Power Grid

Azerbaijan energy sector — PoetRAT espionage with wind-SCADA interest

February–April 2020

Azerbaijan

What happened

Cisco Talos documented waves of a previously unknown Python remote-access trojan, dubbed PoetRAT, delivered via malicious Word documents including COVID-19-themed lures styled as Azerbaijani government letters. Targets included government and energy-sector organizations, and the actor demonstrated specific interest in SCADA systems associated with wind turbines, collecting files, credentials and webcam images. Talos could not link the activity to a known actor, and no operational disruption of turbines was confirmed — this is an espionage record, kept because of the demonstrated targeting of renewable-energy control systems. The marker is a country-level reference at Baku.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Reported / attributed
Confidence
Moderate
Infrastructure
Power Grid
Latitude
40.4100°
Longitude
49.8700°

Attribution

Responsibility has not been established in the cited reporting.

Sources

  1. PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectorsCisco Talos · Incident reporting