ICS/OT CYBERSECURITY YEAR IN REVIEW 2022

2023-02-14 Dragos

https://hub.dragos.com/hubfs/312-Year-in-Review/2022/Dragos_Year-In-Review-Report-2022.pdf

Attachments

Dragos_Year-In-Review-Report-2022.pdf (7 MB)

Thumbnail for ICS/OT CYBERSECURITY YEAR IN REVIEW 2022

Dragos' 2022 ICS/OT review identifies WASSONITE as an activity group with limited technical overlaps to COVELLITE and the cluster tracked by other vendors as Kimsuky. The report says WASSONITE uses customized DTrack and Appleseed RAT variants, Mimikatz, system tools for lateral movement and file transfers, and adversary-controlled domains or compromised services for C2. Its victim profile centers on ICS-related organizations in nuclear energy, electric, oil and gas, advanced manufacturing, pharmaceutical, and aerospace sectors across South and East Asia and North America. Dragos frames the activity as Stage 1 ICS kill-chain access and information-gathering operations rather than disruptive ICS attacks.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN opcfoundation.org 2023-02-14 2023-02-14

Related Actors

Related Reports

« Back