Also known as: Duqu Group, SIG35
**Targets:** Directed at Iranian nuclear facilities **Toolset/Malware:** Stuxnet **Modus Operandi:** Stuxnet is typically introduced to the target environment via an infected USB flash drive.
Olympic Games / Stuxnet; Stuxnet is typically introduced to the target environment via an infected USB flash drive.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Unit 8200, also known as Duqu Group or SIG35, is a nation-state cyber threat group primarily involved in espionage activities targeting critical infrastructure. The group is best known for its involvement in the Stuxnet attacks aimed at Iranian nuclear facilities and has shown a focus on energy, defense, and government sectors. Their operations are characterized by sophisticated malware like Stuxnet, which was introduced via infected USB drives to compromise target environments.
Goals & Targeting
Unit 8200's primary goal appears to be the disruption and sabotage of critical infrastructure, particularly within energy and defense sectors. Their targeting profile suggests a focus on high-value assets in government and industrial control systems, with specific campaigns like the Olympic Games indicating a strategic interest in slowing down or halting progress in sensitive areas such as nuclear technology development. The group's activities are consistent with nation-state cyber espionage objectives, aiming to gather intelligence and/or sabotage operations.
Enhanced Description
Unit 8200 is a highly sophisticated nation-state cyber threat actor known for its involvement in the Stuxnet attacks, a campaign widely recognized as one of the first instances of state-sponsored cyber warfare. The primary tool associated with this group is Stuxnet, a worm-like malware that targets supervisory control and data acquisition (SCADA) systems, particularly those used in industrial infrastructure. The modus operandi for Stuxnet typically involves the use of infected USB flash drives to infiltrate target environments, leveraging the initial access point to deploy the malware and compromise critical systems. Unit 8200's activities are closely linked to the Olympic Games campaign, which targeted Iranian nuclear facilities as part of a broader effort to disrupt their progress in developing nuclear technology. The group has also been associated with Duqu 2.0, another advanced piece of malware used for espionage purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Unit 8200 is known for its involvement in the Olympic Games campaign, which utilized Stuxnet to target Iranian nuclear facilities. The group has also been linked to Duqu 2.0, an advanced malware used in subsequent operations. Their campaigns typically involve targeting critical infrastructure with highly customized malware, often introduced through USB devices. The operational tempo of Unit 8200 suggests a focus on long-term, stealthy espionage and sabotage activities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Unit 8200's involvement with Stuxnet and its nation-state origins. The data gaps include specific details about their current operations beyond Duqu 2.0, as well as the full scope of their targeting profile.
No techniques linked yet.
Olympic Games / Stuxnet
Duqu 2.0
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
1
Tools
2
Campaigns
0
IOCs
0
Observed Data
0
Tactics