BlackEnergy

MITRE ATT&CK: S0089 View on attack.mitre.org

Aliases: Black Energy, BlackEnergy

First seen
2007-01-01 00:00:00
Malware type
botnet, ddos, trojan
Family
Malware family
Operating systems
windows
Related IoCs
3 (3 malicious)
Last IoC activity
2026-08-28 21:41:51
Profile updated
2026-07-07 15:44:43

Targeted industries: energy-and-utilities government-and-public-sector

Targeted regions: country_code:ua country_code:ge

Context

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to BlackEnergy (S0089). The 3 most recently updated:

TypeIndicatorUpdatedSources
hostname tuxuu.u-gu.ru 2026-08-28 1
URL http://tuxuu.u-gu.ru/index.php 2025-09-30 1
URL http://94.100.26.17/stat/auth.php 2025-09-30 1

Detection coverage

  • 1 YARA rules
  • 433 Sigma rules

Malware & tools used

  • Bypass User Account Control (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Screen Capture (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • Process Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Shortcut Modification (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Keylogging (attack-pattern)
  • Windows Service (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Data Destruction (attack-pattern)
  • Services File Permissions Weakness (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

  • Sandworm Team (threat-actor)
  • 2015 Ukraine Electric Power Attack (campaign)

Exploited vulnerabilities

  • CVE-2014-4114 (vulnerability)

Detection rules

  • MALPEDIA_Win_Blackenergy_Auto (yara-rule)

Reports & references

  • MITRE ATT&CK — G0034 (report)
  • services.google.com — Apt44 Unearthing Sandworm (report)
  • CISA — Aa22 110A (report)
  • blog-assets.f-secure.com — Blackenergy Quedagh (report)
  • gov.uk — Uk Exposes Series Of Russian Cyber Attacks Against Olympic And Paralympic Games (report)
  • secureworks.com — Iron Viking (report)
  • Broadcom/Symantec — Attacks Against Critical Infrastructrure (report)
  • tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
  • cocomelonc.github.io — Malware Pers 1 (report)
  • cocomelonc.github.io — Malware Pers 4 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blackenergy (report)
  • Kaspersky — 67353 (report)
  • threatconnect.com — Casting A Light On Blackenergy (report)
  • go.recordedfuture.com — Cta 2021 0909 (report)
  • enterprise.verizon.com — 2019 Data Breach Investigations Report (report)
  • riskint.blog — Revisited Fancy Bear S New Faces And Sandworms Too (report)
  • pds15.egloos.com — Blackenergy Ddos Bot Analysis (report)
  • picussecurity.com — Picus 10 Critical Mitre Attck Techniques T1055 Process Injection (report)
  • Kaspersky — 73440 (report)
  • secureworks.com — Blackenergy2 (report)
  • web.archive.org — Black Energy Crypto (report)
  • virusbulletin.com — Vb2016 Cherepanov Lipovsky (report)
  • marcusedmondson.com — Black Energy Analysis (report)

External references