Skip to main content

2016 · Electric Power

Industroyer / CrashOverride

Malware with modules implementing industrial telecontrol protocols directly, used in a 2016 transmission substation incident causing a brief outage in Kyiv. A later variant was reported in 2022 targeting Ukrainian energy infrastructure.

Direct OT impactUkraine

What happened

A modular framework capable of speaking IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA to interact with grid equipment, alongside a data-wiper component and a denial-of-service module targeting specific protection relays.

Who

Public reporting associates the tooling with a Russia-associated threat activity group.

Where

Ukrainian electricity transmission and later energy infrastructure.

Why

Assessed objective: disrupt electricity supply and demonstrate protocol-native attack capability.

How

Access to the substation environment, followed by execution of protocol modules that issued switching commands, then wiper activity to impede recovery.

Timeline

  1. December 2016Transmission substation incident causing a short-duration outage in Kyiv
  2. June 2017Public technical analysis published describing the protocol modules
  3. April 2022A successor variant reported against Ukrainian energy infrastructure and disrupted before achieving full effect

Attack path

Described at the level required to build detection and controls.

Initial Access

Unknown

Not fully public

Substation environment

Reported

Execution host with protocol reachability

Control systems

Reported

Protocol modules issued switching commands

Physical consequence

Reported

Outage of limited duration

Impact

OT impactDirect issuance of switching commands using native telecontrol protocols.
Safety impactNo publicly documented injuries.
Operational impactShort-duration outage; a wiper component targeted recovery capability.
Detected byPost-incident forensic analysis and subsequent malware research.

Technology involved

Substation SCADAIEC 104 gatewaysIEC 61850 devicesProtection relays

ATT&CK techniques

T0855T0836T0816T0814

Vulnerabilities and weaknesses exploited

  • A denial-of-service issue affecting certain protection relays was reported as part of the tooling

Control failures

  • Protocol-level trust with no authentication
  • Insufficient substation monitoring
  • Recovery dependency on affected workstations

Where earlier detection was possible

  • Baseline of controlling stations per substation
  • Alerting on new IEC 104 sessions
  • Monitoring for unexplained command ASDUs

Defensive lessons

  • Attackers can implement industrial protocols natively — protocol traffic alone is not evidence of legitimacy
  • Substation-level visibility is essential; control-centre logs alone are insufficient
  • Assume the recovery environment may also be targeted

Why should I care?

Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.