Industroyer2

MITRE ATT&CK: S1072 View on attack.mitre.org

Aliases: Industroyer2

First seen
2022-03-23 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
field-controller/rtu/plc/ied, engineering-workstation
Profile updated
2026-07-07 12:44:01

Targeted industries: energy-and-utilities

Targeted regions: country_code:ua

Context

Industroyer2 is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol. It is similar to the IEC-104 module found in Industroyer. Security researchers assess that Industroyer2 was designed to cause impact to high-voltage electrical substations. The initial Industroyer2 sample was compiled on 03/23/2022 and scheduled to execute on 04/08/2022, however it was discovered before deploying, resulting in no impact.

Detection coverage

  • 1 YARA rules
  • 6 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Brute Force I/O (attack-pattern)
  • Service Stop (attack-pattern)
  • Modify Parameter (attack-pattern)
  • Remote System Information Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • Monitor Process State (attack-pattern)
  • Command Message (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Industroyer2_Auto (yara-rule)

Reports & references

  • services.google.com — Google Fog Of War Research Report (report)
  • services.google.com — Apt44 Unearthing Sandworm (report)
  • Microsoft — Analysis Resources Cyber Threat Activity Ukraine (report)
  • Mandiant — Gru Disruptive Playbook (report)
  • dragos.com — 2022 Ics Ot Threat Landscape Recap What To Watch For This Year (report)
  • cybersecurity.att.com — Analysis On Recent Wiper Attacks Examples And How They Wiper Malware Works (report)
  • trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
  • youtube.com — Watch (report)
  • mandiant.widen.net — M Trends 2023 (report)
  • ESET — Industroyer2 Industroyer Reloaded (report)
  • twitter.com — 1513870210398363651 (report)
  • CERT-UA — 39518 (report)
  • Microsoft — Re4Vwwd (report)
  • blog.eset.ie — Industroyer2 Industroyer Reloaded (report)
  • Microsoft — A Year Of Russian Hybrid Warfare In Ukraine Ms Threat Intelligence 1 (report)
  • sos-vo.org — Hotsos2024 Taleoftwoindustroyers (report)
  • zambo99.github.io — S&P2024 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Industroyer2 (report)
  • nozominetworks.com — Industroyer2 Nozomi Networks Labs Analyzes The Iec 104 Payload (report)
  • blog.scadafence.com — Industroyer2 Attack (report)
  • Mandiant — Industroyer V2 Old Malware New Tricks (report)
  • nozominetworks.com — Nozomi Networks Wp Industroyer2 (report)
  • ntop.org — How Ntopng Monitors Iec 60870 5 104 Traffic (report)
  • splunk.com — Threat Update Industroyer2 (report)
  • blogs.blackberry.com — Threat Thursday Malware Rebooted How Industroyer2 Takes Aim At Ukraine Infrastructure (report)

External references