Industroyer2 is an industrial control system malware family used against electric utility infrastructure, specifically high-voltage substations in Ukraine. It was discovered and analyzed by ESET and CERT-UA in April 2022 during an attempted attack on a Ukrainian energy company. The malware is described as a modified, simplified, and more targeted successor to Industroyer/Crash Override, and CERT-UA and ESET assessed with high confidence that it was developed by the same authors as the original Industroyer. Industroyer2 is associated with Sandworm, identified in the content as GRU Unit 74455.
Its core capability is direct interaction with substation equipment using IEC-101 and IEC-104, including sending legitimate IEC-104 commands to circuit breakers and protective relays to disrupt the flow of power and potentially trigger blackouts. Unlike the original Industroyer, which relied on an external .ini file for customization, Industroyer2 embeds network-specific parameters such as IP addresses, ports, and IEC-104 details including Information Object Addresses, indicating it was tailored for a specific target environment. The content states it was designed to control substation breakers and was aimed at a particular Ukrainian energy provider.
The April 2022 operation involved Sandworm moving from the victim’s IT network into the industrial control system network and attempting to deploy Industroyer2 against high-voltage electrical substations. The same intrusion also involved multiple destructive malware families, including CaddyWiper and other Linux, Solaris, and Windows wipers. Ukrainian defenders, CERT-UA, and ESET detected and mitigated the attack before a major blackout occurred, though the operation was characterized as an attempt to cause widespread power outages and a possible third blackout in Ukraine.
High-confidence associations in the content tie Industroyer2 to attacks on Ukrainian critical infrastructure during Russia’s war against Ukraine, especially the energy sector. The malware is repeatedly cited as an example of OT-specific command injection and protocol-aware sabotage tooling that uses legitimate industrial protocol traffic rather than malformed exploits, making behavioral OT monitoring important for detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Related Detections ... Dump LSASS via procdump ... Creation of lsass Dump with Taskmgr ... Access LSASS Memory for Dump Creation ... Detect Credential Dumping through LSASS access ... Dump LSASS via comsvcs DLL ... Windows Credential Dumping LSASS Memory Createdump ... Windows Possible Credential Dumping
"The functionalities of the payload components include mapping the network, and then issuing commands to the specific industrial control devices."
Following Russia’s invasion of Ukraine on 24 February 2022, likely Russian threat actors conducted several disruptive and destructive computer network attacks against Ukrainian targets... To date, there are eight tracked malware families that Russia-linked cyber threat actors have used for destructive activity against Ukraine: WhisperGate/Whisperkill, FoxBlade (HermeticWiper), SonicVote (HermeticRansom), CaddyWiper, DesertBlade, Industroyer2, Lasainraw (IsaacWiper) and FiberLake (DoubleZero).
The following analytic detects attempts to stop or clear a service on Linux systems. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on processes like "systemctl," "service," and "svcadm" executing stop commands.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS/OT malware designed to control substation circuit breakers via IEC-101/104 in attacks against electric utility infrastructure.
ICS-specific malware referenced as an example of OT network command injection against industrial protocols in the Ukrainian power sector.
ICS malware that uses legitimate IEC-104 protocol communications to operate within industrial environments.
Более целевая версия Industroyer, ориентированная на прямое взаимодействие с протоколом IEC 104 на электроподстанциях для нарушения энергоснабжения.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.