LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0089: BlackEnergy

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. [1]

EnterpriseS0089MalwareObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0089: BlackEnergy describes [BlackEnergy](https://attack.mitre.org/software/S0089) is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. (Ci...

Executive priority

S0089: BlackEnergy is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0089: BlackEnergy by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0089: BlackEnergy appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BlackEnergy

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1548.002Bypass User Account ControlSub-technique

BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later.[1]

EnterpriseT1047Windows Management Instrumentation

A BlackEnergy 2 plug-in uses WMI to gather victim host details.CitationSecurelist BlackEnergy Feb 2015

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.[1]CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1070Indicator Removal

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.[1]

EnterpriseT1113Screen Capture

BlackEnergy is capable of taking screenshots.CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

BlackEnergy injects its DLL component into svchost.exe.[1]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

The BlackEnergy component KillDisk is capable of deleting Windows Event Logs.CitationESEST Black Energy Jan 2016

EnterpriseT1553.006Code Signing Policy ModificationSub-technique

BlackEnergy has enabled the TESTSIGNING boot configuration option to facilitate loading of a driver component.[1]

EnterpriseT1057Process Discovery

BlackEnergy has gathered a process list by using Tasklist.exe.[1]CitationSecurelist BlackEnergy Nov 2014CitationESET BlackEnergy Jan 2016

EnterpriseT1083File and Directory Discovery

BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types.[1]CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1046Network Service Discovery

BlackEnergy has conducted port scans on a host.CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1049System Network Connections Discovery

BlackEnergy has gathered information about local network connections using netstat.[1]CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1120Peripheral Device Discovery

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1547.009Shortcut ModificationSub-technique

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.[1]

EnterpriseT1552.001Credentials In FilesSub-technique

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.[1]CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1056.001KeyloggingSub-technique

BlackEnergy has run a keylogger plug-in on a victim.CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1543.003Windows ServiceSub-technique

One variant of BlackEnergy creates a new service using either a hard-coded or randomly generated name.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.[1]

EnterpriseT1485Data Destruction

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.CitationSecurelist BlackEnergy Feb 2015CitationESET BlackEnergy Jan 2016

EnterpriseT1574.010Services File Permissions WeaknessSub-technique

One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence.[1]

EnterpriseT1016System Network Configuration Discovery

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.[1]CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1082System Information Discovery

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.[1]CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1008Fallback Channels

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.CitationSecurelist BlackEnergy Nov 2014

EnterpriseT1071.001Web ProtocolsSub-technique

BlackEnergy communicates with its C2 server over HTTP.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.4
Created
Modified
Raw hash
19eadfbd6c12319d...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.4Current bundle19eadfbd6c12…
19.11.4Older bundle19eadfbd6c12…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  2. [2]
    mitre-attackS0089
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.