Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0089
MITRE ATT&CK Malware

BlackEnergy (S0089)

Black Energy
ShareXLinkedInRedditHN

[BlackEnergy](https://attack.mitre.org/software/S0089) is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. (Citation: F-Secure BlackEnergy 2014)

Platforms: Windows

▪Techniques implemented (28)

T1548.002Bypass User Account ControlT1047Windows Management InstrumentationT1555.003Credentials from Web BrowsersT1070Indicator RemovalT1113Screen CaptureT1055.001Dynamic-link Library InjectionT1685.005Clear Windows Event LogsT1553.006Code Signing Policy ModificationT1057Process DiscoveryT1083File and Directory DiscoveryT1046Network Service DiscoveryT1021.002SMB/Windows Admin SharesT1049System Network Connections DiscoveryT1120Peripheral Device DiscoveryT1547.009Shortcut ModificationT1552.001Credentials In FilesT1056.001KeyloggingT1543.003Windows ServiceT1547.001Registry Run Keys / Startup FolderT1485Data DestructionT1574.010Services File Permissions WeaknessT1016System Network Configuration DiscoveryT1082System Information DiscoveryT1008Fallback ChannelsT1071.001Web ProtocolsT0869Standard Application Layer ProtocolT0865Spearphishing AttachmentT0859Valid Accounts

▪Used by groups (1)

G0034Sandworm Team
S0089on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.