2022-04-08, 15:02:22 UTC. Scheduled task created on a Windows machine inside the operational network of a Ukrainian energy company. Payload: 108_100.exe. Trigger: 16:10:00 UTC, the same day. 16:10:00 UTC. No entry.
The first line comes from ESET's analysis, published four days later. The second line is ours, and it is the reason this case is worth an afternoon of your team's time. The file was Industroyer2, a new build of the malware used to cut power in Ukraine in 2016. It spoke one industrial protocol, IEC-104, and carried its target list in its own body: ESET found eight device IP addresses hardcoded in the sample. At 16:20, ten minutes after the substation commands were due, a disk wiper called CaddyWiper was set to run on the same machine, to stop operators regaining control of their ICS consoles.
16:10 UTC was ten past seven in the evening in Kyiv. Nothing fired. Ukraine's national response team, CERT-UA, closed its public notice on the incident (CERT-UA#4435, in Ukrainian) with a sentence that is careful in the way only responders are careful:
"The implementation of the malicious plan has so far been prevented."
CERT-UA, notice #4435, April 2022. Our translation from the Ukrainian.
This post turns that record into a tabletop exercise you can run in ninety minutes. It assumes you are responsible for incident response at a utility or a plant with remote control of field equipment, and that someone has asked you to run an exercise this year that is not another phishing email.
Why a near-miss makes the better script
Most tabletop scenarios are borrowed from disasters, and everyone in the room already knows the ending, so the talk drifts toward who should have spotted what. A near-miss has a different shape. The defenders won, so nobody is defending a failure. The record is short and specific. And the branch that never happened, the evening the breakers did open, is still there for your team to play.
The Industroyer2 record is unusually good raw material. Two primary sources, written within days of each other, give you dates, times, file names, techniques and the response. CERT-UA says the organisation suffered two waves of attack, with the first compromise no later than February 2022. ESET dates the Industroyer2 build to 23 March from its compile timestamp and concludes the attack was planned for more than two weeks. Between them sits nearly every decision a response plan is meant to cover.
Laid out against a clock, it looks like this.
"We are not Ukraine"
"With respect, this was a state team inside a utility in a country at war. Nobody is parking that in our substations with a timer set. Give me a scenario that could actually happen here."
Fair, and beside the point. You are not rehearsing the adversary. You are rehearsing four decisions, and none depends on who is attacking. An outside party tells you something alarming about your own network. A clock is running and you do not control it. Removing the threat destroys some of the evidence. Afterwards, other operators need to know what you know. A ransomware crew with administrator rights produces every one of those moments.
The mechanics are ordinary too. Group policy and scheduled tasks are everyday Windows administration features, and CERT-UA's notice shows the attackers using exactly those to stage the wipers.
Test the objection in the room: run block three and ask whether that phone call could reach your duty manager today, and how fast. "Nobody knows" answers it.
"When does anyone ask me about the screens?"
"I run the substations. Every tabletop I've sat in, IT spends an hour on domain controllers and nobody asks the only question I care about, which is what I do when the screens go dark."
Right about most tabletops. This case is the exception, because the attackers made the operator the target. ESET says CaddyWiper was set to run on the machine where Industroyer2 executed, with the purpose of preventing operators of the energy company from regaining control of the ICS consoles. The ten minutes between 16:10 and 16:20 were built around the control room.
So block five belongs to operations, and it should be run that way. Hand the inject card to the senior operator, not the exercise lead, and ask three things in order:
- Which substations on the list can be operated locally, by hand, today? Name them.
- Who drives to each one, from where, and how long does the drive take on a Friday evening?
- Who authorises re-closing a breaker when the control room cannot see the network state?
Write the answers on the wall. If nobody can name a substation for question one, stop the clock. That stall is your first finding.
"What do I get for ninety minutes of twelve people?"
"You want twelve senior people in a room for an hour and a half. That's a real cost. What does it buy that a lessons-learned slide about Ukraine doesn't?"
The slide tells people what happened to someone else. The tabletop tells you, in writing, which of your own decisions has no owner. Stall at block two and you have learned nobody may declare an incident on ambiguous evidence. Stall at block four and nobody knows who may touch an engineering workstation mid-shift. Both are a week's work to fix once a name is written against them.
The scenario also costs nothing to write. Two response organisations have already published the story, with times. Preparation is reading two documents.
Price it before you argue it. Twelve people, ninety minutes, their loaded hourly cost. Set that number next to one question: how long would the drive in block five actually take? If the room knows, the exercise was expensive. If it does not, the first finding paid for the meeting.
The entry that stayed blank
Industroyer2 is usually filed as a malware family with a famous predecessor. Read it as a response record instead. Someone saw something, or took a call, and decided quickly. Someone let outside responders into a control network in wartime. Someone shared samples with other operators within days. None of it is described in detail, and each one is a decision your plan either covers or does not.
As far as the record shows, the defenders reached the blank line at 16:10 because those decisions were made in time. Whether yours would be costs one afternoon and a sealed column on a printed table.
Sources: CERT-UA, "Cyberattack by the Sandworm group (UAC-0082) on Ukrainian energy facilities using INDUSTROYER2 and CADDYWIPER" (CERT-UA#4435), April 2022, in Ukrainian | ESET WeLiveSecurity, "Industroyer2: Industroyer reloaded", 12 April 2022


