Skip to main content
OT Atlas

Threats · Activity group

ELECTRUM

activeStage 2 ICS effectsDragosAttribution · High
Last verified

Executive summary

ELECTRUM is the Dragos activity group associated with ICS-capable operations against the Ukrainian electric sector, including the 2016 Kyiv transmission substation event and later attempts using updated Industroyer capability. It is the cluster that demonstrably possesses and has deployed malware able to speak electric-sector protocols directly to field equipment.

Public reporting connects ELECTRUM operations to the broader Sandworm-associated ecosystem, which multiple vendors and governments track under their own names. Those relationships are analytic: they describe overlapping operations and shared capability, not a single interchangeable label.

At a glance

Tracked byDragos
NexusReported by governments and vendors as Russian state-sponsored
First observed2016 (public reporting)
Last reported2022 Industroyer2 deployment attempt; continued reporting through 2024
ICS kill chainStage 1 — Intrusion · Stage 2 — Develop ICS capability · Stage 2 — Execute ICS attack

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

ELECTRUM
  • Sandworm Team
    Associated activityHigh

    Tracked by MITRE ATT&CK — ATT&CK attributes Industroyer/Industroyer2 operations to Sandworm Team; Dragos tracks the ICS-effects cluster as ELECTRUM.

  • APT44
    Associated activityHigh

    Tracked by Google Threat Intelligence / Mandiant

  • Seashell Blizzard
    Associated activityHigh

    Tracked by Microsoft

  • FROZENBARENTS
    Associated activityModerate

    Tracked by Google Threat Intelligence

  • Voodoo Bear
    Associated activityModerate

    Tracked by CrowdStrike

  • IRIDIUM
    AliasHigh

    Tracked by Microsoft — Former Microsoft designation for Seashell Blizzard.

  • TeleBots
    Associated activityModerate

    Tracked by ESET

  • BlackEnergy Group
    Reported linkModerate

    Tracked by Historic vendor reporting

  • Industroyer / CRASHOVERRIDE
    Capability / malware nameConfirmed

    Tracked by ESET / Dragos — Malware and capability naming, not an actor alias.

Relevance

Why OT defenders care

Objectives

  • Disruption of electric transmission and distribution
  • Destruction of engineering and operator systems to slow recovery
  • Strategic pressure during armed conflict

Reported impacts

  • Loss of control and loss of view in an electric transmission environment
  • De-energisation of substations
  • Destruction of supporting IT and engineering systems

Observed behaviours

  • Direct protocol interaction with substation equipment using purpose-built modules
  • Denial-of-service against protection relays to complicate restoration
  • Wiper deployment against Windows and Linux systems supporting operations
  • Scheduled execution timed for maximum operational impact

Targeting

Sectors, geography and assets

Target industries

Electric powerGovernmentCritical manufacturing

Target geography

UkraineEurope

Observed assets

Protection relayRTUSCADA serverHMIEngineering workstation

Protocols in scope

IEC 60870-5-101IEC 60870-5-104IEC 61850 MMSOPC DA

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • Industroyer / CRASHOVERRIDEModular ICS malware with protocol-specific payload modules and a relay denial-of-service component.
  • Industroyer2IEC-104-focused variant recovered during a 2022 attempt against a Ukrainian energy provider.
  • CaddyWiper / other wipersReported alongside the 2022 attempt to destroy supporting Windows and Linux systems.

Commercial tool

Not publicly established

Open-source utility

Not publicly established

Native OS tool

  • Native OS and scheduled task abuse

ATT&CK

Technique mapping

History

Known campaigns and incidents

Reported campaigns

  • 2016 Kyiv transmission substation de-energisation
  • 2022 attempted disruption of a Ukrainian energy provider

Atlas incident case studies

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Baseline every IEC-104 / IEC 61850 / OPC communicating pair and alert on new clients
  • Monitor for control-direction commands from hosts that historically only read
  • Maintain offline, tested engineering backups and relay settings files
  • Rehearse manual operation of the process with engineering

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.

Sources

Last verified