COVELLITE
2018-05-31 • Dragos • Covellite
Dragos tracks Covellite as a threat group that compromises networks associated with civilian electric energy organizations worldwide, gathering intelligence on intellectual property and internal industrial operations, though it lacks industrial-control-system-specific capability. Covellite operates globally with targets primarily in Europe, East Asia, and North America. U.S. targeting emerged in September 2017 through a small, targeted phishing campaign against select electric companies, using emails disguised as resumes or invitations that carried malicious Microsoft Word documents delivering a remote access tool used for reconnaissance and persistent, covert access. Covellite's infrastructure and malware show similarity to tooling associated with the group known as Lazarus and Hidden Cobra, with technical analysis indicating an evolution from known Lazarus toolkits, although Dragos notes it is not established how the two groups' capabilities and operations are otherwise related. Covellite later appeared to abandon North American targeting while remaining active in Europe and East Asia, and Dragos considers it a primary threat to the industrial control systems sector given its infrastructure-focused interest and improving capabilities.
-
60
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster