COVELLITE (Lazarus-linked ICS)
COVELLITE is Dragos's canonical originally-DPRK- attributed designation for a Lazarus-linked ICS- targeting threat group historically active circa 2017-2018 targeting electric energy networks in Europe + East Asia + North America, subsequently retired per Dragos 2020+ year-in-review tracking; DPRK + Lazarus-link attribution via Dragos canonical 2018 disclosure ("COVELLITE, which has been linked to North Korea's Lazarus Group, and which has been observed targeting networks associated with electric energy, primarily in Europe, East Asia, and North America") + SecurityWeek canonical Nine Distinct Threat Groups Targeting Industrial Systems 2019 coverage + SecurityWeek More Threat Groups Target Electric Utilities in North America coverage + Bleeping Computer canonical 2020 New Actors Attack Industrial Control Systems Old Ones Mature retired-status disclosure ("Covellite and Electrum are no longer on the radar due to inactivity. This is likely because the actors switched to different tactics and changed the targeting focus")
honest attribution caveat: COVELLITE operationally interleaves with the broader Lazarus Group (already curated as lazarus_group.yaml in corpus), Dragos tracks COVELLITE as a distinct activity group based on Dragos-taxonomy ICS-focus methodology, but operational independence from broader Lazarus operations is not publicly established + WASSONITE relationship is preserved as alias under andariel.yaml in corpus, with COVELLITE here representing Dragos's electric- sector-focused tracking historically associated with Lazarus rather than the WASSONITE-as-Andariel framing.
standalone cluster paralleling chernovite_pipedream + kamacite + raspite_leafminer in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.
operational target profile signature electric energy networks primary target sector per Dragos + signature Europe + East Asia + North America geographic distribution per Dragos + signature North American electric sector historical attack companies per SecurityWeek Dragos coverage ("COVELLITE did attack companies in the North American electric sector, but the group no longer appears to target this industry, and it lacks the capability to hack industrial systems") + no longer active post-2020 per Dragos year-in-review reports + no demonstrated ICS- disruption capability per Dragos canonical assessment.
operational attack architecture: (1) cluster-defining 2017-2018 operational origin with DPRK-Lazarus-link attribution establishing first-DPRK-attributed-ICS-focused- Activity-Group designation per Dragos taxonomy; (2) cluster-defining electric energy reconnaissance focus in Europe + East Asia + North America geographic distribution.
(3) cluster-defining Lazarus Group malware + infrastructure similarity per SecurityWeek 2019 ("COVELLITE's malware and infrastructure are similar to the one of the North Korea-linked Lazarus Group") providing technical attribution evidence.
(4) cluster-defining WASSONITE distinct-but-related Dragos tracking signature with Dragos canonical assessment ("Another threat group whose existence was revealed in Dragos' report is WASSONITE, which appears to be linked to COVELLITE... Dragos says the COVELLITE-linked WASSONITE, which has been around since at least 2018, has targeted electric generation, nuclear energy, manufacturing, and research entities in India, and likely South Korea and Japan"), curation note: WASSONITE alias preserved under andariel.yaml in corpus, COVELLITE here represents the electric-energy-Europe-East-Asia-North- America-focused historical Dragos tracking.
(5) cluster-defining no-ICS-disruption-capability assessment per Dragos with ICS Cyber Kill Chain Stage 1 reconnaissance-focus operational assessment distinguishing COVELLITE from ELECTRUM + XENOTIME + CHERNOVITE disruption-capable actors; (6) cluster-defining retired-inactive post-2020 status per Bleeping Computer Dragos coverage preserving COVELLITE as historically-significant- but-operationally-dormant cluster with tactics + targeting focus shifting hypothesized rather than definitive operational termination.
(7) signature DTrack RAT + credential capture tools + system tools tradecraft per Dragos WASSONITE-related analysis applicable to broader DPRK Lazarus- associated cluster tooling.
(8) signature ICS Cyber Kill Chain Stage 1 reconnaissance + initial access operational pattern consistent with Lazarus-associated DPRK cluster intelligence collection objectives prior to capability transition; cluster fills the Dragos-COVELLITE-DPRK-Lazarus- linked-ICS-Activity-Group + electric-energy- Europe-East-Asia-North-America-targeting + 2017- 2018-active-period + retired-post-2020 + WASSONITE-relationship-distinct-tracking + no-demonstrated-ICS-disruption-capability + ICS-Cyber-Kill-Chain-Stage-1-reconnaissance-focus position in OT/ICS Dragos-taxonomy actor cluster cell.
canonical illustration of first-DPRK- attributed-ICS-focused-Activity-Group per Dragos taxonomy + Lazarus-Group-similarity attribution + electric energy reconnaissance focus + retired- inactive-status methodology for historical clusters + WASSONITE-distinct-but-related tracking pattern + no-ICS-disruption-capability assessment cited in essentially all subsequent DPRK-attributed ICS-targeting historical industry analyses through 2017-2026 period.