CARDS
CARDS
2015 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used BlackEnergy (specifically BlackEnergy3) and KillDisk to target and disrupt transmission and distribution substations within the Ukrainian power grid. This campaign was the first major public attack conducted against the Ukrainian power grid by Sandworm Team.
Last updated Aug 31, 2026, 6:03 AM EDT
Evidence Boundary
Bottom Line Up Front
2015 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used BlackEnergy (specifically BlackEnergy3) and KillDisk to target and disrupt transmission and distribution substations within the Ukrainian power grid. This campaign was the first major public attack conducted against the Ukrainian power grid by Sandworm Team.[1][2][3]
Potential espionage, credential theft, operational disruption, or data exposure depending on campaign objective.[1][2][3]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3]
Decision Summary
2015 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used BlackEnergy (specifically BlackEnergy3) and KillDisk to target and disrupt transmission and distribution substations within the Ukrainian power grid. This campaign was the first major public attack conducted against the Ukrainian power grid by Sandworm Team.
The retained record scopes this as threat actor campaign activity during 2015-12-01 to 2016-01-01. Potential espionage, credential theft, operational disruption, or data exposure depending on campaign objective.[1][2][3]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for MITRE-tracked campaign metadata and ATT&CK relationships; operational currentness should be validated..[1][2][3]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Campaign row is compressed for directory seeding. Confirm actor linkage, infrastructure, and targeting with source-specific reports and local telemetry.
IntelliOS
None Found
Citations