BlackEnergy has the capability to communicate over a backup channel via plus.google.com.2
tool
BlackEnergy S0089
- Type
- malware
- Platform
- Windows
- Created
- 31 May 2017
- Last modified
- 6 October 2023
BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. [1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0089
BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.34
BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.5
BlackEnergy has conducted port scans on a host.6
A BlackEnergy 2 plug-in uses WMI to gather victim host details.7
BlackEnergy has gathered information about local network connections using netstat.89
Standing S0089
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
88th percentile · 88% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
98th percentile · 98% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
60th percentile · 60% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S0089
680 distinct rules cover the 25 techniques recorded for this tool. The 732 technique-to-rule mappings resolve to 680 distinct rules, because one rule can cover several techniques. 475 Sigma · 205 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org