Case Study - Industrial Control System (ICS) Cyberattack
Ukraine Power Grid Attack
Year – 2015
Estimated Economic Losses – No authoritative total financial loss figure publicly established
Systems Affected – Approximately 225,000 Customers
Type of Attack – Critical Infrastructure Cyberattack | ICS/SCADA Attack
Suspected Group / Organization – Associated with the Sandworm Group and attributed to Russian state-sponsored cyber actors
Detailed Working
Attackers used spear-phishing emails and malicious attachments to gain initial access to Ukrainian power distribution companies. After infiltrating the networks, they stole credentials, moved laterally, accessed operational control systems, and remotely opened circuit breakers at electrical substations, causing widespread power outages.
Forensic Investigations
Investigators used malware analysis, network traffic examination, system log analysis, and ICS/SCADA forensics to reconstruct the attack. The investigation identified Black Energy malware, compromised credentials, unauthorized remote access, malicious activity within operational networks, and destructive KillDisk malware, while threat intelligence and infrastructure analysis contributed to the attack’s attribution.
Investigators used malware analysis, network traffic examination, system log analysis, and ICS/SCADA forensics to reconstruct the attack. The investigation identified Black Energy malware, compromised credentials, unauthorized remote access, malicious activity within operational networks, and destructive KillDisk malware, while threat intelligence and infrastructure analysis contributed to the attack’s attribution.
+91-7087055115
Subscribe Now.
No content is added yet.