BlackEnergy is a highly modular Windows Trojan used for credential theft, espionage, and operations against industrial control system environments. Its functionality varies by deployment, with plug-ins supporting browser credential theft, keylogging, screenshot capture, process enumeration, and discovery of network configuration and routing information. Modules also search network-connected file shares and removable media to facilitate lateral movement.
BlackEnergy injects its DLL component into a legitimate Windows service-host process. BlackEnergy 3 establishes persistence through a startup shortcut to its main DLL component. The family has also attempted to bypass default Windows User Account Control settings by abusing a backward-compatibility mechanism in Windows 7 and later.
BlackEnergy is associated with Sandworm Team, a Russian military intelligence-linked threat actor. An industrial campaign active since at least 2011 compromised Internet-connected human-machine interfaces, including GE Cimplicity and Advantech/BroadWin WebAccess systems. Confirmed delivery mechanisms include exploitation of GE Cimplicity vulnerability CVE-2014-0751 and malicious Microsoft Word spearphishing attachments. Separate BlackEnergy campaigns exploited CVE-2014-4114.
BlackEnergy 3 was present in systems associated with Ukraine's December 2015 electricity outage, although its presence alone does not establish that it directly caused the outage. Sandworm used the associated KillDisk destructive component to overwrite files on Windows-based human-machine interfaces and corrupt master boot records, rendering infected computers inoperable. Unlike Industroyer, BlackEnergy is not established as directly controlling electricity breakers through industrial communication protocols.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Analysis of victim system artifacts has determined that the actors have been exploiting a vulnerability in GE’s Cimplicity HMI product since at least January 2012. The vulnerability, CVE-2014-0751, was published in ICS-CERT advisory ICSA-14-023-01 on January 23, 2014.
Public reports reference a BlackEnergy-based campaign against a variety of overseas targets leveraging vulnerability CVE-2014-4114 (affecting Microsoft Windows and Windows Server 2008 and 2012). ICS-CERT has not observed the use of this vulnerability to target control system environments.
Spear-phishing, documents with exploits (RTF CVE-2014-1761, PPTS CVE-2014-4114, …) | Like BlackEnergy (a.k.a. Sandworm, Quedagh), Potao is an example of targeted espionage (APT) malware detected mostly in Ukraine and a number of other CIS countries.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has used the BlackEnergy KillDisk component to overwrite files on Windows-based Human-Machine Interfaces.
the code implementing this algorithm included a subtle error, a mistake that was identical to exhibited by code used in the BlackEnergy attacks against Ukraine and elsewhere.
the code implementing this algorithm included a subtle error, a mistake that was identical to exhibited by code used in the BlackEnergy attacks against Ukraine and elsewhere.
For example, the group has been observed using custom-developed backdoors, such as “Pterodo” and “BlackEnergy”, to gain access to target systems and to maintain persistence within a network.
DOJ’s 2020 GRU Unit 74455 indictment describes destructive malware operations against Ukraine’s power grid, Ministry of Finance, and State Treasury Service, including BlackEnergy, Industroyer, and KillDisk, as part of a wider destabilization campaign.
"The malware, known as BlackEnergy, appears to have been used in cyberattacks against Georgia during the Russo-Georgian conflict of 2008 too, but has also been operated by criminals as a means to steal credit card data."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
164 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as having been used to breach Ukrainian utilities in an attack that disrupted electric power.
Named malware family associated in the text with Sandworm's early activity labeling.
Malware used in destructive operations against Ukrainian state and power-sector targets as part of Russia’s wider destabilization campaign.
Referenced as an example of malware that evolved from DDoS-oriented use into targeted attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.