Industroyer2 is an ICS-specific malware used by the Sandworm threat actor, widely linked to Russia’s GRU Unit 74455, in a 2022 operation against a Ukrainian energy provider. It is a successor to the original Industroyer malware used against Ukraine’s power grid in 2016 and is designed to disrupt electric distribution operations by issuing legitimate IEC 60870-5-104 control commands to high-voltage substation equipment. Unlike the earlier Industroyer framework, which supported multiple industrial protocols, Industroyer2 is narrowly focused on IEC-104 and was built as a standalone Windows executable with hardcoded operational parameters embedded directly in the binary.
The malware was tailored for a specific target environment. Analyses show it contained predefined station parameters, command types, and ordered lists of information object addresses to manipulate, indicating detailed prior knowledge of the victim’s OT network and substation configuration. Its command sequence was intended to operate circuit breakers and thereby interrupt power distribution. Industroyer2 established IEC-104 sessions, performed protocol handshakes and interrogation, and then transmitted configured single or double commands to target objects in a deterministic order. It also included options for delayed execution and logging.
Beyond direct OT manipulation, Industroyer2 incorporated host-level actions to facilitate execution in the target environment, including terminating specific processes and renaming associated files. The malware showed little emphasis on obfuscation or endpoint evasion, consistent with operation from a privileged position inside a compromised utility network with direct access to substation devices. Multiple tailored builds were identified, reinforcing the assessment that operators generated target-specific variants for distinct substations or organizations.
Industroyer2 was deployed as part of a broader destructive campaign against Ukrainian infrastructure and was associated with concurrent use of wiper malware such as CaddyWiper and Unix-like platform wipers in the same operation. Its design and deployment underscore Sandworm’s continued specialization in disruptive attacks against electric-sector operational technology, particularly in Ukraine.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2022-04-12 ⋅ Cert-UA ⋅ Cyberattack of Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
2022-04-12 ⋅ Cert-UA ⋅ Cyberattack of Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Windows Hidden Schedule Task Settings ... A scheduled task was created to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with hidden settings that are unique entry of malware like Industroyer2
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Windows Hidden Schedule Task Settings ... A scheduled task was created to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with hidden settings that are unique entry of malware like Industroyer2
Related Detections ... Dump LSASS via procdump ... Creation of lsass Dump with Taskmgr ... Access LSASS Memory for Dump Creation ... Detect Credential Dumping through LSASS access ... Dump LSASS via comsvcs DLL ... Windows Credential Dumping LSASS Memory Createdump ... Windows Possible Credential Dumping
"The functionalities of the payload components include mapping the network, and then issuing commands to the specific industrial control devices."
This function enumerates all running processes in the targeted host and looks for the process named “PServiceControl.exe” and also the process name stated in its config data.
The first parameter is “-t” which will trigger a waiting timer relative to the current minute of the system time.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
Terminate Process and Rename Process File Path ... looks for the process named “PServiceControl.exe” ... and rename it with “.MZ” file extension. | Linux Disable Services This analytic identifies events that attempt to disable a service. | Linux Stop Services This analytic identifies events that attempt to stop or clear a service.
After terminating PServiceControl.exe, and based on the configuration, PService_PPD.exe which is then renamed with .MZ appended to its name, the sample begins IEC 104 interaction.
The takeaway for security teams is that advanced threat actors are continuously refining their OT capabilities to adapt to different operational scenarios... their ability to analyze the targeted environment and modify its status was demonstrated once more with Industroyer2.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Novel attack malware used against Ukrainian energy facilities and referenced alongside CaddyWiper.
ICS/OT malware designed to control substation circuit breakers via IEC-101/104 in attacks against electric utility infrastructure.
ICS-specific malware referenced as an example of OT network command injection against industrial protocols in the Ukrainian power sector.
ICS malware that uses legitimate IEC-104 protocol communications to operate within industrial environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.