Sandworm is GRU Unit 74455, the Main Centre for Special Technologies. It is the most destructive cyber actor in the public record, and the only one credited with causing physical electricity blackouts through malware.
In December 2015 it cut power to roughly 230,000 people in western Ukraine by remotely operating breakers at three distribution companies — the first confirmed cyber-induced blackout in history. It returned in December 2016 with Industroyer, malware that speaks native grid protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) and manipulates substation equipment directly, without needing to understand the specific vendor's HMI.
In June 2017 it released NotPetya through a compromised update to M.E.Doc, Ukrainian tax accounting software. Disguised as ransomware but designed with no recoverable decryption path, it spread via EternalBlue and credential theft into every network connected to a Ukrainian subsidiary. Maersk, Merck, FedEx/TNT, Mondelez, and Saint-Gobain were among the casualties; the White House put total global damage above $10 billion, making it the costliest cyberattack ever conducted.
Its Olympic Destroyer operation against the 2018 Pyeongchang Winter Olympics remains the most sophisticated false-flag operation publicly documented: the malware was deliberately salted with forged artifacts imitating Lazarus Group code, specifically to mislead the analysts who would examine it.
Since February 2022 the group has run a sustained wiper campaign against Ukrainian infrastructure and, in October 2022, achieved a third grid disruption — this time by pivoting into a substation's hypervisor and issuing native SCADA commands, timed to coincide with missile strikes.