mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
4.3 KiB
4.3 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Industroyer2 | 2022-04-21 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
Leverage searches that allow you to detect and investigate unusual activities that might relate to the Industroyer2 attack, including file writes associated with its payload, lateral movement, persistence, privilege escalation and data destruction.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2022-04-21
- Author: Teoderick Contreras, Splunk
- ID: 7ff7db2b-b001-498e-8fe8-caf2dbc3428a
Narrative
Industroyer2 is part of continuous attack to ukraine targeting energy facilities. This malware is a windows binary that implement IEC-104 protocol to communicate with industrial equipments. This attack consist of several destructive linux script component to wipe or delete several linux critical files, powershell for domain enumeration and caddywiper to wipe boot sector of the targeted host.
Detections
Reference
- https://cert.gov.ua/article/39518
- https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
source | version: 1