Summary

On 12 April 2022, ESET (working with CERT-UA) disclosed Industroyer2, a new version of the Industroyer grid malware. It was deployed against high-voltage electrical substations of a Ukrainian energy provider and scheduled to run on 8 April 2022 at 16:10 UTC. The sample was compiled on 23 March 2022, so the operation was planned at least two weeks ahead.

Industroyer2 is stripped down compared with its 2016 predecessor. It implements only IEC 60870-5-104, with its target configuration hard-coded into the binary for the specific victim. It was deployed with a set of destructive tools meant to cover tracks and delay recovery:

  • CaddyWiper on Windows;
  • ORCSHRED (a Linux worm), SOLOSHRED and AWFULSHRED (Linux and Solaris wipers).

ESET attributes the attack to Sandworm with high confidence. Ukrainian authorities reported that the attack was detected and thwarted before it could cut power.

Apa maksudnya untuk Malaysia? 🇲🇾

Two lessons carry over to Malaysian energy operators:

  1. The capability is maintained and reusable. Six years after the first Industroyer, the same group fielded a leaner version. It was tailored per victim, which means the attackers had detailed knowledge of the target’s substation configuration beforehand. Protect the documents that reveal it: network diagrams, IEC-104 address maps (IOAs) and SCADA configuration exports.
  2. Defence won here. Detection before the scheduled execution prevented an outage. Continuous OT monitoring and a practised incident response plan are what make that possible. Under the Cyber Security Act 2024, NCII entities must also report incidents to NACSA.

Details / TTPs (ATT&CK for ICS)

TechniqueNameObserved behavior
T0888Remote System Information DiscoveryQueries configured stations before acting
T1692.001Command MessageIEC-104 commands to substation equipment
T0806Brute Force I/OIterates over hard-coded information object addresses
T0881Service StopTerminates specified processes before sending commands
T0809Data DestructionCaddyWiper, ORCSHRED, SOLOSHRED, AWFULSHRED

Detection guidance

  • Allow-list IEC-104 masters per outstation and alert on new sources of control commands.
  • Monitor for scheduled tasks and group-policy changes pushing binaries to OT-adjacent servers; that is how the wipers were staged.
  • Keep offline copies of substation configuration and RTU/IED settings for rebuild.

IoCs

Hashes and detection names are published in the referenced ESET and CERT-UA reporting.

References