logo

ELECTRUM Targeted Ukrainian Electric Entity Using Custom Tools and CaddyWiper Malware, October 2022

ID: 8f9b431b-8427-5b76-a507-61b901aa0b51

STIX ID: report--8f9b431b-8427-5b76-a507-61b901aa0b51

Feed Name: Dragos Blog

Threat Score
88/100

Date Published: 2023-12-11

Date Updated: 2026-04-27

...
...

Executive summary: Dragos and Mandiant reporting describes ELECTRUM (linked to Sandworm) operations against Ukrainian electric substations in 2022 that involved compromise of an end-of-life MicroSCADA hypervisor, long dwell times, and deployment of destructive tooling including a CaddyWiper variant and Industroyer2. The initial access vector remains unknown, but investigators highlight the importance of OT-specific detection and proactive threat hunting (monitoring file transfers into OT, unexpected script execution, and anomalous SCADA commands) to detect similar adversary activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.