Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstate-sponsored-disruptionoperational-disruptionindustrial-control-system-vulnerability

Sandworm Linked to Cyberattack That Disrupted Ukraine’s Power Grid

Updated 28d agoFirst seen May 25, 20266 sources

Ukrainian electric utilities suffered a coordinated cyberattack that caused power outages for civilians, marking one of the clearest cases of a cyber operation producing a real-world disruption of critical infrastructure. Reporting from iSIGHT Partners and SANS ICS assessed with high confidence that the outage was intentional and attributed the intrusion to Sandworm Team, citing the presence of BlackEnergy 3 malware in affected environments and the use of the destructive component KillDisk during the operation.

U.S. government industrial control system alerts later documented the incident as a cyberattack against Ukrainian critical infrastructure and tied it to a broader, ongoing malware campaign targeting ICS environments. The reporting said KillDisk may have been used less to trigger the outage than to hinder restoration and operator visibility after the attack, while flooding utility call centers with phone traffic likely complicated response efforts; the incident also fit Sandworm’s wider pattern of targeting Ukrainian entities, regional power organizations, and other government and media networks while showing sustained interest in SCADA and industrial control systems.

Share:
Sandworm Linked to Cyberattack That Disrupted Ukraine’s Power Grid
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jul 22, 20215y ago

CISA republishes Update E on ongoing sophisticated ICS malware campaign

CISA republished Update E of its alert on an ongoing sophisticated malware campaign compromising industrial control systems, preserving related historical reporting in its archive. The referenced campaign provides context for Sandworm's earlier ICS-focused activity.

Jul 20, 20215y ago

CISA republishes archived alert on Ukrainian critical infrastructure attack

CISA republished the historical incident response alert covering the cyberattack against Ukrainian critical infrastructure as part of its advisory archive. This was a republication of earlier government reporting rather than a new incident.

Feb 25, 201610y ago

US-CERT publishes alert on cyberattack against Ukrainian critical infrastructure

US-CERT/CISA published an incident response alert documenting the cyberattack against Ukrainian critical infrastructure. The alert formalized U.S. government reporting on the incident.

Jan 7, 201610y ago

iSIGHT and SANS assess outage was a deliberate cyberattack by Sandworm

iSIGHT Partners and SANS ICS assessed with high confidence that the 2015 Ukrainian power outages were caused by a coordinated cyberattack and attributed the incident to Sandworm Team. The assessment framed the event as a milestone in cyber operations affecting civilian critical infrastructure.

Dec 23, 201511y ago

BlackEnergy 3 and KillDisk found in affected Ukrainian environments

Investigators found BlackEnergy 3 malware and related KillDisk destructive malware in environments affected by the Ukrainian power outage. Analysts assessed KillDisk may have been used to hinder restoration or operator visibility rather than directly cause the outage.

Coordinated cyberattack disrupts electric power in Ukraine

In 2015, Ukrainian power utilities suffered a coordinated, intentional cyberattack that caused power outages affecting civilians. The incident also involved phone flooding against utility support lines, which likely complicated response efforts.

Oct 14, 201412y ago

Public reporting links Sandworm to CVE-2014-4114 exploitation

Public reporting identified Sandworm Team's use of CVE-2014-4114 and highlighted the group's interest in industrial control systems. These findings became part of the attribution context for later attacks on Ukrainian critical infrastructure.

May 1, 201412y ago

Sandworm begins broader targeting of Ukrainian and regional entities

Before the 2015 outage, Sandworm Team had already been reported targeting Ukrainian organizations as well as EU, NATO, media, and regional power entities, including reconnaissance against SCADA and other critical infrastructure systems. This activity established the broader campaign context later tied to the power-sector incident.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Sandworm Linked to Cyberattack That Disrupted Ukraine’s Power Grid | Mallory