KOSTOVITE is an industrial intrusion activity group tracked for operations against ICS/OT environments. It has been assessed as reaching Stage 2 of the ICS Cyber Kill Chain, indicating confirmed access into operational technology networks and devices rather than remaining limited to IT-side reconnaissance. The group has been linked to compromises of internet-exposed remote access infrastructure and perimeter access devices, followed by use of stolen credentials and living-off-the-land techniques to move laterally from enterprise environments into OT networks. KOSTOVITE has been associated with an intrusion against an energy organization in early 2021 in which the actor exploited a vulnerability in a remote access solution, then leveraged credential abuse and lateral movement to gain access into OT. Reporting also links KOSTOVITE to activity involving perimeter-device compromise, reconnaissance, and exfiltration. APT5 is referenced as a KOSTOVITE-linked group, with observed exploitation of a zero-day affecting Citrix perimeter access devices. Overall, KOSTOVITE is characterized by strong initial-access tradecraft against exposed remote access systems, effective lateral movement into industrial environments, and post-compromise activity consistent with reconnaissance and data theft in support of operations against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Specializes in compromising remote access and lateral movement into ICS/OT, linked to APT5, and exploits zero-days in perimeter devices.
Compromises perimeter devices and uses LOTL techniques for reconnaissance and data exfiltration.
Compromises perimeter devices and uses LOTL techniques for reconnaissance and data exfiltration.
Stage 2 ICS intrusion group targeting energy organizations, exploiting remote access and VPN vulnerabilities, stealing credentials, and moving laterally into OT using living-off-the-land techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.