The Russian state-run hacking group known as Sandworm on Friday attempted to destroy a major Ukrainian energy provider by disconnecting its electrical substations with a new variant of the Industroyer malware for industrial control systems (ICS) and a new version of the CaddyWiper data destruction malware.
See also: Google sues Puppy Scammer targeting consumers

The threat actor used a version of the Industroyer ICS malware tailored for the targeted high-voltage electrical substations and then attempted to erase traces of the attack by running CaddyWiper and other data-wiping malware families tracked as Orcshred, Soloshred, and Awfulshred for Linux and Solaris systems.
Researchers from cybersecurity firm ESET , who are working with the Ukrainian Computer Emergency Response Team (CERT) to restore and protect the attacked network , say they do not know how the attacker compromised the environment or how he managed to move from the IT network to the ICS environment.
See also: CISA in organizations: Fix the WatchGuard bug
The image below shows an overview of the data wiping elements used in the attack:

The ICS malware used in the attack is now being tracked as Industroyer2 and ESET assess “with high confidence” that it was built using the source code used in 2016 to cut power in Ukraine and attributed to the Russian state-sponsored.
CERT-UA and ESET say the Sandworm group planned to launch the final stage of the attack on Friday, April 8 (at 14:58 UTC) by deploying malware to the following types of systems:
- Windows computers and automated workstations with the deployment of the CaddyWiper malware, which is decrypted, loaded and executed via the ArgeuPatch and Tailjump tools (at 14:58 UTC)
- Linux servers using the OrcShred, Soloshred and AwfulShred scripts (at 14:58 UTC)
- high-voltage electrical substations using the INDUSTROYER2 malware. Sandworm operators created a scheduled task at 15:02:22 UTC to launch the malware at 16:10 UTC and cut off power in a region of Ukraine
- active network equipment
At 16:20 UTC, the adversary executed CaddyWiper on the machines to erase Industroyer2's traces.
See also: Fakecalls trojan: Hacks users' calls to bank customer support
CERT-UA says that “the implementation of Sandworm’s malicious plan has so far been prevented,” while ESET notes in a technical report on the malware used in this attack that “Sandworm attackers attempted to deploy the Industroyer2 malware against high-voltage electrical substations in Ukraine.”.
New Industroyer version
Industroyer, also known as CrashOverride, was first analyzed in 2017, with ESET calling it the “biggest threat to industrial control systems since Stuxnet.”.
The new variant used last week on a Ukrainian energy provider is an evolution of the original malware used in the 2016 power outage attacks in Ukraine.
Information source: bleepingcomputer.com
