Home/Threat Actor/COVELLITE (Lazarus-linked ICS)
Threat Actor

COVELLITE (Lazarus-linked ICS)

covellite_lazarus_ics · dprk_lazarus_linked_dragos_tracked_ics_electric_sector_2017_2018_retired · active since 2017-01

COVELLITE is Dragos's canonical originally-DPRK- attributed designation for a Lazarus-linked ICS- targeting threat group historically active circa 2017-2018 targeting electric energy networks in Europe + East Asia + North America, subsequently retired per Dragos 2020+ year-in-review tracking; DPRK + Lazarus-link attribution via Dragos canonical 2018 disclosure ("COVELLITE, which has been linked to North Korea's Lazarus Group, and which has been observed targeting networks associated with electric energy, primarily in Europe, East Asia, and North America") + SecurityWeek canonical Nine Distinct Threat Groups Targeting Industrial Systems 2019 coverage + SecurityWeek More Threat Groups Target Electric Utilities in North America coverage + Bleeping Computer canonical 2020 New Actors Attack Industrial Control Systems Old Ones Mature retired-status disclosure ("Covellite and Electrum are no longer on the radar due to inactivity. This is likely because the actors switched to different tactics and changed the targeting focus")

honest attribution caveat: COVELLITE operationally interleaves with the broader Lazarus Group (already curated as lazarus_group.yaml in corpus), Dragos tracks COVELLITE as a distinct activity group based on Dragos-taxonomy ICS-focus methodology, but operational independence from broader Lazarus operations is not publicly established + WASSONITE relationship is preserved as alias under andariel.yaml in corpus, with COVELLITE here representing Dragos's electric- sector-focused tracking historically associated with Lazarus rather than the WASSONITE-as-Andariel framing.

standalone cluster paralleling chernovite_pipedream + kamacite + raspite_leafminer in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

operational target profile signature electric energy networks primary target sector per Dragos + signature Europe + East Asia + North America geographic distribution per Dragos + signature North American electric sector historical attack companies per SecurityWeek Dragos coverage ("COVELLITE did attack companies in the North American electric sector, but the group no longer appears to target this industry, and it lacks the capability to hack industrial systems") + no longer active post-2020 per Dragos year-in-review reports + no demonstrated ICS- disruption capability per Dragos canonical assessment.

operational attack architecture: (1) cluster-defining 2017-2018 operational origin with DPRK-Lazarus-link attribution establishing first-DPRK-attributed-ICS-focused- Activity-Group designation per Dragos taxonomy; (2) cluster-defining electric energy reconnaissance focus in Europe + East Asia + North America geographic distribution.

(3) cluster-defining Lazarus Group malware + infrastructure similarity per SecurityWeek 2019 ("COVELLITE's malware and infrastructure are similar to the one of the North Korea-linked Lazarus Group") providing technical attribution evidence.

(4) cluster-defining WASSONITE distinct-but-related Dragos tracking signature with Dragos canonical assessment ("Another threat group whose existence was revealed in Dragos' report is WASSONITE, which appears to be linked to COVELLITE... Dragos says the COVELLITE-linked WASSONITE, which has been around since at least 2018, has targeted electric generation, nuclear energy, manufacturing, and research entities in India, and likely South Korea and Japan"), curation note: WASSONITE alias preserved under andariel.yaml in corpus, COVELLITE here represents the electric-energy-Europe-East-Asia-North- America-focused historical Dragos tracking.

(5) cluster-defining no-ICS-disruption-capability assessment per Dragos with ICS Cyber Kill Chain Stage 1 reconnaissance-focus operational assessment distinguishing COVELLITE from ELECTRUM + XENOTIME + CHERNOVITE disruption-capable actors; (6) cluster-defining retired-inactive post-2020 status per Bleeping Computer Dragos coverage preserving COVELLITE as historically-significant- but-operationally-dormant cluster with tactics + targeting focus shifting hypothesized rather than definitive operational termination.

(7) signature DTrack RAT + credential capture tools + system tools tradecraft per Dragos WASSONITE-related analysis applicable to broader DPRK Lazarus- associated cluster tooling.

(8) signature ICS Cyber Kill Chain Stage 1 reconnaissance + initial access operational pattern consistent with Lazarus-associated DPRK cluster intelligence collection objectives prior to capability transition; cluster fills the Dragos-COVELLITE-DPRK-Lazarus- linked-ICS-Activity-Group + electric-energy- Europe-East-Asia-North-America-targeting + 2017- 2018-active-period + retired-post-2020 + WASSONITE-relationship-distinct-tracking + no-demonstrated-ICS-disruption-capability + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.

canonical illustration of first-DPRK- attributed-ICS-focused-Activity-Group per Dragos taxonomy + Lazarus-Group-similarity attribution + electric energy reconnaissance focus + retired- inactive-status methodology for historical clusters + WASSONITE-distinct-but-related tracking pattern + no-ICS-disruption-capability assessment cited in essentially all subsequent DPRK-attributed ICS-targeting historical industry analyses through 2017-2026 period.

dprk_lazarus_linked_dragos_tracked_ics_electric_sector_2017_2018_retired confidence: high 14 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

COVELLITE is Dragos's canonical originally-DPRK- attributed designation for a Lazarus-linked ICS- targeting threat group historically active circa 2017-2018 targeting electric energy networks in Europe + East Asia + North America, subsequently retired per Dragos. DPRK + Lazarus-link attribution via Dragos canonical 2018 disclosure + SecurityWeek + Bleeping Computer industry coverage. Honest attribution caveat: COVELLITE operationally interleaves with the broader Lazarus Group (already curated as lazarus_group.yaml in corpus). WASSONITE relationship preserved as alias under andariel.yaml.

COVELLITE here represents Dragos's electric-sector-focused historical tracking. Standalone cluster paralleling chernovite_pipedream + kamacite + raspite_leafminer in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

Operational target profile
  • Electric energy networks signature primary.
  • Europe + East Asia + North America signature.
  • North American electric sector historical attacks per Dragos.
  • No longer active post-2020 per Dragos.
  • No demonstrated ICS-disruption capability per Dragos Operational attack architecture: (1) 2017 origin + DPRK-Lazarus-link (cluster- defining) (2) Electric energy reconnaissance Europe + East Asia + North America (cluster-defining) (3) Lazarus Group malware + infrastructure similarity (cluster-defining) (4) WASSONITE distinct-but-related Dragos tracking (cluster-defining) (5) No ICS-disruption-capability + ICS Cyber Kill Chain Stage 1 reconnaissance-focus assessment (cluster-defining) (6) Retired inactive post-2020 (cluster- defining) The cluster fills the Dragos-COVELLITE-DPRK- Lazarus-linked-ICS-Activity-Group + electric- energy-Europe-East-Asia-North-America-targeting + 2017-2018-active-period + retired-post-2020 + WASSONITE-relationship-distinct-tracking + no-demonstrated-ICS-disruption-capability + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.

Aliases

14
covellite_lazarus_icscovellitecovellite activity groupdragos covellite trackingcovellite dprk north korea attributedcovellite lazarus group infrastructure similaritycovellite electric energy europe east asia north americacovellite 2017 2018 active periodcovellite retired no longer active per dragoscovellite wassonite linked but distinctcovellite ics cyber kill chain stage 1 reconnaissancecovellite first dprk attributed ics focused activity groupcovellite electric energy reconnaissance onlycovellite dragos 2018 disclosure

Notable Campaigns

7
2020COVELLITE Retired Inactive Post-2020 Signature
2018COVELLITE WASSONITE Distinct-But-Related Dragos Tracking Signature
2017-2026Continued Industry Reference Status (2017-2026)
2017-2019COVELLITE No ICS-Disruption-Capability Assessment Signature
2017-2018COVELLITE North American Electric Sector Historical Attacks Signature
2017-2018COVELLITE Lazarus Group Malware + Infrastructure Similarity Signature
2017COVELLITE Origin, 2017 DPRK-Lazarus-Linked ICS Targeting

Attribution & Reporting

Attributed by
Dragos (canonical COVELLITE DPRK-Lazarus-linked Activity Group designation 2018)SecurityWeek (canonical Nine Distinct Threat Groups Targeting Industrial Systems Dragos coverage 2019)SecurityWeek (canonical More Threat Groups Target Electric Utilities in North America Dragos coverage)Bleeping Computer (canonical 2020 Dragos coverage New Actors Attack Industrial Control Systems retired-status disclosure)
Key reporting
reportDragos (2018): canonical COVELLITE DPRK-Lazarus-linked Activity Group designation
reportSecurityWeek (2019): Nine Distinct Threat Groups Targeting Industrial Systems Dragos coverage
reportSecurityWeek: More Threat Groups Target Electric Utilities in North America
reportBleeping Computer (2020): New Actors Attack Industrial Control Systems Old Ones Mature, retired-status disclosure
reportDragos threat groups summary: COVELLITE historical cluster reference

Operational

State sponsor

COVELLITE is Dragos's canonical originally-DPRK- attributed designation for a Lazarus-linked ICS- targeting threat group historically active circa 2017-2018 targeting electric energy networks in Europe + East Asia + North America, subsequently retired per Dragos. Per SecurityWeek covering Dragos: "The ninth group in Dragos' report is COVELLITE, which has been linked to North Korea's Lazarus Group, and which has been observed targeting networks associated with electric energy, primarily in Europe, East Asia, and North America." Honest attribution caveat: COVELLITE operationally interleaves with the broader Lazarus Group (already curated as lazarus_group.yaml in corpus). Dragos tracks COVELLITE as a distinct activity group based on Dragos-taxonomy ICS-focus methodology, but operational independence from broader Lazarus operations is not publicly established.

WASSONITE relationship is preserved as alias under andariel.yaml in corpus, COVELLITE here represents Dragos's electric- sector-focused tracking historically associated with Lazarus Group rather than the WASSONITE-as- Andariel framing. Per Bleeping Computer 2020 Dragos coverage: "Covellite and Electrum are no longer on the radar due to inactivity. This is likely because the actors switched to different tactics and changed the targeting focus." Per SecurityWeek covering Dragos: "COVELLITE did attack companies in the North American electric sector, but the group no longer appears to target this industry, and it lacks the capability to hack industrial systems." Attribution chain: (1) Dragos canonical 2018 COVELLITE designation + Lazarus-link: per SecurityWeek covering Dragos: "COVELLITE, which has been linked to North Korea's Lazarus Group, and which has been observed targeting networks associated with electric energy, primarily in Europe, East Asia, and North America." Cluster-defining canonical DPRK + Lazarus-link attribution.

(2) SecurityWeek 2019 + Bleeping Computer 2020 Dragos coverage retired-status disclosure: per SecurityWeek 2019: "COVELLITE's malware and infrastructure are similar to the one of the North Korea-linked Lazarus Group." Per Bleeping Computer 2020: "Covellite and Electrum are no longer on the radar due to inactivity. This is likely because the actors switched to different tactics and changed the targeting focus." (3) Dragos WASSONITE distinct-but-related tracking: per SecurityWeek 2019: "Another threat group whose existence was revealed in Dragos' report is WASSONITE, which appears to be linked to COVELLITE. COVELLITE's malware and infrastructure are similar to the one of the North Korea-linked Lazarus Group.

According to Dragos, COVELLITE did attack companies in the North American electric sector, but the group no longer appears to target this industry, and it lacks the capability to hack industrial systems. Dragos says the COVELLITE-linked WASSONITE, which has been around since at least 2018, has targeted electric generation, nuclear energy, manufacturing, and research entities in India, and likely South Korea and Japan." (4) Dragos retired status confirmation 2024+: COVELLITE no longer actively tracked as operational ICS threat group per Dragos 2024+ year-in-review reports, historically significant cluster preserved for reference.

Operational target profile
  • Electric energy networks signature primary per Dragos.
  • Europe signature per Dragos.
  • East Asia signature per Dragos.
  • North America signature per Dragos.
  • North American electric sector signature with attack against companies per SecurityWeek Dragos coverage.
  • No longer active electric sector targeting per Dragos 2020+.
  • No demonstrated ICS-disruption capability per Dragos, assessed as reconnaissance-focus The cluster fills the Dragos-COVELLITE-DPRK- Lazarus-linked-ICS-Activity-Group + electric- energy-Europe-East-Asia-North-America-targeting + 2017-2018-active-period + retired-post-2020 + WASSONITE-relationship-distinct-tracking + no-demonstrated-ICS-disruption-capability + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.
Motivations
dprk_lazarus_linked_ics_focused_threat_actor_dragos_designation_historical, electric_energy_network_reconnaissance_2017_2018_signature, europe_east_asia_north_america_electric_targeting_signature, lazarus_group_infrastructure_malware_similarity_signature, retired_inactive_post_2020_dragos_assessment_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)52/60 · 86%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SWITCHED TO DIFFERENT TACTICS + CHANGED TARGETING FOCUS PER DRAGOS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin