Skip to main content
SentinelOne Discovers a New Delivery Tactic for BlackEnergy 3
From the Front Lines

SentinelOne Discovers a New Delivery Tactic for BlackEnergy 3

By Ehud Shamir

We’ve recently detected a new distribution mechanism for BlackEnergy 3 that’s actively in use today affecting SCADA systems across Europe. BlackEnergy of course has been in existence since 2007, and has evolved significantly into a complete rootkit that can perform data exfiltration and network sniffing, among other tasks. In the following write up SentinelOne security researchers detail the results of reverse engineering this latest sample that demonstrates a new delivery tactic utilizing Microsoft Office.

You can download the full report here.

Related Articles

Decorative background gradient

Subscribe

Get the Latest From the 
SentinelOne Blog