{
  "schemaVersion": 1,
  "id": "actor-sandworm-team",
  "slug": "sandworm-team",
  "name": "Sandworm Team",
  "summary": "A Russian GRU Unit 74455 threat group responsible for destructive global operations and multiple attacks that produced or attempted operational effects in Ukraine's electric grid.",
  "distribution": "TLP:CLEAR",
  "status": "active",
  "actorType": "State-sponsored destructive threat group",
  "primaryFocus": "Espionage, disruption, destructive operations and cyber-physical effects",
  "lastReviewed": "2026-07-19",
  "overallConfidence": "high",
  "stateAffiliation": {
    "state": "Russia",
    "assessment": "The United States attributes Sandworm operations to the Russian General Staff Main Intelligence Directorate Main Center for Special Technologies, Military Unit 74455.",
    "confidence": "high",
    "sourceIds": [
      "mitre-g0034",
      "doj-sandworm-2020",
      "cisa-aa22-110a"
    ]
  },
  "observedSince": [
    {
      "label": "Sandworm Team",
      "value": "2009",
      "qualification": "MITRE reports the group active since at least 2009.",
      "sourceIds": [
        "mitre-g0034"
      ]
    },
    {
      "label": "Publicly attributed OT disruption",
      "value": "2015",
      "qualification": "The 2015 Ukraine electric-power attack produced the first widely recognised cyber-induced power outage.",
      "sourceIds": [
        "mitre-g0034",
        "doj-sandworm-2020",
        "cisa-aa22-110a"
      ]
    }
  ],
  "designations": [
    {
      "provider": "MITRE ATT&CK",
      "name": "Sandworm Team",
      "externalId": "G0034",
      "relationship": "canonical",
      "description": "The primary public group record used for this dossier.",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034"
      ]
    },
    {
      "provider": "Google Threat Intelligence",
      "name": "APT44 / FROZENBARENTS",
      "externalId": "",
      "relationship": "associated",
      "description": "Google/Mandiant designations for the broader Russian military cyber-sabotage organisation.",
      "confidence": "high",
      "sourceIds": [
        "mandiant-apt44",
        "mitre-g0034"
      ]
    },
    {
      "provider": "Microsoft",
      "name": "Seashell Blizzard",
      "externalId": "",
      "relationship": "associated",
      "description": "Microsoft's designation for the broader organisation and its access subgroup.",
      "confidence": "high",
      "sourceIds": [
        "microsoft-badpilot",
        "mitre-g0034"
      ]
    },
    {
      "provider": "Dragos",
      "name": "ELECTRUM",
      "externalId": "",
      "relationship": "overlap",
      "description": "A Dragos cluster for ICS-specific operations that overlaps Sandworm activity; kept distinct from access-enabling KAMACITE.",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034",
        "cisa-aa22-110a"
      ]
    },
    {
      "provider": "U.S. Department of Justice",
      "name": "GRU Military Unit 74455",
      "externalId": "",
      "relationship": "overlap",
      "description": "Government attribution scope for officers charged over destructive and disruptive operations.",
      "confidence": "high",
      "sourceIds": [
        "doj-sandworm-2020"
      ]
    }
  ],
  "assessment": [
    {
      "text": "Sandworm has demonstrated the full path from enterprise intrusion to deliberate physical-process disruption, combining patient access, legitimate operator functionality, purpose-built ICS malware and destructive recovery inhibition.",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034",
        "doj-sandworm-2020",
        "eset-industroyer2"
      ]
    },
    {
      "text": "The group's operations are global, but Ukraine remains the central proving ground for electric-grid attacks, wipers and operationally coordinated cyber activity supporting Russian military objectives.",
      "confidence": "high",
      "sourceIds": [
        "mandiant-apt44",
        "cisa-aa22-110a",
        "doj-sandworm-2020"
      ]
    },
    {
      "text": "BadPilot illustrates the access layer behind destructive capability: scalable perimeter exploitation and persistent access may precede a later high-impact operation by months or years.",
      "confidence": "high",
      "sourceIds": [
        "microsoft-badpilot",
        "mitre-g0034"
      ]
    },
    {
      "text": "Sandworm's OT effect tooling is trending toward less code and faster deployment: a four-protocol framework in 2016, a single IEC-104 binary with hardcoded targets in 2022, then native SCADA functionality with no custom ICS malware in October 2022.",
      "confidence": "high",
      "sourceIds": [
        "eset-industroyer-whitepaper",
        "eset-industroyer2",
        "mandiant-microscada-2022"
      ]
    },
    {
      "text": "Initial access is the least evidenced phase of the grid campaigns. Only 2015 has a confirmed vector (spearphishing with macro-bearing Office documents); 2016 is assessed as likely phishing, and neither 2022 intrusion has a publicly identified vector. Dossier claims about entry for those campaigns are inference, not confirmation.",
      "confidence": "medium",
      "sourceIds": [
        "dragos-crashoverride-2018",
        "certua-4435",
        "mandiant-microscada-2022"
      ]
    },
    {
      "text": "Every documented grid intrusion entered through the enterprise IT estate and worked toward OT, typically via dual-homed hosts, shared Active Directory identity or remote access paths. The IT-to-OT pivot, not the PLC or RTU, is the decisive detection point.",
      "confidence": "high",
      "sourceIds": [
        "dragos-crashoverride-2018",
        "cisa-aa22-110a",
        "mandiant-microscada-2022"
      ]
    },
    {
      "text": "Dwell time between enterprise access and OT impact is measured in months: roughly six months in 2015, between two and eleven months in 2016, and around four months in October 2022, where Mandiant assessed the attacker may have held SCADA access for up to three months and developed the OT capability as late as three weeks before the outage.",
      "confidence": "medium",
      "sourceIds": [
        "dragos-crashoverride-2018",
        "mandiant-microscada-2022",
        "mitre-g0034"
      ]
    },
    {
      "text": "ESET's 2018 discovery of the Exaramel backdoor supplied the first code-level link between Industroyer and the TeleBots activity behind BlackEnergy and NotPetya, consolidating separate campaigns under one operator.",
      "confidence": "high",
      "sourceIds": [
        "eset-exaramel-2018"
      ]
    }
  ],
  "targets": {
    "regions": [
      {
        "name": "Ukraine",
        "sourceIds": [
          "mitre-g0034",
          "mandiant-apt44",
          "cisa-aa22-110a"
        ]
      },
      {
        "name": "Europe and NATO member states",
        "sourceIds": [
          "cisa-aa22-110a",
          "microsoft-badpilot"
        ]
      },
      {
        "name": "United States, Canada and Australia",
        "sourceIds": [
          "microsoft-badpilot"
        ]
      },
      {
        "name": "Global organisations tied to Russian strategic interests",
        "sourceIds": [
          "mandiant-apt44",
          "doj-sandworm-2020"
        ]
      }
    ],
    "sectors": [
      {
        "name": "Electric power and energy",
        "sourceIds": [
          "mitre-g0034",
          "cisa-aa22-110a",
          "eset-industroyer2"
        ]
      },
      {
        "name": "Government and defence",
        "sourceIds": [
          "doj-sandworm-2020",
          "mandiant-apt44"
        ]
      },
      {
        "name": "Telecommunications",
        "sourceIds": [
          "microsoft-badpilot",
          "mandiant-apt44"
        ]
      },
      {
        "name": "Transportation, logistics and manufacturing",
        "sourceIds": [
          "doj-sandworm-2020",
          "cisa-aa22-110a"
        ]
      },
      {
        "name": "Technology and managed infrastructure",
        "sourceIds": [
          "microsoft-badpilot"
        ]
      }
    ],
    "technologies": [
      {
        "name": "Electric substation SCADA and IEC-104 systems",
        "sourceIds": [
          "mitre-g0034",
          "eset-industroyer2"
        ]
      },
      {
        "name": "Microsoft Exchange, Outlook and enterprise perimeter servers",
        "sourceIds": [
          "microsoft-badpilot"
        ]
      },
      {
        "name": "Fortinet, Zimbra, OpenFire, TeamCity and ScreenConnect",
        "sourceIds": [
          "microsoft-badpilot"
        ]
      },
      {
        "name": "Windows, Linux and Solaris infrastructure",
        "sourceIds": [
          "eset-industroyer2",
          "mitre-g0034"
        ]
      },
      {
        "name": "Hitachi Energy MicroSCADA control platforms and their native utilities",
        "sourceIds": [
          "mandiant-microscada-2022"
        ]
      },
      {
        "name": "Hypervisors hosting SCADA management virtual machines",
        "sourceIds": [
          "mandiant-microscada-2022"
        ]
      },
      {
        "name": "Dual-homed historians and engineering workstations bridging IT and OT",
        "sourceIds": [
          "dragos-crashoverride-2018"
        ]
      }
    ]
  },
  "campaigns": [
    {
      "id": "ukraine-power-2015",
      "name": "2015 Ukraine electric-power attack",
      "period": "December 2015",
      "scope": "Sandworm / associated Ukraine operation",
      "summary": "Spearphishing emails carrying macro-bearing Microsoft Office documents installed the BlackEnergy 3 toolkit at three electricity distribution companies. Months of enterprise access and credential harvesting culminated on 23 December in remote use of operator workstations to open breakers at roughly 30 substations, overwrite serial-to-Ethernet device firmware and inhibit recovery. This is the only grid campaign with a publicly confirmed initial access vector.",
      "impact": "Approximately 225,000 customers lost power; operators restored service manually while call centers and remote control were disrupted.",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034",
        "doj-sandworm-2020",
        "cisa-aa22-110a"
      ]
    },
    {
      "id": "ukraine-power-2016",
      "name": "2016 Ukraine electric-power attack",
      "period": "December 2016",
      "scope": "Sandworm / ELECTRUM overlap",
      "summary": "Industroyer/CrashOverride automated interaction with electric-grid protocols and issued commands to a transmission substation in Kyiv on 17 December. Initial access was never publicly confirmed; the intrusion may have begun with phishing as early as January 2016, with IT network access evidenced no later than October 2016. The attackers used valid accounts, living-off-the-land techniques, PsExec and Mimikatz to traverse the enterprise, pivoted into the ICS network via a likely dual-homed host, and reached Windows Server 2003 SQL Server systems assessed as data historians before reaching equipment-facing hosts.",
      "impact": "Part of Kyiv lost power for roughly an hour, and the operation demonstrated reusable, protocol-aware ICS attack capability.",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034",
        "doj-sandworm-2020",
        "cisa-aa22-110a",
        "dragos-crashoverride-2018",
        "eset-industroyer-whitepaper"
      ]
    },
    {
      "id": "notpetya-2017",
      "name": "NotPetya",
      "period": "June 2017",
      "scope": "GRU Unit 74455 attributed operation",
      "summary": "A compromised M.E.Doc update distributed a destructive wiper disguised as ransomware, which propagated rapidly through enterprise networks.",
      "impact": "Global collateral damage disrupted shipping, logistics, pharmaceuticals and other sectors; the U.S. indictment cites nearly one billion dollars in losses among three victims alone.",
      "confidence": "high",
      "sourceIds": [
        "doj-sandworm-2020",
        "cisa-aa22-110a",
        "mitre-g0034"
      ]
    },
    {
      "id": "industroyer2-2022",
      "name": "Industroyer2 attempt",
      "period": "April 2022",
      "scope": "Sandworm",
      "summary": "A targeted IEC-104 payload built from the original Industroyer source was scheduled against Ukrainian high-voltage substations alongside Windows, Linux and Solaris wipers. Target IP addresses, ASDU addresses and information object addresses were hardcoded into the binary rather than read from a configuration file. CERT-UA reported the initial compromise occurred no later than February 2022; the entry vector was not identified publicly.",
      "impact": "Defenders disrupted the attempt before the planned power interruption; the operation showed refined, target-specific ICS execution.",
      "confidence": "high",
      "sourceIds": [
        "eset-industroyer2",
        "certua-4435",
        "mitre-g0034"
      ]
    },
    {
      "id": "ukraine-power-2022-microscada",
      "name": "October 2022 MicroSCADA living-off-the-land outage",
      "period": "October 2022",
      "scope": "Sandworm",
      "summary": "No custom ICS malware was used. The attacker executed a native MicroSCADA binary, scilc.exe, from an ISO image mounted on the hypervisor hosting the victim's SCADA management instance, issuing commands that opened breakers. The intrusion began on or before June 2022, with SCADA access assessed as possibly held for up to three months and the OT capability potentially developed as late as three weeks before execution. Mandiant could not identify the initial access vector.",
      "impact": "An unscheduled power outage at a Ukrainian substation, timed to coincide with Russian missile strikes on Ukrainian cities; CaddyWiper was deployed across the IT estate two days later to compound disruption and destroy forensic evidence.",
      "confidence": "high",
      "sourceIds": [
        "mandiant-microscada-2022"
      ]
    },
    {
      "id": "badpilot-access",
      "name": "BadPilot global access operation",
      "period": "Late 2021 onward",
      "scope": "Seashell Blizzard access subgroup",
      "summary": "A multiyear access campaign exploited perimeter products at scale, established persistence, harvested credentials and expanded from Ukraine to organisations across several continents.",
      "impact": "Long-lived access provides espionage value and can establish the conditions for later destructive operations.",
      "confidence": "high",
      "sourceIds": [
        "microsoft-badpilot",
        "mitre-g0034"
      ]
    }
  ],
  "capabilities": [
    {
      "name": "Operate industrial processes through intended functionality",
      "description": "Use SCADA interfaces and protocol-valid commands to manipulate breakers and deny operator control.",
      "scope": "Sandworm / ELECTRUM overlap",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034",
        "eset-industroyer2"
      ]
    },
    {
      "name": "Develop purpose-built ICS malware",
      "description": "Create reusable frameworks and target-specific payloads that communicate with electric-power equipment.",
      "scope": "Sandworm / ELECTRUM overlap",
      "confidence": "high",
      "sourceIds": [
        "eset-industroyer2",
        "doj-sandworm-2020"
      ]
    },
    {
      "name": "Destroy enterprise and recovery infrastructure",
      "description": "Deploy wipers, modify firmware, disable tooling and coordinate data destruction with operational effects.",
      "scope": "Sandworm",
      "confidence": "high",
      "sourceIds": [
        "doj-sandworm-2020",
        "cisa-aa22-110a",
        "eset-industroyer2"
      ]
    },
    {
      "name": "Cause OT impact with native platform tooling",
      "description": "Execute vendor-supplied SCADA binaries and scripting interfaces already present on control hosts, removing the need for custom ICS malware and shrinking the detectable footprint.",
      "scope": "October 2022 Ukraine campaign",
      "confidence": "high",
      "sourceIds": [
        "mandiant-microscada-2022"
      ]
    },
    {
      "name": "Pivot from enterprise IT into control networks",
      "description": "Traverse the corporate estate with valid accounts, credential dumping and living-off-the-land tooling, then cross into OT through dual-homed hosts, shared domain identity or remote access paths.",
      "scope": "Ukraine electric-power campaigns",
      "confidence": "high",
      "sourceIds": [
        "dragos-crashoverride-2018",
        "cisa-aa22-110a"
      ]
    },
    {
      "name": "Sustain long pre-impact dwell in OT environments",
      "description": "Hold access for months while learning the process environment and equipment addressing, then build or configure an effect capability specific to the plant shortly before execution.",
      "scope": "Sandworm",
      "confidence": "medium",
      "sourceIds": [
        "mandiant-microscada-2022",
        "dragos-crashoverride-2018"
      ]
    },
    {
      "name": "Acquire persistent access at scale",
      "description": "Exploit exposed perimeter products, deploy web shells and remote tools, and collect credentials for later tasking.",
      "scope": "Seashell Blizzard access subgroup",
      "confidence": "high",
      "sourceIds": [
        "microsoft-badpilot"
      ]
    }
  ],
  "malware": [
    {
      "name": "BlackEnergy 3 and KillDisk",
      "description": "Enterprise intrusion and destructive components used around the 2015 Ukraine power operation.",
      "scope": "Sandworm-associated activity",
      "confidence": "high",
      "sourceIds": [
        "mitre-g0034",
        "cisa-aa22-110a"
      ]
    },
    {
      "name": "Industroyer / CrashOverride",
      "description": "A modular ICS framework with four protocol payloads (IEC-101, IEC-104, IEC-61850 and OPC DA), a main backdoor, a second backdoor hidden in a trojanised Notepad application and a wiper component, capable of automating operational disruption at substation equipment.",
      "scope": "Sandworm / ELECTRUM overlap",
      "confidence": "high",
      "sourceIds": [
        "doj-sandworm-2020",
        "cisa-aa22-110a",
        "eset-industroyer-whitepaper"
      ]
    },
    {
      "name": "Exaramel",
      "description": "A backdoor whose code-level similarity to Industroyer's main backdoor gave the first public evidence tying Industroyer to the TeleBots group behind BlackEnergy and NotPetya.",
      "scope": "Sandworm / TeleBots overlap",
      "confidence": "high",
      "sourceIds": [
        "eset-exaramel-2018"
      ]
    },
    {
      "name": "scilc.exe (native MicroSCADA utility)",
      "description": "A legitimate vendor binary abused to run SCIL commands against substation equipment in October 2022, delivered via an ISO mounted on the SCADA host's hypervisor.",
      "scope": "October 2022 Ukraine campaign",
      "confidence": "high",
      "caveat": "Not attacker-authored. Detection must key on anomalous invocation of trusted platform tooling rather than file reputation.",
      "sourceIds": [
        "mandiant-microscada-2022"
      ]
    },
    {
      "name": "NotPetya",
      "description": "A destructive wiper masquerading as ransomware that spread globally from a compromised Ukrainian software update.",
      "scope": "GRU Unit 74455 attributed operation",
      "confidence": "high",
      "sourceIds": [
        "doj-sandworm-2020",
        "cisa-aa22-110a"
      ]
    },
    {
      "name": "Industroyer2",
      "description": "A streamlined IEC-104 payload configured for a targeted 2022 attempt against Ukrainian substations.",
      "scope": "Sandworm",
      "confidence": "high",
      "sourceIds": [
        "eset-industroyer2"
      ]
    },
    {
      "name": "CaddyWiper / ORCSHRED / SOLOSHRED / AWFULSHRED",
      "description": "Destructive payloads for Windows, Linux and Solaris coordinated with the Industroyer2 attempt, with CaddyWiper reused across the IT estate two days after the October 2022 outage to compound disruption and destroy forensic evidence.",
      "scope": "Sandworm",
      "confidence": "high",
      "sourceIds": [
        "eset-industroyer2",
        "mandiant-microscada-2022"
      ]
    }
  ],
  "ttps": {
    "enterprise": [
      {
        "id": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access",
        "behaviour": "Malicious Office and archive attachments established footholds, including in the 2015 power campaign. Lures are tailored to the recipient's role and to current events, and the 2020 indictment records the same pattern against election, Olympic, Novichok-investigation and Georgian government targets.",
        "scope": "Sandworm",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034",
          "doj-sandworm-2020"
        ]
      },
      {
        "id": "T1204.002",
        "name": "User Execution: Malicious File",
        "tactic": "Execution",
        "behaviour": "Recipients opened weaponised Word documents and enabled macros, which downloaded and installed the BlackEnergy 3 backdoor.",
        "scope": "2015 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034",
          "cisa-aa22-110a"
        ]
      },
      {
        "id": "T1078",
        "name": "Valid Accounts",
        "tactic": "Lateral Movement",
        "behaviour": "Harvested credentials were reused for months of low-signal movement through the enterprise estate and for reaching systems bridging IT and OT.",
        "scope": "Ukraine electric-power campaigns",
        "confidence": "high",
        "sourceIds": [
          "dragos-crashoverride-2018",
          "mitre-g0034"
        ]
      },
      {
        "id": "T1003",
        "name": "OS Credential Dumping",
        "tactic": "Credential Access",
        "behaviour": "Mimikatz and comparable tooling harvested credentials to expand access toward control-network paths.",
        "scope": "2016 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "dragos-crashoverride-2018"
        ]
      },
      {
        "id": "T1569.002",
        "name": "System Services: Service Execution",
        "tactic": "Execution",
        "behaviour": "PsExec and similar administrative utilities executed payloads remotely, keeping activity within expected administrative behaviour.",
        "scope": "2016 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "dragos-crashoverride-2018"
        ]
      },
      {
        "id": "T1059.001",
        "name": "Command and Scripting Interpreter: PowerShell",
        "tactic": "Execution",
        "behaviour": "PowerShell supported credential harvesting, deployment and destructive tooling.",
        "scope": "Sandworm",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T1021.002",
        "name": "Remote Services: SMB/Windows Admin Shares",
        "tactic": "Lateral Movement",
        "behaviour": "Administrative shares and remote services moved payloads through enterprise networks.",
        "scope": "Sandworm",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T1485",
        "name": "Data Destruction",
        "tactic": "Impact",
        "behaviour": "NotPetya and coordinated wipers rendered systems and recovery infrastructure inoperable.",
        "scope": "Sandworm",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034",
          "doj-sandworm-2020",
          "eset-industroyer2"
        ]
      },
      {
        "id": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "behaviour": "BadPilot exploited multiple enterprise perimeter products to establish scalable, persistent access.",
        "scope": "Seashell Blizzard access subgroup",
        "confidence": "high",
        "sourceIds": [
          "microsoft-badpilot"
        ]
      }
    ],
    "ics": [
      {
        "id": "T0822",
        "name": "External Remote Services",
        "tactic": "Initial Access",
        "behaviour": "Valid accounts and remote services provided access to operator and control environments.",
        "scope": "Sandworm",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T0823",
        "name": "Graphical User Interface",
        "tactic": "Execution",
        "behaviour": "Attackers operated SCADA/HMI interfaces to issue breaker commands during the 2015 attack.",
        "scope": "2015 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T0805",
        "name": "Block Serial COM",
        "tactic": "Inhibit Response Function",
        "behaviour": "Firmware on serial-to-Ethernet converters was overwritten to sever downstream communications.",
        "scope": "2015 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T0853",
        "name": "Scripting",
        "tactic": "Execution",
        "behaviour": "A native MicroSCADA utility ran attacker-supplied SCIL commands from an ISO mounted on the hosting hypervisor, achieving process impact without custom ICS malware.",
        "scope": "October 2022 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "mandiant-microscada-2022"
        ]
      },
      {
        "id": "T0812",
        "name": "Default Credentials",
        "tactic": "Lateral Movement",
        "behaviour": "Weak boundaries between enterprise and control identity, including shared domain accounts and flat segmentation, eased the pivot into process networks.",
        "scope": "Ukraine electric-power campaigns",
        "confidence": "medium",
        "sourceIds": [
          "dragos-crashoverride-2018",
          "cisa-aa22-110a"
        ]
      },
      {
        "id": "T0809",
        "name": "Data Destruction",
        "tactic": "Inhibit Response Function",
        "behaviour": "Wipers were deployed after or alongside process impact to obstruct recovery and destroy forensic evidence, including CaddyWiper two days after the October 2022 outage.",
        "scope": "Sandworm",
        "confidence": "high",
        "sourceIds": [
          "mandiant-microscada-2022",
          "eset-industroyer2"
        ]
      },
      {
        "id": "T0855",
        "name": "Unauthorized Command Message",
        "tactic": "Impair Process Control",
        "behaviour": "Protocol-valid commands were issued to electric substation equipment.",
        "scope": "Ukraine electric-power campaigns",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034",
          "eset-industroyer2"
        ]
      },
      {
        "id": "T0813",
        "name": "Denial of Control",
        "tactic": "Impact",
        "behaviour": "Device and communication sabotage denied operators reliable downstream control.",
        "scope": "2015 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T0826",
        "name": "Loss of Availability",
        "tactic": "Impact",
        "behaviour": "Breaker operations and destructive actions interrupted electric service and system availability.",
        "scope": "Ukraine electric-power campaigns",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T0827",
        "name": "Loss of Control",
        "tactic": "Impact",
        "behaviour": "Operators lost remote control and relied on manual restoration procedures.",
        "scope": "2015 Ukraine campaign",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034"
        ]
      },
      {
        "id": "T0831",
        "name": "Manipulation of Control",
        "tactic": "Impact",
        "behaviour": "Breaker states and operational commands were deliberately altered to disrupt the grid.",
        "scope": "Ukraine electric-power campaigns",
        "confidence": "high",
        "sourceIds": [
          "mitre-g0034",
          "eset-industroyer2"
        ]
      }
    ]
  },
  "indicatorNotice": "This dossier prioritises durable behaviour over historical campaign infrastructure. Sandworm routinely changes access infrastructure and reuses legitimate services; point-in-time indicators should remain tied to the source campaign and collection date.",
  "indicators": [],
  "defensivePriorities": [
    {
      "name": "Separate process control from enterprise identity failure",
      "description": "Enforce strong segmentation, dedicated OT identities, controlled jump paths and independent operator authentication.",
      "sourceIds": [
        "cisa-aa22-110a",
        "mitre-g0034"
      ]
    },
    {
      "name": "Detect valid but abnormal control actions",
      "description": "Baseline breaker operations, engineering changes and IEC-104 command sequences; alert on commands that are technically valid but operationally unexpected.",
      "sourceIds": [
        "eset-industroyer2",
        "mitre-g0034"
      ]
    },
    {
      "name": "Protect restoration and manual operations",
      "description": "Maintain offline recovery, tested manual control, independent communications and rehearsed black-start or degraded-mode procedures.",
      "sourceIds": [
        "cisa-aa22-110a",
        "mitre-g0034"
      ]
    },
    {
      "name": "Hunt perimeter access as pre-attack activity",
      "description": "Treat exploitation, web shells, OWA credential collection and new remote tools as potential preparation for later destructive tasking.",
      "sourceIds": [
        "microsoft-badpilot"
      ]
    },
    {
      "name": "Instrument the IT-to-OT pivot as the primary chokepoint",
      "description": "Inventory dual-homed hosts, historians and engineering workstations, separate OT identity from the corporate domain, and alert on any enterprise-originated authentication or file transfer crossing into the control network.",
      "sourceIds": [
        "dragos-crashoverride-2018",
        "cisa-aa22-110a"
      ]
    },
    {
      "name": "Alert on native SCADA tooling used outside normal operations",
      "description": "Baseline execution of vendor utilities on control hosts, and treat unexpected invocation, mounted ISO or removable images on SCADA hypervisors, and out-of-band scripting as high-severity events even when the binary is signed and legitimate.",
      "sourceIds": [
        "mandiant-microscada-2022"
      ]
    },
    {
      "name": "Harden and monitor the phishing entry path for OT-adjacent staff",
      "description": "Block or restrict macros in documents from the internet, apply attachment detonation, and prioritise engineers, control-room staff and anyone handling operational documentation for phishing-resistant authentication and targeted awareness.",
      "sourceIds": [
        "mitre-g0034",
        "doj-sandworm-2020"
      ]
    },
    {
      "name": "Contain coordinated wiper deployment",
      "description": "Protect domain controllers, software distribution, hypervisors and backups from shared administrative paths and Group Policy abuse.",
      "sourceIds": [
        "eset-industroyer2",
        "mitre-g0034"
      ]
    }
  ],
  "sources": [
    {
      "id": "mitre-g0034",
      "publisher": "MITRE ATT&CK",
      "title": "Sandworm Team, Group G0034",
      "url": "https://attack.mitre.org/groups/G0034/",
      "published": "2017-05-31",
      "updated": "2024-12-04",
      "type": "knowledge base"
    },
    {
      "id": "doj-sandworm-2020",
      "publisher": "U.S. Department of Justice",
      "title": "Six Russian GRU Officers Charged in Connection with Destructive Malware",
      "url": "https://www.justice.gov/usao-wdpa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "published": "2020-10-19",
      "type": "government attribution"
    },
    {
      "id": "cisa-aa22-110a",
      "publisher": "CISA and partner agencies",
      "title": "Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure",
      "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-110a",
      "published": "2022-04-20",
      "type": "government advisory"
    },
    {
      "id": "eset-industroyer2",
      "publisher": "ESET Research",
      "title": "Industroyer2: Industroyer reloaded",
      "url": "https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/",
      "published": "2022-04-12",
      "type": "incident and malware research"
    },
    {
      "id": "mandiant-apt44",
      "publisher": "Google Threat Intelligence Group",
      "title": "Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm",
      "published": "2024-04-17",
      "type": "threat research"
    },
    {
      "id": "microsoft-badpilot",
      "publisher": "Microsoft Threat Intelligence",
      "title": "The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation",
      "url": "https://www.microsoft.com/en-us/security/blog/2025/02/12/the-badpilot-campaign-seashell-blizzard-subgroup-conducts-multiyear-global-access-operation/",
      "published": "2025-02-12",
      "type": "threat research"
    },
    {
      "id": "eset-industroyer-whitepaper",
      "publisher": "ESET Research",
      "title": "Win32/Industroyer: A new threat for industrial control systems",
      "url": "https://www.welivesecurity.com/wp-content/uploads/2017/06/Win32_Industroyer.pdf",
      "published": "2017-06-12",
      "type": "incident and malware research"
    },
    {
      "id": "eset-exaramel-2018",
      "publisher": "ESET Research",
      "title": "New TeleBots backdoor: First evidence linking Industroyer to NotPetya",
      "url": "https://www.welivesecurity.com/2018/10/11/new-telebots-backdoor-linking-industroyer-notpetya/",
      "published": "2018-10-11",
      "type": "threat research"
    },
    {
      "id": "dragos-crashoverride-2018",
      "publisher": "Joe Slowik, Dragos (VB2018)",
      "title": "Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE",
      "url": "https://www.virusbulletin.com/uploads/pdf/magazine/2018/VB2018-Slowik.pdf",
      "published": "2018-10-04",
      "type": "incident analysis"
    },
    {
      "id": "certua-4435",
      "publisher": "CERT-UA",
      "title": "Cyberattack of Sandworm group on Ukrainian energy facilities (CERT-UA#4435)",
      "url": "https://cert.gov.ua/article/39518",
      "published": "2022-04-12",
      "type": "national CERT advisory"
    },
    {
      "id": "mandiant-microscada-2022",
      "publisher": "Mandiant / Google Cloud",
      "title": "Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology",
      "url": "https://cloud.google.com/blog/topics/threat-intelligence/sandworm-disrupts-power-ukraine-operational-technology",
      "published": "2023-11-09",
      "type": "incident response report"
    }
  ],
  "url": "/threat-actors/sandworm-team/",
  "artifacts": {
    "json": "/threat-actors/data/sandworm-team.json",
    "enterpriseNavigator": "/threat-actors/data/sandworm-team-enterprise-navigator.json",
    "icsNavigator": "/threat-actors/data/sandworm-team-ics-navigator.json"
  }
}
