Summary
CrashOverride (Dragos) / Industroyer (ESET) is a modular attack platform disclosed on 12 June 2017. It was used against a transmission substation near Kyiv on 17 December 2016, cutting power to part of the city for about an hour, a year after the 2015 BlackEnergy 3 attack.
Unlike 2015, where attackers drove the utilities’ own software by hand, Industroyer automated the attack in code. It shipped protocol modules that issue valid commands directly to field equipment. According to the U.S. advisory, its components included:
- payload modules for IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA, the protocols that run substations;
- a module able to toggle circuit breakers in a rapid open-close-open-close pattern;
- a denial-of-service tool against Siemens SIPROTEC protective relays;
- network scanning to map targets, and a wiper that renders Windows hosts inoperable to delay recovery.
The U.S. government attributes CrashOverride to Russian nation-state actors (attribution updated July 2021). The activity is tracked as ELECTRUM (Dragos) and Sandworm.
Apa maksudnya untuk Malaysia? 🇲🇾
IEC 60870-5-104 and IEC 61850 are standard protocols in modern substations worldwide. Industroyer proved an attacker does not need a vulnerability in them: legitimate protocol commands, sent from the wrong host, are enough. For Malaysian energy operators (an NCII sector under the Cyber Security Act 2024), the defensive question is visibility:
- Can you see every host that sends control commands (select/operate, breaker control) on your substation networks, and would a new one raise an alert?
- Are protective relays patched and segmented? A relay knocked offline removes protection exactly when it’s needed most.
- Industroyer was later rebuilt as Industroyer2 (2022). The capability is maintained, not retired.
Details / TTPs (ATT&CK for ICS)
| Technique | Name | Observed behavior |
|---|---|---|
| T0846 | Remote System Discovery | Network scanning to locate substation devices |
| T1692.001 | Command Message | IEC 101/104/61850 and OPC commands to open breakers |
| T0814 | Denial of Service | DoS against Siemens SIPROTEC relays |
| T0837 | Loss of Protection | Protective relays knocked offline |
| T0809 | Data Destruction | Wiper module to delay recovery |
| T0813 | Denial of Control | Operators prevented from controlling the process |
| T0827 | Loss of Control | Breakers operated by the attacker |
Detection guidance
- Maintain an allow-list of master stations per substation protocol, and alert on control commands from any other source.
- Alert on rapid repeated state changes of the same breaker.
- Monitor relay availability; a relay dropping off the network should be treated as a security event, not just maintenance.
IoCs
Indicators and YARA rules are published in the referenced CISA alert and the ESET/Dragos reports.
References
- CISA, CrashOverride Malware (TA17-163A, 12 Jun 2017): https://www.cisa.gov/news-events/alerts/2017/06/12/crashoverride-malware
- ESET, Industroyer: Biggest threat to industrial control systems since Stuxnet (12 Jun 2017): https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/