BlackEnergy 3 is malware strongly associated with the Russian state-linked Sandworm threat group and its operations against Ukrainian and European targets. It was used to compromise corporate IT environments at Ukrainian electricity distribution companies during the December 2015 Ukraine power-grid attack. Sandworm operators used access obtained through BlackEnergy 3 to pivot from IT networks into SCADA environments, where they remotely opened substations and disrupted electrical distribution. The operation affected approximately 230,000 consumers and is widely recognized as the first publicly acknowledged cyberattack to successfully disrupt an electrical power grid. BlackEnergy 3 activity also targeted Ukrainian government entities, media organizations, and regional power authorities. Destructive KillDisk malware was deployed in affected environments during the Ukraine operation, apparently to impede restoration or reduce operator visibility, although KillDisk was a distinct payload and its precise role in causing the outage was not conclusively established. BlackEnergy 3 is regarded as an operational-technology and critical-infrastructure-focused malware family and as a prominent Sandworm-associated tool.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2014-4114 ... BlackEnergy 3 ... Christmas 2015 Attacks
Analysis of victim system artifacts has determined that the actors have been exploiting a vulnerability in GE’s Cimplicity HMI product since at least January 2012. The vulnerability, CVE-2014-0751, was published in ICS‑CERT advisory ICSA-14-023-01 on January 23, 2014.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Sandworm team was attributed to the attack and their use of the BLACKENERGY 3 malware.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
We have linked Sandworm Team to the incident, principally based on BlackEnergy 3... specifically the role of destructive malware... On the Ukrainian Power Authority Incidents... we place this malware within the greater context of activity tied to BlackEnergy 3... We believe this KillDisk malware is related to the destructive malware leveraged during Ukrainian elections in October.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used to compromise corporate networks (via spear-phishing) at Ukrainian energy distribution companies, enabling remote access and subsequent operational disruption of power distribution (SCADA takeover and switching substations off).
A malware family closely associated with Sandworm Team and used in intrusion activity against Ukrainian targets, including media and regional power authorities. The content describes it as central to the Ukraine power incident context and prior reconnaissance/preparation activity against SCADA-related environments.
BlackEnergy 3 is described as the malware closely associated with Sandworm Team, used in intrusion activity in Ukraine and tied to targeting of SCADA systems and affected power authorities.
Malware used by Sandworm in the 2015 Ukraine power outage to gain access to an IT network and pivot into SCADA environments to manipulate industrial control systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.