- Home
- APT groups
- Sandworm
APT group profile
Sandworm
Sabotage and espionage unit attributed to Russia's GRU Unit 74455, active since at least 2009 and responsible for the blackouts in Ukraine and for NotPetya, one of the most destructive cyberattacks on record.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
Sandworm is the destructive operations group attributed by MITRE ATT&CK and by several governments to GRU Unit 74455, the Main Center for Special Technologies (GTsST) of Russian military intelligence. It has been active since at least 2009 and, unlike other Russian actors specialized in a single mission, it combines espionage, sabotage and influence operations. Mandiant, which tracks it as APT44, describes it as the cyber actor with the most central role in supporting Russia’s military campaign in Ukraine.
Its track record includes the first malware-caused blackouts (Ukraine, 2015 and 2016), the 2017 NotPetya attack, which according to the DOJ indictment caused nearly $1 billion in losses to just three victims, and the sabotage of the opening ceremony of the 2018 Winter Olympics with Olympic Destroyer. Since 2022 it has deployed multiple wipers against Ukraine and has used hacktivist-front Telegram channels (XakNet Team, CyberArmyofRussia_Reborn, Solntsepek) to claim its operations.
Although its focus is Ukraine and Europe, the full Mandiant report notes sustained access and espionage operations in North America, Europe, the Middle East, Central Asia and Latin America. The initial access subgroup described by Microsoft opportunistically compromises exposed infrastructure worldwide. There are no public reports of victims in Colombia as of this review.
Notable campaigns
- 2015–2016 — Ukraine’s power grid. BlackEnergy and KillDisk in 2015 and Industroyer in 2016 caused power outages. Both attacks are included in the indictment against six GRU officers (DOJ).
- 2017 — NotPetya. Destructive malware distributed through the compromised update of a Ukrainian accounting software, with global impact (DOJ).
- 2018 — Olympic Destroyer. Disruption of systems at the Pyeongchang Winter Olympics (DOJ).
- 2019–2022 — Cyclops Blink. Modular botnet on WatchGuard devices, successor to VPNFilter, exposed in a joint UK–U.S. advisory (CISA).
- 2022 — Industroyer2. Attempted attack on a Ukrainian electric utility combined with wipers such as CaddyWiper (ESET).
- 2022 — Operational technology (OT) attack. Power outage through the execution of MicroSCADA commands and the subsequent deployment of CaddyWiper (Mandiant).
- 2021–2025 — BadPilot. Initial access subgroup that exploits vulnerabilities in Exchange, Zimbra, TeamCity, ScreenConnect and FortiClient EMS, and persists with legitimate RMM tools (Microsoft).
- 2025 — Poland’s energy sector. Attempted deployment of the DynoWiper wiper in late December, attributed to Sandworm with medium confidence and with no known disruption (ESET).
Key TTPs
Initial access. Spearphishing with malicious attachments (T1566.001), mass exploitation of exposed services (T1190), software supply chain compromise (T1195.002), abuse of trusted relationships between organizations (T1199), VPN and remote services (T1133) and valid domain accounts (T1078.002).
Execution and persistence. PowerShell (T1059.001), VBScript (T1059.005) and WMI (T1047); systemd services on Linux (T1543.002) and web shells (T1505.003). To deploy payloads at scale it modifies GPOs (T1484.001), a recurring technique in its destructive attacks.
Credentials and discovery. LSASS dumping (T1003.001), traffic capture to obtain passwords (T1040) and LDAP queries to enumerate hosts (T1018).
Lateral movement and C2. SMB shares (T1021.002), tool transfer between hosts (T1570), encrypted tunnels such as GOGETTER or Chisel (T1572) and legitimate remote administration tools (T1219).
Impact. Wipers (T1485, T1561.002), front ransomware such as Prestige (T1486), deletion of backups and catalogs (T1490), denial of service (T1499) and website defacement (T1491.002).
Detection and mitigation
- Perimeter. Prioritize patching of Exchange, Zimbra, ScreenConnect, FortiClient EMS, TeamCity and edge devices (
M1051). Do not expose management interfaces of firewalls or SOHO devices, and review their firmware (M1046). - RMM and tunnels. Inventory authorized remote access tools and alert on new installations (Atera, Splashtop, ScreenConnect), unexpected OpenSSH or Tor services, and tunneling binaries such as Chisel or plink (
M1038,M1037). - GPO and mass deployment. Audit changes to Group Policy Objects (events 5136/5137) and the creation of scheduled tasks or services from domain controllers. This is the most useful early signal of a wiper (
M1047,M1026). - Credentials. Enable LSA Protection and Credential Guard (
M1043), enforce MFA on VPN and vendor access (M1032) and monitor anomalous use of domain accounts outside business hours. - Resilience against sabotage. Maintain offline, immutable backups and test their restoration (
M1053). Alert onwbadmin delete catalog,vssadmin delete shadowsand direct writes to the MBR or to physical disks. - OT and utilities. Segment IT and OT networks (
M1030), monitor the execution of SCADA binaries outside operating windows and restrict hypervisor access to control systems. - Priority in LATAM. Energy, telecommunications, government and logistics organizations with suppliers or relationships in Eastern Europe should include in their hunting the use of unauthorized RMM tools and web shells on exposed mail servers, the access pattern described by Microsoft.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Malware and tools
Malware
References
Public sources this profile is based on.
- [1] Sandworm Team, Group G0034 · MITRE ATT&CK
- [2] Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace · U.S. Department of Justice, Oct 2020
- [3] New Sandworm Malware Cyclops Blink Replaces VPNFilter (AA22-054A) · CISA / NCSC / NSA / FBI, Feb 2022
- [4] Industroyer2: Industroyer reloaded · ESET, Apr 2022
- [5] Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology · Mandiant, Nov 2023
- [6] Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm · Mandiant, Apr 2024
- [7] APT44: Unearthing Sandworm (informe completo, PDF) · Mandiant, Apr 2024
- [8] The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation · Microsoft Threat Intelligence, Feb 2025
- [9] ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025 · ESET, Jan 2026
Profile last updated: