ELECTRUM is an industrial-control-system-focused threat activity group associated with disruptive operations against electric utilities, particularly in Ukraine. The group is widely known for the 2016 CRASHOVERRIDE event, also referred to as Industroyer, which demonstrated the ability to interact directly with electric grid operations through native industrial protocols. ELECTRUM has been assessed as capable of developing malware that can modify electric equipment processes and manipulate operational communications within power environments. ELECTRUM’s tradecraft is notable for specialized ICS and OT intrusion capability rather than commodity enterprise intrusion alone. Its operations indicate post-compromise expertise in electric utility environments, including the use of malware tailored to grid operations and the potential to interfere with restoration and recovery activities in ways that could prolong outages and increase operational risk. The group’s known activity centers on electric utilities and disruptive effects in the power sector rather than broad opportunistic targeting. Known aliases and naming overlap are limited in the supplied facts, but the CRASHOVERRIDE malware associated with ELECTRUM is also commonly referred to as Industroyer. High-confidence reporting supports ELECTRUM as one of the comparatively few activity groups with demonstrated ICS-specific disruptive capability against electric infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.