Summary

On 23 December 2015, three regional electricity distribution companies (oblenergos) in Ukraine suffered coordinated cyberattacks that caused unscheduled outages for approximately 225,000 customers. It is the first publicly confirmed case of a cyberattack causing a power outage.

The intrusion began months earlier with spear-phishing emails carrying malicious Microsoft Office attachments that installed BlackEnergy 3. The attackers harvested credentials and then used the utilities’ own VPN access and remote ICS client software to operate breakers from outside. To slow recovery they also:

  • wiped workstations and servers with KillDisk, which corrupts the master boot record;
  • corrupted the firmware of serial-to-Ethernet converters at substations, cutting operators off from field devices;
  • scheduled disconnects of the uninterruptible power supplies (UPS) feeding control-centre servers.

Operators restored power by switching substations manually, and operations stayed constrained for months afterwards. In October 2020 the U.S. Department of Justice indicted officers of Russia’s GRU Unit 74455 (Sandworm), whose charges cover the attacks on Ukraine’s power grid.

BlackEnergy 3 itself is not ICS-specific malware. The physical effect came from attackers using legitimate control software with stolen credentials. That is why this case still shapes OT defence today.

Apa maksudnya untuk Malaysia? 🇲🇾

Energy is one of the 11 National Critical Information Infrastructure (NCII) sectors under the Cyber Security Act 2024. Every step of this attack maps onto an ordinary corporate weakness that Malaysian utilities and large industrial sites can audit today:

  • Remote access into OT without MFA. The attackers reached the HMIs through the utilities’ own VPNs. Edge devices that grant OT access are a prime target here too; see the FortiBleed credential campaign that affected Malaysian organisations in June 2026.
  • Flat IT/OT networks. Phishing a corporate mailbox led to control of breakers. NC4’s March 2026 alert on network segmentation to prevent malware propagation addresses exactly this path.
  • No manual fallback. Ukraine recovered because crews could still operate substations by hand. Test whether your plant or substation can run, and be restored, without its SCADA and engineering workstations.

Details / TTPs (ATT&CK for ICS)

TechniqueNameObserved behavior
T0865Spearphishing AttachmentOffice documents delivering BlackEnergy 3
T0822External Remote ServicesUtility VPNs used to reach the control network
T0859Valid AccountsHarvested credentials for VPN and ICS clients
T0823Graphical User InterfaceAttackers drove the operators’ HMI/DMS software remotely
T0831Manipulation of ControlBreakers opened at substations via the operators’ own software
T1693.001System FirmwareMalicious firmware bricked serial-to-Ethernet converters
T0816Device Restart/ShutdownScheduled UPS disconnects took down control-centre servers
T0809Data DestructionKillDisk wiped systems and the master boot record
T0826Loss of AvailabilityOutage for ~225,000 customers
T0827Loss of ControlOperators locked out of remote control during recovery

Detection guidance

  • Alert on OT remote-access sessions outside change windows, and on any HMI session originating from the VPN rather than the control room.
  • Baseline breaker operations: unexpected open commands across multiple substations within minutes is a high-fidelity signal.
  • Monitor firmware writes to network and serial gateways, and keep known-good firmware images offline.
  • Enforce MFA and jump hosts for every path into OT, and keep the UPS and out-of-band management off the corporate network.

IoCs

BlackEnergy 3 and KillDisk indicators are published in the referenced advisory and in vendor reporting. Behavioural detections (above) remain more durable than hashes for this campaign.

References