A cyberespionage group focused on companies and organizations in the energy sector has recently updated its arsenal with a destructive data-wiping component and a backdoored SSH server. The group is known in the security community as Sandworm or BlackEnergy, after its primary malware tool, and has been active for several years. It has primarily targeted companies that operate industrial control systems, but has also gone after high-level government organizations, banks, academic research institutions and property companies. In November, the Computer Emergency Response Team of Ukraine reported that multiple media organizations were attacked with BlackEnergy malware leading to the loss of video content and other data.”]

