Netskope Threat Labs

Industroyer

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Industroyer targets industrial control systems with advanced malware capabilities, and researchers regard it as one of the most capable ICS attack tools ever observed. It speaks multiple industrial protocols natively, allowing it to switch breakers and manipulate equipment in electric power environments, and it played a central role in the December 2016 attack on the Kyiv power grid. Its successors have reused its approach, and its disclosure reshaped how defenders assess grid security.

First seen
February 2022
Last seen
October 2026
CrashOverride

19 techniques across 6 tactics.

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1554Compromise Host Software Binary

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1078Valid Accounts
  • T1140Deobfuscate/Decode Files or Information

TA0007 Discovery

  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1018Remote System Discovery
  • T1046Network Service Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

Alert Name
Gen:Variant.Industroyer.2
Gen:Variant.Industroyer.4
Gen:Variant.Industroyer.6
Gen:Variant.Industroyer.9
Trojan.Industroyer.A
Trojan.Industroyer.B
Win32.Backdoor.CrashOverride
Win32.Backdoor.Industroyer
Win32.Trojan.CrashOverride
Win32.Trojan.Industroyer