Sandworm — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    Sandworm

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    Sandworm
    Threat actor emblem (illustrative)
    Also known asAPT44 · Voodoo Bear · Seashell Blizzard · Iridium · TeleBots · Iron Viking
    Formationc. 2009
    TypeAdvanced persistent threat (state-sponsored)
    PurposeSabotage, disruption, cyberwarfare
    Target SectorsEnergy, ICS/SCADA, Government, Logistics
    Alleged parent org.GRU (Unit 74455)
    Attribution confidenceHigh
    Status● Critical
    Notable toolsBlackEnergy, Industroyer, NotPetya, CaddyWiper

    Sandworm, also known as APT44, Voodoo Bear, and Seashell Blizzard, is a highly aggressive Russian state-sponsored cyber-espionage and sabotage unit. Publicly attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), specifically Unit 74455, the group is widely considered the most dangerous threat actor currently active.[1]

    While many APT groups focus on data theft, Sandworm is distinguished by its mandate to conduct destructive operations. The group is responsible for the first recorded cyber-induced power outages in history and the release of the NotPetya malware, which caused over $10 billion in global damages.[2]

    Aliases used by other vendors:
    APT44 (Mandiant) · Seashell Blizzard (Microsoft) · Iridium (Microsoft, legacy) · Voodoo Bear (CrowdStrike) · TeleBots (ESET) · Quedagh (F-Secure) · Iron Viking (Secureworks)

    Overview

    Sandworm has been active since at least 2009. Unlike the GRU’s APT28, which focuses on intelligence and influence, Sandworm functions as a “kinetic” cyber unit, often timing its attacks to coincide with military movements or political pressure.[1]

    Attribution

    In 2020, the U.S. Department of Justice indicted six officers of GRU Unit 74455 for their roles in Sandworm operations.[3] Forensic links between the 2015/2016 Ukraine power grid attacks and the 2017 NotPetya outbreak have led to a “High” confidence attribution.

    “No other group has demonstrated the same willingness to risk collateral damage or the same technical proficiency in compromising the automated systems that underpin modern society.”
    — Security Research Synthesis, 2024[4]

    Targets and victimology

    • Energy Grids — Electrical substations and distribution management systems.
    • Logistics & Transport — Rail, shipping, and port authorities.
    • Government — Regional administrations and emergency services in conflict zones.

    History

    PeriodDevelopment
    2009–2013Development of “BlackEnergy” malware; targeting of NATO.
    2014–2015Pivot to Ukraine; deployment of destructive wipers.
    2016–2017Peak global disruption; release of Industroyer and NotPetya.
    2022–2024Sustained cyber-kinetic warfare against Ukrainian infrastructure.

    Notable campaigns

    DateCampaignDescription
    Dec 2015Ukraine Power GridFirst ever cyber-attack to take down a power grid.
    Dec 2016Industroyer (Kiev)Automated attack on a Kiev substation using ICS-aware malware.
    June 2017NotPetyaGlobal wiper that paralyzed shipping and finance sectors.
    Feb 2018Olympic DestroyerAttack on the Pyeongchang Winter Olympics.

    Destructive Toolset

    NameFunction
    BlackEnergyInitial modular toolkit used for industrial disruption.
    IndustroyerMalware designed to communicate directly with electrical breakers.
    NotPetyaA wormable wiper that spreads via SMB vulnerabilities.
    CaddyWiperLightweight wiper used to erase user data.

    Tactics, techniques and procedures

    TacticTechnique IDExamples
    ImpactT1485Data Destruction: Deployment of various wipers.
    Inhibit ResponseT0836Modify Parameter: Altering settings on ICS equipment.
    Lateral MovementT1570Lateral Tool Transfer: Pushing payloads across segmented networks.

    Industrial Control Impact

    Sandworm is unique in its ability to navigate Operational Technology (OT) environments. They have demonstrated proficiency in protocols such as IEC-104 and IEC-61850.

    References

    1. Mandiant, “APT44: Sandworm’s Evolution into a Global Threat” (2024).
    2. Greenberg, A., “Sandworm” (2019).
    3. U.S. Department of Justice Indictment (October 2020).
    4. ESET Research, “Industroyer2” (2022).
    Categories: Advanced persistent threats · Russian state-sponsored hacking · GRU · Industrial Control Systems · Cyberwarfare
    This page was last synced August 2026. Content is summarized from public threat intelligence research.