Industroyer2 is a Windows-based industrial-control-system malware used by the Sandworm threat actor, assessed as Russia’s GRU Unit 74455, in an attempted April 2022 disruption of a Ukrainian electric utility. It is an evolution of the Industroyer malware used against Ukraine’s power grid in 2016 and was deployed in a broader destructive operation that also involved CaddyWiper and other wipers. Industroyer2 is purpose-built to manipulate high-voltage electrical-substation equipment via IEC 60870-5-104 (IEC-104). It establishes IEC-104 sessions, interrogates configured stations, and sends legitimate protocol commands to predefined information object addresses, apparently to operate circuit breakers and interrupt power distribution. The malware is tailored to individual target environments: station parameters, device addresses, command types, execution sequence, and target outputs are embedded in its configuration rather than dynamically discovered. It can also terminate specified operational processes and rename associated executables before beginning IEC-104 activity. Code and structural similarities with the original Industroyer IEC-104 component indicate development from the same evolving source code base. The 2022 operation was detected and stopped before the intended grid disruption occurred.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2022-04-12 ⋅ Cert-UA ⋅ Cyberattack of Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
2022-04-12 ⋅ Cert-UA ⋅ Cyberattack of Sandworm Group (UAC-0082) on energy facilities of Ukraine using malicious programs INDUSTROYER2 and CADDYWIPER
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Windows Hidden Schedule Task Settings ... A scheduled task was created to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with hidden settings that are unique entry of malware like Industroyer2
Linux Adding Crontab Using List Parameter ... This command line parameter can be abused by malware like Industroyer2, adversaries, and red teamers to add a crontab entry to their malicious code to execute to the schedule they want.
Windows Hidden Schedule Task Settings ... A scheduled task was created to identify suspicious tasks registered on Windows either via schtasks.exe OR TaskService with hidden settings that are unique entry of malware like Industroyer2
Related Detections ... Dump LSASS via procdump ... Creation of lsass Dump with Taskmgr ... Access LSASS Memory for Dump Creation ... Detect Credential Dumping through LSASS access ... Dump LSASS via comsvcs DLL ... Windows Credential Dumping LSASS Memory Createdump ... Windows Possible Credential Dumping
"The functionalities of the payload components include mapping the network, and then issuing commands to the specific industrial control devices."
This function enumerates all running processes in the targeted host and looks for the process named “PServiceControl.exe” and also the process name stated in its config data.
The first parameter is “-t” which will trigger a waiting timer relative to the current minute of the system time.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
Terminate Process and Rename Process File Path ... looks for the process named “PServiceControl.exe” ... and rename it with “.MZ” file extension. | Linux Disable Services This analytic identifies events that attempt to disable a service. | Linux Stop Services This analytic identifies events that attempt to stop or clear a service.
After terminating PServiceControl.exe, and based on the configuration, PService_PPD.exe which is then renamed with .MZ appended to its name, the sample begins IEC 104 interaction.
The takeaway for security teams is that advanced threat actors are continuously refining their OT capabilities to adapt to different operational scenarios... their ability to analyze the targeted environment and modify its status was demonstrated once more with Industroyer2.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated Analytic Story: Industroyer2.
Novel attack malware used against Ukrainian energy facilities and referenced alongside CaddyWiper.
ICS/OT malware designed to control substation circuit breakers via IEC-101/104 in attacks against electric utility infrastructure.
ICS-specific malware referenced as an example of OT network command injection against industrial protocols in the Ukrainian power sector.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.