Sandworm Team — APT Profile
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.Also tracked as
ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44, UAC-0082, Rime Isotope, Unit 74455 (GRU GTsST)
Tools & malware
- AcidPour Wiper
- AcidRain Wiper
- ArguePatch loader
- AWFULSHRED wiper (Linux)
- Bad Rabbit Ransomware
- BidSwipe wiper
- BlackEnergy ICS Malware
- CaddyWiper wiper
- Cobalt Strike Adversary Simulation
- Cyclops Blink Botnet
- Empire Post-Exploitation Framework
- Exaramel for Linux Backdoor
- Exaramel for Windows Backdoor
- GreyEnergy ICS Malware
- Impacket Network Toolkit
- Impacket Network Toolkit
- Industroyer ICS Malware
- Industroyer2 ICS Malware
- Industroyer2 ICS Malware
- Invoke-PSImage Steganography Tool
- Kapeka Backdoor
- KillDisk Wiper
- Mimikatz Credential Harvesting
- Neo-reGeorg Tunneling Tool
- Net Network Reconnaissance
- NotPetya Wiper
- Olympic Destroyer Wiper
- ORCSHRED wiper (Linux)
- P.A.S. Webshell Web Shell
- PoshC2 Post-Exploitation Framework
- POWERGAP PowerShell deployment script
- Prestige Ransomware
- PsExec Remote Execution
- SDelete abused legitimate utility
- SDelete abused legitimate utility
- SOLOSHRED wiper (Solaris)
- VPNFilter ICS Malware
- ZeroWipe wiper
Vendor research
- Кібератака групи Sandworm (UAC-0082) на об'єкти енергетики України з використанням шкідливих програм INDUSTROYER2 та CADDYWIPER (CERT-UA#4435) CERT-UA
- Industroyer2: Industroyer reloaded ESET
- Sandworm uses a new version of ArguePatch to attack targets in Ukraine ESET
- Кібератака UAC-0082 (Sandworm) на інформаційне агентство Укрінформ із використанням деструктивного ПЗ (CERT-UA#5850) CERT-UA
- How Microsoft names threat actors Microsoft
- IRON VIKING Threat Profile Secureworks
- ELECTRUM Threat Profile Dragos
- Microsoft Zero Day Traced to Russian ‘Sandworm’ Hackers InfoSecurity
- NCSC supports US advisory regarding GRU intrusion set Sandworm NCSC
- The United States Condemns Russian Cyber Attack Against the Country of Georgia USDOJ Sandworm
- Ukraine remains Russia’s biggest cyber focus in 2023 Leonard TAG
- United States vs. Yuriy Sergeyevich Andrienko et al US District Court
- IRON VIKING Threat Profile Secureworks
- UK exposes series of Russian cyber attacks against Olympic and Paralympic Games UK NCSC
- et al. (n.d.). APT44: Unearthing Sandworm mandiant apt44 unearthing sandworm
- Indictment - United States vs Aleksei Sergeyevich Morenets, et al US District Court
- ELECTRUM Threat Profile Dragos
- BlackEnergy & Quedagh: The convergence of crimeware and APT attacks F-Secure BlackEnergy
- Sandworm Team and the Ukrainian Power Authority Attacks iSIGHT
- Meet CrowdStrike’s Adversary of the Month for January: VOODOO BEAR Crowdstrike
- New “Prestige” ransomware impacts organizations in Ukraine and Poland Microsoft