Summary
IRON VIKING is a cyber operations unit operated by Russian military intelligence (GRU) that has conducted multiple disruptive and destructive cyber campaigns since 2013, primarily targeting Ukraine's government, energy, and financial sectors.
Early IRON VIKING activity centered on a heavily modified, modular variant of the BlackEnergy malware. In mid-2013, CTU researchers observed BlackEnergy being used against a government-funded research organisation, with additional plugins designed to facilitate data theft. In December 2015, the group disrupted electricity distribution in western Ukraine after gaining access to a power company through BlackEnergy. The resulting disruption forced the company to rely on manual processes for approximately four months. The group also conducted operations against Ukrainian mining and transportation organisations, as well as a Ukrainian television broadcaster.
In January 2016, IRON VIKING targeted Ukrainian financial institutions using the TeleBots and GCAT backdoors. Later that year, in December 2016, the group launched another attack against Ukraine's energy sector using the Industroyer malware. Unlike previous tools, Industroyer could directly interact with common industrial control system (ICS) protocols, enabling attacks against operational technology environments. Subsequent destructive campaigns increasingly relied on malware developed for specific operations, such as NotPetya and BadRabbit in 2017, or malware tailored to particular target environments, including those of Ukrainian energy providers.
From 2016 onwards, IRON VIKING developed and deployed the VPNFilter botnet, compromising hundreds of thousands of SOHO and NAS devices globally. VPNFilter supported credential theft, IoT protocol monitoring, and destructive capabilities. Following a US-led disruption effort in 2018, the malware evolved into a more sophisticated modular framework known as Cyclops Blink. First observed on 32-bit PowerPC-based WatchGuard Firebox devices in 2019, Cyclops Blink established a large-scale foothold across affected networks before becoming the subject of a court-authorized disruption operation in 2022. Its core functionality focused on reconnaissance and data exfiltration. Analysis conducted by the CTU in 2026 identified an updated Cyclops Blink variant targeting 64-bit x86 Linux systems and incorporating additional modules for active network scanning and selective packet capture, expanding the malware's intelligence-gathering capabilities.
The UK and US governments have publicly attributed several disruptive cyber operations to IRON VIKING and condemned the group's activities. On 20 February 2020, both countries linked the group to cyber attacks against Georgia that occurred on 28 October 2019 and attributed the activity to the GRU's Main Center for Special Technologies (GTsST), also referred to as Military Unit 74455.
Early IRON VIKING activity centered on a heavily modified, modular variant of the BlackEnergy malware. In mid-2013, CTU researchers observed BlackEnergy being used against a government-funded research organisation, with additional plugins designed to facilitate data theft. In December 2015, the group disrupted electricity distribution in western Ukraine after gaining access to a power company through BlackEnergy. The resulting disruption forced the company to rely on manual processes for approximately four months. The group also conducted operations against Ukrainian mining and transportation organisations, as well as a Ukrainian television broadcaster.
In January 2016, IRON VIKING targeted Ukrainian financial institutions using the TeleBots and GCAT backdoors. Later that year, in December 2016, the group launched another attack against Ukraine's energy sector using the Industroyer malware. Unlike previous tools, Industroyer could directly interact with common industrial control system (ICS) protocols, enabling attacks against operational technology environments. Subsequent destructive campaigns increasingly relied on malware developed for specific operations, such as NotPetya and BadRabbit in 2017, or malware tailored to particular target environments, including those of Ukrainian energy providers.
From 2016 onwards, IRON VIKING developed and deployed the VPNFilter botnet, compromising hundreds of thousands of SOHO and NAS devices globally. VPNFilter supported credential theft, IoT protocol monitoring, and destructive capabilities. Following a US-led disruption effort in 2018, the malware evolved into a more sophisticated modular framework known as Cyclops Blink. First observed on 32-bit PowerPC-based WatchGuard Firebox devices in 2019, Cyclops Blink established a large-scale foothold across affected networks before becoming the subject of a court-authorized disruption operation in 2022. Its core functionality focused on reconnaissance and data exfiltration. Analysis conducted by the CTU in 2026 identified an updated Cyclops Blink variant targeting 64-bit x86 Linux systems and incorporating additional modules for active network scanning and selective packet capture, expanding the malware's intelligence-gathering capabilities.
The UK and US governments have publicly attributed several disruptive cyber operations to IRON VIKING and condemned the group's activities. On 20 February 2020, both countries linked the group to cyber attacks against Georgia that occurred on 28 October 2019 and attributed the activity to the GRU's Main Center for Special Technologies (GTsST), also referred to as Military Unit 74455.

Contact us
Contact us directly whether your organization needs immediate assistance or
you want to discuss your incident readiness, response, and testing needs.