Industroyer2 (CrashOverride 2)
¿Qué es Industroyer2 (CrashOverride 2)?
Industroyer2 (CrashOverride 2)A 2022 evolution of the Industroyer/CrashOverride electric-grid malware, attributed by ESET to Sandworm and used in an unsuccessful April 2022 attempt to cut power in a Ukrainian regional utility.
Industroyer2 is a 2022 ICS malware sample attributed by ESET and CERT-UA to Russia's Sandworm group, used in a 8 April 2022 attempt to disrupt a Ukrainian high-voltage substation. It is a leaner, single-target evolution of the 2016 Industroyer / CrashOverride malware that caused a Kyiv power outage. Industroyer2 implements the IEC 60870-5-104 protocol directly, with the target substation's IEC-104 endpoints and addresses hard-coded into the binary, indicating that the operator had performed long-running reconnaissance and obtained engineering data before deployment. The intended outcome — opening circuit breakers in a coordinated manner to cause a regional blackout — was prevented by Ukrainian defenders and ESET researchers in time. The campaign also delivered destructive wipers (CaddyWiper, Industroyer2-paired ORCSHRED/AWFULSHRED/SOLOSHRED scripts) to make recovery harder. Industroyer2 is the clearest public example of state-sponsored grid-targeted malware actually used in a kinetic conflict.
● Ejemplos
- 01
The April 2022 Industroyer2 attack on a Ukrainian regional electric utility was thwarted by defenders before circuit-breaker manipulation succeeded.
- 02
An OT NDR vendor publishes a YARA rule that detects Industroyer2's hard-coded IEC 60870-5-104 station address structure in suspect binaries.
● Preguntas frecuentes
¿Qué es Industroyer2 (CrashOverride 2)?
A 2022 evolution of the Industroyer/CrashOverride electric-grid malware, attributed by ESET to Sandworm and used in an unsuccessful April 2022 attempt to cut power in a Ukrainian regional utility. Pertenece a la categoría de OT / ICS / IoT en ciberseguridad.
¿Qué significa Industroyer2 (CrashOverride 2)?
A 2022 evolution of the Industroyer/CrashOverride electric-grid malware, attributed by ESET to Sandworm and used in an unsuccessful April 2022 attempt to cut power in a Ukrainian regional utility.
¿Cómo funciona Industroyer2 (CrashOverride 2)?
Industroyer2 is a 2022 ICS malware sample attributed by ESET and CERT-UA to Russia's Sandworm group, used in a 8 April 2022 attempt to disrupt a Ukrainian high-voltage substation. It is a leaner, single-target evolution of the 2016 Industroyer / CrashOverride malware that caused a Kyiv power outage. Industroyer2 implements the IEC 60870-5-104 protocol directly, with the target substation's IEC-104 endpoints and addresses hard-coded into the binary, indicating that the operator had performed long-running reconnaissance and obtained engineering data before deployment. The intended outcome — opening circuit breakers in a coordinated manner to cause a regional blackout — was prevented by Ukrainian defenders and ESET researchers in time. The campaign also delivered destructive wipers (CaddyWiper, Industroyer2-paired ORCSHRED/AWFULSHRED/SOLOSHRED scripts) to make recovery harder. Industroyer2 is the clearest public example of state-sponsored grid-targeted malware actually used in a kinetic conflict.
¿Cómo defenderse de Industroyer2 (CrashOverride 2)?
Las defensas contra Industroyer2 (CrashOverride 2) combinan habitualmente controles técnicos y prácticas operativas, como se detalla en la definición.
¿Cuáles son otros nombres para Industroyer2 (CrashOverride 2)?
Nombres alternativos comunes: Industroyer 2, CrashOverride 2.
● Términos relacionados
- ot-iot№ 588
Industroyer / CrashOverride
Malware ICS modular usado en el ataque a la red eléctrica ucraniana de 2016 y actualizado como Industroyer2 en 2022, capaz de hablar los protocolos nativos de la red.
- ot-iot№ 587
Sistema de Control Industrial (ICS)
Término que agrupa los sistemas que automatizan y supervisan procesos industriales, incluyendo SCADA, DCS, PLC, RTU y controladores de seguridad.
- ot-iot№ 1083
SCADA
Sistemas de supervisión, control y adquisición de datos que recogen telemetría de dispositivos de campo remotos y permiten operar grandes procesos industriales.
- ot-iot№ 1229
Stuxnet
Gusano altamente sofisticado de 2010 que saboteó centrífugas de enriquecimiento de uranio iraníes reprogramando PLC Siemens, atribuido a EE. UU. e Israel.
- ot-iot№ 1297
TRITON / TRISIS
Malware descubierto en 2017 que atacaba sistemas instrumentados de seguridad Triconex de Schneider en una planta petroquímica saudí, atribuido a un actor vinculado a Rusia.
- ot-iot№ 854
Tecnología Operativa (OT)
Hardware y software que monitorizan y controlan procesos físicos, dispositivos e infraestructuras como fábricas, centrales eléctricas y servicios públicos.
● Véase también
- № 570IEC 61850