COSMICENERGY is an operational technology malware framework designed to interact with industrial control systems that use the IEC 60870-5-104 protocol. It is notable for targeting electric transmission and distribution environments and for its potential to disrupt power operations by issuing commands to IEC-104 devices. The malware has been described as using a command-line interface together with Python-based components to communicate with targeted industrial equipment. Reported tradecraft also includes handling Base64-encoded executables with native Windows tooling for staging or execution support. COSMICENERGY is regarded as one of the relatively rare OT-specific malware families identified in recent years, alongside other specialized ICS threats such as Industroyer2 and INCONTROLLER. High-confidence reporting supports its relevance to electric-sector environments in Europe, the Middle East, and Asia. Publicly available information in this context does not establish a specific threat actor attribution or a confirmed initial infection vector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as background on recent OT malware discoveries.
Operational-technology malware that interacts with IEC 60870-5-104 devices via CLI/Python to disrupt electric transmission/distribution operations.
Google Cloud Threat Intelligence COSCMICENERGY 2023
After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via certutil -hashfile ). [Google Cloud Threat Intelligence COSCMICENERGY 2023 [[URL_df298dca_76]]]
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.