Section 3: Industroyer / CrashOverride (2016)
One year after the BlackEnergy incident, Ukraine once again became the target of a sophisticated cyberattack — this time involving a new malware strain known as Industroyer, or CrashOverride.
- Target: Ukraine’s industrial control systems.
- Method: Malware exploited industrial protocols like IEC 101/104.
- Impact: Temporary power outages.
- Lesson: Malware designed specifically for OT protocols is a major threat.


