Skip to content
RussiaState-SponsoredActiveMITRE G0034Malpedia ↗

Sandworm

The only actor to have caused blackouts with malware — twice. GRU Unit 74455, responsible for NotPetya, Industroyer, and the Ukrainian grid attacks.

ATTRIBUTED TORussia › GRU — Main Intelligence Directorate of the General Staff › Unit 74455

Open MITRE Navigator layer ↗Download profile JSON
Active
2009–present
Motivation
Sabotage / Destruction, Espionage, Information Operations
Aliases
14
Exploited CVEs
5
ATT&CK techniques
16
Cited sources
14

Overview

Sandworm is GRU Unit 74455, the Main Centre for Special Technologies. It is the most destructive cyber actor in the public record, and the only one credited with causing physical electricity blackouts through malware.

In December 2015 it cut power to roughly 230,000 people in western Ukraine by remotely operating breakers at three distribution companies — the first confirmed cyber-induced blackout in history. It returned in December 2016 with Industroyer, malware that speaks native grid protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) and manipulates substation equipment directly, without needing to understand the specific vendor's HMI.

In June 2017 it released NotPetya through a compromised update to M.E.Doc, Ukrainian tax accounting software. Disguised as ransomware but designed with no recoverable decryption path, it spread via EternalBlue and credential theft into every network connected to a Ukrainian subsidiary. Maersk, Merck, FedEx/TNT, Mondelez, and Saint-Gobain were among the casualties; the White House put total global damage above $10 billion, making it the costliest cyberattack ever conducted.

Its Olympic Destroyer operation against the 2018 Pyeongchang Winter Olympics remains the most sophisticated false-flag operation publicly documented: the malware was deliberately salted with forged artifacts imitating Lazarus Group code, specifically to mislead the analysts who would examine it.

Since February 2022 the group has run a sustained wiper campaign against Ukrainian infrastructure and, in October 2022, achieved a third grid disruption — this time by pivoting into a substation's hypervisor and issuing native SCADA commands, timed to coincide with missile strikes.

Attribution

Down to the named unit where public evidence supports it.

RussiaGRU — Main Intelligence Directorate of the General StaffUnit 74455Confirmed

Main Centre for Special Technologies (GTsST), 22 Kirova Street, Khimki — 'the Tower'

Attributed to GRU Unit 74455 by U.S. federal indictment. In October 2020 the Department of Justice charged six named officers over NotPetya, the 2015 and 2016 Ukrainian grid attacks, Olympic Destroyer, the 2017 French election interference, and attacks on the Novichok poisoning investigation. The UK NCSC concurrently attributed Olympic Destroyer to the GRU, and Unit 74455 officers were also charged in the July 2018 election interference indictment for operating the DCLeaks and Guccifer 2.0 personas.

Attributing sources

Cross-vendor naming crosswalk

14 designators across 10 organisations.

4 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • Sandworm Team

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Seashell BlizzardFormerly IRIDIUM
  • IRIDIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Voodoo Bear

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT44Graduated from 'Sandworm' to a numbered APT designator in April 2024
  • FROZENBARENTSGoogle TAG designator, now aligned to APT44

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • IRON VIKING

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • UAC-0002CERT-UA designator adopted in Ukrainian reporting

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

ESET Research

index ↗
  • TeleBots
  • BlackEnergy GrouppartialEarlier phase of the same actor, named for the BlackEnergy toolset

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • HadespartialKaspersky's designator for the Olympic Destroyer cluster

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Dragos

index ↗
  • ELECTRUMpartialDragos scopes ELECTRUM to the ICS-capable element; KAMACITE is tracked as the associated IT-access arm that hands off to ELECTRUM
  • KAMACITEpartialInitial-access and enablement operations feeding ELECTRUM

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

CISA / NSA / FBI

index ↗
  • GRU Unit 74455

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Industroyer / CrashOverridemalware

ICS-aware malware implementing IEC 60870-5-101/104, IEC 61850, and OPC DA to operate substation breakers directly. Only the second ICS-specific malware ever found, after Stuxnet.

Malpedia ↗
Industroyer2malware

2022 rewrite with IEC-104 parameters hardcoded per-target rather than configurable — a purpose-built, single-use weapon.

Malpedia ↗
NotPetyawiper

Wiper disguised as ransomware. Overwrote the MFT and MBR with no recovery path; spread via EternalBlue, EternalRomance, and stolen credentials.

Malpedia ↗
BlackEnergy 3malware

Modular platform used in the 2015 grid attack, with KillDisk for post-attack destruction of operator workstations.

Malpedia ↗
Olympic Destroyerwiper

Destructive worm salted with forged code artifacts imitating Lazarus Group — the most sophisticated public false-flag to date.

Malpedia ↗
AcidRainwiper

Modem/router wiper used against Viasat KA-SAT terminals on 24 February 2022, bricking tens of thousands of devices across Europe.

Malpedia ↗
HermeticWiperwiper

Deployed against Ukrainian organisations hours before the February 2022 invasion, using a signed EaseUS partition driver to corrupt the MBR.

Malpedia ↗
CaddyWiperwiper

Minimalist wiper paired with Industroyer2 in the April 2022 grid attack to destroy forensic evidence.

VPNFiltermalware

Router implant on 500,000+ SOHO devices with a destructive firmware-overwrite capability; disrupted by an FBI sinkhole in May 2018.

Malpedia ↗
KillDiskwiper

Disk-wiping component deployed to prolong recovery after grid and government intrusions.

Exaramelbackdoor

Windows and Linux backdoor providing the technical link between the Industroyer and TeleBots toolsets.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Sandworm
CVE-2023-38831KEVransomware7.81 Sep 2023WinRAR spoofing bug used in campaigns against Ukrainian targets in late 2023.SRCGoogle Threat Analysis Group
CVE-2022-30190KEVransomware7.81 Jun 2022Follina MSDT exploit used in phishing against Ukrainian media organisations to deliver CredoMap.SRCCERT-UA
CVE-2020-1472KEVransomware10.01 Jan 2021Zerologon used for domain compromise in intrusions against Ukrainian government networks.SRCCERT-UA
CVE-2017-0144KEVransomware8.127 Jun 2017EternalBlue built directly into NotPetya's propagation engine alongside EternalRomance and credential-based lateral movement, producing worm-speed spread across flat corporate networks.SRCESET
CVE-2014-41140-dayKEV7.31 Sep 2014OLE package manager zero-day delivered in PowerPoint lures against NATO, Ukrainian government, and energy targets. The exploit's discovery — and the Dune references found in the C2 code — gave the group its name.SRCiSIGHT Partners

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 16 techniques
  1. 02

    Persistence

    1 technique

    Holds legitimate VPN and operator credentials. In 2015 the actor did not need malware on the HMI — it logged in and operated the breakers as an engineer would.

  2. 04

    Credential Access

    1 technique

    NotPetya carried its own Mimikatz derivative, harvesting credentials from memory automatically and using them to reach hosts that were fully patched against EternalBlue. Propagation did not depend on the exploit.

  3. 05

    Lateral Movement

    1 technique

    EternalBlue and EternalRomance for unpatched hosts, stolen credentials for the rest. The combination is what produced worm-speed spread across flat corporate networks.

  4. 06

    Command and Control

    1 technique

    Exaramel and remote access tooling across Windows and Linux, with router implants providing a resilient layer that survives cleanup of the corporate estate.

  5. 07

    Impact

    6 techniques

    The point of the operation. Industroyer speaks IEC 60870-5-101/104, IEC 61850 and OPC DA natively, so it manipulates substation equipment without needing the vendor's HMI. Wipers destroy the evidence and the recovery path together, and AcidRain bricked tens of thousands of satellite modems in the invasion's opening hours.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
16 techniques across 7 tactics · 12 with actor-specific notes

Campaign timeline

  1. Industroyer2

    Attempted attack on a Ukrainian high-voltage electrical substation using a purpose-built Industroyer rewrite with target parameters hardcoded, paired with CaddyWiper to destroy evidence. Disrupted by CERT-UA and ESET before the intended effect.

    EnergyCritical Infrastructure
  2. Viasat KA-SAT / AcidRain

    Wiper deployed against Viasat KA-SAT satellite modems in the opening hours of the invasion of Ukraine, bricking tens of thousands of terminals and incidentally disabling remote monitoring for roughly 5,800 wind turbines in Germany.

    TelecommunicationsCritical InfrastructureEnergy
  3. Olympic Destroyer

    Destructive attack on the Pyeongchang Winter Olympics opening ceremony, disabling ticketing, Wi-Fi, and broadcast systems. The malware was deliberately salted with forged artifacts imitating Lazarus Group code — the most sophisticated false-flag operation publicly documented.

    GovernmentMedia & JournalismTransportationTelecommunications
  4. landmark

    NotPetya

    Wiper disguised as ransomware, distributed through a compromised update to Ukrainian tax accounting software and spread worldwide via EternalBlue and credential theft. Maersk, Merck, FedEx/TNT, Mondelez, and Saint-Gobain were among the casualties. The White House assessed total damage above $10 billion — the costliest cyberattack ever conducted.

    CVE-2017-0144ManufacturingTransportationFinancial ServicesHealthcare
  5. landmark

    Industroyer / Kyiv Substation Attack

    Deployment of Industroyer against a Kyiv transmission substation — the first malware written to speak native grid protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) and manipulate substation equipment directly. Only the second ICS-specific malware ever found, after Stuxnet.

    EnergyCritical Infrastructure
  6. landmark

    Ukraine Power Grid Attack (2015)

    The first confirmed cyber-induced power outage in history. Operators used hijacked VPN credentials to remotely open breakers at three regional distribution companies, cutting power to roughly 230,000 people, then deployed KillDisk and attacked the phone system to impede recovery.

    EnergyCritical Infrastructure

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.