Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0025
MITRE ATT&CK Campaign · 2016–2016

2016 Ukraine Electric Power Attack (C0025)

ShareXLinkedInRedditHN

[2016 Ukraine Electric Power Attack](https://attack.mitre.org/campaigns/C0025) was a [Sandworm Team](https://attack.mitre.org/groups/G0034) campaign during which they used [Industroyer](https://attack.mitre.org/software/S0604) malware to target and disrupt distribution substations within the Ukrainian power grid. This campaign was the second major public attack conducted against Ukraine by [Sandworm Team](https://attack.mitre.org/groups/G0034).(Citation: ESET Industroyer)(Citation: Dragos Crashoverride 2018)

▪Attributed groups (1)

G0034Sandworm Team

▪Techniques used (27)

T1059.005Visual BasicT1036.008Masquerade File TypeT1059.001PowerShellT1036.005Match Legitimate Resource Name or LocationT1505.001SQL Stored ProceduresT1136Create AccountT1685.001Disable or Modify Windows Event LogT1570Lateral Tool TransferT1059.003Windows Command ShellT1027Obfuscated Files or InformationT1543.003Windows ServiceT1027.002Software PackingT1036.010Masquerade Account NameT1003.001LSASS MemoryT1047Windows Management InstrumentationT1098Account ManipulationT1110Brute ForceT1136.002Domain AccountT1018Remote System DiscoveryT1554Compromise Host Software BinaryT1021.002SMB/Windows Admin SharesT0867Lateral Tool TransferT0886Remote ServicesT0853ScriptingT0859Valid AccountsT0807Command-Line InterfaceT0849Masquerading

▪Software used (1)

S0604Industroyermalware
C0025on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.