NEW: Group Profiler — instant APT intel lookup. Try it →

Sandworm Team

G0034 Russia Espionage MITRE ATT&CK →

Also known as: ELECTRUM · Telebots · IRON VIKING · BlackEnergy (Group) · Quedagh · Voodoo Bear · IRIDIUM · Seashell Blizzard · FROZENBARENTS · APT44

Overview

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.

Naming & attribution

Sandworm Team is tracked under 11 names across the industry. It uses 79 documented ATT&CK techniques — more than 96% of the 174 groups tracked here. Activity attributed since at least 2009.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
ELECTRUMDragos
TelebotsNCSC
IRON VIKINGScott W. Brady
BlackEnergy (Group)NCSC
QuedaghHultquist, J.
Voodoo BearMeyers, A
IRIDIUMMSTIC
Seashell BlizzardMicrosoft
FROZENBARENTSBilly Leonard
APT44Roncone, G. et al

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1499 Endpoint Denial of Service — used by 1 of 174 groups
  • T1590.001 Domain Properties — used by 1 of 174 groups
  • T1491.002 External Defacement — used by 2 of 174 groups
  • T1586.001 Social Media Accounts — used by 2 of 174 groups
  • T1195 Supply Chain Compromise — used by 3 of 174 groups
  • T1588.006 Vulnerabilities — used by 3 of 174 groups
  • T1589.003 Employee Names — used by 3 of 174 groups
  • T1591.002 Business Relationships — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Magic Hound Iran — 38 shared techniques (32% overlap)
  • APT32 Vietnam — 35 shared techniques (29% overlap)
  • Lazarus Group North Korea — 37 shared techniques (27% overlap)
  • OilRig Iran — 33 shared techniques (27% overlap)
  • Kimsuky North Korea — 43 shared techniques (26% overlap)
  • MuddyWater Iran — 30 shared techniques (26% overlap)

Malware families with current indicators

6 families attributed to Sandworm Team, carrying 67 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • PoshC2 56 indicators
  • VPNFilter 4 indicators
  • BadRabbit 3 indicators
  • Industroyer 2 indicators
  • Kapeka 1 indicators
  • NotPetya 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Energy · Government · Industrial · Private sector

Regions

Azerbaijan · Belarus · Georgia · Iran · Israel · Kazakhstan · Kyrgyzstan · Lithuania · Poland · Russia · Ukraine

Capabilities

  • Supply-chain compromise — ATT&CK T1195, T1195.002
  • Destructive / data-wiping operations — ATT&CK T1485, T1561.002; software: AcidRain, Industroyer, Industroyer2, NotPetya, KillDisk, Olympic Destroyer
  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203
  • Custom malware/implant development — ATT&CK: 19 attributed custom malware families

TTPs — 79 techniques across 13 tactics

Resource Development

Persistence

Credential Access

Lateral Movement

Collection

Command and Control

Exfiltration

Tools & malware (27)

Bad Rabbit · Mimikatz · Exaramel for Linux · Exaramel for Windows · GreyEnergy · PsExec · Prestige · P.A.S. Webshell · AcidPour · VPNFilter · Neo-reGeorg · Cyclops Blink · SDelete · Empire · Kapeka · AcidRain · Industroyer · Industroyer2 · BlackEnergy · Cobalt Strike · NotPetya · KillDisk · Net · PoshC2 · Impacket · Invoke-PSImage · Olympic Destroyer

Reporting (3)