iec 60870 5 104 Traffic (report)
- splunk.com — Threat Update Industroyer2 (report)
- blogs.blackberry.com — Threat Thursday Malware Rebooted How Industroyer2 Takes Aim At Ukraine Infrastructure (report)