Saltar al contenido

Perfil de grupo APT

Sandworm

Unidad de sabotaje y espionaje atribuida a la Unidad 74455 del GRU ruso, activa desde al menos 2009 y responsable de los apagones en Ucrania y de NotPetya, uno de los ciberataques más destructivos registrados.

MITRE G0034 Sabotaje / destrucciónEspionaje Actualizado

Técnicas MITRE ATT&CK

Técnicas atribuidas al grupo en fuentes públicas, agrupadas por táctica. Cada ID enlaza a attack.mitre.org.

Acceso inicial

  • T1078.002 Valid Accounts: Domain Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
  • T1199 Trusted Relationship
  • T1566.001 Phishing: Spearphishing Attachment

Ejecución

  • T1047 Windows Management Instrumentation
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic

Persistencia

  • T1505.003 Server Software Component: Web Shell
  • T1543.002 Create or Modify System Process: Systemd Service

Escalamiento de privilegios

  • T1484.001 Domain or Tenant Policy Modification: Group Policy Modification

Acceso a credenciales

  • T1003.001 OS Credential Dumping: LSASS Memory
  • T1040 Network Sniffing

Descubrimiento

  • T1018 Remote System Discovery

Movimiento lateral

  • T1021.002 Remote Services: SMB/Windows Admin Shares
  • T1570 Lateral Tool Transfer

Comando y control

  • T1219 Remote Access Tools
  • T1572 Protocol Tunneling

Impacto

  • T1485 Data Destruction
  • T1486 Data Encrypted for Impact
  • T1490 Inhibit System Recovery
  • T1491.002 Defacement: External Defacement
  • T1499 Endpoint Denial of Service
  • T1561.002 Disk Wipe: Disk Structure Wipe

Malware y herramientas

Referencias

Fuentes públicas en las que se basa este perfil.

  1. [1] Sandworm Team, Group G0034 · MITRE ATT&CK
  2. [2] Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace · U.S. Department of Justice, oct. 2020
  3. [3] New Sandworm Malware Cyclops Blink Replaces VPNFilter (AA22-054A) · CISA / NCSC / NSA / FBI, feb. 2022
  4. [4] Industroyer2: Industroyer reloaded · ESET, abr. 2022
  5. [5] Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology · Mandiant, nov. 2023
  6. [6] Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm · Mandiant, abr. 2024
  7. [7] APT44: Unearthing Sandworm (informe completo, PDF) · Mandiant, abr. 2024
  8. [8] The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation · Microsoft Threat Intelligence, feb. 2025
  9. [9] ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025 · ESET, ene. 2026

Última actualización del perfil:

¿Le preocupa este grupo?

El servicio MDR de Ventura Systems monitorea 24/7 las técnicas de este y otros actores, con caza de amenazas basada en ATT&CK.