Power Grid

Ukrainian high-voltage substations — Industroyer2 attempt

8 April 2022 (planned detonation; disrupted in advance)

Ukraine (regional energy provider; sites undisclosed)

What happened

CERT-UA and ESET disrupted an attempted attack on high-voltage electrical substations of a Ukrainian regional energy provider using Industroyer2, an updated variant of the malware behind the 2016 Kyiv blackout, deployed alongside CaddyWiper and other destructive tools for Linux and Solaris systems. The malware was scheduled to cut power on 8 April 2022 during the Russian invasion and to wipe systems afterward to slow recovery. The targeted operator and substation locations were not disclosed, so the marker is a country-level reference. The attempt was largely mitigated before the planned detonation.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
49.0000°
Longitude
31.4000°

Attribution

Attributed to Sandworm (Russian military intelligence)

CERT-UA and ESET attributed the operation to Sandworm with high confidence.

Sources

  1. Industroyer2: Industroyer reloadedESET WeLiveSecurity, with CERT-UA · Incident reporting