Sandworm Team
MITRE ATT&CK: G0034 View on attack.mitre.org
Aliases: ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44, VOODOO BEAR, TEMP.Noble, TeleBots, Blue Echidna, UAC-0113, UAC-0082, Sandworm Team, Sandworm, BE2, PHANTOM, BlackEnergy Lite
- First seen
- 2009-01-01 00:00:00
- Origin
- RU
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 17 (14 malicious)
- Last IoC activity
- 2026-09-01 20:39:02
- Profile updated
- 2026-07-07 12:34:05
Targeted industries: energy-and-utilities government-and-public-sector transportation-and-logistics media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:ua country_code:fr country_code:ge
Context
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.
Recent IoC activity
14 malicious indicators in Maltiverse are attributed to Sandworm Team (G0034). The 14 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | cpcpipe.org | 2026-09-03 | 1 |
| hostname | cpcpipe.com | 2026-09-02 | 2 |
| hostname | telegram.org.4234e8234ad0f.24o1.com | 2026-04-30 | 1 |
| file sample | aea823d6446fbf9059391125a9b7fceb9f433b846275d28dc5f433645984a683.exe | 2026-01-27 | 2 |
| file sample | e252a54e441ea88aafa694259386afd002153481af25a5b7b2df46d17ac53fcc | 2025-10-22 | 1 |
| file sample | c78767cb268589c7e3519f8643c7d7bc891ee3e8f8660f9340419af278ade263.exe | 2025-07-12 | 2 |
| file sample | e54a6551dd6e290cbe53d9ceda9e6d2bf36c1010ee939f3192c97de6b5a2650c.exe | 2025-02-14 | 2 |
| hostname | ukroboronprom.com.ukr.pm | 2025-02-05 | 1 |
| hostname | telegram.org.security.ohsxy.com | 2023-04-28 | 1 |
| file sample | c80656fe59bdeb3e701d1f7eeaaba2ef673368b2c4947945f598e3e84a6cb7f8 | 2023-04-28 | 1 |
| file sample | Dark.exe | 2023-03-03 | 2 |
| file sample | 01e2a830989de3a870e4a2dac876487a.exe | 2023-03-03 | 2 |
| file sample | 30c1f93a3d798bb18ef3439db0ada4e0059e1f6ddd5d860ec993393b31a62842 | 2023-03-03 | 1 |
| file sample | 1af2037acbabfe804a522a5c4dd5a4ce.exe | 2023-03-03 | 2 |
Detection coverage
- 182 YARA rules
- 818 Sigma rules
Malware & tools used
- Vulnerabilities (attack-pattern)
- Network Sniffing (attack-pattern)
- Command Obfuscation (attack-pattern)
- Vulnerability Scanning (attack-pattern)
- Social Media Accounts (attack-pattern)
- Social Media Accounts (attack-pattern)
- Standard Encoding (attack-pattern)
- Databases (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- PowerShell (attack-pattern)
- Proxy (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Scheduled Task (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Domain Accounts (attack-pattern)
- NTDS (attack-pattern)
- Masquerading (attack-pattern)
- Spearphishing Link (attack-pattern)
- External Remote Services (attack-pattern)
- Malware (attack-pattern)
- Software Deployment Tools (attack-pattern)
- Botnet (attack-pattern)
- Spearphishing Link (attack-pattern)
- Remote System Discovery (attack-pattern)
Related threat objects
- GreyEnergy (threat-actor)
- IRIDIUM (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- dragos.com — 2017 Review Industrial Control System Threats (report)
- dragos.com — Adversaries (report)
- blog.google — Continued Cyber Activity In Eastern Europe Observed By Tag (report)
- blog.google — Fog Of War How The Ukraine Conflict Transformed The Cyber Threat Landscape (report)
- cip.gov.ua — Download (report)
- dragos.com — Crashoverride 01 (report)
- us-cert.gov — Ta17 163A (report)
- ics.sans.org — Confirmation Of A Coordinated Attack On The Ukrainian Power Grid (report)
- web.archive.org — Sandworm Windows Zero Day Vulnerability Being Actively Exploited Targeted Attacks (report)
- ics.sans.org — Current Reporting On The Cyber Attack In Ukraine Resulting In Power Outage (report)
- web.archive.org — Timeline Of Sandworm Attacks (report)
- MITRE ATT&CK — G0034 (report)
- ESET — Win32 Industroyer (report)
- ESET — Rise Telebots Analyzing Disruptive Killdisk Attacks (report)
- ESET — Killdisk Now Targeting Linux Demands 250K Ransom Cant Decrypt (report)
- ESET — Telebots Back Supply Chain Attacks Against Ukraine (report)
- ESET — Xdata Ransomware Making Rounds Amid Global Wannacryptor Scare (report)
- ESET — New Ransomware Attack Hits Ukraine (report)
- ESET — Bad Rabbit Not Petya Back (report)
- recordedfuture.com — Russia Nexus Uac 0113 Emulating Telecommunication Providers In Ukraine (report)
- CERT-UA — 405538 (report)
- packetstormsecurity.com — Recent Ot And Espionage Attacks Linked To Russias Sandworm Now Named Apt44 (report)
- cloud.google.com — Apt44 Unearthing Sandworm (report)
- services.google.com — Apt44 Unearthing Sandworm (report)
Attributed from
- 2015 Ukraine Electric Power Attack (campaign)
- 2016 Ukraine Electric Power Attack (campaign)
- 2022 Ukraine Electric Power Attack (campaign)
- BadPilot (campaign)
External references
- mitre-attack — G0034
- Voodoo Bear
- ELECTRUM
- Sandworm Team
- Quedagh
- FROZENBARENTS
- APT44
- IRIDIUM
- Seashell Blizzard
- BlackEnergy (Group)
- Telebots
- IRON VIKING
- Leonard TAG 2023
- US District Court Indictment GRU Oct 2018
- Dragos ELECTRUM
- F-Secure BlackEnergy 2014
- iSIGHT Sandworm 2014
- CrowdStrike VOODOO BEAR
- Microsoft Threat Actor Naming July 2023
- Microsoft Prestige ransomware October 2022