Investigators linked a second cyber-induced power disruption in Ukraine to the same threat actors believed responsible for the 2015 grid attack, reinforcing concerns that attackers had developed repeatable capabilities against electric utilities. Reporting on the incident said the intrusion affected a Ukrainian power station and was widely viewed as further evidence that grid operators remained exposed to targeted attacks capable of interrupting electricity delivery.
At the same time, U.S. officials disclosed that malware associated with the Russian campaign labeled Grizzly Steppe had been found on a Burlington Electric laptop in Vermont, prompting warnings about possible reconnaissance against American energy infrastructure. Burlington Electric said the compromised device was not connected to grid control systems, was isolated immediately, and did not disrupt operations, but the discovery intensified fears that Russian-linked operators were probing utility networks in the United States while earlier attacks in Ukraine demonstrated the potential consequences.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By January 2017, reporting and technical analysis concluded that the December 2016 Ukraine outage was likely carried out by the same group responsible for the 2015 grid attack. This attribution strengthened the view that the adversary was conducting a sustained campaign against Ukrainian energy infrastructure.
Media reports on the Burlington Electric discovery said Russian hackers had penetrated a U.S. utility, raising alarm about possible probing of the American electrical grid. Officials said the malware was not used to disrupt operations, but the case intensified concern about future Russian access to utility networks.
Burlington Electric Department in Vermont detected malware code associated with the Russian-linked Grizzly Steppe campaign on a company laptop. The utility said the laptop was not connected to grid operations, isolated the device, and notified federal authorities.
After publicly attributing Russian cyber activity, DHS, FBI, and ODNI shared indicators associated with the Grizzly Steppe campaign with critical infrastructure operators. Those indicators were later used by utilities and investigators to identify related malware on systems in the United States.
A second cyber-induced blackout struck Ukraine in December 2016, affecting a power transmission facility near Kyiv. Subsequent analysis and reporting linked the incident to the same actors behind the 2015 Ukraine grid attack.
Attackers linked to the BlackEnergy campaign disrupted Ukraine's power grid in late 2015, causing outages and establishing a precedent for cyberattacks on electric utilities. Later reporting tied the 2016 Ukraine blackout to the same adversaries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
vice.com
Open sourcedarkreading.com
Open sourcevtdigger.org
Open sourcewashingtonpost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.