{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "sandworm",
    "slug": "sandworm",
    "name": "Sandworm",
    "shortName": "Sandworm",
    "country": "Russia",
    "countryCode": "RU",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2009",
    "prominence": 96,
    "mitreGroupId": "G0034",
    "malpediaSlug": "sandworm",
    "tagline": "The only actor to have caused blackouts with malware — twice. GRU Unit 74455, responsible for NotPetya, Industroyer, and the Ukrainian grid attacks.",
    "bio": "Sandworm is GRU Unit 74455, the Main Centre for Special Technologies. It is the most destructive cyber actor in the public record, and the only one credited with causing physical electricity blackouts through malware.\n\nIn December 2015 it cut power to roughly 230,000 people in western Ukraine by remotely operating breakers at three distribution companies — the first confirmed cyber-induced blackout in history. It returned in December 2016 with Industroyer, malware that speaks native grid protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) and manipulates substation equipment directly, without needing to understand the specific vendor's HMI.\n\nIn June 2017 it released NotPetya through a compromised update to M.E.Doc, Ukrainian tax accounting software. Disguised as ransomware but designed with no recoverable decryption path, it spread via EternalBlue and credential theft into every network connected to a Ukrainian subsidiary. Maersk, Merck, FedEx/TNT, Mondelez, and Saint-Gobain were among the casualties; the White House put total global damage above $10 billion, making it the costliest cyberattack ever conducted.\n\nIts Olympic Destroyer operation against the 2018 Pyeongchang Winter Olympics remains the most sophisticated false-flag operation publicly documented: the malware was deliberately salted with forged artifacts imitating Lazarus Group code, specifically to mislead the analysts who would examine it.\n\nSince February 2022 the group has run a sustained wiper campaign against Ukrainian infrastructure and, in October 2022, achieved a third grid disruption — this time by pivoting into a substation's hypervisor and issuing native SCADA commands, timed to coincide with missile strikes.",
    "attribution": {
      "sponsor": "Russia",
      "service": "GRU — Main Intelligence Directorate of the General Staff",
      "unit": "Unit 74455",
      "unitDetail": "Main Centre for Special Technologies (GTsST), 22 Kirova Street, Khimki — 'the Tower'",
      "confidence": "confirmed",
      "summary": "Attributed to GRU Unit 74455 by U.S. federal indictment. In October 2020 the Department of Justice charged six named officers over NotPetya, the 2015 and 2016 Ukrainian grid attacks, Olympic Destroyer, the 2017 French election interference, and attacks on the Novichok poisoning investigation. The UK NCSC concurrently attributed Olympic Destroyer to the GRU, and Unit 74455 officers were also charged in the July 2018 election interference indictment for operating the DCLeaks and Guccifer 2.0 personas.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware",
          "url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and",
          "date": "2020-10-19"
        },
        {
          "org": "NCSC-UK",
          "title": "UK exposes series of Russian cyber attacks against Olympic and Paralympic Games",
          "url": "https://www.ncsc.gov.uk/news/uk-exposes-russian-cyber-attacks",
          "date": "2020-10-19"
        },
        {
          "org": "CISA / NSA / FBI / NCSC-UK",
          "title": "Sandworm Actors Exploiting Vulnerability in Exim Mail Transfer Agent",
          "url": "https://media.defense.gov/2020/May/28/2002306626/-1/-1/0/CSA%20Sandworm%20Actors%20Exploiting%20Vulnerability%20in%20Exim%20Transfer%20Agent%2020200528.pdf",
          "date": "2020-05-28"
        }
      ]
    },
    "motivations": [
      "sabotage",
      "espionage",
      "information-operations"
    ],
    "targetSectors": [
      "Energy",
      "Critical Infrastructure",
      "ICS / SCADA",
      "Government",
      "Transportation",
      "Telecommunications",
      "Financial Services",
      "Media & Journalism",
      "Manufacturing",
      "Water & Wastewater",
      "Nuclear"
    ],
    "targetCountries": [
      "Ukraine",
      "United States",
      "France",
      "South Korea",
      "Poland",
      "Georgia",
      "Denmark",
      "United Kingdom"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Sandworm Team",
        "url": "https://attack.mitre.org/groups/G0034/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Seashell Blizzard",
        "correlation": "exact",
        "note": "Formerly IRIDIUM"
      },
      {
        "org": "microsoft",
        "name": "IRIDIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Voodoo Bear",
        "url": "https://www.crowdstrike.com/adversaries/voodoo-bear/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT44",
        "correlation": "exact",
        "note": "Graduated from 'Sandworm' to a numbered APT designator in April 2024"
      },
      {
        "org": "mandiant",
        "name": "FROZENBARENTS",
        "correlation": "exact",
        "note": "Google TAG designator, now aligned to APT44"
      },
      {
        "org": "secureworks",
        "name": "IRON VIKING",
        "correlation": "exact"
      },
      {
        "org": "dragos",
        "name": "ELECTRUM",
        "correlation": "partial",
        "note": "Dragos scopes ELECTRUM to the ICS-capable element; KAMACITE is tracked as the associated IT-access arm that hands off to ELECTRUM"
      },
      {
        "org": "dragos",
        "name": "KAMACITE",
        "correlation": "partial",
        "note": "Initial-access and enablement operations feeding ELECTRUM"
      },
      {
        "org": "eset",
        "name": "TeleBots",
        "correlation": "exact"
      },
      {
        "org": "eset",
        "name": "BlackEnergy Group",
        "correlation": "partial",
        "note": "Earlier phase of the same actor, named for the BlackEnergy toolset"
      },
      {
        "org": "kaspersky",
        "name": "Hades",
        "correlation": "partial",
        "note": "Kaspersky's designator for the Olympic Destroyer cluster"
      },
      {
        "org": "cisa",
        "name": "GRU Unit 74455",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "UAC-0002",
        "correlation": "exact",
        "note": "CERT-UA designator adopted in Ukrainian reporting"
      }
    ],
    "tools": [
      {
        "name": "Industroyer / CrashOverride",
        "type": "malware",
        "custom": true,
        "description": "ICS-aware malware implementing IEC 60870-5-101/104, IEC 61850, and OPC DA to operate substation breakers directly. Only the second ICS-specific malware ever found, after Stuxnet.",
        "malpediaSlug": "win.industroyer"
      },
      {
        "name": "Industroyer2",
        "type": "malware",
        "custom": true,
        "description": "2022 rewrite with IEC-104 parameters hardcoded per-target rather than configurable — a purpose-built, single-use weapon.",
        "malpediaSlug": "win.industroyer2"
      },
      {
        "name": "NotPetya",
        "type": "wiper",
        "custom": true,
        "description": "Wiper disguised as ransomware. Overwrote the MFT and MBR with no recovery path; spread via EternalBlue, EternalRomance, and stolen credentials.",
        "malpediaSlug": "win.notpetya"
      },
      {
        "name": "BlackEnergy 3",
        "type": "malware",
        "custom": true,
        "description": "Modular platform used in the 2015 grid attack, with KillDisk for post-attack destruction of operator workstations.",
        "malpediaSlug": "win.blackenergy"
      },
      {
        "name": "Olympic Destroyer",
        "type": "wiper",
        "custom": true,
        "description": "Destructive worm salted with forged code artifacts imitating Lazarus Group — the most sophisticated public false-flag to date.",
        "malpediaSlug": "win.olympic_destroyer"
      },
      {
        "name": "AcidRain",
        "type": "wiper",
        "custom": true,
        "description": "Modem/router wiper used against Viasat KA-SAT terminals on 24 February 2022, bricking tens of thousands of devices across Europe.",
        "malpediaSlug": "elf.acidrain"
      },
      {
        "name": "HermeticWiper",
        "type": "wiper",
        "custom": true,
        "description": "Deployed against Ukrainian organisations hours before the February 2022 invasion, using a signed EaseUS partition driver to corrupt the MBR.",
        "malpediaSlug": "win.hermeticwiper"
      },
      {
        "name": "CaddyWiper",
        "type": "wiper",
        "custom": true,
        "description": "Minimalist wiper paired with Industroyer2 in the April 2022 grid attack to destroy forensic evidence."
      },
      {
        "name": "VPNFilter",
        "type": "malware",
        "custom": true,
        "description": "Router implant on 500,000+ SOHO devices with a destructive firmware-overwrite capability; disrupted by an FBI sinkhole in May 2018.",
        "malpediaSlug": "elf.vpnfilter"
      },
      {
        "name": "KillDisk",
        "type": "wiper",
        "custom": true,
        "description": "Disk-wiping component deployed to prolong recovery after grid and government intrusions."
      },
      {
        "name": "Exaramel",
        "type": "backdoor",
        "custom": true,
        "description": "Windows and Linux backdoor providing the technical link between the Industroyer and TeleBots toolsets."
      }
    ],
    "techniques": [
      {
        "tCode": "T1195.002",
        "name": "Supply Chain Compromise: Compromise Software Supply Chain",
        "tactic": "Initial Access",
        "note": "M.E.Doc accounting software update server used to deliver NotPetya"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access",
        "note": "BlackEnergy delivered via macro documents to grid operators"
      },
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Exim MTA and Zimbra exploitation for perimeter access"
      },
      {
        "tCode": "T1133",
        "name": "External Remote Services",
        "tactic": "Initial Access",
        "note": "Hijacked legitimate VPN accounts to operate grid HMIs in 2015"
      },
      {
        "tCode": "T1210",
        "name": "Exploitation of Remote Services",
        "tactic": "Lateral Movement",
        "note": "EternalBlue and EternalRomance in NotPetya"
      },
      {
        "tCode": "T1003.001",
        "name": "OS Credential Dumping: LSASS Memory",
        "tactic": "Credential Access",
        "note": "Custom Mimikatz derivative embedded in NotPetya for automated credential harvesting"
      },
      {
        "tCode": "T1561.002",
        "name": "Disk Wipe: Disk Structure Wipe",
        "tactic": "Impact",
        "note": "MBR/MFT destruction across the wiper family"
      },
      {
        "tCode": "T1485",
        "name": "Data Destruction",
        "tactic": "Impact"
      },
      {
        "tCode": "T1495",
        "name": "Firmware Corruption",
        "tactic": "Impact",
        "note": "VPNFilter and AcidRain overwrite device firmware"
      },
      {
        "tCode": "T0831",
        "name": "Manipulation of Control",
        "tactic": "Impact",
        "note": "ICS technique — direct operation of substation breakers"
      },
      {
        "tCode": "T0816",
        "name": "Device Restart/Shutdown",
        "tactic": "Impact",
        "note": "ICS technique — Industroyer protection-relay DoS module"
      },
      {
        "tCode": "T1529",
        "name": "System Shutdown/Reboot",
        "tactic": "Impact"
      },
      {
        "tCode": "T1036.005",
        "name": "Masquerading: Match Legitimate Name or Location",
        "tactic": "Defense Evasion",
        "note": "NotPetya presented a functional-looking ransom note that could never decrypt"
      },
      {
        "tCode": "T1027",
        "name": "Obfuscated Files or Information",
        "tactic": "Defense Evasion",
        "note": "Olympic Destroyer's forged Lazarus-lookalike artifacts"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1219",
        "name": "Remote Access Software",
        "tactic": "Command and Control"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2014-4114",
        "firstExploited": "2014-09-01",
        "zeroDay": true,
        "usage": "OLE package manager zero-day delivered in PowerPoint lures against NATO, Ukrainian government, and energy targets. The exploit's discovery — and the Dune references found in the C2 code — gave the group its name.",
        "source": {
          "org": "iSIGHT Partners",
          "title": "Sandworm Team — Russian cyber espionage campaign exploiting CVE-2014-4114",
          "url": "https://www.cisa.gov/news-events/ics-alerts/ics-alert-14-281-01b",
          "date": "2014-10-14"
        }
      },
      {
        "cveId": "CVE-2017-0144",
        "firstExploited": "2017-06-27",
        "usage": "EternalBlue built directly into NotPetya's propagation engine alongside EternalRomance and credential-based lateral movement, producing worm-speed spread across flat corporate networks.",
        "source": {
          "org": "ESET",
          "title": "TeleBots are back: supply-chain attacks against Ukraine",
          "url": "https://www.welivesecurity.com/2017/06/30/telebots-back-supply-chain-attacks-against-ukraine/",
          "date": "2017-06-30"
        }
      },
      {
        "cveId": "CVE-2022-30190",
        "firstExploited": "2022-06-01",
        "usage": "Follina MSDT exploit used in phishing against Ukrainian media organisations to deliver CredoMap.",
        "source": {
          "org": "CERT-UA",
          "title": "Cyberattack against media organizations using CVE-2022-30190",
          "url": "https://cert.gov.ua/article/341128",
          "date": "2022-06-20"
        }
      },
      {
        "cveId": "CVE-2023-38831",
        "firstExploited": "2023-09-01",
        "usage": "WinRAR spoofing bug used in campaigns against Ukrainian targets in late 2023.",
        "source": {
          "org": "Google Threat Analysis Group",
          "title": "Government-backed actors exploiting WinRAR vulnerability",
          "url": "https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/",
          "date": "2023-10-18"
        }
      },
      {
        "cveId": "CVE-2020-1472",
        "firstExploited": "2021-01-01",
        "usage": "Zerologon used for domain compromise in intrusions against Ukrainian government networks.",
        "source": {
          "org": "CERT-UA",
          "title": "UAC-0002 activity reporting",
          "url": "https://cert.gov.ua/",
          "date": "2022-04-12"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt28",
        "type": "same-sponsor",
        "confidence": "confirmed",
        "note": "Both GRU, charged jointly in the 2018 Netyksho indictment. Unit 74455 operated the leak platforms for material Unit 26165 collected."
      },
      {
        "relatedActorId": "gamaredon",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "CERT-UA has documented Gamaredon providing initial footholds in Ukrainian networks subsequently used by other Russian services."
      },
      {
        "relatedActorId": "berserk-bear",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Both pursue energy-sector access; Sandworm executes destructive effects while Berserk Bear focuses on persistent reconnaissance."
      }
    ],
    "reports": [
      {
        "org": "SANS ICS / E-ISAC",
        "title": "Analysis of the Cyber Attack on the Ukrainian Power Grid",
        "url": "https://media.threatpost.com/wp-content/uploads/sites/103/2016/03/22194604/E-ISAC_SANS_Ukraine_DUC_5.pdf",
        "date": "2016-03-18"
      },
      {
        "org": "ESET",
        "title": "Industroyer: Biggest threat to industrial control systems since Stuxnet",
        "url": "https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/",
        "date": "2017-06-12"
      },
      {
        "org": "ESET / CERT-UA",
        "title": "Industroyer2: Industroyer reloaded — attack against Ukrainian energy company",
        "url": "https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/",
        "date": "2022-04-12"
      },
      {
        "org": "Mandiant",
        "title": "APT44: Unearthing Sandworm",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm",
        "date": "2024-04-17"
      },
      {
        "org": "Mandiant",
        "title": "Sandworm Disrupts Power in Ukraine Using Novel Attack Against Operational Technology",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/sandworm-disrupts-power-ukraine-operational-technology",
        "date": "2023-11-09"
      },
      {
        "org": "The White House",
        "title": "Statement from the Press Secretary on NotPetya Attack",
        "url": "https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/",
        "date": "2018-02-15"
      }
    ],
    "campaigns": [
      {
        "id": "industroyer2-2022",
        "actorId": "sandworm",
        "name": "Industroyer2",
        "date": "2022-04-08",
        "significance": "major",
        "targetSectors": [
          "Energy",
          "Critical Infrastructure"
        ],
        "targetCountries": [
          "Ukraine"
        ],
        "cveIds": [],
        "summary": "Attempted attack on a Ukrainian high-voltage electrical substation using a purpose-built Industroyer rewrite with target parameters hardcoded, paired with CaddyWiper to destroy evidence. Disrupted by CERT-UA and ESET before the intended effect.",
        "sources": [
          {
            "org": "ESET / CERT-UA",
            "title": "Industroyer2: Industroyer reloaded",
            "url": "https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/",
            "date": "2022-04-12"
          }
        ]
      },
      {
        "id": "viasat-acidrain",
        "actorId": "sandworm",
        "name": "Viasat KA-SAT / AcidRain",
        "date": "2022-02-24",
        "significance": "major",
        "targetSectors": [
          "Telecommunications",
          "Critical Infrastructure",
          "Energy"
        ],
        "targetCountries": [
          "Ukraine",
          "Germany",
          "France",
          "Poland",
          "Italy"
        ],
        "cveIds": [],
        "summary": "Wiper deployed against Viasat KA-SAT satellite modems in the opening hours of the invasion of Ukraine, bricking tens of thousands of terminals and incidentally disabling remote monitoring for roughly 5,800 wind turbines in Germany.",
        "sources": [
          {
            "org": "SentinelOne",
            "title": "AcidRain: A Modem Wiper Rains Down on Europe",
            "url": "https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/",
            "date": "2022-03-31"
          },
          {
            "org": "Council of the EU",
            "title": "Russian cyber operations against Ukraine: Declaration by the High Representative",
            "url": "https://www.consilium.europa.eu/en/press/press-releases/2022/05/10/russian-cyber-operations-against-ukraine-declaration-by-the-high-representative-on-behalf-of-the-european-union/",
            "date": "2022-05-10"
          }
        ]
      },
      {
        "id": "olympic-destroyer",
        "actorId": "sandworm",
        "name": "Olympic Destroyer",
        "date": "2018-02-09",
        "significance": "major",
        "targetSectors": [
          "Government",
          "Media & Journalism",
          "Transportation",
          "Telecommunications"
        ],
        "targetCountries": [
          "South Korea"
        ],
        "cveIds": [],
        "summary": "Destructive attack on the Pyeongchang Winter Olympics opening ceremony, disabling ticketing, Wi-Fi, and broadcast systems. The malware was deliberately salted with forged artifacts imitating Lazarus Group code — the most sophisticated false-flag operation publicly documented.",
        "sources": [
          {
            "org": "NCSC-UK",
            "title": "UK exposes series of Russian cyber attacks against Olympic and Paralympic Games",
            "url": "https://www.ncsc.gov.uk/news/uk-exposes-russian-cyber-attacks",
            "date": "2020-10-19"
          }
        ]
      },
      {
        "id": "notpetya",
        "actorId": "sandworm",
        "name": "NotPetya",
        "date": "2017-06-27",
        "significance": "landmark",
        "targetSectors": [
          "Manufacturing",
          "Transportation",
          "Financial Services",
          "Healthcare",
          "Government",
          "Energy"
        ],
        "targetCountries": [
          "Ukraine",
          "United States",
          "United Kingdom",
          "Denmark",
          "France",
          "Germany",
          "India"
        ],
        "cveIds": [
          "CVE-2017-0144"
        ],
        "summary": "Wiper disguised as ransomware, distributed through a compromised update to Ukrainian tax accounting software and spread worldwide via EternalBlue and credential theft. Maersk, Merck, FedEx/TNT, Mondelez, and Saint-Gobain were among the casualties. The White House assessed total damage above $10 billion — the costliest cyberattack ever conducted.",
        "sources": [
          {
            "org": "The White House",
            "title": "Statement from the Press Secretary on NotPetya",
            "url": "https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/",
            "date": "2018-02-15"
          },
          {
            "org": "ESET",
            "title": "TeleBots are back: supply-chain attacks against Ukraine",
            "url": "https://www.welivesecurity.com/2017/06/30/telebots-back-supply-chain-attacks-against-ukraine/",
            "date": "2017-06-30"
          }
        ]
      },
      {
        "id": "industroyer-2016",
        "actorId": "sandworm",
        "name": "Industroyer / Kyiv Substation Attack",
        "date": "2016-12-17",
        "significance": "landmark",
        "targetSectors": [
          "Energy",
          "Critical Infrastructure"
        ],
        "targetCountries": [
          "Ukraine"
        ],
        "cveIds": [],
        "summary": "Deployment of Industroyer against a Kyiv transmission substation — the first malware written to speak native grid protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) and manipulate substation equipment directly. Only the second ICS-specific malware ever found, after Stuxnet.",
        "sources": [
          {
            "org": "ESET",
            "title": "Industroyer: Biggest threat to industrial control systems since Stuxnet",
            "url": "https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/",
            "date": "2017-06-12"
          }
        ]
      },
      {
        "id": "ukraine-grid-2015",
        "actorId": "sandworm",
        "name": "Ukraine Power Grid Attack (2015)",
        "date": "2015-12-23",
        "significance": "landmark",
        "targetSectors": [
          "Energy",
          "Critical Infrastructure"
        ],
        "targetCountries": [
          "Ukraine"
        ],
        "cveIds": [],
        "summary": "The first confirmed cyber-induced power outage in history. Operators used hijacked VPN credentials to remotely open breakers at three regional distribution companies, cutting power to roughly 230,000 people, then deployed KillDisk and attacked the phone system to impede recovery.",
        "sources": [
          {
            "org": "SANS ICS / E-ISAC",
            "title": "Analysis of the Cyber Attack on the Ukrainian Power Grid",
            "url": "https://media.threatpost.com/wp-content/uploads/sites/103/2016/03/22194604/E-ISAC_SANS_Ukraine_DUC_5.pdf",
            "date": "2016-03-18"
          }
        ]
      }
    ],
    "flag": "🇷🇺",
    "profile": "/apt/sandworm/"
  }
}