Industroyer2 is Windows-based industrial-control-system malware designed to disrupt electricity supply by manipulating substation equipment. It is associated with Sandworm, also known as IRIDIUM, a Russian military intelligence threat group linked to GRU Unit 74455. Sandworm deployed it against a Ukrainian electricity provider in April 2022; CERT-UA and ESET helped thwart the operation before it caused a power outage.
A successor to the Industroyer malware used in the 2016 Kyiv electricity disruption, Industroyer2 is a standalone executable focused exclusively on IEC 60870-5-104 communications. It embeds victim-specific station configurations, information object addresses, and command parameters, allowing it to issue single and double commands that manipulate outputs controlling circuit breakers. It can communicate with multiple configured stations concurrently, interrogate devices, and execute predetermined switching sequences. These tailored configurations reflect detailed knowledge of the targeted operational environment.
Industroyer2 can terminate selected control-system processes and rename their executables before initiating industrial-protocol communications. It also supports delayed execution and execution logging. The April 2022 operation included separate destructive payloads, including CaddyWiper and wipers targeting Linux and Solaris systems. Those accompanying tools are distinct from Industroyer2’s industrial-control manipulation functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Most recently, the group has been deploying “Industroyer2” against the Ukrainian energy industry.
2022-04-12 ⋅ Cert-UA ⋅ Cyberattack of Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Windows Hidden Schedule Task Settings ... A scheduled task was created to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with hidden settings that are unique entry of malware like Industroyer2
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Windows Hidden Schedule Task Settings ... A scheduled task was created to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with hidden settings that are unique entry of malware like Industroyer2
Related Detections ... Dump LSASS via procdump ... Creation of lsass Dump with Taskmgr ... Access LSASS Memory for Dump Creation ... Detect Credential Dumping through LSASS access ... Dump LSASS via comsvcs DLL ... Windows Credential Dumping LSASS Memory Createdump ... Windows Possible Credential Dumping
"The functionalities of the payload components include mapping the network, and then issuing commands to the specific industrial control devices."
This function enumerates all running processes in the targeted host and looks for the process named “PServiceControl.exe” and also the process name stated in its config data.
The first parameter is “-t” which will trigger a waiting timer relative to the current minute of the system time.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
Terminate Process and Rename Process File Path ... looks for the process named “PServiceControl.exe” ... and rename it with “.MZ” file extension. | Linux Disable Services This analytic identifies events that attempt to disable a service. | Linux Stop Services This analytic identifies events that attempt to stop or clear a service.
After terminating PServiceControl.exe, and based on the configuration, PService_PPD.exe which is then renamed with .MZ appended to its name, the sample begins IEC 104 interaction.
The takeaway for security teams is that advanced threat actors are continuously refining their OT capabilities to adapt to different operational scenarios... their ability to analyze the targeted environment and modify its status was demonstrated once more with Industroyer2.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware designed to manipulate electricity substation control systems directly. Its April 2022 deployment against a Ukrainian electricity provider aimed to cut power to roughly two million people, but CERT-UA and ESET detected and thwarted the attack.
Associated Analytic Story: Industroyer2.
Novel attack malware used against Ukrainian energy facilities and referenced alongside CaddyWiper.
ICS/OT malware designed to control substation circuit breakers via IEC-101/104 in attacks against electric utility infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.