{"id":54462,"date":"2023-11-09T08:00:00","date_gmt":"2023-11-09T08:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot\/sandworm-cyberattackers-ukrainian-power-grid-missile-strikes"},"modified":"2023-11-09T08:00:00","modified_gmt":"2023-11-09T08:00:00","slug":"sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/","title":{"rendered":"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Russia&#8217;s infamous Sandworm advanced persistent threat (APT) group used living-off-the-land (LotL) techniques to precipitate a power outage in a Ukrainian city in October 2022, coinciding with a barrage of missile strikes.<\/p>\n<p>Sandworm, linked to Russia&#8217;s Main Center for Special Technologies, has a storied history of cyberattacks in Ukraine: <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/3-years-after-attacks-on-ukraine-power-grid-blackenergy-successor-poses-growing-threat\" target=\"_blank\" rel=\"noopener\">BlackEnergy-induced blackouts<\/a> in 2015 and 2016, the infamous NotPetya wiper, <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/russia-sandworm-apt-swarm-wiper-attacks-ukraine\" target=\"_blank\" rel=\"noopener\">and more recent campaigns<\/a> overlapping with the Ukraine war. To some extent, the war has provided a smokescreen for its more recent, comparably sized cyberattacks.<\/p>\n<p>Take one instance from October 2022, described today in <a href=\"https:\/\/www.mandiant.com\/resources\/blog\/sandworm-disrupts-power-ukraine-operational-technology\" target=\"_blank\" rel=\"noopener\">a report by Mandiant<\/a>. During a downpour of <a href=\"https:\/\/www.understandingwar.org\/backgrounder\/russian-offensive-campaign-assessment-october-10\" target=\"_blank\" rel=\"noopener\">84 cruise missiles and 24 drone attacks<\/a> across 20 Ukrainian cities, Sandworm cashed in on two months of preparation and forced an unexpected power outage in one affected city.<\/p>\n<p>Unlike with previous Sandworm grid attacks, this one wasn&#8217;t notable for some piece of advanced cyber weaponry. Instead, the group took advantage of LotL binaries to undermine Ukraine&#8217;s increasingly sophisticated critical infrastructure cyber defenses.<\/p>\n<p>To Mandiant chief analyst John Hultquist, it sets a worrying precedent. &#8220;We&#8217;re going to have to ask ourselves some tough questions about whether or not we can defend against something like this,&#8221; he says.<\/p>\n<h2 class=\"regular-text\">Yet Another Sandworm Power Outage<\/h2>\n<p>Though the exact method of intrusion is still unknown researchers dated Sandworm&#8217;s initial breach of the Ukrainian substation to at least June 2022.<\/p>\n<p>Soon after, the group was able to breach the divide between the IT and operational technology (OT) networks, and access a hypervisor hosting a supervisory control and data acquisition (SCADA) management instance (where plant operators manage their machinery and processes).<\/p>\n<p>After up to three months of SCADA access, Sandworm picked its moment. Coinciding (coincidentally or otherwise) with an onslaught of kinetic warfare the same day, it used an optical disc (ISO) image file to execute a binary native to the MicroSCADA control system. The precise commands are unknown, but the group likely used an infected MicroSCADA server to send commands to the substation&#8217;s remote terminal units (RTUs), instructing them to open circuit breakers and thereby cut power.<\/p>\n<p>Two days after the outage, Sandworm came back for seconds, deploying a new version of its CaddyWiper wiper malware. This attack did not touch industrial systems \u2014 only the IT network \u2014 and may have been intended to wipe forensic evidence of their first attack, or simply cause further disruption.<\/p>\n<h2 class=\"regular-text\">Russia vs. Ukraine Is Becoming More Even<\/h2>\n<p>Sandworm&#8217;s BlackEnergy and NotPetya attacks were seminal events in cybersecurity, Ukrainian, and military history, affecting both how global powers view combination kinetic-cyber warfare, and how cybersecurity defenders protect industrial systems.<\/p>\n<p>As a result of this heightened awareness, in years since, similar attacks by the same group have fallen some ways short of its early standard. There was, for example, <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/-russian-group-sandworm-s-attempt-to-disrupt-ukraine-power-grid-foiled\" target=\"_blank\" rel=\"noopener\">the second Industroyer attack<\/a>, not long after the invasion \u2014 though the malware was equally powerful, if not more so, than that which took down Ukraine&#8217;s power in 2016, the attack overall failed to cause any serious consequences.<\/p>\n<p>&#8220;You can look at the history of this actor trying to leverage tools like Industroyer and ultimately failing because they were discovered,&#8221; Hultquist says, while pondering whether this latest case was a turning point.<\/p>\n<p>&#8220;I think that this incident demonstrates that there&#8217;s another way, and, unfortunately, that other way is going to really challenge us as defenders because this is something that we&#8217;re not going to necessarily be able to use signatures against and search for en masse,&#8221; he says. &#8220;We&#8217;re going to have to work really hard to find this stuff.&#8221;<\/p>\n<p>He also offers another way to look at Russian-Ukrainian cyber history: less that Russia&#8217;s attacks have become tamer and more that Ukraine&#8217;s defenses have become more robust.<\/p>\n<p>&#8220;If Ukraine&#8217;s networks were under the same pressure that they are under now, with the same defenses that were in place maybe a decade ago, this situation would have been much different,&#8221; Hultquist concludes. &#8220;They&#8217;re more experienced than anyone defending against cyberwar, and we have a lot to learn from them.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/ics-ot\/sandworm-cyberattackers-ukrainian-power-grid-missile-strikes\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A premier Russian APT used living-off-the-land techniques in a major OT hit, raising tough questions about whether or not we can defend against the attack vector.Read More <a href=\"https:\/\/www.darkreading.com\/ics-ot\/sandworm-cyberattackers-ukrainian-power-grid-missile-strikes\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-54462","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-09T08:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes\",\"datePublished\":\"2023-11-09T08:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/\"},\"wordCount\":681,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt0125cbd2847bb23e\\\/6282691cbcee916ef6429d1d\\\/Ukraine-Russia_Daniren_Alamy.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/\",\"name\":\"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt0125cbd2847bb23e\\\/6282691cbcee916ef6429d1d\\\/Ukraine-Russia_Daniren_Alamy.jpg\",\"datePublished\":\"2023-11-09T08:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt0125cbd2847bb23e\\\/6282691cbcee916ef6429d1d\\\/Ukraine-Russia_Daniren_Alamy.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt0125cbd2847bb23e\\\/6282691cbcee916ef6429d1d\\\/Ukraine-Russia_Daniren_Alamy.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/","og_locale":"en_US","og_type":"article","og_title":"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-11-09T08:00:00+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes","datePublished":"2023-11-09T08:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/"},"wordCount":681,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/","url":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/","name":"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg","datePublished":"2023-11-09T08:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt0125cbd2847bb23e\/6282691cbcee916ef6429d1d\/Ukraine-Russia_Daniren_Alamy.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/sandworm-cyberattackers-down-ukrainian-power-grid-during-missile-strikes\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=54462"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54462\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=54462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=54462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=54462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}