At 3:35 PM on December 23, 2015, control room operators at three Ukrainian electricity distribution companies watched their cursors move across the screen without their hands on the mouse. Remote attackers had taken control of their supervisory control and data acquisition systems and were systematically opening circuit breakers - cutting power to approximately 230,000 customers across western Ukraine for one to six hours. It was the first confirmed cyberattack to successfully cause a power outage. It would not be the last.
The December 2015 Ukraine power grid attack, and its sequel in December 2016, were the work of Sandworm - a hacking group operating within Russia's GRU military intelligence directorate, Unit 74455, also known as the Main Center for Special Technologies. Sandworm is the most destructive cyberattack group ever documented: responsible for the Ukraine power grid attacks, for NotPetya (the $10 billion wiper disguised as ransomware), for the 2018 Winter Olympics Destroyer, and for sustained operations against Ukrainian infrastructure throughout Russia's war. Understanding Sandworm means understanding what a nation-state that has chosen to use offensive cyber capabilities without restraint actually looks like in practice.
The 2015 Attack: How Sandworm Cut the Lights
The 2015 attack was sophisticated in its preparation but surprisingly conventional in its initial access. Sandworm had compromised the energy company networks months earlier using BlackEnergy malware delivered through spear-phishing emails with malicious Excel attachments. The emails were targeted at employees at electricity distribution companies, sent with content plausible to someone working in energy infrastructure. Once installed, BlackEnergy established persistence and gave the attackers a foothold in the corporate IT networks.
Over the subsequent months, the attackers conducted reconnaissance - learning the network topology, identifying the OT (operational technology) networks that controlled the actual power distribution systems, and understanding how the systems worked well enough to plan a coordinated disruption. The OT systems were connected to the corporate IT networks, a common and dangerous configuration that allowed the attackers to pivot from email compromise to SCADA access.
On December 23, the attackers executed simultaneously across three companies. They used legitimate remote access tools - the companies' own VPN infrastructure, with stolen credentials - to connect to the SCADA systems. They opened circuit breakers remotely, cutting power. Simultaneously, they deployed a tool called KillDisk to wipe the drives of systems in the control centers, preventing operators from quickly restoring control. They also attacked the UPS (uninterruptible power supply) systems to prevent orderly shutdown procedures. Finally, they flooded the companies' customer service phone lines with fake calls to prevent customers from reaching support, maximizing the chaos during the outage.
The power was restored within hours by operators working manually - physically driving to substations and switching breakers by hand. The SCADA systems had to be rebuilt from scratch because of the KillDisk wiper. The attack demonstrated both what was possible and what the limits of pure software disruption were: physical control systems can be operated manually if operators are present and trained.
The 2016 Attack: Industroyer
December 2016 brought a second attack on Ukrainian power infrastructure, this time against a transmission substation in Kyiv. The December 17 attack cut power to approximately a fifth of Kyiv's total capacity for about an hour. But what interested security researchers more than the outage itself was the malware used: a framework called Industroyer (also named Crashoverride by Dragos), which represented a qualitative leap in ICS malware sophistication.
Previous attacks on industrial control systems - including Stuxnet - were highly targeted, designed to attack a specific configuration of specific hardware at a specific facility. Industroyer was designed differently: it was a modular framework capable of speaking multiple industrial communication protocols natively, allowing it to operate against different types of ICS equipment. The malware included modules supporting IEC 104 (a protocol used in European power systems), IEC 101, IEC 61850, and OPC DA - covering the major protocols used in power distribution and transmission globally.
This modularity meant Industroyer was not a one-use weapon designed for Ukraine specifically. It was a reusable platform that could be directed against electricity infrastructure in multiple countries with different ICS protocol configurations. The implication - that Sandworm was building a capability for future use against any country's power grid, not just Ukraine - was what made the discovery of Industroyer so alarming to Western power grid security researchers.
Industroyer2 and the 2022 Escalation
When Russia invaded Ukraine in February 2022, Sandworm activated a new campaign against Ukrainian infrastructure at a pace and scale that reflected both expanded operational tempo and preparation that had clearly begun months before the invasion. On April 8, 2022 - just six weeks into the war - ESET and CERT-UA discovered and disrupted an attack targeting a Ukrainian energy provider that used a new variant called Industroyer2.
Industroyer2 was specifically compiled for the target: the binary contained hardcoded configuration data for the specific substations and IEC 104 protocol addresses at the targeted Ukrainian energy company. This customization meant the malware would only work against that specific target - evidence that Sandworm had done detailed reconnaissance of the facility and incorporated that intelligence into the malware before deployment.
The April 2022 attack was disrupted before the power was cut, making it significant in a different way: it demonstrated Ukrainian defenders had improved sufficiently to catch the attack in progress. Ukraine's cybersecurity agency CERT-UA, working with ESET and industrial security firm Mandiant, identified the malware and removed it before the scheduled execution. The incident provided detailed technical intelligence about Sandworm's current capabilities and deployment methodology.
The same attack package included a wiper called CaddyWiper that would have erased Linux systems in the environment, and Orcshred/Soloshred/Awfulshred tools targeting Linux and Solaris machines - suggesting the attack was planned to be as comprehensive and disruptive as possible, with data destruction to complicate recovery following the power disruption.
Sandworm's Broader Portfolio
The Ukraine power grid attacks are the most technically documented Sandworm operations, but they are not the group's only significant work. The full Sandworm portfolio illustrates the range of operations a well-resourced, state-sponsored group with minimal constraints will conduct.
Olympic Destroyer, deployed against the 2018 PyeongChang Winter Olympics, took down the internet, Wi-Fi, and broadcast systems at the opening ceremony, making it impossible to print tickets and briefly disrupting the TV broadcast feed. The malware was deliberately constructed to include false attribution indicators from multiple other nation-state actor groups - North Korean, Chinese, and Russian code artifacts were present - in what may be the most sophisticated deliberate false-flag operation in documented cyber history. Researchers eventually attributed it to Sandworm based on infrastructure and operational patterns, but the attribution took months of careful analysis.
NotPetya, deployed in June 2017 initially through the Ukrainian accounting software MeDoc, used EternalBlue and Mimikatz to propagate globally. Though it presented a ransom note, the payment mechanism was non-functional - NotPetya was not ransomware but a wiper. It destroyed the data and functionality of systems at Maersk, Merck, FedEx, Mondelez, and dozens of other major companies that had operations in Ukraine, causing estimated damages of $10 billion globally. The attack was not targeted at Western companies but destroyed their systems as collateral damage.
VPNFilter, a sophisticated modular malware that had infected over 500,000 routers and NAS devices globally by 2018, included the capability to render infected devices permanently inoperable on command. The FBI's public warning about VPNFilter and subsequent takedown operation was unusual in its specificity - naming Sandworm as the operator and describing the full-take infection capability that could brick half a million devices simultaneously.
Why Ukraine Was the Test Range
The concentration of Sandworm operations in Ukraine is not coincidental. Russia's ongoing conflict with Ukraine - both the 2014 annexation of Crimea and destabilization of the Donbas, and the 2022 full-scale invasion - created conditions where aggressive offensive cyber operations could be used with limited concern for diplomatic consequences. Ukraine was a live laboratory where new capabilities, including Industroyer, could be tested against real infrastructure under real operational conditions.
This operational experience has significant implications for Western critical infrastructure security. The techniques developed and refined against Ukrainian power grids - the SCADA reconnaissance, the ICS protocol manipulation, the coordinated multi-site execution, the KillDisk wiper for recovery interference - represent a mature playbook. The specific configurations used in the Ukrainian attacks would need adaptation for different Western power grid architectures, but the operational methodology is transferable.
This is part of the reason why CISA's advisories about Volt Typhoon's pre-positioning in US critical infrastructure carry such urgency. The most alarming scenario is not an attack that comes without preparation - it is an attack that uses months of pre-positioned access and a mature operational playbook to execute simultaneously against multiple infrastructure targets in a moment of geopolitical crisis.
The Deterrence Problem
Sandworm's operations present a deterrence problem that Western governments have not resolved. The operations against Ukrainian power infrastructure caused real harm to civilians - hundreds of thousands without heat in winter, hospitals on backup power, disruption to essential services. The NotPetya collateral damage to Western companies caused billions in losses. Yet the diplomatic response has been limited: indictments of GRU officers in 2020 who will never be extradited, sanctions that have not changed Russian behavior, and repeated advisories about defensive measures that have not been fully implemented.
Part of the deterrence failure is structural. Offensive cyber operations exist in a gray zone below the threshold of conventional military response. Even NotPetya - the most destructive cyberattack in history, affecting companies in dozens of countries - did not trigger a response that Sandworm operators would recognize as costly. The US government eventually attributed it publicly to Russia, but attribution without consequence is not deterrence.
The most effective response to Sandworm's operations against Ukraine has been defensive: CERT-UA has developed capabilities to detect and disrupt Sandworm attacks that it did not have in 2015. The interception of the April 2022 Industroyer2 deployment before the power was cut represents genuine defensive success. But the same group continues to operate, continues to develop new capabilities, and continues to enjoy the cover of a state patron that has not been made to bear costs commensurate with the damage its cyber forces have caused.