LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0089: BlackEnergy

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. [1]

EnterpriseS0089MalwareObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BlackEnergy matters because ATT&CK describes it as a long-running Windows malware toolkit whose use evolved from DDoS botnets to plug-in-supported operations, including targeting Ukrainian institutions. Its relationship to the 2015 Ukraine Electric Power Attack makes it especially relevant for organizations where enterprise IT access can affect operational technology or service continuity.

Executive priority

Treat this as a resilience and control-validation topic, not just a malware signature topic. Leaders should ask whether Windows endpoint visibility, identity controls, email attachment defenses, SMB/WMI monitoring, and command-and-control monitoring are strong enough to detect a toolkit that can support discovery, persistence, credential collection, lateral movement, and impact behaviors. For critical infrastructure or OT-connected environments, validate that incident response plans cover enterprise-to-operations escalation and business continuity decisions.

Technical view

ATT&CK provides no official detection text for BlackEnergy, so SOC and IR teams should validate coverage through the related techniques. Focus on Windows telemetry for service creation or modification, WMI execution, SMB/admin share activity, DLL injection indicators, keylogging-related collection, screen capture, file/process/network discovery, indicator removal, web-protocol C2, fallback channels, and data destruction behaviors. Relationship context also links BlackEnergy3 with the 2015 Ukraine Electric Power Attack and KillDisk, so defenders in ICS-adjacent environments should correlate enterprise compromise behaviors with access to substations, control networks, or remote administration paths where locally applicable.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows service creation/modification events and related registry changes
  • WMI operational and remote execution logs
  • SMB/admin share access and lateral movement evidence
  • Authentication logs for valid account use, especially remote access patterns

Detection direction

  • Do not rely on a BlackEnergy family name alone; ATT&CK lists broad plug-in-supported behavior, so map detections to the related techniques.
  • Prioritize correlation across phishing attachment delivery, Windows persistence, discovery, credential collection, SMB/WMI lateral movement, and outbound web-protocol communications.
  • Tune for administrative false positives: WMI, SMB admin shares, service changes, and discovery commands are common in IT operations, so detections need user, host role, timing, and change-management context.
  • Validate visibility for fallback C2: confirm proxy, DNS, firewall, and endpoint telemetry can show alternate outbound paths, not only known blocked destinations.
  • For OT or critical-infrastructure environments, look for enterprise Windows activity that precedes or coincides with access to systems supporting transmission, distribution, or other operational functions.

Mitigation priorities

  • Strengthen email attachment controls and user-reporting workflows for targeted spearphishing scenarios.
  • Enforce least privilege, privileged access management, and strong authentication for accounts that can access Windows hosts, shares, remote administration, or OT-adjacent systems.
  • Restrict and monitor SMB/admin shares, WMI, and remote service management to approved administrative paths.
  • Harden Windows endpoints with service-change monitoring, application control where feasible, and EDR coverage for process injection and suspicious collection behaviors.
  • Segment enterprise IT from operational or critical systems and tightly govern remote access between zones.
Additional notes and limits

The most decision-relevant relationships are to the 2015 Ukraine Electric Power Attack, Sandworm Team, and techniques covering valid accounts, spearphishing attachments, standard application-layer protocols, fallback channels, Windows admin shares, WMI, DLL injection, keylogging, discovery, indicator removal, web protocols, screen capture, data destruction, and Windows services.

MITRE does not provide official detection guidance for this software object, and the object’s listed platform is Windows. Some related techniques have broader platform lists, but those should not be assumed for BlackEnergy without local evidence. This take is based only on the supplied ATT&CK fields, references, and relationships and does not assert current activity or customer exposure.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BlackEnergy

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1548.002Bypass User Account ControlSub-technique

BlackEnergy attempts to bypass default User Access Control (UAC) settings by exploiting a backward-compatibility setting found in Windows 7 and later.[1]

EnterpriseT1047Windows Management Instrumentation

A BlackEnergy 2 plug-in uses WMI to gather victim host details.[2]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.[1][3]

EnterpriseT1070Indicator Removal

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.[1]

EnterpriseT1113Screen Capture

BlackEnergy is capable of taking screenshots.[3]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

BlackEnergy injects its DLL component into svchost.exe.[1]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

The BlackEnergy component KillDisk is capable of deleting Windows Event Logs.[4]

EnterpriseT1553.006Code Signing Policy ModificationSub-technique

BlackEnergy has enabled the TESTSIGNING boot configuration option to facilitate loading of a driver component.[1]

EnterpriseT1057Process Discovery

BlackEnergy has gathered a process list by using Tasklist.exe.[1][3][5]

EnterpriseT1083File and Directory Discovery

BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types.[1][3]

EnterpriseT1046Network Service Discovery

BlackEnergy has conducted port scans on a host.[3]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.[3]

EnterpriseT1049System Network Connections Discovery

BlackEnergy has gathered information about local network connections using netstat.[1][3]

EnterpriseT1120Peripheral Device Discovery

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.[3]

EnterpriseT1547.009Shortcut ModificationSub-technique

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.[1]

EnterpriseT1552.001Credentials In FilesSub-technique

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.[1][3]

EnterpriseT1056.001KeyloggingSub-technique

BlackEnergy has run a keylogger plug-in on a victim.[3]

EnterpriseT1543.003Windows ServiceSub-technique

One variant of BlackEnergy creates a new service using either a hard-coded or randomly generated name.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.[1]

EnterpriseT1485Data Destruction

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.[2][5]

EnterpriseT1574.010Services File Permissions WeaknessSub-technique

One variant of BlackEnergy locates existing driver services that have been disabled and drops its driver component into one of those service's paths, replacing the legitimate executable. The malware then sets the hijacked service to start automatically to establish persistence.[1]

EnterpriseT1016System Network Configuration Discovery

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.[1][3]

EnterpriseT1082System Information Discovery

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.[1][3]

EnterpriseT1008Fallback Channels

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.[3]

EnterpriseT1071.001Web ProtocolsSub-technique

BlackEnergy communicates with its C2 server over HTTP.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
19eadfbd6c12319d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundle19eadfbd6c12…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  2. [2]
    Securelist BlackEnergy Feb 2015

    Baumgartner, K. and Garnaeva, M.. (2015, February 17). BE2 extraordinary plugins, Siemens targeting, dev fails. Retrieved March 24, 2016.

    Open source URL
  3. [3]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  4. [4]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  5. [5]
    ESET BlackEnergy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020.

    Open source URL
  6. [6]
    iSIGHT Sandworm 2014

    Hultquist, J.. (2016, January 7). Sandworm Team and the Ukrainian Power Authority Attacks. Retrieved October 6, 2017.

    Open source URL
  7. [7]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  8. [8]
    UK NCSC Olympic Attacks October 2020

    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

    Open source URL
  9. [9]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  10. [10]
    Booz Allen Hamilton

    Booz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.

    Open source URL
  11. [11]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  12. [12]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  13. [13]
    mitre-attackS0089
    Open source URL
  14. [14]
    mitre-attackS0089
    Open source URL
  15. [15]
    mitre-attackS0089
    Open source URL
  16. [16]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  17. [17]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  18. [18]
    Securelist BlackEnergy Feb 2015

    Baumgartner, K. and Garnaeva, M.. (2015, February 17). BE2 extraordinary plugins, Siemens targeting, dev fails. Retrieved March 24, 2016.

    Open source URL
  19. [19]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  20. [20]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  21. [21]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  22. [22]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  23. [23]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  24. [24]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  25. [25]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  26. [26]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  27. [27]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  28. [28]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  29. [29]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  30. [30]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  31. [31]
    ESET BlackEnergy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020.

    Open source URL
  32. [32]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  33. [33]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  34. [34]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  35. [35]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  36. [36]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  37. [37]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  38. [38]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  39. [39]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  40. [40]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  41. [41]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  42. [42]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  43. [43]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  44. [44]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  45. [45]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  46. [46]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  47. [47]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  48. [48]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  49. [49]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  50. [50]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  51. [51]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  52. [52]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  53. [53]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  54. [54]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  55. [55]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  56. [56]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  57. [57]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  58. [58]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  59. [59]
    UK NCSC Olympic Attacks October 2020

    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

    Open source URL
  60. [60]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  61. [61]
    iSIGHT Sandworm 2014

    Hultquist, J.. (2016, January 7). Sandworm Team and the Ukrainian Power Authority Attacks. Retrieved October 6, 2017.

    Open source URL
  62. [62]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  63. [63]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  64. [64]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  65. [65]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  66. [66]
    Booz Allen Hamilton

    Booz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.

    Open source URL
  67. [67]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  68. [68]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  69. [69]
    ESET BlackEnergy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020.

    Open source URL
  70. [70]
    ESET BlackEnergy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020.

    Open source URL
  71. [71]
    Securelist BlackEnergy Feb 2015

    Baumgartner, K. and Garnaeva, M.. (2015, February 17). BE2 extraordinary plugins, Siemens targeting, dev fails. Retrieved March 24, 2016.

    Open source URL
  72. [72]
    Securelist BlackEnergy Feb 2015

    Baumgartner, K. and Garnaeva, M.. (2015, February 17). BE2 extraordinary plugins, Siemens targeting, dev fails. Retrieved March 24, 2016.

    Open source URL
  73. [73]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  74. [74]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  75. [75]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  76. [76]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  77. [77]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  78. [78]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  79. [79]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  80. [80]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.