Skip to main content
QUIETLYTIC
Campaign

2016 Ukraine Electric Power Attack

Sandworm Team's use of Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid in December 2016, the second major public attack Sandworm Team conducted against Ukraine.

Threat Level
CRITICAL
Status
Resolved
Actors Involved
Sandworm Team
Targets
Ukrainian electric power distribution substations

Overview

The 2016 Ukraine Electric Power Attack (MITRE ATT&CK ID C0025) was conducted by Sandworm Team using Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid, per MITRE’s campaign profile. MITRE documents this as the second major public attack conducted against Ukraine’s grid by Sandworm Team, following the 2015 Ukraine Electric Power Attack. Industroyer is notable, per MITRE’s citations, as purpose-built malware capable of directly communicating with industrial control system protocols used by grid equipment — rather than relying on generic remote-access tooling repurposed for the task.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window is December 2016.

Actors and malware involved (per MITRE ATT&CK relationship data)

MITRE ATT&CK attributes this campaign to Sandworm Team. Malware documented in this campaign is Industroyer, purpose-built to interact directly with the industrial control protocols used in electric grid distribution substations.

What we don’t have

MITRE’s ingested data doesn’t include the specific initial-access method used to reach the targeted substation networks in this campaign. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no data on whether Industroyer’s protocol-specific modules were reused unmodified from earlier tooling or purpose-built for this campaign specifically.

Frequently Asked Questions

What was the 2016 Ukraine Electric Power Attack? A campaign, per MITRE ATT&CK, in which Sandworm Team used the purpose-built Industroyer malware to disrupt Ukrainian power grid distribution substations in December 2016.

How is Industroyer different from the malware used in the 2015 attack? The 2015 attack used BlackEnergy3 and KillDisk, general-purpose access and destructive tools. Industroyer, used in this 2016 campaign, was purpose-built to communicate directly with industrial control system protocols specific to grid equipment, per MITRE’s documentation.

Who was behind the 2016 Ukraine Electric Power Attack? Sandworm Team, per MITRE ATT&CK’s relationship data — the same actor MITRE attributes to the earlier 2015 attack on the Ukrainian grid.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0025, aggregated September 20, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools