This video is on how to generate IOC matching queries for majority of SIEM, EDR and even grep friendly. As well as behaviour Sigma rules to see traces of the latest attack by Sandworm APT group targeting power grid in Ukraine, and maybe not only in Ukraine. Full details on how to hun in the video.
From CERT-UA research:
"The Computer Emergency Response Team of Ukraine (CERT-UA) has taken urgent measures to respond to the cybersecurity incident involving a targeted attack on the Ukrainian power facilities.
Cybercriminals aimed to destabilize a set of infrastructure elements, more specifically:
1)High-voltage electrical substations using the INDUSTROYER2 malware; each file contained a statistically defined set of unique parameters for the corresponding substations. The file compilation date is March 23, 2022;
2) computers running Windows OS, including the personal computers, servers, and automated process control systems by means of the CADDYWIPER data destructive malware. To decipher and launch the latter, cybercriminals aimed to apply the ARGUEPATCH loader and TAILJUMP shellcode;
3) Server equipment running Linux OS using the malicious data-wiping scripts, like ORSHRED, SOLOSHRED, and AWFULSHRED;
4) Active network equipment."
1 comment
[ 3.4 ms ] story [ 13.8 ms ] threadFrom CERT-UA research: "The Computer Emergency Response Team of Ukraine (CERT-UA) has taken urgent measures to respond to the cybersecurity incident involving a targeted attack on the Ukrainian power facilities.
Cybercriminals aimed to destabilize a set of infrastructure elements, more specifically: 1)High-voltage electrical substations using the INDUSTROYER2 malware; each file contained a statistically defined set of unique parameters for the corresponding substations. The file compilation date is March 23, 2022; 2) computers running Windows OS, including the personal computers, servers, and automated process control systems by means of the CADDYWIPER data destructive malware. To decipher and launch the latter, cybercriminals aimed to apply the ARGUEPATCH loader and TAILJUMP shellcode; 3) Server equipment running Linux OS using the malicious data-wiping scripts, like ORSHRED, SOLOSHRED, and AWFULSHRED; 4) Active network equipment."
original research in Ukrainian https://cert.gov.ua/article/39518