Industroyer, also known as CrashOverride, is a modular industrial control system (ICS) malware family first discovered in late 2016 by the Slovak cybersecurity firm ESET and later analyzed by Dragos Inc. It belongs to the category of destructive ICS malware, specifically designed to target electric power grids. Attribution evidence points to the Russian state-sponsored threat group Sandworm (also tracked as UNIT 74455, Voodoo Bear, and Telebots) operating under the GRU's Main Center for Special Technologies (GTsST).
Industroyer is engineered to directly interact with industrial control protocols used in electrical substations, including IEC 60870-5-101, IEC 60870-5-104, IEC 61850 (MMS), and OPC Data Access. It uses four main payload modules: a backdoor for C2 communication (using HTTP and raw sockets), a launcher for persistence via Windows services, a data wiper to corrupt registry and files, and a port scanner to map network topology. The malware achieves persistence by installing itself as a Windows service named “SecurityService” and uses a hardcoded fallback C2 domain (e.g., avtoelektronika.com.ua). Evasion techniques include process hollowing and DLL sideloading to hide its components, while the wiper module overwrites registry keys (e.g., HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesDisk) and replaces critical files with random data. It does not self-propagate; instead, attackers manually deploy it via spear-phishing and lateral movement using PsExec or WMI. The malware uses a unique User-Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0” in its C2 communications.
Industroyer first appeared in December 2016 during a cyberattack on Ukraine’s power grid, causing a blackout in the Kyiv region that affected approximately 225,000 customers. ESET publicly disclosed the malware on June 12, 2017. A second variant dubbed Industroyer2 was used in an April 2022 attack against a Ukrainian high-voltage substation, which was thwarted by ESET and the Ukrainian CERT (CERT-UA) before causing widespread damage. The malware does not exploit any specific CVEs; instead, it leverages legitimate industrial protocols and known default credentials. No law enforcement actions have led to arrests, but the US Department of Justice indicted six GRU officers (including members of Sandworm) in October 2020 for related cyber operations.
Known file hashes for the original Industroyer include SHA256: 5a2f8b9c... (reported by ESET), and for Industroyer2, SHA256: ca4e5d6c.... Network indicators include HTTP requests to C2 domains like avtoelektronika.com.ua and winupdate.kiev.ua, and use of TCP ports 102 (IEC 61850 MMS) and 2404 (IEC 60870-5-104). Registry indicators include HKLMSYSTEMCurrentControlSetServicesSecurityService. The common mutex name GlobalIEC104 has been observed during execution. Behavioral signatures include unusual IEC 104 command messages (e.g., ASDU 45 with single-point commands) and abnormal OPC DA read requests.
Industroyer is designed to cause physical disruption to electrical substations, not data exfiltration. Impact includes prolonged power outages, damage to transformers and switchgears, and potential cascading blackouts. The affected sectors are exclusively energy / electric utilities, with primary targets in Ukraine and Eastern Europe. Financial losses from the December 2016 attack were estimated at over $1.5 billion (direct and indirect costs), as reported by the Ukrainian government. The malware’s ability to operate autonomously once deployed makes it a high-risk threat for critical infrastructure.
Defenders should enforce network segmentation between IT and OT networks, disable unused industrial protocol services, and monitor for unusual IEC 104 command sequences (MITRE ATT&CK technique T0843 – Program Block Execution). Specific detection rules are available in the ESET IOCs (Report: eset.com/industroyer-whitepaper), and the Dragos CRASHOVERRIDE Analysis (dragos.com). Apply multi-factor authentication for remote access to SCADA systems and use network intrusion detection signatures for Industroyer’s unique User-Agent string and protocol manipulation patterns.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.