| Sandworm | |
|---|---|
| ⚡ Threat actor emblem (illustrative) | |
| Also known as | APT44 · Voodoo Bear · Seashell Blizzard · Iridium · TeleBots · Iron Viking |
| Formation | c. 2009 |
| Type | Advanced persistent threat (state-sponsored) |
| Purpose | Sabotage, disruption, cyberwarfare |
| Target Sectors | Energy, ICS/SCADA, Government, Logistics |
| Alleged parent org. | GRU (Unit 74455) |
| Attribution confidence | High |
| Status | ● Critical |
| Notable tools | BlackEnergy, Industroyer, NotPetya, CaddyWiper |
Sandworm, also known as APT44, Voodoo Bear, and Seashell Blizzard, is a highly aggressive Russian state-sponsored cyber-espionage and sabotage unit. Publicly attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), specifically Unit 74455, the group is widely considered the most dangerous threat actor currently active.[1]
While many APT groups focus on data theft, Sandworm is distinguished by its mandate to conduct destructive operations. The group is responsible for the first recorded cyber-induced power outages in history and the release of the NotPetya malware, which caused over $10 billion in global damages.[2]
APT44 (Mandiant) · Seashell Blizzard (Microsoft) · Iridium (Microsoft, legacy) · Voodoo Bear (CrowdStrike) · TeleBots (ESET) · Quedagh (F-Secure) · Iron Viking (Secureworks)
Overview
Sandworm has been active since at least 2009. Unlike the GRU’s APT28, which focuses on intelligence and influence, Sandworm functions as a “kinetic” cyber unit, often timing its attacks to coincide with military movements or political pressure.[1]
Attribution
In 2020, the U.S. Department of Justice indicted six officers of GRU Unit 74455 for their roles in Sandworm operations.[3] Forensic links between the 2015/2016 Ukraine power grid attacks and the 2017 NotPetya outbreak have led to a “High” confidence attribution.
Targets and victimology
- Energy Grids — Electrical substations and distribution management systems.
- Logistics & Transport — Rail, shipping, and port authorities.
- Government — Regional administrations and emergency services in conflict zones.
History
| Period | Development |
|---|---|
| 2009–2013 | Development of “BlackEnergy” malware; targeting of NATO. |
| 2014–2015 | Pivot to Ukraine; deployment of destructive wipers. |
| 2016–2017 | Peak global disruption; release of Industroyer and NotPetya. |
| 2022–2024 | Sustained cyber-kinetic warfare against Ukrainian infrastructure. |
Notable campaigns
| Date | Campaign | Description |
|---|---|---|
| Dec 2015 | Ukraine Power Grid | First ever cyber-attack to take down a power grid. |
| Dec 2016 | Industroyer (Kiev) | Automated attack on a Kiev substation using ICS-aware malware. |
| June 2017 | NotPetya | Global wiper that paralyzed shipping and finance sectors. |
| Feb 2018 | Olympic Destroyer | Attack on the Pyeongchang Winter Olympics. |
Destructive Toolset
| Name | Function |
|---|---|
| BlackEnergy | Initial modular toolkit used for industrial disruption. |
| Industroyer | Malware designed to communicate directly with electrical breakers. |
| NotPetya | A wormable wiper that spreads via SMB vulnerabilities. |
| CaddyWiper | Lightweight wiper used to erase user data. |
Tactics, techniques and procedures
| Tactic | Technique ID | Examples |
|---|---|---|
| Impact | T1485 | Data Destruction: Deployment of various wipers. |
| Inhibit Response | T0836 | Modify Parameter: Altering settings on ICS equipment. |
| Lateral Movement | T1570 | Lateral Tool Transfer: Pushing payloads across segmented networks. |
Industrial Control Impact
Sandworm is unique in its ability to navigate Operational Technology (OT) environments. They have demonstrated proficiency in protocols such as IEC-104 and IEC-61850.
References
- Mandiant, “APT44: Sandworm’s Evolution into a Global Threat” (2024).
- Greenberg, A., “Sandworm” (2019).
- U.S. Department of Justice Indictment (October 2020).
- ESET Research, “Industroyer2” (2022).
