Sandworm Team — APT Profile
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44, UAC-0082, Rime Isotope, Unit 74455 (GRU GTsST), Sandworm, TEMP.Noble, G0034, Blue Echidna, UAC-0113, SANDWORM RELIC
IntelFusions coverage (7)
- Spies and ransomware crews root Cisco firewall servers 2026-09-09 · Vulnerabilities
- Russia's Sandworm poses as a recruiter to trap IT admins 2026-08-10 · Nation-State
- Satellite attacks went from TV pranks to wiper malware 2026-08-06 · Cyber Incidents
- Russia-aligned hackers keep hitting Ukraine through an old WinRAR bug 2026-06-09 · Nation-State
- Sandworm (APT44) Deploys Trojanized KMS Activators Against Ukrainian Users: BACKORDER Go Loader, DcRAT Espionage, and Kalambur TOR-Based RDP Backdoor 2026-02-16 · Nation-State
- Sandworm (UAC-0133) Plans Coordinated Cyber Sabotage Against 20 Ukrainian Critical Infrastructure Facilities: BIASBOAT Linux QUEUESEED Variant, LOADGRIP ptrace Injector, and Supply Chain Compromise 2026-02-16 · Nation-State
- The Enigmatic Energetic Bear: Russia's Most Successful Critical Infrastructure Intruder You've Never Heard Of 2026-02-16 · Nation-State
Tools & malware
- AcidPour Wiper
- AcidRain Wiper
- ArguePatch loader
- AWFULSHRED wiper (Linux)
- Bad Rabbit Ransomware
- BidSwipe wiper
- BlackEnergy ICS Malware
- CaddyWiper wiper
- Cobalt Strike Adversary Simulation
- Cyclops Blink Botnet
- Empire Post-Exploitation Framework
- Exaramel for Linux Backdoor
- Exaramel for Windows Backdoor
- GreyEnergy ICS Malware
- Impacket Network Toolkit
- Industroyer ICS Malware
- Industroyer2 ICS Malware
- Invoke-PSImage Steganography Tool
- Kapeka Backdoor
- KillDisk Wiper
- Mimikatz Credential Harvesting
- Neo-reGeorg Tunneling Tool
- Net Network Reconnaissance
- NotPetya Wiper
- Olympic Destroyer Wiper
- ORCSHRED wiper (Linux)
- P.A.S. Webshell Web Shell
- PoshC2 Post-Exploitation Framework
- POWERGAP PowerShell deployment script
- Prestige Ransomware
- PsExec Remote Execution
- SDelete Defense Evasion
- SOLOSHRED wiper (Solaris)
- VPNFilter ICS Malware
- ZeroWipe wiper
Vendor research
- IRON VIKING Threat Profile Secureworks
- Sandworm Team and the Ukrainian Power Authority Attacks Hultquist, J.
- the CERT-UA report CERT-UA
- Trojanized KMS activation tools leveraged in latest Sandworm APT campaigns (Protection Bulletin, 12 Feb 2025) Symantec (Broadcom)
- SwiftSlicer — new wiper discovered in Ukraine (Protection Bulletin, 30 Jan 2023) Symantec (Broadcom)
- Industroyer2: Industroyer reloaded ESET
- Кібератака групи Sandworm (UAC-0082) на об'єкти енергетики України з використанням шкідливих програм INDUSTROYER2 та CADDYWIPER (CERT-UA#4435) CERT-UA
- Sandworm uses a new version of ArguePatch to attack targets in Ukraine ESET
- Кібератака UAC-0082 (Sandworm) на інформаційне агентство Укрінформ із використанням деструктивного ПЗ (CERT-UA#5850) CERT-UA
- ELECTRUM Threat Profile Dragos
- How Microsoft names threat actors Microsoft
- IRON VIKING Threat Profile Secureworks
- UK exposes series of Russian cyber attacks against Olympic and Paralympic Games UK NCSC
- Ukraine remains Russia’s biggest cyber focus in 2023 Leonard TAG
- Sandworm Team and the Ukrainian Power Authority Attacks iSIGHT
- Indictment - United States vs Aleksei Sergeyevich Morenets, et al US District Court
- ELECTRUM Threat Profile Dragos
- BlackEnergy & Quedagh: The convergence of crimeware and APT attacks F-Secure BlackEnergy
- Meet CrowdStrike’s Adversary of the Month for January: VOODOO BEAR Crowdstrike
- New “Prestige” ransomware impacts organizations in Ukraine and Poland Microsoft
- Microsoft Zero Day Traced to Russian ‘Sandworm’ Hackers InfoSecurity
- NCSC supports US advisory regarding GRU intrusion set Sandworm NCSC
- The United States Condemns Russian Cyber Attack Against the Country of Georgia USDOJ Sandworm
- et al. (n.d.). APT44: Unearthing Sandworm mandiant apt44 unearthing sandworm
- United States vs. Yuriy Sergeyevich Andrienko et al US District Court
Countries linked to this actor
- Estonia targets
- France targets
- Poland targets
- Ukraine targets
- Russia origin
- United Kingdom targets
- Georgia targets
- Serbia targets
- Greece targets
- Czech Republic targets
- Netherlands targets
- Australia targets
- Angola targets