BlackEnergy 3 is a malware family closely associated with the Russian GRU-linked Sandworm Team and is described in the source material as the group’s “calling card.” It was used in intrusions against Ukrainian targets and is specifically linked to the December 23, 2015 cyberattack on three Ukrainian electricity distribution companies, where it enabled the actor to gain access to the IT network of a power company and pivot into the SCADA environment, giving the attackers the ability to manipulate industrial control systems. The attack temporarily disrupted electricity supply to roughly 225,000-230,000 consumers, and the malware was deployed in the broader context of Sandworm operations targeting Ukrainian government entities, media, regional power authorities, and other European targets. The content states that BlackEnergy 3 reemerged in Ukraine in early 2015 and that increased intrusion activity using it was observed throughout that year. It is also identified as one of several malware packages tailored for targeting OT and critical infrastructure systems. In the Ukraine power incident, BlackEnergy 3 activity was associated with destructive KillDisk malware found on affected systems; sources indicated BlackEnergy 3 was deployed on at least one affected Ukrainian power system that also had KillDisk, although the material notes KillDisk’s exact role in causing the outage could not be confirmed. The attack chain described in the content includes spear-phishing emails carrying BlackEnergy malware, compromise of corporate networks, lateral movement into OT/SCADA environments, remote switching of substations, destruction of files on servers and workstations via KillDisk, and disruption of utility support phone lines. High-confidence associations in the content tie BlackEnergy 3 to Sandworm and to operations against Ukrainian energy infrastructure and other OT/critical infrastructure targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, we have linked Sandworm Team to the incident, principally based on BlackEnergy 3, the malware that has become their calling card.
Analysis of victim system artifacts has determined that the actors have been exploiting a vulnerability in GE’s Cimplicity HMI product since at least January 2012. The vulnerability, CVE-2014-0751, was published in ICS‑CERT advisory ICSA-14-023-01 on January 23, 2014.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Sandworm team was attributed to the attack and their use of the BLACKENERGY 3 malware.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
We have linked Sandworm Team to the incident, principally based on BlackEnergy 3... specifically the role of destructive malware... On the Ukrainian Power Authority Incidents... we place this malware within the greater context of activity tied to BlackEnergy 3... We believe this KillDisk malware is related to the destructive malware leveraged during Ukrainian elections in October.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used to compromise corporate networks (via spear-phishing) at Ukrainian energy distribution companies, enabling remote access and subsequent operational disruption of power distribution (SCADA takeover and switching substations off).
A malware family closely associated with Sandworm Team and used in intrusion activity against Ukrainian targets, including media and regional power authorities. The content describes it as central to the Ukraine power incident context and prior reconnaissance/preparation activity against SCADA-related environments.
BlackEnergy 3 is described as the malware closely associated with Sandworm Team, used in intrusion activity in Ukraine and tied to targeting of SCADA systems and affected power authorities.
Malware used by Sandworm in the 2015 Ukraine power outage to gain access to an IT network and pivot into SCADA environments to manipulate industrial control systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.