2016 · Electric Power
Industroyer / CrashOverride
Malware with modules implementing industrial telecontrol protocols directly, used in a 2016 transmission substation incident causing a brief outage in Kyiv. A later variant was reported in 2022 targeting Ukrainian energy infrastructure.
What happened
A modular framework capable of speaking IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA to interact with grid equipment, alongside a data-wiper component and a denial-of-service module targeting specific protection relays.
Who
Public reporting associates the tooling with a Russia-associated threat activity group.
Where
Ukrainian electricity transmission and later energy infrastructure.
Why
Assessed objective: disrupt electricity supply and demonstrate protocol-native attack capability.
How
Access to the substation environment, followed by execution of protocol modules that issued switching commands, then wiper activity to impede recovery.
Timeline
- December 2016Transmission substation incident causing a short-duration outage in Kyiv
- June 2017Public technical analysis published describing the protocol modules
- April 2022A successor variant reported against Ukrainian energy infrastructure and disrupted before achieving full effect
Attack path
Described at the level required to build detection and controls.
Initial Access
UnknownNot fully public
Substation environment
ReportedExecution host with protocol reachability
Control systems
ReportedProtocol modules issued switching commands
Physical consequence
ReportedOutage of limited duration
Impact
Technology involved
ATT&CK techniques
Vulnerabilities and weaknesses exploited
- A denial-of-service issue affecting certain protection relays was reported as part of the tooling
Control failures
- Protocol-level trust with no authentication
- Insufficient substation monitoring
- Recovery dependency on affected workstations
Where earlier detection was possible
- Baseline of controlling stations per substation
- Alerting on new IEC 104 sessions
- Monitoring for unexplained command ASDUs
Defensive lessons
- Attackers can implement industrial protocols natively — protocol traffic alone is not evidence of legitimacy
- Substation-level visibility is essential; control-centre logs alone are insufficient
- Assume the recovery environment may also be targeted
Why should I care?
Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.
Sources & further reading