Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It was their use of the BLACKENERGY 2 malware that caught the ICS industry’s attention. This ICS tailored malware contained exploits for specific types of HMI applications including Siemens SIMATIC, GE CIMPLICITY, and Advantech WebAccess.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Part 1 : Process Injection ... It looks like that the dll has been injected in this process (PID 856). Let us look for the sign of the injection in the process and dump any suspicious section if the memory of this process using malfind ... Hence, it is confirmed that this dll is injected in the memory of this process (PID 856).
Today, we are going to revisit the long forgotten master piece of Kernel Rootkit — BlackEnergy 2 (BE2) ... It has a handle to the module named str.sys that is residing under system32 directory.
Part 1 : Process Injection ... It looks like that the dll has been injected in this process (PID 856). Let us look for the sign of the injection in the process and dump any suspicious section if the memory of this process using malfind ... Hence, it is confirmed that this dll is injected in the memory of this process (PID 856).
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content describes BlackEnergy 2 as a kernel rootkit/backdoor analyzed via memory forensics. It discusses suspicious process activity, reflective DLL injection into svchost.exe, and references a related driver component (str.sys) and injected main.dll functionality.
OT-targeted malware family cited as tailored for targeting critical infrastructure systems.
ICS-tailored malware used to target internet-connected HMIs, exploit specific HMI applications, and provide footholds for espionage and positioning within industrial control environments.
ICS-tailored malware used to target internet-connected HMIs, exploit specific HMI applications, and provide footholds for espionage and positioning within industrial control environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.