(Lab) Step into the role of Sandworm Team and recreate the December 23, 2015 cyberattack that cut power to roughly 225,000 Ukrainian customers, the first confirmed cyberattack to cause a large-scale blackout. Starting from a single phishing email, establish a foothold on an IT workstation, pivot into the OT network over VPN, and use the operators' own HMI to open breakers across a simulated substation. Then carry out the same anti-recovery playbook the real attackers used — bricking serial-to-ethernet gateways, cutting UPS power, and deploying a KillDisk-style wiper — to understand firsthand why the real outage lasted hours instead of minutes.
After completing this course, users will be able to:
• Gain and persist a foothold on an IT network through phishing, C2, and credential theft
• Pivot from IT to OT through VPN infrastructure and enumerate a segmented control network
• Access and operate an HMI to manipulate breakers and cause a physical outage
• Execute anti-recovery techniques — firmware sabotage, UPS shutdown, and disk wiping — to disable a defender's recovery tools
• Map each stage of the attack to real-world ATT&CK for ICS techniques and evaluate the defenses and recovery procedures that would blunt it