BlackEnergy malware family

GPTKB entity

Statements (103)
Predicate Object
gptkbp:instanceOf malware
gptkbp:abilities plugin support
credential harvesting
information theft
modular architecture
destructive payloads
file exfiltration
keylogging
gptkbp:alsoKnownAs gptkb:BlackEnergy
gptkbp:category Trojan
backdoor
botnet
rootkit
gptkbp:connectsTo gptkb:Sandworm_group
gptkb:APT28
gptkbp:detects antivirus signatures
gptkbp:developedBy unknown
gptkbp:discoveredBy 2007
gptkbp:exploits gptkb:CVE-2014-4114
CVE-2015-1769
CVE-2015-1770
CVE-2015-2426
CVE-2015-2433
CVE-2015-2455
CVE-2015-2545
CVE-2015-2546
CVE-2015-2547
CVE-2015-2548
CVE-2015-2549
CVE-2015-2550
CVE-2015-2551
CVE-2015-2552
CVE-2015-2553
CVE-2015-2554
CVE-2015-2555
CVE-2015-2556
CVE-2015-2557
CVE-2015-2558
CVE-2015-2559
CVE-2015-2560
CVE-2015-2561
CVE-2015-2562
CVE-2015-2563
CVE-2015-2564
CVE-2015-2565
CVE-2015-2566
CVE-2015-2567
CVE-2015-2568
CVE-2015-2569
CVE-2015-2570
CVE-2015-2571
CVE-2015-2572
CVE-2015-2573
CVE-2015-2574
CVE-2015-2575
CVE-2015-2576
CVE-2015-2577
CVE-2015-2578
CVE-2015-2579
CVE-2015-2580
CVE-2015-2581
CVE-2015-2582
CVE-2015-2583
CVE-2015-2584
CVE-2015-2585
CVE-2015-2586
CVE-2015-2587
CVE-2015-2588
CVE-2015-2589
CVE-2015-2590
CVE-2015-2591
CVE-2015-2592
CVE-2015-2593
CVE-2015-2594
CVE-2015-2595
CVE-2015-2596
CVE-2015-2597
CVE-2015-2598
CVE-2015-2599
https://www.w3.org/2000/01/rdf-schema#label BlackEnergy malware family
gptkbp:industry gptkb:energy
gptkb:government
gptkb:government_ministry
gptkbp:notableBattle gptkb:2015_Ukraine_power_grid_attack
gptkbp:notableFor 2014
2015
2016
gptkbp:platform gptkb:Windows
gptkbp:remedy system reimaging
patching vulnerabilities
removal tools
gptkbp:spreadTo phishing emails
malicious documents
drive-by downloads
gptkbp:usedFor DDoS attacks
cybercrime
industrial sabotage
gptkbp:variant gptkb:BlackEnergy_2
gptkb:BlackEnergy_3
gptkbp:writtenBy gptkb:C++
C
gptkbp:bfsParent gptkb:GreyEnergy_family
gptkbp:bfsLayer 7