FORENSIA

THREAT_ACTOR · G0034

Sandworm Team

Also known as: Sandworm Team, ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44

Profile

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.

MITRE ATT&CK ↗

Techniques

79 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.003 NTDST1005 Data from Local SystemT1018 Remote System DiscoveryT1021.002 SMB/Windows Admin SharesT1027 Obfuscated Files or InformationT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1036 MasqueradingT1036.005 Match Legitimate Resource Name or LocationT1040 Network SniffingT1041 Exfiltration Over C2 ChannelT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1056.001 KeyloggingT1059.001 PowerShellT1059.005 Visual BasicT1070.004 File DeletionT1071.001 Web ProtocolsT1072 Software Deployment ToolsT1078 Valid AccountsT1078.002 Domain AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.002 Domain AccountT1087.003 Email AccountT1090 ProxyT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1106 Native APIT1132.001 Standard EncodingT1133 External Remote ServicesT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1195.002 Compromise Software Supply ChainT1199 Trusted RelationshipT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1213.006 DatabasesT1218.011 Rundll32T1219 Remote Access ToolsT1485 Data DestructionT1486 Data Encrypted for ImpactT1489 Service StopT1490 Inhibit System RecoveryT1491.002 External DefacementT1499 Endpoint Denial of ServiceT1505.003 Web ShellT1539 Steal Web Session CookieT1555.003 Credentials from Web BrowsersT1561.002 Disk Structure WipeT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1570 Lateral Tool TransferT1571 Non-Standard PortT1583 Acquire InfrastructureT1583.001 DomainsT1583.004 ServerT1584.004 ServerT1584.005 BotnetT1585.001 Social Media AccountsT1585.002 Email AccountsT1586.001 Social Media AccountsT1587.001 MalwareT1588.002 ToolT1588.006 VulnerabilitiesT1589.002 Email AddressesT1589.003 Employee NamesT1590.001 Domain PropertiesT1591.002 Business RelationshipsT1592.002 SoftwareT1593 Search Open Websites/DomainsT1594 Search Victim-Owned WebsitesT1595.002 Vulnerability ScanningT1598.003 Spearphishing LinkT1608.001 Upload Malware

Software

27 malware/tools attributed to this actor.

MimikatzPsExecNetBlackEnergyCobalt StrikeSDeleteInvoke-PSImageGreyEnergyExaramel for WindowsImpacketEmpireOlympic DestroyerNotPetyaPoshC2Exaramel for LinuxP.A.S. WebshellIndustroyerBad RabbitKillDiskCyclops BlinkVPNFilterPrestigeIndustroyer2AcidRainAcidPourNeo-reGeorgKapeka

Related corpus activity

10,464 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Sandworm Team.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-11837cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2025-0921cve852
cve-2013-3307cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2016-5681cve852
cve-2025-66478cve852
cve-2026-22584cve852
cve-2021-27076cve851
cve-2025-68670cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2020-22658cve852
cve-2022-47945cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,464.