Industroyer

MITRE ATT&CK: S0604 View on attack.mitre.org

Aliases: CRASHOVERRIDE, Win32/Industroyer, Crash, CrashOverride, Industroyer

First seen
2016-12-01 00:00:00
Malware type
wiper
Family
Malware family
Operating systems
windows
Related IoCs
3 (3 malicious)
Last IoC activity
2026-06-26 06:27:09
Profile updated
2026-07-07 12:44:30

Targeted industries: energy-and-utilities

Targeted regions: country_code:ua

Context

Industroyer is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS), specifically components used in electrical substations. Industroyer was used in the attacks on the Ukrainian power grid in December 2016. This is the first publicly known malware specifically designed to target and impact operations in the electric grid.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to Industroyer (S0604). The 3 most recently updated:

Detection coverage

  • 1 YARA rules
  • 475 Sigma rules

Malware & tools used

  • Windows Service (attack-pattern)
  • Data Destruction (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Service Stop (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Application or System Exploitation (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Query Registry (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Command-Line Interface (attack-pattern)
  • Connection Proxy (attack-pattern)
  • Denial of Service (attack-pattern)
  • Reporting Message (attack-pattern)
  • Remote System Information Discovery (attack-pattern)

Used by threat actors

  • 2016 Ukraine Electric Power Attack (campaign)
  • Sandworm Team (threat-actor)

Detection rules

  • MALPEDIA_Win_Industroyer_Auto (yara-rule)

Reports & references

  • dragos.com — Crashoverride 01 (report)
  • ESET — Win32 Industroyer (report)
  • services.google.com — Apt44 Unearthing Sandworm (report)
  • CISA — Aa22 110A (report)
  • gov.uk — Uk Exposes Series Of Russian Cyber Attacks Against Olympic And Paralympic Games (report)
  • secureworks.com — Iron Viking (report)
  • ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
  • pylos.co — Threat Intelligence And The Limits Of Malware Analysis (report)
  • tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
  • ESET — Industroyer2 Industroyer Reloaded (report)
  • riskint.blog — Revisited Fancy Bear S New Faces And Sandworms Too (report)
  • CERT-UA — 39518 (report)
  • Mandiant — Mandiant Red Team Emulates Fin11 Tactics (report)
  • virusbulletin.com — Vb2019 Paper Rich Headers Leveraging Mysterious Artifact Pe Format (report)
  • blog.nviso.eu — Threat Update Ukraine Russia Tensions (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Industroyer (report)
  • Wikipedia — Industroyer (report)
  • sos-vo.org — Hotsos2024 Taleoftwoindustroyers (report)
  • hub.dragos.com — Dragos Manufacturing%20Threat%20Perspective 1120 (report)
  • ESET — Industroyer Biggest Threat Industrial Control Systems Since Stuxnet (report)
  • domaintools.com — Visibility Monitoring And Critical Infrastructure Security (report)
  • zambo99.github.io — S&P2024 (report)
  • virusbulletin.com — Last Minute Paper Industroyer Biggest Threat Industrial Control Systems Stuxnet (report)

External references