Skip to content

cado-security/DFIR_Resources_Industroyer2

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 

Repository files navigation

DFIR_Resources_Industroyer2

On Tuesday April 12th 2022, CERT-UA released information about an ongoing cyberattack against a Ukrainian energy company by the Sandworm group. This attack leveraged the destructive CaddyWiper malware and an updated version of Industroyer, now named Industroyer2.

We've released YARA rules to catch some components of the malware used in this attack, based on publicly-available information. We hope this will assist defenders and DIFR professionals affected by this malware.

References:

About

IoCs and YARA rules for Industroyer2

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages