Also known as: ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44, Sandworm Team, TEMP.Noble, Quedagh Group, BE2 APT, Black Energy, Samurai Panda, PLA Navy, APT4, Wisp Team, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon, G0034, Blue Echidna, UAC-0113, UAC-0082
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.(Citation: US District Court Indictment GRU Oct 2018)
Black Energy; Ukrenergo; NPetya, NotPetya
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Sandworm Team is a highly destructive threat group attributed to Russia's General Staff Main Intelligence Directorate, with a primary motivation of disruption. They have been active since at least 2009, targeting various sectors including energy, government, and critical infrastructure. Their targets have included Ukraine, the US, and European countries, with notable attacks such as the 2017 NotPetya attack and the 2018 Olympic Destroyer attack.
Goals & Targeting
The Sandworm Team's strategic objectives appear to be focused on disruption and destruction, with a particular emphasis on targeting critical infrastructure and government organizations. They have targeted various countries, including Ukraine, the US, and European nations, and have been associated with several high-profile attacks. The group's typical victims include energy companies, government organizations, and critical infrastructure providers, and their attacks have been characterized by their use of custom malware and social engineering tactics.
Enhanced Description
The Sandworm Team's motivations and goals are not entirely clear, but their attacks have been largely focused on disruption and destruction. They have targeted various countries, including Ukraine, the US, and European nations, and have been associated with several high-profile attacks. The group's activities have been extensively documented by various cybersecurity researchers and government agencies, and their operations have been noted for their complexity and sophistication.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Sandworm Team's campaign patterns have been characterized by their use of custom malware and social engineering tactics to gain initial access to their targets' systems. They have been known to target various sectors, including energy, government, and critical infrastructure, and have been associated with several high-profile attacks. The group's operational tempo has been noted for its complexity and sophistication, with their attacks often involving multiple stages and the use of various tools and techniques.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is high, with extensive documentation from various cybersecurity researchers and government agencies. However, there may be some gaps in the available information, particularly regarding the group's motivations and goals. Further research and analysis are needed to fully understand the Sandworm Team's activities and capabilities.
Black Energy
Ukrenergo
NPetya, NotPetya
Australian Parliament Hack
Citrix Hack
Olympic Destroyer
No observed data linked yet.
79
Techniques
28
Tools
6
Campaigns
44
IOCs
0
Observed Data
13
Tactics