KOSTOVITE
KOSTOVITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group with significant tactics, techniques, and procedures (TTP) and technical overlaps with UNC2630 (Mandiant alternative tracking, later attributed to APT5 Chinese state-sponsored cluster) that compromised a renewable energy operator in March 2021 via Ivanti Connect Secure (Pulse Secure) zero-day vulnerability exploitation reaching ICS Cyber Kill Chain Stage 2 with confirmed OT network and device access per Dragos canonical threat profile ("KOSTOVITE is an adversary with significant tactics, techniques, and procedures TTP and technical overlaps with the threat group known as UNC2630... In March of 2021, the activity group KOSTOVITE compromised a renewable energy operator... In March 2021, when KOSTOVITE compromised the perimeter of this ICS/OT network, it exploited a zero-day vulnerability in the popular remote access solution Ivanti Connect Secure, formerly known as Pulse Secure")
state-actor attribution via Dragos canonical KOSTOVITE Activity Group designation + Mandiant UNC2630 alternative tracking + APT5 Chinese state-sponsored attribution overlap + Dragos 2025 threat groups summary continued tracking + Dragos MITRE ATT&CK for ICS framework taxonomy listing.
honest attribution caveat: KOSTOVITE significantly overlaps with UNC2630 (Mandiant tracking) which Mandiant attributes to APT5 Chinese state- sponsored cluster, UNC2630/APT5 not currently curated in corpus, KOSTOVITE here represents Dragos's ICS-focused subset tracking + Dragos doesn't explicitly endorse APT5 attribution due to canonical no-public-nation-attribution policy; standalone cluster paralleling laurionite + gananite + bauxite in v0.1.172 OT/ICS Dragos- newer-taxonomy actor cluster cell continuation extending v0.1.166 chernovite/kamacite/raspite/ covellite classic Dragos taxonomy cell; operational target profile signature renewable energy operator primary target per Dragos canonical March 2021 case + signature multi- continental facilities (two continents from one ingress per Dragos) + signature OT environments of multiple facilities reflecting interconnectivity- risk operational scope + signature non- opportunistic-purposeful-execution per Dragos investigation conclusion ("Dragos deployed a team of investigators to analyze the intrusion and determined that the organization was not an opportunistic target. This narrative is the background behind the investigation and successful remediation and recovery following the purposefully executed intrusion")
operational attack architecture: (1) cluster-defining UNC2630/APT5 significant TTP + technical overlap signature per Dragos canonical assessment establishing Chinese-state-sponsored attribution via Mandiant cross-vendor agreement (Dragos no- public-nation-attribution policy preserved)
(2) cluster-defining March 2021 renewable energy operator compromise canonical case establishing KOSTOVITE operational pattern with Dragos investigation team forensic analysis.
(3) cluster-defining Ivanti Connect Secure (Pulse Secure) zero-day exploitation initial access consistent with UNC2630/APT5 broader Pulse Secure 2021 campaign tradecraft (CVE-2021-22893 + related April 2021 vulnerabilities)
(4) cluster-defining ICS Cyber Kill Chain Stage 2 capability with confirmed OT network and device access placing KOSTOVITE among elite Dragos- tracked Stage-2-capable clusters (alongside BAUXITE + CHERNOVITE + VOLTZITE + ELECTRUM); (5) cluster-defining dedicated operational relay infrastructure origin obfuscation tradecraft consistent with Chinese-state- sponsored APT operational relay box (ORB) practices.
(6) cluster-defining legitimate account credentials theft + reuse lateral movement two-continents single-ingress signature with OT environments of multiple facilities accessed via stolen account information from one single ingress location highlighting interconnectivity-risk operational scope.
(7) cluster-defining organic-infrastructure-only post-perimeter LOTL signature per Dragos ("Once past the perimeter ingress, KOSTOVITE used only what is referred to as the target's organic infrastructure, meaning no tools or code from outside the target's network, to move laterally across target infrastructure") distinguishing from external-tool-dependent actors.
(8) cluster- defining undetected-at-least-one-month-OT- networks signature per Dragos investigation assessment highlighting visibility gap concerns for OT defenders.
(9) cluster-defining monitoring + control servers access signature establishing Stage 2 OT operational impact capability.
(10) signature 2025 Dragos continued tracking with perimeter device compromise + LOTL tradecraft summary ("KOSTOVITE: Uses perimeter device compromise and LOTL techniques for reconnaissance and exfiltration")
(11) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference-status alongside BAUXITE + BENTONITE + CHERNOVITE + CHRYSENE + DYMALLOY + ELECTRUM + GANANITE + GRAPHITE + HEXANE + KAMACITE + LAURIONITE + MAGNALLIUM + PARISITE + PETROVITE + RASPITE + STIBNITE + TALONITE + VANADINITE + VOLTZITE + WASSONITE + XENOTIME Dragos-tracked clusters; cluster fills the Dragos-KOSTOVITE-Activity- Group + UNC2630-APT5-significant-TTP-technical- overlap + March-2021-renewable-energy-operator- compromise + Ivanti-Connect-Secure-Pulse-Secure- zero-day-exploitation + ICS-Cyber-Kill-Chain- Stage-2-capability + dedicated-operational-relay- infrastructure-obfuscation + legitimate-account- credentials-theft-reuse + lateral-movement-two- continents-single-ingress + organic-infrastructure- only-post-perimeter-LOTL + undetected-at-least- one-month-OT-networks position in OT/ICS Dragos- newer-taxonomy actor cluster cell.
canonical illustration of UNC2630/APT5 significant-TTP- technical-overlap methodology + Ivanti Connect Secure (Pulse Secure) zero-day exploitation + ICS Cyber Kill Chain Stage 2 capability with confirmed OT access + dedicated operational relay infrastructure obfuscation tradecraft + legitimate credentials lateral movement two-continents single-ingress interconnectivity risk + organic- infrastructure-only post-perimeter LOTL + undetected-one-month-OT-networks visibility-gap signature cited in essentially all subsequent Ivanti-Pulse-Secure + Stage-2-ICS-capable industry analyses through 2021-2026 period.