Home/Threat Actor/KOSTOVITE
Threat Actor

KOSTOVITE

kostovite · dragos_tracked_ics_activity_group_unc2630_apt5_significant_overlap_stage_2_capable · active since 2021-03

KOSTOVITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group with significant tactics, techniques, and procedures (TTP) and technical overlaps with UNC2630 (Mandiant alternative tracking, later attributed to APT5 Chinese state-sponsored cluster) that compromised a renewable energy operator in March 2021 via Ivanti Connect Secure (Pulse Secure) zero-day vulnerability exploitation reaching ICS Cyber Kill Chain Stage 2 with confirmed OT network and device access per Dragos canonical threat profile ("KOSTOVITE is an adversary with significant tactics, techniques, and procedures TTP and technical overlaps with the threat group known as UNC2630... In March of 2021, the activity group KOSTOVITE compromised a renewable energy operator... In March 2021, when KOSTOVITE compromised the perimeter of this ICS/OT network, it exploited a zero-day vulnerability in the popular remote access solution Ivanti Connect Secure, formerly known as Pulse Secure")

state-actor attribution via Dragos canonical KOSTOVITE Activity Group designation + Mandiant UNC2630 alternative tracking + APT5 Chinese state-sponsored attribution overlap + Dragos 2025 threat groups summary continued tracking + Dragos MITRE ATT&CK for ICS framework taxonomy listing.

honest attribution caveat: KOSTOVITE significantly overlaps with UNC2630 (Mandiant tracking) which Mandiant attributes to APT5 Chinese state- sponsored cluster, UNC2630/APT5 not currently curated in corpus, KOSTOVITE here represents Dragos's ICS-focused subset tracking + Dragos doesn't explicitly endorse APT5 attribution due to canonical no-public-nation-attribution policy; standalone cluster paralleling laurionite + gananite + bauxite in v0.1.172 OT/ICS Dragos- newer-taxonomy actor cluster cell continuation extending v0.1.166 chernovite/kamacite/raspite/ covellite classic Dragos taxonomy cell; operational target profile signature renewable energy operator primary target per Dragos canonical March 2021 case + signature multi- continental facilities (two continents from one ingress per Dragos) + signature OT environments of multiple facilities reflecting interconnectivity- risk operational scope + signature non- opportunistic-purposeful-execution per Dragos investigation conclusion ("Dragos deployed a team of investigators to analyze the intrusion and determined that the organization was not an opportunistic target. This narrative is the background behind the investigation and successful remediation and recovery following the purposefully executed intrusion")

operational attack architecture: (1) cluster-defining UNC2630/APT5 significant TTP + technical overlap signature per Dragos canonical assessment establishing Chinese-state-sponsored attribution via Mandiant cross-vendor agreement (Dragos no- public-nation-attribution policy preserved)

(2) cluster-defining March 2021 renewable energy operator compromise canonical case establishing KOSTOVITE operational pattern with Dragos investigation team forensic analysis.

(3) cluster-defining Ivanti Connect Secure (Pulse Secure) zero-day exploitation initial access consistent with UNC2630/APT5 broader Pulse Secure 2021 campaign tradecraft (CVE-2021-22893 + related April 2021 vulnerabilities)

(4) cluster-defining ICS Cyber Kill Chain Stage 2 capability with confirmed OT network and device access placing KOSTOVITE among elite Dragos- tracked Stage-2-capable clusters (alongside BAUXITE + CHERNOVITE + VOLTZITE + ELECTRUM); (5) cluster-defining dedicated operational relay infrastructure origin obfuscation tradecraft consistent with Chinese-state- sponsored APT operational relay box (ORB) practices.

(6) cluster-defining legitimate account credentials theft + reuse lateral movement two-continents single-ingress signature with OT environments of multiple facilities accessed via stolen account information from one single ingress location highlighting interconnectivity-risk operational scope.

(7) cluster-defining organic-infrastructure-only post-perimeter LOTL signature per Dragos ("Once past the perimeter ingress, KOSTOVITE used only what is referred to as the target's organic infrastructure, meaning no tools or code from outside the target's network, to move laterally across target infrastructure") distinguishing from external-tool-dependent actors.

(8) cluster- defining undetected-at-least-one-month-OT- networks signature per Dragos investigation assessment highlighting visibility gap concerns for OT defenders.

(9) cluster-defining monitoring + control servers access signature establishing Stage 2 OT operational impact capability.

(10) signature 2025 Dragos continued tracking with perimeter device compromise + LOTL tradecraft summary ("KOSTOVITE: Uses perimeter device compromise and LOTL techniques for reconnaissance and exfiltration")

(11) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference-status alongside BAUXITE + BENTONITE + CHERNOVITE + CHRYSENE + DYMALLOY + ELECTRUM + GANANITE + GRAPHITE + HEXANE + KAMACITE + LAURIONITE + MAGNALLIUM + PARISITE + PETROVITE + RASPITE + STIBNITE + TALONITE + VANADINITE + VOLTZITE + WASSONITE + XENOTIME Dragos-tracked clusters; cluster fills the Dragos-KOSTOVITE-Activity- Group + UNC2630-APT5-significant-TTP-technical- overlap + March-2021-renewable-energy-operator- compromise + Ivanti-Connect-Secure-Pulse-Secure- zero-day-exploitation + ICS-Cyber-Kill-Chain- Stage-2-capability + dedicated-operational-relay- infrastructure-obfuscation + legitimate-account- credentials-theft-reuse + lateral-movement-two- continents-single-ingress + organic-infrastructure- only-post-perimeter-LOTL + undetected-at-least- one-month-OT-networks position in OT/ICS Dragos- newer-taxonomy actor cluster cell.

canonical illustration of UNC2630/APT5 significant-TTP- technical-overlap methodology + Ivanti Connect Secure (Pulse Secure) zero-day exploitation + ICS Cyber Kill Chain Stage 2 capability with confirmed OT access + dedicated operational relay infrastructure obfuscation tradecraft + legitimate credentials lateral movement two-continents single-ingress interconnectivity risk + organic- infrastructure-only post-perimeter LOTL + undetected-one-month-OT-networks visibility-gap signature cited in essentially all subsequent Ivanti-Pulse-Secure + Stage-2-ICS-capable industry analyses through 2021-2026 period.

dragos_tracked_ics_activity_group_unc2630_apt5_significant_overlap_stage_2_capable confidence: high 15 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited1

Profile

KOSTOVITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group with significant TTPs and technical overlaps with UNC2630 (Mandiant alternative tracking, later attributed to APT5 Chinese state-sponsored cluster). Compromised a renewable energy operator in March 2021 via Ivanti Connect Secure (Pulse Secure) zero-day reaching ICS Cyber Kill Chain Stage 2 with confirmed OT network and device access. State-actor attribution via Dragos canonical KOSTOVITE Activity Group designation + Mandiant UNC2630 alternative tracking + APT5 Chinese state-sponsored attribution overlap (UNC2630/APT5 not currently curated in corpus, KOSTOVITE represents Dragos's ICS-focused subset tracking).

Honest attribution caveat: KOSTOVITE significantly overlaps with UNC2630 (Mandiant) which Mandiant attributes to APT5 Chinese state-sponsored cluster, Dragos doesn't explicitly endorse the attribution due to canonical no-public-nation- attribution policy but UNC2630-overlap implies potential Chinese state-sponsored attribution. Standalone cluster paralleling laurionite + gananite + bauxite in v0.1.172 OT/ICS Dragos- newer-taxonomy actor cluster cell continuation.

Operational target profile
  • Renewable energy operator signature primary.
  • Multi-continental facilities (two continents from one ingress)
  • OT environments of multiple facilities.
  • Not opportunistic targeting Operational attack architecture: (1) UNC2630/APT5 significant TTP + technical overlap (cluster-defining) (2) March 2021 renewable energy operator compromise (cluster-defining) (3) Ivanti Connect Secure (Pulse Secure) zero- day exploitation initial access (cluster-defining) (4) ICS Cyber Kill Chain Stage 2 capability with confirmed OT access (cluster-defining) (5) Dedicated operational relay infrastructure origin obfuscation (cluster-defining) (6) Legitimate account credentials lateral movement two-continents single-ingress (cluster- defining) (7) Organic-infrastructure-only post-perimeter LOTL signature (cluster-defining) (8) Undetected at least one month in OT networks (cluster-defining) The cluster fills the Dragos-KOSTOVITE-Activity- Group + UNC2630-APT5-significant-TTP-technical- overlap + March-2021-renewable-energy-operator- compromise + Ivanti-Connect-Secure-Pulse-Secure- zero-day-exploitation + ICS-Cyber-Kill-Chain- Stage-2-capability + dedicated-operational-relay- infrastructure-obfuscation + legitimate-account- credentials-theft-reuse + lateral-movement-two- continents-single-ingress + organic-infrastructure- only-post-perimeter-LOTL + undetected-at-least- one-month-OT-networks + 2024-Dragos-Year-in- Review-disclosure position in OT/ICS Dragos- newer-taxonomy actor cluster cell.

Aliases

15
kostovitekostovite activity groupdragos kostovite trackingkostovite unc2630 overlapkostovite march 2021 renewable energy operator compromisekostovite ivanti connect secure pulse secure zero-day exploitationkostovite ics cyber kill chain stage 2 capabilitykostovite confirmed ot network device accesskostovite perimeter device compromise lotl tradecraftkostovite lateral movement two continents single ingresskostovite dedicated operational relay infrastructure obfuscationkostovite legitimate account credentials theft signaturekostovite undetected ot networks at least one monthkostovite organic infrastructure only post-perimeter signaturekostovite renewable energy ics ot target compromise

Notable Campaigns

10
2025KOSTOVITE 2025 Dragos Perimeter Device + LOTL Continued Tracking Signature
2021-2026Continued Industry Reference Status (2021-2026)
2021KOSTOVITE Canonical March 2021 Renewable Energy Operator Compromise
2021KOSTOVITE Ivanti Connect Secure (Pulse Secure) Zero-Day Exploitation Initial Access Signature
2021KOSTOVITE UNC2630 Significant TTP + Technical Overlap Signature
2021KOSTOVITE ICS Cyber Kill Chain Stage 2 Capability with Confirmed OT Access Signature
2021KOSTOVITE Dedicated Operational Relay Infrastructure Origin Obfuscation Signature
2021KOSTOVITE Legitimate Credentials Lateral Movement Two-Continents Single-Ingress Signature
2021KOSTOVITE Organic-Infrastructure-Only Post-Perimeter LOTL Signature
2021KOSTOVITE Undetected At Least One Month in OT Networks Signature

Attribution & Reporting

Attributed by
Dragos (canonical KOSTOVITE Activity Group designation + March 2021 renewable energy operator investigation)Dragos threat profile / WorldView Threat Intelligence (canonical)Mandiant (canonical UNC2630 alternative tracking + APT5 Chinese state-sponsored attribution)Dragos threat groups summary 2025 (canonical perimeter device + LOTL tradecraft summary)Dragos MITRE ATT&CK for ICS framework documentation (canonical taxonomy listing)
Key reporting
reportDragos: canonical KOSTOVITE Activity Group designation + March 2021 renewable energy operator investigation
reportDragos threat profile / WorldView Threat Intelligence: canonical KOSTOVITE tracking
reportMandiant: canonical UNC2630 alternative tracking + APT5 Chinese state-sponsored attribution
reportDragos threat groups summary (2025): perimeter device + LOTL tradecraft summary
reportDragos MITRE ATT&CK for ICS framework: canonical taxonomy listing

Operational

State sponsor

KOSTOVITE is Dragos's tracked Activity Group designation for an ICS-targeting threat group with significant tactics, techniques, and procedures (TTP) and technical overlaps with UNC2630 (Mandiant alternative tracking), UNC2630 later attributed by Mandiant to APT5 Chinese state-sponsored cluster. KOSTOVITE compromised a renewable energy operator in March 2021 via Ivanti Connect Secure (Pulse Secure) zero-day vulnerability exploitation reaching ICS Cyber Kill Chain Stage 2 with confirmed OT network and device access. Honest attribution caveat: KOSTOVITE operationally overlaps significantly with UNC2630 (Mandiant tracking) which Mandiant attributes to APT5 Chinese state-sponsored cluster.

UNC2630/APT5 is not currently curated as a separate cluster in corpus, KOSTOVITE here represents Dragos's ICS- focused subset tracking. Dragos doesn't publicly attribute KOSTOVITE to specific nation-state consistent with canonical no-public-nation- attribution policy, but UNC2630-overlap implies potential Chinese state-sponsored attribution that is documented but not explicitly endorsed by Dragos. Attribution chain: (1) Dragos canonical KOSTOVITE Activity Group designation: per Dragos threat profile: "KOSTOVITE is an adversary with significant tactics, techniques, and procedures (TTP) and technical overlaps with the threat group known as UNC2630." (2) March 2021 renewable energy operator compromise canonical investigation: per Dragos: "In March of 2021, the activity group KOSTOVITE compromised a renewable energy operator.

Dragos deployed a team of investigators to analyze the intrusion and determined that the organization was not an opportunistic target. This narrative is the background behind the investigation and successful remediation and recovery following the purposefully executed intrusion by the activity group Dragos now tracks as KOSTOVITE." (3) Ivanti Connect Secure (Pulse Secure) zero- day exploitation initial access canonical attribution: per Dragos: "In March 2021, when KOSTOVITE compromised the perimeter of this ICS/ OT network, it exploited a zero-day vulnerability in the popular remote access solution Ivanti Connect Secure, formerly known as Pulse Secure." Cluster-defining Ivanti Connect Secure zero-day exploitation signature. (4) ICS Cyber Kill Chain Stage 2 capability + OT network device access canonical: per Dragos: "The Dragos investigation for KOSTOVITE's target showed that KOSTOVITE reached Stage 2 of ICS Kill Chain capabilities with confirmed access into the OT networks and devices." Cluster- defining Stage 2 capability designation.

(5) Dedicated operational relay infrastructure + legitimate account credentials canonical tradecraft: per Dragos: "KOSTOVITE used dedicated operational relay infrastructure against this target to obfuscate the origin of its activities and then stole and used legitimate account credentials for its intrusion. KOSTOVITE then used the stolen account information to move laterally and gain access to the OT environments of multiple facilities on two continents from the one single ingress location." (6) Organic-infrastructure-only post-perimeter LOTL signature: per Dragos: "Once past the perimeter ingress, KOSTOVITE used only what is referred to as the target's organic infrastructure, meaning no tools or code from outside the target's network, to move laterally across target infrastructure. This adversary then accessed servers used by the target for monitoring and control." (7) Undetected for at least one month canonical assessment: per Dragos: "In the course of the investigation, the Dragos analysts determined the adversary had been undetected and active in the OT networks for at least a month." (8) Dragos 2025 KOSTOVITE perimeter device + LOTL tradecraft summary: per Dragos threat groups summary 2025: "KOSTOVITE: Uses perimeter device compromise and LOTL techniques for reconnaissance and exfiltration.

" Operational target profile
  • Renewable energy operator signature primary per Dragos canonical March 2021 case.
  • Multi-continental facilities per Dragos (two continents from one ingress)
  • OT environments of multiple facilities signature interconnected-organizations risk per Dragos.
  • Not opportunistic targeting per Dragos investigation conclusion The cluster fills the Dragos-KOSTOVITE-Activity- Group + UNC2630-APT5-significant-TTP-technical- overlap + March-2021-renewable-energy-operator- compromise + Ivanti-Connect-Secure-Pulse-Secure- zero-day-exploitation + ICS-Cyber-Kill-Chain- Stage-2-capability + dedicated-operational-relay- infrastructure-obfuscation + legitimate-account- credentials-theft-reuse + lateral-movement-two- continents-single-ingress + organic-infrastructure- only-post-perimeter-LOTL + undetected-at-least- one-month-OT-networks + 2024-Dragos-Year-in- Review-disclosure position in OT/ICS Dragos- newer-taxonomy actor cluster cell.
Motivations
dragos_tracked_ics_activity_group_unc2630_apt5_significant_overlap, ivanti_connect_secure_pulse_secure_zero_day_exploitation_signature, ics_cyber_kill_chain_stage_2_capability_confirmed_ot_access, dedicated_operational_relay_infrastructure_obfuscation_tradecraft, organic_infrastructure_only_post_perimeter_lotl_signature, lateral_movement_two_continents_single_ingress_interconnectivity_risk
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)44/60 · 73%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MONITORING AND CONTROL SERVERS ACCESS SIGNATURE

CVEs Exploited

1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin