The Russian Sandworm APT group if the first suspect for the Ukrainian power outage, states experts at eiSight Partners. The attacks caused blackouts across the Ivano-Frankivsk region of Ukraine on 23rd December. According to a Ukrainian media TSN, the power outage was caused by a destructive malware that disconnected electrical substations. The attack was managed by a Russian group called Sandworm, state experts at iSIGHT Partners. In 2014, the Russian group targeted a Polish energy firm, a Western European government agency and also a French telecommunications firm.”]
Source: https://securityaffairs.co/wordpress/43413/malware/sandworm-apt-ukrainian-power-outage.html

