BlackEnergy
MITRE ATT&CK: S0089 View on attack.mitre.org
Aliases: Black Energy, BlackEnergy
- First seen
- 2007-01-01 00:00:00
- Malware type
- botnet, ddos, trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3 (3 malicious)
- Last IoC activity
- 2026-08-28 21:41:51
- Profile updated
- 2026-07-07 15:44:43
Targeted industries: energy-and-utilities government-and-public-sector
Targeted regions: country_code:ua country_code:ge
Context
BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to BlackEnergy (S0089). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | tuxuu.u-gu.ru | 2026-08-28 | 1 |
| URL | http://tuxuu.u-gu.ru/index.php | 2025-09-30 | 1 |
| URL | http://94.100.26.17/stat/auth.php | 2025-09-30 | 1 |
Detection coverage
- 1 YARA rules
- 433 Sigma rules
Malware & tools used
- Bypass User Account Control (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Indicator Removal (attack-pattern)
- Screen Capture (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Code Signing Policy Modification (attack-pattern)
- Process Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Network Service Discovery (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Shortcut Modification (attack-pattern)
- Credentials In Files (attack-pattern)
- Keylogging (attack-pattern)
- Windows Service (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Data Destruction (attack-pattern)
- Services File Permissions Weakness (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Fallback Channels (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
- 2015 Ukraine Electric Power Attack (campaign)
Exploited vulnerabilities
- CVE-2014-4114 (vulnerability)
Detection rules
- MALPEDIA_Win_Blackenergy_Auto (yara-rule)
Reports & references
- MITRE ATT&CK — G0034 (report)
- services.google.com — Apt44 Unearthing Sandworm (report)
- CISA — Aa22 110A (report)
- blog-assets.f-secure.com — Blackenergy Quedagh (report)
- gov.uk — Uk Exposes Series Of Russian Cyber Attacks Against Olympic And Paralympic Games (report)
- secureworks.com — Iron Viking (report)
- Broadcom/Symantec — Attacks Against Critical Infrastructrure (report)
- tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
- CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
- ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
- cocomelonc.github.io — Malware Pers 1 (report)
- cocomelonc.github.io — Malware Pers 4 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Blackenergy (report)
- Kaspersky — 67353 (report)
- threatconnect.com — Casting A Light On Blackenergy (report)
- go.recordedfuture.com — Cta 2021 0909 (report)
- enterprise.verizon.com — 2019 Data Breach Investigations Report (report)
- riskint.blog — Revisited Fancy Bear S New Faces And Sandworms Too (report)
- pds15.egloos.com — Blackenergy Ddos Bot Analysis (report)
- picussecurity.com — Picus 10 Critical Mitre Attck Techniques T1055 Process Injection (report)
- Kaspersky — 73440 (report)
- secureworks.com — Blackenergy2 (report)
- web.archive.org — Black Energy Crypto (report)
- virusbulletin.com — Vb2016 Cherepanov Lipovsky (report)
- marcusedmondson.com — Black Energy Analysis (report)