Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Unit 8200

Also known as: Duqu Group, SIG35

Description

**Targets:** Directed at Iranian nuclear facilities **Toolset/Malware:** Stuxnet **Modus Operandi:** Stuxnet is typically introduced to the target environment via an infected USB flash drive.

TTP Summary

Olympic Games / Stuxnet; Stuxnet is typically introduced to the target environment via an infected USB flash drive.

Goals & Targeting

Targeted Sectors

Energy
Defense
Government

Targeted Countries / Regions

IR
DE

AI Analysis

· 1 week ago

Executive Summary

Unit 8200, also known as Duqu Group or SIG35, is a nation-state cyber threat group primarily involved in espionage activities targeting critical infrastructure. The group is best known for its involvement in the Stuxnet attacks aimed at Iranian nuclear facilities and has shown a focus on energy, defense, and government sectors. Their operations are characterized by sophisticated malware like Stuxnet, which was introduced via infected USB drives to compromise target environments.

Goals & Targeting

Unit 8200's primary goal appears to be the disruption and sabotage of critical infrastructure, particularly within energy and defense sectors. Their targeting profile suggests a focus on high-value assets in government and industrial control systems, with specific campaigns like the Olympic Games indicating a strategic interest in slowing down or halting progress in sensitive areas such as nuclear technology development. The group's activities are consistent with nation-state cyber espionage objectives, aiming to gather intelligence and/or sabotage operations.

Enhanced Description

Unit 8200 is a highly sophisticated nation-state cyber threat actor known for its involvement in the Stuxnet attacks, a campaign widely recognized as one of the first instances of state-sponsored cyber warfare. The primary tool associated with this group is Stuxnet, a worm-like malware that targets supervisory control and data acquisition (SCADA) systems, particularly those used in industrial infrastructure. The modus operandi for Stuxnet typically involves the use of infected USB flash drives to infiltrate target environments, leveraging the initial access point to deploy the malware and compromise critical systems. Unit 8200's activities are closely linked to the Olympic Games campaign, which targeted Iranian nuclear facilities as part of a broader effort to disrupt their progress in developing nuclear technology. The group has also been associated with Duqu 2.0, another advanced piece of malware used for espionage purposes.

Key Capabilities

  • Development of sophisticated malware targeting SCADA systems
  • Use of USB-based infection vectors for initial access
  • Advanced persistent threat (APT) capabilities including espionage
  • State-sponsored cyber warfare tactics

MITRE ATT&CK Tactics

Collection
Disruption
Persistence
Espionage
Subversion

ATT&CK Techniques

T1059.003
T1078
T1201
T1046
T1566

Software / Tooling

Stuxnet
Duqu 2.0

Campaigns & Victims

Unit 8200 is known for its involvement in the Olympic Games campaign, which utilized Stuxnet to target Iranian nuclear facilities. The group has also been linked to Duqu 2.0, an advanced malware used in subsequent operations. Their campaigns typically involve targeting critical infrastructure with highly customized malware, often introduced through USB devices. The operational tempo of Unit 8200 suggests a focus on long-term, stealthy espionage and sabotage activities.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux domains
  • USB-based infection vectors for initial access
  • Staging infrastructure on bulletproof hosting services
  • SCADA system compromise attempts

Recommended Actions

  • Enforce USB drive sanitization policies and restrictions
  • Monitor external devices for unauthorized activity
  • Implement network segmentation to isolate SCADA systems
  • Conduct regular security updates and patch management
  • Deploy endpoint detection and response (EDR) solutions
  • Perform periodic red teaming exercises focusing on industrial control systems

Suggested Tags

nation-state
espionage
cyber warfare
Olympic Games
Stuxnet
energy sector

Confidence Assessment

High confidence in Unit 8200's involvement with Stuxnet and its nation-state origins. The data gaps include specific details about their current operations beyond Duqu 2.0, as well as the full scope of their targeting profile.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

2

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
nation-state
espionage
cyber warfare
Olympic Games
Stuxnet
energy sector

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Israel (IL)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.