Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0028
MITRE ATT&CK Campaign · 2015–2016

2015 Ukraine Electric Power Attack (C0028)

ShareXLinkedInRedditHN

[2015 Ukraine Electric Power Attack](https://attack.mitre.org/campaigns/C0028) was a [Sandworm Team](https://attack.mitre.org/groups/G0034) campaign during which they used [BlackEnergy](https://attack.mitre.org/software/S0089) (specifically BlackEnergy3) and [KillDisk](https://attack.mitre.org/software/S0607) to target and disrupt transmission and distribution substations within the Ukrainian power grid. This campaign was the first major public attack conducted against the Ukrainian power grid by Sandworm Team.

▪Attributed groups (1)

G0034Sandworm Team

▪Techniques used (37)

T1566.001Spearphishing AttachmentT1112Modify RegistryT1685Disable or Modify ToolsT1070.004File DeletionT1018Remote System DiscoveryT1133External Remote ServicesT1105Ingress Tool TransferT1204.002Malicious FileT1078Valid AccountsT1040Network SniffingT1136.002Domain AccountT1218.011Rundll32T1059.005Visual BasicT1071.001Web ProtocolsT1570Lateral Tool TransferT1056.001KeyloggingT1055Process InjectionT0822External Remote ServicesT0884Connection ProxyT0859Valid AccountsT0886Remote ServicesT0828Loss of Productivity and RevenueT0831Manipulation of ControlT1693.001System FirmwareT0885Commonly Used PortT1695.001Serial COMT0814Denial of ServiceT0867Lateral Tool TransferT0816Device Restart/ShutdownT0823Graphical User InterfaceT0813Denial of ControlT0846Remote System DiscoveryT1691.001Command MessageT1692.001Command MessageT0827Loss of ControlT1691.002Reporting MessageT0826Loss of Availability

▪Software used (2)

S0607KillDiskmalwareS0089BlackEnergymalware
C0028on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.