Industroyer, also known as CRASHOVERRIDE, is a Windows-based industrial control system malware framework designed to disrupt electric power grids. It was used against a Ukrainian electrical transmission substation in December 2016, causing a power outage in Kyiv. The malware is associated with Sandworm, a Russian state-sponsored threat group linked to GRU Unit 74455.
Its modular payloads directly control switches and circuit breakers through four industrial communication protocols, including IEC 61850 and IEC 60870-5-104. This protocol-aware functionality enables interference with power-system operations rather than merely compromising operator workstations. Industroyer can enumerate remote computers and local network adapters, use supplied credentials to execute processes and stop services, and disable key alarms. Supporting modules provide persistence and command-and-control communication, including communication through Tor nodes. It also decrypts code used to establish command-and-control connections.
Its demonstrated operational target was Ukraine’s electricity infrastructure. Industroyer2, deployed in a thwarted attack against Ukraine’s energy sector in April 2022, is a distinct successor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SIPROTEC DoS Module ... ESET’s analysis claims the module sends UDP packets to port 50000 exploiting CVE-2015-5374 causing the SIPROTEC digital relay to fall into an unresponsive state. ... Using CVE-2015-5374 to Hamper Protective Relays ... Siemens released a patch for this in July 2015 under Siemens advisory SCA-732541. | The malware self-identifies as “crash” in multiple locations thus leading to the naming convention “CRASHOVERRIDE” for the malware framework.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This ICS-targeting malware was very likely built with the source code of Industroyer, which was used to shut down Kyiv’s power grid in 2016.
DOJ’s 2020 GRU Unit 74455 indictment describes destructive malware operations against Ukraine’s power grid, Ministry of Finance, and State Treasury Service, including BlackEnergy, Industroyer, and KillDisk, as part of a wider destabilization campaign.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
Signature Malware: Custom wipers (e.g. “Av3ngers” family), Industroyer-like ICS tools, Rust-enhanced payloads.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The first task of the wiper writes zeros into all of the registry keys in: SYSTEM\CurrentControlSet\Services
The OPC module ... enumerates all OPC servers and their associated items ... Also, CRASHOVERRIDE is the second, out of four, ICS tailored malware suite with OPC capabilities. OPC will appear abnormal in the CRASHOVERRIDE usage as it is being used to scan all devices on the network
After authentication opens HTTP channel to external command and control server (C2) through internal proxy ... Receives commands via the external command and control (C2) server
On execution, the malware attempts to contact a hard-coded proxy address located within the local network... The malware expects to communicate to an internal proxy listening on TCP 3128.
To disguise the source of malicious traffic, adversaries may chain together multiple proxies.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
119 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS malware referenced as an example of targeted industrial sabotage intended to disrupt or physically affect operational processes.
Destructive ICS malware associated with Sandworm attacks on the energy sector.
Industrial-control-focused malware designed to interact directly with industrial control protocols to disrupt electrical distribution and operational technology.
ICS malware cited as a historical example of attacks on electric power infrastructure that required compromise of OT devices such as RTUs, HMIs, and SCADA servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.