
One year later: Industroyer (Dec 2016). Different target, Ukrenergo's Pivnichna 330kV transmission substation. Higher up the grid. The malware spoke IEC-104 natively to open breakers via RTUs, and used CVE-2015-5374 to disable Siemens SIPROTEC protection relays.
Post summary
The Industroyer malware targeted Ukraine’s grid, actively exploiting CVE‑2015‑5374 to disable Siemens SIPROTEC protection relays via IEC‑104 communication, illustrating a real‑world attack.

