Skip to content

APT group profile

Sandworm

Sabotage and espionage unit attributed to Russia's GRU Unit 74455, active since at least 2009 and responsible for the blackouts in Ukraine and for NotPetya, one of the most destructive cyberattacks on record.

MITRE G0034 Sabotage / destructiveEspionage LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Initial Access

  • T1078.002 Valid Accounts: Domain Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
  • T1199 Trusted Relationship
  • T1566.001 Phishing: Spearphishing Attachment

Execution

  • T1047 Windows Management Instrumentation
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic

Persistence

  • T1505.003 Server Software Component: Web Shell
  • T1543.002 Create or Modify System Process: Systemd Service

Privilege Escalation

  • T1484.001 Domain or Tenant Policy Modification: Group Policy Modification

Credential Access

  • T1003.001 OS Credential Dumping: LSASS Memory
  • T1040 Network Sniffing

Discovery

  • T1018 Remote System Discovery

Lateral Movement

  • T1021.002 Remote Services: SMB/Windows Admin Shares
  • T1570 Lateral Tool Transfer

Command and Control

  • T1219 Remote Access Tools
  • T1572 Protocol Tunneling

Impact

  • T1485 Data Destruction
  • T1486 Data Encrypted for Impact
  • T1490 Inhibit System Recovery
  • T1491.002 Defacement: External Defacement
  • T1499 Endpoint Denial of Service
  • T1561.002 Disk Wipe: Disk Structure Wipe

Malware and tools

References

Public sources this profile is based on.

  1. [1] Sandworm Team, Group G0034 · MITRE ATT&CK
  2. [2] Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace · U.S. Department of Justice, Oct 2020
  3. [3] New Sandworm Malware Cyclops Blink Replaces VPNFilter (AA22-054A) · CISA / NCSC / NSA / FBI, Feb 2022
  4. [4] Industroyer2: Industroyer reloaded · ESET, Apr 2022
  5. [5] Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology · Mandiant, Nov 2023
  6. [6] Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm · Mandiant, Apr 2024
  7. [7] APT44: Unearthing Sandworm (informe completo, PDF) · Mandiant, Apr 2024
  8. [8] The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation · Microsoft Threat Intelligence, Feb 2025
  9. [9] ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025 · ESET, Jan 2026

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.