{"id":8317,"date":"2022-06-13T12:00:00","date_gmt":"2022-06-13T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/2022\/06\/13\/industroyer-a-cyber-weapon-that-brought-down-a-power-grid\/"},"modified":"2022-06-13T12:00:00","modified_gmt":"2022-06-13T09:00:00","slug":"industroyer-a-cyber-weapon-that-brought-down-a-power-grid","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2022\/06\/13\/industroyer-a-cyber-weapon-that-brought-down-a-power-grid\/","title":{"rendered":"Industroyer: A cyber-weapon that brought down a power grid"},"content":{"rendered":"<p>On June 12<sup>th<\/sup> 2017, <a href=\"https:\/\/www.welivesecurity.com\/2017\/06\/12\/industroyer-biggest-threat-industrial-control-systems-since-stuxnet\/\">ESET researchers published their findings<\/a> about unique malware that was capable of causing a widespread blackout. Industroyer, as they named it, was the first known piece of malware that was developed specifically to target a power grid.<\/p>\n<p>Indeed, Industroyer had been deployed to considerable effect a few months earlier \u2013 it caused thousands of homes in parts of Kyiv, Ukraine to lose power supplies for about an hour on December 17<sup>th<\/sup>, 2016, after the malware struck a local electrical substation. A few days later, ESET malware researcher <a href=\"https:\/\/www.welivesecurity.com\/author\/acherepanov\/\">Anton Cherepanov<\/a> would start dissecting Industroyer.<\/p>\n<h2>A ticking bomb<\/h2>\n<p>Once planted, Industroyer spread throughout the substation\u2019s network looking for specific industrial control devices whose communication protocols it could speak. Then, like a time bomb going off, it apparently opened every circuit breaker at once, while defying any attempts of the substation operators to regain easy control: if an operator tried to close a breaker, the malware opened it back up.<\/p>\n<p>To clean up its footprint, the malware unleashed a data wiper that was designed to leave the substation\u2019s computers inoperable and delayed the return to normal operations. Indeed, the wiper often failed, but had it been more successful, the consequences could have been much worse \u2013 especially in wintertime when a power outage can allow pipes filled with water to crack when they freeze.<\/p>\n<p>A final malicious act was made by the malware to disable some of the protective relays at the substation, but that failed too. Without functioning protective relays in place, the substation equipment could have been at high risk of damage when the operators eventually reestablished electric transmission.<\/p>\n<p><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/06\/industroyer.jpg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"282\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/06\/industroyer.jpg\" width=\"901\"><\/a><\/p>\n<p>As Cherepanov and fellow ESET researcher <a href=\"https:\/\/www.welivesecurity.com\/author\/lipovsky\/\">Robert Lipovsky<\/a><br \/>\n<a href=\"https:\/\/web-assets.esetstatic.com\/wls\/2017\/06\/Win32_Industroyer.pdf\">said at the time<\/a>, the sophistication of Industroyer makes it possible to adapt the malware to any similar environment. In fact, the industrial communication protocols that Industroyer speaks are used not only in Kyiv, but also \u201cworldwide in power supply infrastructure, transportation control systems, and other critical infrastructure systems (such as water and gas)\u201d.<\/p>\n<p>On the other hand, considering how sophisticated Industroyer was, its impact was ultimately rather underwhelming, as <a href=\"https:\/\/www.youtube.com\/watch?v=oGE6xHEQyog\">ESET researchers noted themselves<\/a> back in 2017. Perhaps it was only a test for future attacks, or perhaps it was a sign of what the group behind it could do.<\/p>\n<h2>The work of Sandworm<\/h2>\n<p>The shenanigans of the malware, ESET researchers noted, mirror the malicious intentions of the people who created it. At a <a href=\"https:\/\/www.youtube.com\/watch?v=oGE6xHEQyog\">Virus Bulletin conference in 2017<\/a>, Lipovsky highlighted that the \u201cattackers had to understand the architecture of a power grid, what commands to send, and how that will be achieved\u201d. Its creators went a long way to create this malware, and their objective was not just a power outage. \u201cSome clues in the Industroyer configuration suggest they wanted to cause equipment damage and malfunction\u201d.<\/p>\n<p><a href=\"https:\/\/www.eset.com\/us\/black-hat-2017-post\/\">At Black Hat 2017<\/a>, Cherepanov also pointed out that it \u201cseems very unlikely anyone could write and test such malware without access to the specialized equipment used in the specific, targeted industrial environment\u201d.<\/p>\n<p>In October 2020, the <a href=\"https:\/\/www.justice.gov\/opa\/pr\/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and\">United States attributed the attack<\/a> to six officers belonging to Unit 74455, aka <a href=\"https:\/\/www.welivesecurity.com\/2022\/03\/21\/sandworm-tale-disruption-told-anew\/\">Sandworm<\/a>, a unit within Russia\u2019s military intelligence agency GRU.<\/p>\n<h2>A comeback for Industroyer<\/h2>\n<p>Fast forward to 2022 and it\u2019s no surprise that in the weeks just before and after <a href=\"https:\/\/www.welivesecurity.com\/2022\/06\/03\/100-days-war-ukraine-conflict-cyberspace\/\">Russia\u2019s invasion<\/a> on February 24<sup>th<\/sup>, <a href=\"https:\/\/www.welivesecurity.com\/2022\/06\/02\/eset-threat-report-t12022\/\">ESET telemetry showed<\/a> an increase in cyberattacks targeting Ukraine.<\/p>\n<p>On April 12<sup>th<\/sup>, together with CERT-UA, ESET researchers announced they had identified a new variant of Industroyer that targeted an energy supplier in Ukraine. <a href=\"https:\/\/www.welivesecurity.com\/2022\/04\/12\/industroyer2-industroyer-reloaded\/\">Industroyer2<\/a> had been scheduled to cut power for a region in Ukraine on April 8<sup>th<\/sup>; fortunately, the attack was thwarted before it could wreak further havoc on the war-torn country. ESET researchers assessed with high confidence that Sandworm was again responsible for this new attack.<\/p>\n<h2>A harbinger of things to come<\/h2>\n<p>In recent years, it\u2019s become more than clear that the world\u2019s critical infrastructure services are at major risk for disruptions. The string of <a href=\"https:\/\/www.welivesecurity.com\/2022\/04\/21\/critical-infrastructure-cyberattack-longer-think\/\">incidents that have impacted critical infrastructure<\/a> in Ukraine (and, indeed, other parts of the world) have awakened much of the public to the risks of cyberattack-induced power outages, water supply interruptions, fuel distribution disruptions, loss of medical data and many other consequences that can do far more than just disrupt our daily routines \u2013 they can be truly life-threatening.<\/p>\n<p>Back in 2017, both Cherepanov and Lipovsky concluded their <a href=\"https:\/\/www.welivesecurity.com\/2017\/06\/12\/industroyer-biggest-threat-industrial-control-systems-since-stuxnet\/\">research blog<\/a> with a warning that, five years later, still holds true: \u201cRegardless of whether or not the recent attack on the Ukrainian power grid was a test, it should serve as a wake-up call for those responsible for security of critical systems around the world\u201d.<\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/2022\/06\/13\/industroyer-cyber-weapon-brought-down-power-grid\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Five years ago, ESET researchers released their analysis of the first ever malware that was designed specifically to attack power grids<\/p>\n","protected":false},"author":5,"featured_media":8318,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-8317","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8317"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8317\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8318"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}