Summary

CrashOverride (Dragos) / Industroyer (ESET) is a modular attack platform disclosed on 12 June 2017. It was used against a transmission substation near Kyiv on 17 December 2016, cutting power to part of the city for about an hour, a year after the 2015 BlackEnergy 3 attack.

Unlike 2015, where attackers drove the utilities’ own software by hand, Industroyer automated the attack in code. It shipped protocol modules that issue valid commands directly to field equipment. According to the U.S. advisory, its components included:

  • payload modules for IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA, the protocols that run substations;
  • a module able to toggle circuit breakers in a rapid open-close-open-close pattern;
  • a denial-of-service tool against Siemens SIPROTEC protective relays;
  • network scanning to map targets, and a wiper that renders Windows hosts inoperable to delay recovery.

The U.S. government attributes CrashOverride to Russian nation-state actors (attribution updated July 2021). The activity is tracked as ELECTRUM (Dragos) and Sandworm.

Apa maksudnya untuk Malaysia? 🇲🇾

IEC 60870-5-104 and IEC 61850 are standard protocols in modern substations worldwide. Industroyer proved an attacker does not need a vulnerability in them: legitimate protocol commands, sent from the wrong host, are enough. For Malaysian energy operators (an NCII sector under the Cyber Security Act 2024), the defensive question is visibility:

  • Can you see every host that sends control commands (select/operate, breaker control) on your substation networks, and would a new one raise an alert?
  • Are protective relays patched and segmented? A relay knocked offline removes protection exactly when it’s needed most.
  • Industroyer was later rebuilt as Industroyer2 (2022). The capability is maintained, not retired.

Details / TTPs (ATT&CK for ICS)

TechniqueNameObserved behavior
T0846Remote System DiscoveryNetwork scanning to locate substation devices
T1692.001Command MessageIEC 101/104/61850 and OPC commands to open breakers
T0814Denial of ServiceDoS against Siemens SIPROTEC relays
T0837Loss of ProtectionProtective relays knocked offline
T0809Data DestructionWiper module to delay recovery
T0813Denial of ControlOperators prevented from controlling the process
T0827Loss of ControlBreakers operated by the attacker

Detection guidance

  • Maintain an allow-list of master stations per substation protocol, and alert on control commands from any other source.
  • Alert on rapid repeated state changes of the same breaker.
  • Monitor relay availability; a relay dropping off the network should be treated as a security event, not just maintenance.

IoCs

Indicators and YARA rules are published in the referenced CISA alert and the ESET/Dragos reports.

References