ICS/OT CYBERSECURITY YEAR IN REVIEW 2022
2023-02-14 • Dragos •
https://hub.dragos.com/hubfs/312-Year-in-Review/2022/Dragos_Year-In-Review-Report-2022.pdf
Attachments
Dragos' 2022 ICS/OT review identifies WASSONITE as an activity group with limited technical overlaps to COVELLITE and the cluster tracked by other vendors as Kimsuky. The report says WASSONITE uses customized DTrack and Appleseed RAT variants, Mimikatz, system tools for lateral movement and file transfers, and adversary-controlled domains or compromised services for C2. Its victim profile centers on ICS-related organizations in nuclear energy, electric, oil and gas, advanced manufacturing, pharmaceutical, and aerospace sectors across South and East Asia and North America. Dragos frames the activity as Stage 1 ICS kill-chain access and information-gathering operations rather than disruptive ICS attacks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | opcfoundation.org | 2023-02-14 | 2023-02-14 |