Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Sandworm Team

Also known as: ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44, Sandworm Team, TEMP.Noble, Quedagh Group, BE2 APT, Black Energy, Samurai Panda, PLA Navy, APT4, Wisp Team, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon, G0034, Blue Echidna, UAC-0113, UAC-0082

Description

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.(Citation: US District Court Indictment GRU Oct 2018)

TTP Summary

Black Energy; Ukrenergo; NPetya, NotPetya

Goals & Targeting

Targeted Sectors

Energy
Government
Defense
Critical infrastructure

Targeted Countries / Regions

GB
europe
CN

AI Analysis

· 2 weeks ago

Executive Summary

The Sandworm Team is a highly destructive threat group attributed to Russia's General Staff Main Intelligence Directorate, with a primary motivation of disruption. They have been active since at least 2009, targeting various sectors including energy, government, and critical infrastructure. Their targets have included Ukraine, the US, and European countries, with notable attacks such as the 2017 NotPetya attack and the 2018 Olympic Destroyer attack.

Goals & Targeting

The Sandworm Team's strategic objectives appear to be focused on disruption and destruction, with a particular emphasis on targeting critical infrastructure and government organizations. They have targeted various countries, including Ukraine, the US, and European nations, and have been associated with several high-profile attacks. The group's typical victims include energy companies, government organizations, and critical infrastructure providers, and their attacks have been characterized by their use of custom malware and social engineering tactics.

Enhanced Description

The Sandworm Team's motivations and goals are not entirely clear, but their attacks have been largely focused on disruption and destruction. They have targeted various countries, including Ukraine, the US, and European nations, and have been associated with several high-profile attacks. The group's activities have been extensively documented by various cybersecurity researchers and government agencies, and their operations have been noted for their complexity and sophistication.

Key Capabilities

  • Custom malware development
  • Social engineering
  • Network exploitation
  • System compromise
  • Data destruction

MITRE ATT&CK Tactics

Defense Evasion
Execution
Persistence
Privilege Escalation
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1190
T1204

Software / Tooling

Black Energy
NotPetya
Olympic Destroyer

Campaigns & Victims

The Sandworm Team's campaign patterns have been characterized by their use of custom malware and social engineering tactics to gain initial access to their targets' systems. They have been known to target various sectors, including energy, government, and critical infrastructure, and have been associated with several high-profile attacks. The group's operational tempo has been noted for its complexity and sophistication, with their attacks often involving multiple stages and the use of various tools and techniques.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Implement robust network security measures, including firewalls and intrusion detection systems
  • Conduct regular security audits and vulnerability assessments
  • Implement a robust incident response plan
  • Provide regular security awareness training to employees

Suggested Tags

APT
Destruction
Disruption
Energy
Government
Critical Infrastructure

Confidence Assessment

The confidence level in the available data is high, with extensive documentation from various cybersecurity researchers and government agencies. However, there may be some gaps in the available information, particularly regarding the group's motivations and goals. Further research and analysis are needed to fully understand the Sandworm Team's activities and capabilities.

ATT&CK Techniques

Command & Control
7 techniques
Credential Access
5 techniques
Discovery
7 techniques
Execution
9 techniques
Impact
7 techniques
Initial Access
6 techniques
Reconnaissance
9 techniques
Resource Development
12 techniques
Stealth
9 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

IPV4 2 IPv4 Address 4 MD5 6 SHA256 6 SHA1 2

References

  1. Leonard TAG 2023 — Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.
  2. US District Court Indictment GRU Oct 2018 — Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.
  3. Dragos ELECTRUM — Dragos. (2017, January 1). ELECTRUM Threat Profile. Retrieved June 10, 2020.
  4. F-Secure BlackEnergy 2014 — F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.
  5. iSIGHT Sandworm 2014 — Hultquist, J.. (2016, January 7). Sandworm Team and the Ukrainian Power Authority Attacks. Retrieved October 6, 2017.
  6. CrowdStrike VOODOO BEAR — Meyers, A. (2018, January 19). Meet CrowdStrike’s Adversary of the Month for January: VOODOO BEAR. Retrieved May 22, 2018.
  7. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  8. Microsoft Prestige ransomware October 2022 — MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.
  9. InfoSecurity Sandworm Oct 2014 — Muncaster, P.. (2014, October 14). Microsoft Zero Day Traced to Russian ‘Sandworm’ Hackers. Retrieved October 6, 2017.
  10. NCSC Sandworm Feb 2020 — NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020.
  11. USDOJ Sandworm Feb 2020 — Pompeo, M. (2020, February 20). The United States Condemns Russian Cyber Attack Against the Country of Georgia. Retrieved September 12, 2024.
  12. mandiant_apt44_unearthing_sandworm — Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024.
  13. US District Court Indictment GRU Unit 74455 October 2020 — Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.
  14. Secureworks IRON VIKING — Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.
  15. UK NCSC Olympic Attacks October 2020 — UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

Intel Summary

79

Techniques

28

Tools

6

Campaigns

44

IOCs

0

Observed Data

13

Tactics

Tags

Government Targeting
Wiper / Destructive

Details

MITRE ID
G0034
Type
Unknown
Resource Level
Government
Primary Motivation
Disruption
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--381fcf73-60f6-4ab2-9991-6af3cbc35192
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.