Analyzing a New Variant of BlackEnergy 3

BlackEnergy was first reported in 2007 (named BlackEnergy 1) and at the time was a relatively simple form of malware that generated random bots to support Distributed Denial of Service (DDoS) attacks and has continually become more dangerous since.

It's expected that this particular sample is already resident in many systems across the Ukraine, and likely other nations in Europe which could lead to more blackouts and "mysterious" malfunctions within major utilities, transportation systems, and even healthcare institutions. There may be different variants of BlackEnergy used within each of these environments, but they all originate from the same common core.

This White Paper breaks down the attack vectors of this malicious virus and how to protect your data from BlackEnergy 3 in the future.

