Power Grid
Azerbaijan energy sector — PoetRAT espionage with wind-SCADA interest
February–April 2020
Azerbaijan
What happened
Cisco Talos documented waves of a previously unknown Python remote-access trojan, dubbed PoetRAT, delivered via malicious Word documents including COVID-19-themed lures styled as Azerbaijani government letters. Targets included government and energy-sector organizations, and the actor demonstrated specific interest in SCADA systems associated with wind turbines, collecting files, credentials and webcam images. Talos could not link the activity to a known actor, and no operational disruption of turbines was confirmed — this is an espionage record, kept because of the demonstrated targeting of renewable-energy control systems. The marker is a country-level reference at Baku.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Reported / attributed
- Confidence
- Moderate
- Infrastructure
- Power Grid
- Latitude
- 40.4100°
- Longitude
- 49.8700°
Attribution
Responsibility has not been established in the cited reporting.
