Threats · Activity group
ELECTRUM
Executive summary
ELECTRUM is the Dragos activity group associated with ICS-capable operations against the Ukrainian electric sector, including the 2016 Kyiv transmission substation event and later attempts using updated Industroyer capability. It is the cluster that demonstrably possesses and has deployed malware able to speak electric-sector protocols directly to field equipment.
Public reporting connects ELECTRUM operations to the broader Sandworm-associated ecosystem, which multiple vendors and governments track under their own names. Those relationships are analytic: they describe overlapping operations and shared capability, not a single interchangeable label.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- Sandworm TeamAssociated activityHigh
Tracked by MITRE ATT&CK — ATT&CK attributes Industroyer/Industroyer2 operations to Sandworm Team; Dragos tracks the ICS-effects cluster as ELECTRUM.
- APT44Associated activityHigh
Tracked by Google Threat Intelligence / Mandiant
- Seashell BlizzardAssociated activityHigh
Tracked by Microsoft
- FROZENBARENTSAssociated activityModerate
Tracked by Google Threat Intelligence
- Voodoo BearAssociated activityModerate
Tracked by CrowdStrike
- IRIDIUMAliasHigh
Tracked by Microsoft — Former Microsoft designation for Seashell Blizzard.
- TeleBotsAssociated activityModerate
Tracked by ESET
- BlackEnergy GroupReported linkModerate
Tracked by Historic vendor reporting
- Industroyer / CRASHOVERRIDECapability / malware nameConfirmed
Tracked by ESET / Dragos — Malware and capability naming, not an actor alias.
Relevance
Why OT defenders care
Objectives
- Disruption of electric transmission and distribution
- Destruction of engineering and operator systems to slow recovery
- Strategic pressure during armed conflict
Reported impacts
- Loss of control and loss of view in an electric transmission environment
- De-energisation of substations
- Destruction of supporting IT and engineering systems
Observed behaviours
- Direct protocol interaction with substation equipment using purpose-built modules
- Denial-of-service against protection relays to complicate restoration
- Wiper deployment against Windows and Linux systems supporting operations
- Scheduled execution timed for maximum operational impact
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- Industroyer / CRASHOVERRIDEModular ICS malware with protocol-specific payload modules and a relay denial-of-service component.
- Industroyer2IEC-104-focused variant recovered during a 2022 attempt against a Ukrainian energy provider.
- CaddyWiper / other wipersReported alongside the 2022 attempt to destroy supporting Windows and Linux systems.
Commercial tool
Not publicly established
Open-source utility
Not publicly established
Native OS tool
- Native OS and scheduled task abuse
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- 2016 Kyiv transmission substation de-energisation
- 2022 attempted disruption of a Ukrainian energy provider
Atlas incident case studies
- Ukraine 2015 Power Grid Incident2015 · Electric Power
- Industroyer / CrashOverride2016 · Electric Power
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Baseline every IEC-104 / IEC 61850 / OPC communicating pair and alert on new clients
- Monitor for control-direction commands from hosts that historically only read
- Maintain offline, tested engineering backups and relay settings files
- Rehearse manual operation of the process with engineering
Hunt for this activity
- New IT-to-OT communication pathA corporate system has begun communicating with an OT asset over a path that is not in the approved conduit list.
- New scheduled taskA scheduled task was created on an OT-supporting host outside change control.
- New service creationA new Windows service was installed on an OT-supporting host.
- Known malicious hash presentA hash matching public malicious reporting exists in the environment.
- Protocol use from an unexpected Purdue levelAn industrial protocol is being used across a Purdue boundary where it should not appear.
- Unexpected controller write or programming behaviourA controller received a write or programming operation that does not match an approved change.
- New ICS protocol communicating pairTwo devices are speaking an industrial protocol to each other for the first time.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- Vendor IntelligenceDragosCRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations (opens in a new tab)
- Vendor IntelligenceESETIndustroyer2: Industroyer reloaded (opens in a new tab)
- ATT&CKMITRE ATT&CKSandworm Team (G0034) (opens in a new tab)
- Vendor IntelligenceGoogle Threat Intelligence / MandiantAPT44: Unearthing Sandworm (opens in a new tab)
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)