BlackEnergy operators targeted Ukrainian media organizations and electric power companies with spearphishing emails carrying malicious Microsoft Word documents that used macros to install BlackEnergy v3. One lure referenced Ukraine’s Right Sector party and was likely used against the television channel STB. The malware dropped an executable, installed a DLL payload as FONTCACHE.DAT, created persistence through a startup .LNK file, and communicated with a hardcoded command-and-control server over HTTP, reflecting a broader campaign against Ukrainian government, media, energy, and other critical sectors.
Investigators also found the group using BlackEnergy as a backdoor to deploy the destructive KillDisk component and a trojanized Dropbear SSH service known as SSHBearDoor for persistent remote access. KillDisk variants were customized by target type: media-focused samples overwrote files and rendered systems unbootable, while energy-sector variants also targeted processes tied to industrial control environments, indicating an intent to disrupt operations as well as destroy data. The activity showed an escalation from espionage and foothold establishment to destructive attacks against Ukrainian critical infrastructure.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
The malicious Word document "$RR143TB.doc" was uploaded to a multiscanner service from Ukraine, revealing a sample that used macros to drop a BlackEnergy v3 payload.
CERT-UA documented the first known use of the KillDisk component in November 2015 during attacks on Ukrainian news media companies.
The Securelist analysis noted that STB had previously been publicly identified as a victim of BlackEnergy wiper attacks in October 2015.
Metadata on the malicious Word document "$RR143TB.doc" showed creation and last-saved timestamps of 2015-07-27 10:21:00, indicating the lure was prepared by that date.
ESET said the 2015 attacks destroyed video materials and documents during the Ukrainian local elections, showing operational impact on media organizations.
During 2015, BlackEnergy operators targeted Ukrainian news media and the electric power industry, using BlackEnergy malware and macro-enabled XLS lures as part of their intrusion chain.
ESET reported that the BlackEnergy malware family, active since 2007, resurged in 2014 before later campaigns against Ukrainian targets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.