← Back to all campaigns
ActiveMITRE ATT&CK

2022 Ukraine Electric Power Attack

The 2022 Ukraine Electric Power Attack was a Sandworm Team campaign that used a combination of GOGETTER, Neo-REGEORG, CaddyWiper, and living of the land (LotL) techniques to gain access to a Ukrainian electric utility to send unauthorized commands from their SCADA system.

First observedJun 1, 2022
Last observedOct 1, 2022
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been ...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

Sandworm Team attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

2022 Ukraine Electric Power Attack last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

2022 Ukraine Electric Power Attack first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Related vulnerabilities 0

No linked CVEs are available.

ATT&CK techniques 79

Malware and tools 27

  • AcidPourMalware | Sandworm Team
  • AcidRainMalware | Sandworm Team
  • Bad RabbitMalware | Sandworm Team
  • BlackEnergyMalware | Sandworm Team
  • Cobalt StrikeMalware | Sandworm Team
  • Cyclops BlinkMalware | Sandworm Team
  • Exaramel for LinuxMalware | Sandworm Team
  • Exaramel for WindowsMalware | Sandworm Team
  • GreyEnergyMalware | Sandworm Team
  • IndustroyerMalware | Sandworm Team
  • Industroyer2Malware | Sandworm Team
  • KapekaMalware | Sandworm Team

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.

Continue investigating

Campaigns with shared actors