logo

sektorcert-angrebet-mod-dansk-kritisk-infrastruktur-tlp-clear-en.pdf

ID: 41e0c186-d265-446b-879d-9a0678269b72

STIX ID: report--41e0c186-d265-446b-879d-9a0678269b72

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2023-11-15

Last Modified Date: 2023-11-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
In May 2023 a coordinated campaign exploited critical Zyxel firewall vulnerabilities to compromise firewalls at dozens of Danish energy companies (22 affected), allowing attackers to execute code as root, exfiltrate configurations, and install Mirai/MooBot-derived payloads to conduct DDoS and brute-force operations; SektorCERT detected the campaign via a sector-wide sensor network, helped contain infections and island affected sites, collected IOCs and malware, engaged authorities, and issued recommendations including patching, network segmentation, supplier management and contingency planning. Indicators include multiple malicious payload URLs, specific IPs and domains, and temporal correlation of exploit activity across many targets; attribution remains uncertain though some indicators point to possible Sandworm involvement.