Industroyer, also known as CrashOverride, is an ICS-specific malware framework designed to disrupt electric power operations by directly interacting with industrial control protocols used in substations and grid environments. It is most closely associated with the 2016 attack on Ukraine’s power grid and is widely linked to the Russian GRU’s Sandworm ecosystem; multiple analyses also associate the disruptive OT phase specifically with the ELECTRUM activity group, with KAMACITE assessed as enabling access operations in some reporting. The malware is notable as the first publicly documented malware used to induce a power outage through native grid-control protocol manipulation.
The malware is modular and includes components for multiple industrial protocols, including IEC 60870-5-101, IEC 60870-5-104, IEC 61850, and OPC Data Access. Its design allows operators to enumerate network adapters and local addressing information, identify and communicate with SCADA or substation-related devices, and issue protocol-native commands to manipulate electrical equipment. Reported functionality includes decrypting code to establish command-and-control communications and sending host and execution information back to operators over that channel. Some reporting also notes the presence of a destructive or wiper component used alongside the OT-disruption capability.
Industroyer targets Windows systems in operational environments and is intended for use against electric utilities and transmission or distribution infrastructure. Its architecture and protocol support reflect detailed knowledge of power-system operations and industrial communications. A later evolution, Industroyer2, focused narrowly on IEC-104 and further demonstrated continued refinement of the same OT attack capability against Ukrainian energy targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A similar, but less potent, attempt to disrupt IEDs was made as part of the 2016 Industroyer attack against the Ukrainian electric grid.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2016, these actors conducted a cyber-intrusion campaign against a Ukrainian electrical transmission company and deployed CrashOverride malware specifically designed to attack power grids.
DOJ’s 2020 GRU Unit 74455 indictment describes destructive malware operations against Ukraine’s power grid, Ministry of Finance, and State Treasury Service, including BlackEnergy, Industroyer, and KillDisk, as part of a wider destabilization campaign.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
Signature Malware: Custom wipers (e.g. “Av3ngers” family), Industroyer-like ICS tools, Rust-enhanced payloads.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
‘Kills’ legitimate the master process on the victim host • Masquerades as the new master
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
without a configuration file it enumerates the local network to identify potential targets
The command sequence polls the target device for the appropriate addresses.
The first action is to try to kill the communications service process which acts as the master process.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
AsyncRAT can proxy C2 through a Tor client. Attor has used Tor for C2 communication. Cyclops Blink has used Tor nodes for C2 traffic. GreyEnergy has used Tor relays for Command and Control servers. Siloscape uses Tor to communicate with C2. WannaCry uses Tor for command and control traffic.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
On execution, the malware attempts to contact a hard-coded proxy address located within the local network. ELECTRUM must establish the internal proxy before the installation of the backdoor.
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
Overwrites all ICS configuration files across the hard drives and all mapped network drives specifically targeting ABB PCM600 configuration files in this sample
The first action is to try to kill the communications service process which acts as the master process.
After terminating PServiceControl.exe, and based on the configuration, PService_PPD.exe which is then renamed with .MZ appended to its name, the sample begins IEC 104 interaction.
The December, 2015 attack on the Ukrainian power grid left nearly 230,000 people without power
the module sends UDP packets to port 50000 exploiting CVE-2015-5374 causing the SIPROTEC digital relay to fall into an unresponsive state
The first task of the wiper writes zeros into all of the registry keys in: SYSTEM\CurrentControlSet\Services
The takeaway for security teams is that advanced threat actors are continuously refining their OT capabilities to adapt to different operational scenarios... their ability to analyze the targeted environment and modify its status was demonstrated once more with Industroyer2.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
104 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS malware referenced as an example of targeted industrial sabotage intended to disrupt or physically affect operational processes.
Destructive ICS malware associated with Sandworm attacks on the energy sector.
Industrial-control-focused malware designed to interact directly with industrial control protocols to disrupt electrical distribution and operational technology.
ICS malware cited as a historical example of attacks on electric power infrastructure that required compromise of OT devices such as RTUs, HMIs, and SCADA servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.