{ "type": "bundle", "id": "bundle--ecda400a-e104-4623-a754-e90807fd5315", "spec_version": "2.0", "objects": [ { "modified": "2022-10-20T20:37:50.556Z", "name": "Industroyer", "description": "[Industroyer](https://attack.mitre.org/software/S0604) is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS), specifically components used in electrical substations.(Citation: ESET Industroyer) [Industroyer](https://attack.mitre.org/software/S0604) was used in the attacks on the Ukrainian power grid in December 2016.(Citation: Dragos Crashoverride 2017) This is the first publicly known malware specifically designed to target and impact operations in the electric grid.(Citation: Dragos Crashoverride 2018)", "x_mitre_platforms": [ "Windows" ], "x_mitre_deprecated": false, "x_mitre_domains": [ "enterprise-attack", "ics-attack" ], "x_mitre_version": "1.1", "x_mitre_contributors": [ "Dragos Threat Intelligence", "Joe Slowik - Dragos" ], "x_mitre_aliases": [ "Industroyer", "CRASHOVERRIDE", "Win32/Industroyer" ], "type": "malware", "id": "malware--e401d4fe-f0c9-44f0-98e6-f93487678808", "created": "2021-01-04T20:42:21.997Z", "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5", "revoked": false, "external_references": [ { "source_name": "mitre-attack", "url": "https://attack.mitre.org/software/S0604", "external_id": "S0604" }, { "source_name": "CRASHOVERRIDE", "description": "(Citation: Dragos Crashoverride 2017)" }, { "source_name": "Win32/Industroyer", "description": "(Citation: ESET Industroyer)" }, { "source_name": "ESET Industroyer", "description": "Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020.", "url": "https://www.welivesecurity.com/wp-content/uploads/2017/06/Win32_Industroyer.pdf" }, { "source_name": "Dragos Crashoverride 2017", "description": "Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020.", "url": "https://dragos.com/blog/crashoverride/CrashOverride-01.pdf" }, { "source_name": "Dragos Crashoverride 2018", "description": "Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.", "url": "https://www.dragos.com/wp-content/uploads/CRASHOVERRIDE2018.pdf" } ], "object_marking_refs": [ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168" ], "labels": [ "malware" ], "x_mitre_attack_spec_version": "2.1.0", "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5" } ] }