CERT-UA disclosed a targeted attack on a Ukrainian energy facility in which operators attempted to disrupt high-voltage substations and destroy Windows, Linux, and network infrastructure. The operation used INDUSTROYER2 to issue hardcoded IEC 60870-5-104 (IEC-104) commands against specific substations, while CADDYWIPER targeted Windows systems and ORCSHRED, SOLOSHRED, and AWFULSHRED were prepared to wipe Linux hosts. CERT-UA said the attackers had access no later than February 2022, launched two attack waves, and planned the disruptive phase for April 8, but the intended impact was prevented; supporting tooling included ARGUEPATCH, TAILJUMP, PowerShell-based POWERGAP, SSH tunnel chains, and Impacket for remote execution and lateral movement.
Technical analyses from Nozomi Networks, Netresec, and Splunk found that Industroyer2 was a tailored, standalone executable focused exclusively on IEC-104, with hardcoded station parameters, IP addresses, and Information Object Addresses (IOAs) for deterministic command execution against predefined substations. Researchers reported strong code and structural similarities to the original Industroyer used in the 2016 Ukraine grid attack, concluding the malware likely evolved from the same source code and reflects Sandworm’s continued refinement of OT attack capabilities. The payload was designed to run in a privileged environment with direct substation access, terminate selected processes, manage IEC-104 sessions including TESTFR handling, and in some samples connect to specific targets over TCP port 2404, underscoring detailed prior knowledge of the victim’s operational technology environment.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research published a threat update on Industroyer2, describing its use against Ukraine's electric grid alongside CaddyWiper and outlining its execution logic and hardcoded targeting data. Splunk also released Linux and Windows detection analytics tied to behaviors observed in the campaign.
Nozomi Networks published analysis concluding that Industroyer2 closely resembles the original Industroyer IEC-104 component and likely came from the same evolving source code. The report described hardcoded station and IOA configurations and the malware's IEC-104 command sequence.
Netresec analyzed sample "40_115.exe" and concluded it was hard-coded to attack specific Ukrainian electric utility substations over IEC-104 on port 2404. The analysis also noted a second sample, "108_100.exe," configured for a different set of substations, indicating tailored malware builds.
CERT-UA said the planned shutdown of substations and broader infrastructure disruption was scheduled for the evening of Friday, 8 April 2022. The operation was intended to affect substations, Windows systems, Linux servers, and network equipment.
CERT-UA and Netresec reported that Industroyer2 binaries used in the operation were compiled on 2022-03-23 and contained hardcoded parameters for specific substations. The tailored builds indicate preparation for distinct target environments.
CERT-UA reported that the victim organization's initial compromise occurred no later than February 2022. This marked the start of the broader operation against the Ukrainian energy facility.
The original Industroyer malware was first deployed by Sandworm against Ukraine's power grid in 2016. Multiple references identify this as the earlier precursor to Industroyer2.
CERT-UA reported that the attackers' plan against the Ukrainian energy-sector facility was prevented from being carried out. The agency described two attack waves and shared operational information, malware samples, IOCs, and YARA rules with selected partners and Ukrainian energy-sector entities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
splunk.com
Open sourcenozominetworks.com
Open sourcenetresec.com
Open sourcenozominetworks.com
Open sourcecert.gov.ua
Open sourcedatatracker.ietf.org
Open sourcecollaborate.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.