State-sponsored destructive threat group
Sandworm Team
A Russian GRU Unit 74455 threat group responsible for destructive global operations and multiple attacks that produced or attempted operational effects in Ukraine's electric grid.
- Primary focus
- Espionage, disruption, destructive operations and cyber-physical effects
- State alignment
- Russia
- Microsoft family
- Blizzard
- Sandworm Team
- 2009
- Publicly attributed OT disruption
- 2015
- Last reviewed
- 2026-07-19
Designations
Aliases and related groups
The same activity is tracked under several vendor names. Each designation is listed separately below.
MITRE ATT&CK
Sandworm Team
G0034
The primary public group record used for this dossier.
SourcesMITRE ATT&CKNote: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.
Key assessment
Key judgements
Sandworm has demonstrated the full path from enterprise intrusion to deliberate physical-process disruption, combining patient access, legitimate operator functionality, purpose-built ICS malware and destructive recovery inhibition.
SourcesMITRE ATT&CKU.S. Department of JusticeESET ResearchThe group's operations are global, but Ukraine remains the central proving ground for electric-grid attacks, wipers and operationally coordinated cyber activity supporting Russian military objectives.
SourcesGoogle Threat Intelligence GroupCISA and partner agenciesU.S. Department of JusticeBadPilot illustrates the access layer behind destructive capability: scalable perimeter exploitation and persistent access may precede a later high-impact operation by months or years.
SourcesMicrosoft Threat IntelligenceMITRE ATT&CKSandworm's OT effect tooling is trending toward less code and faster deployment: a four-protocol framework in 2016, a single IEC-104 binary with hardcoded targets in 2022, then native SCADA functionality with no custom ICS malware in October 2022.
SourcesESET ResearchESET ResearchMandiant / Google CloudInitial access is the least evidenced phase of the grid campaigns. Only 2015 has a confirmed vector (spearphishing with macro-bearing Office documents); 2016 is assessed as likely phishing, and neither 2022 intrusion has a publicly identified vector. Dossier claims about entry for those campaigns are inference, not confirmation.
SourcesJoe Slowik, Dragos (VB2018)CERT-UAMandiant / Google CloudEvery documented grid intrusion entered through the enterprise IT estate and worked toward OT, typically via dual-homed hosts, shared Active Directory identity or remote access paths. The IT-to-OT pivot, not the PLC or RTU, is the decisive detection point.
SourcesJoe Slowik, Dragos (VB2018)CISA and partner agenciesMandiant / Google CloudDwell time between enterprise access and OT impact is measured in months: roughly six months in 2015, between two and eleven months in 2016, and around four months in October 2022, where Mandiant assessed the attacker may have held SCADA access for up to three months and developed the OT capability as late as three weeks before the outage.
SourcesJoe Slowik, Dragos (VB2018)Mandiant / Google CloudMITRE ATT&CKESET's 2018 discovery of the Exaramel backdoor supplied the first code-level link between Industroyer and the TeleBots activity behind BlackEnergy and NotPetya, consolidating separate campaigns under one operator.
SourcesESET ResearchTargeting
Regions, sectors and technology
Regions
- UkraineSourcesMITRE ATT&CKGoogle Threat Intelligence GroupCISA and partner agencies
- Europe and NATO member statesSourcesCISA and partner agenciesMicrosoft Threat Intelligence
- United States, Canada and AustraliaSourcesMicrosoft Threat Intelligence
- Global organisations tied to Russian strategic interestsSourcesGoogle Threat Intelligence GroupU.S. Department of Justice
Sectors
- Electric power and energySourcesMITRE ATT&CKCISA and partner agenciesESET Research
- Government and defenceSourcesU.S. Department of JusticeGoogle Threat Intelligence Group
- TelecommunicationsSourcesMicrosoft Threat IntelligenceGoogle Threat Intelligence Group
- Transportation, logistics and manufacturingSourcesU.S. Department of JusticeCISA and partner agencies
- Technology and managed infrastructureSourcesMicrosoft Threat Intelligence
Technology
- Electric substation SCADA and IEC-104 systemsSourcesMITRE ATT&CKESET Research
- Microsoft Exchange, Outlook and enterprise perimeter serversSourcesMicrosoft Threat Intelligence
- Fortinet, Zimbra, OpenFire, TeamCity and ScreenConnectSourcesMicrosoft Threat Intelligence
- Windows, Linux and Solaris infrastructureSourcesESET ResearchMITRE ATT&CK
- Hitachi Energy MicroSCADA control platforms and their native utilitiesSourcesMandiant / Google Cloud
- Hypervisors hosting SCADA management virtual machinesSourcesMandiant / Google Cloud
- Dual-homed historians and engineering workstations bridging IT and OTSourcesJoe Slowik, Dragos (VB2018)
Campaign chronology
Timeline
- December 2015High confidence
Sandworm / associated Ukraine operation
2015 Ukraine electric-power attack
Spearphishing emails carrying macro-bearing Microsoft Office documents installed the BlackEnergy 3 toolkit at three electricity distribution companies. Months of enterprise access and credential harvesting culminated on 23 December in remote use of operator workstations to open breakers at roughly 30 substations, overwrite serial-to-Ethernet device firmware and inhibit recovery. This is the only grid campaign with a publicly confirmed initial access vector.
Operational consequence: Approximately 225,000 customers lost power; operators restored service manually while call centers and remote control were disrupted.
SourcesMITRE ATT&CKU.S. Department of JusticeCISA and partner agencies - December 2016High confidence
Sandworm / ELECTRUM overlap
2016 Ukraine electric-power attack
Industroyer/CrashOverride automated interaction with electric-grid protocols and issued commands to a transmission substation in Kyiv on 17 December. Initial access was never publicly confirmed; the intrusion may have begun with phishing as early as January 2016, with IT network access evidenced no later than October 2016. The attackers used valid accounts, living-off-the-land techniques, PsExec and Mimikatz to traverse the enterprise, pivoted into the ICS network via a likely dual-homed host, and reached Windows Server 2003 SQL Server systems assessed as data historians before reaching equipment-facing hosts.
Operational consequence: Part of Kyiv lost power for roughly an hour, and the operation demonstrated reusable, protocol-aware ICS attack capability.
SourcesMITRE ATT&CKU.S. Department of JusticeCISA and partner agenciesJoe Slowik, Dragos (VB2018)ESET Research - June 2017High confidence
GRU Unit 74455 attributed operation
NotPetya
A compromised M.E.Doc update distributed a destructive wiper disguised as ransomware, which propagated rapidly through enterprise networks.
Operational consequence: Global collateral damage disrupted shipping, logistics, pharmaceuticals and other sectors; the U.S. indictment cites nearly one billion dollars in losses among three victims alone.
SourcesU.S. Department of JusticeCISA and partner agenciesMITRE ATT&CK - April 2022High confidence
Sandworm
Industroyer2 attempt
A targeted IEC-104 payload built from the original Industroyer source was scheduled against Ukrainian high-voltage substations alongside Windows, Linux and Solaris wipers. Target IP addresses, ASDU addresses and information object addresses were hardcoded into the binary rather than read from a configuration file. CERT-UA reported the initial compromise occurred no later than February 2022; the entry vector was not identified publicly.
Operational consequence: Defenders disrupted the attempt before the planned power interruption; the operation showed refined, target-specific ICS execution.
SourcesESET ResearchCERT-UAMITRE ATT&CK - October 2022High confidence
Sandworm
October 2022 MicroSCADA living-off-the-land outage
No custom ICS malware was used. The attacker executed a native MicroSCADA binary, scilc.exe, from an ISO image mounted on the hypervisor hosting the victim's SCADA management instance, issuing commands that opened breakers. The intrusion began on or before June 2022, with SCADA access assessed as possibly held for up to three months and the OT capability potentially developed as late as three weeks before execution. Mandiant could not identify the initial access vector.
Operational consequence: An unscheduled power outage at a Ukrainian substation, timed to coincide with Russian missile strikes on Ukrainian cities; CaddyWiper was deployed across the IT estate two days later to compound disruption and destroy forensic evidence.
SourcesMandiant / Google Cloud - Late 2021 onwardHigh confidence
Seashell Blizzard access subgroup
BadPilot global access operation
A multiyear access campaign exploited perimeter products at scale, established persistence, harvested credentials and expanded from Ukraine to organisations across several continents.
Operational consequence: Long-lived access provides espionage value and can establish the conditions for later destructive operations.
SourcesMicrosoft Threat IntelligenceMITRE ATT&CK
Capabilities and malware
Capabilities and tooling
Operate industrial processes through intended functionality
Use SCADA interfaces and protocol-valid commands to manipulate breakers and deny operator control.
SourcesMITRE ATT&CKESET ResearchDevelop purpose-built ICS malware
Create reusable frameworks and target-specific payloads that communicate with electric-power equipment.
SourcesESET ResearchU.S. Department of JusticeDestroy enterprise and recovery infrastructure
Deploy wipers, modify firmware, disable tooling and coordinate data destruction with operational effects.
SourcesU.S. Department of JusticeCISA and partner agenciesESET ResearchCause OT impact with native platform tooling
Execute vendor-supplied SCADA binaries and scripting interfaces already present on control hosts, removing the need for custom ICS malware and shrinking the detectable footprint.
SourcesMandiant / Google CloudPivot from enterprise IT into control networks
Traverse the corporate estate with valid accounts, credential dumping and living-off-the-land tooling, then cross into OT through dual-homed hosts, shared domain identity or remote access paths.
SourcesJoe Slowik, Dragos (VB2018)CISA and partner agenciesSustain long pre-impact dwell in OT environments
Hold access for months while learning the process environment and equipment addressing, then build or configure an effect capability specific to the plant shortly before execution.
SourcesMandiant / Google CloudJoe Slowik, Dragos (VB2018)Acquire persistent access at scale
Exploit exposed perimeter products, deploy web shells and remote tools, and collect credentials for later tasking.
SourcesMicrosoft Threat IntelligenceSandworm-associated activity
High confidenceBlackEnergy 3 and KillDisk
Enterprise intrusion and destructive components used around the 2015 Ukraine power operation.
SourcesMITRE ATT&CKCISA and partner agenciesSandworm / ELECTRUM overlap
High confidenceIndustroyer / CrashOverride
A modular ICS framework with four protocol payloads (IEC-101, IEC-104, IEC-61850 and OPC DA), a main backdoor, a second backdoor hidden in a trojanised Notepad application and a wiper component, capable of automating operational disruption at substation equipment.
SourcesU.S. Department of JusticeCISA and partner agenciesESET ResearchSandworm / TeleBots overlap
High confidenceExaramel
A backdoor whose code-level similarity to Industroyer's main backdoor gave the first public evidence tying Industroyer to the TeleBots group behind BlackEnergy and NotPetya.
SourcesESET ResearchOctober 2022 Ukraine campaign
High confidencescilc.exe (native MicroSCADA utility)
A legitimate vendor binary abused to run SCIL commands against substation equipment in October 2022, delivered via an ISO mounted on the SCADA host's hypervisor.
Scope caveat: Not attacker-authored. Detection must key on anomalous invocation of trusted platform tooling rather than file reputation.
SourcesMandiant / Google CloudGRU Unit 74455 attributed operation
High confidenceNotPetya
A destructive wiper masquerading as ransomware that spread globally from a compromised Ukrainian software update.
SourcesU.S. Department of JusticeCISA and partner agenciesSandworm
High confidenceIndustroyer2
A streamlined IEC-104 payload configured for a targeted 2022 attempt against Ukrainian substations.
SourcesESET ResearchSandworm
High confidenceCaddyWiper / ORCSHRED / SOLOSHRED / AWFULSHRED
Destructive payloads for Windows, Linux and Solaris coordinated with the Industroyer2 attempt, with CaddyWiper reused across the IT estate two days after the October 2022 outage to compound disruption and destroy forensic evidence.
SourcesESET ResearchMandiant / Google CloudTactics, techniques and procedures
Mapped ATT&CK techniques
Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.
Enterprise ATT&CK
Enterprise access and manipulation
-
T1566.001Phishing: Spearphishing AttachmentMalicious Office and archive attachments established footholds, including in the 2015 power campaign. Lures are tailored to the recipient's role and to current events, and the 2020 indictment records the same pattern against election, Olympic, Novichok-investigation and Georgian government targets.
High confidenceSourcesMITRE ATT&CKU.S. Department of Justice -
T1204.002User Execution: Malicious FileRecipients opened weaponised Word documents and enabled macros, which downloaded and installed the BlackEnergy 3 backdoor.
High confidenceSourcesMITRE ATT&CKCISA and partner agencies -
T1078Valid AccountsHarvested credentials were reused for months of low-signal movement through the enterprise estate and for reaching systems bridging IT and OT.
High confidenceSourcesJoe Slowik, Dragos (VB2018)MITRE ATT&CK -
T1003OS Credential DumpingMimikatz and comparable tooling harvested credentials to expand access toward control-network paths.
High confidenceSourcesJoe Slowik, Dragos (VB2018) -
T1569.002System Services: Service ExecutionPsExec and similar administrative utilities executed payloads remotely, keeping activity within expected administrative behaviour.
High confidenceSourcesJoe Slowik, Dragos (VB2018) -
T1059.001Command and Scripting Interpreter: PowerShellPowerShell supported credential harvesting, deployment and destructive tooling.
High confidenceSourcesMITRE ATT&CK -
T1021.002Remote Services: SMB/Windows Admin SharesAdministrative shares and remote services moved payloads through enterprise networks.
High confidenceSourcesMITRE ATT&CK -
T1485Data DestructionNotPetya and coordinated wipers rendered systems and recovery infrastructure inoperable.
High confidenceSourcesMITRE ATT&CKU.S. Department of JusticeESET Research -
T1190Exploit Public-Facing ApplicationBadPilot exploited multiple enterprise perimeter products to establish scalable, persistent access.
High confidenceSourcesMicrosoft Threat Intelligence
ICS ATT&CK
ICS effects and access
-
T0822External Remote ServicesValid accounts and remote services provided access to operator and control environments.
High confidenceSourcesMITRE ATT&CK -
T0823Graphical User InterfaceAttackers operated SCADA/HMI interfaces to issue breaker commands during the 2015 attack.
High confidenceSourcesMITRE ATT&CK -
T0805Block Serial COMFirmware on serial-to-Ethernet converters was overwritten to sever downstream communications.
High confidenceSourcesMITRE ATT&CK -
T0853ScriptingA native MicroSCADA utility ran attacker-supplied SCIL commands from an ISO mounted on the hosting hypervisor, achieving process impact without custom ICS malware.
High confidenceSourcesMandiant / Google Cloud -
T0812Default CredentialsWeak boundaries between enterprise and control identity, including shared domain accounts and flat segmentation, eased the pivot into process networks.
Medium confidenceSourcesJoe Slowik, Dragos (VB2018)CISA and partner agencies -
T0809Data DestructionWipers were deployed after or alongside process impact to obstruct recovery and destroy forensic evidence, including CaddyWiper two days after the October 2022 outage.
High confidenceSourcesMandiant / Google CloudESET Research -
T0855Unauthorized Command MessageProtocol-valid commands were issued to electric substation equipment.
High confidenceSourcesMITRE ATT&CKESET Research -
T0813Denial of ControlDevice and communication sabotage denied operators reliable downstream control.
High confidenceSourcesMITRE ATT&CK -
T0826Loss of AvailabilityBreaker operations and destructive actions interrupted electric service and system availability.
High confidenceSourcesMITRE ATT&CK -
T0827Loss of ControlOperators lost remote control and relied on manual restoration procedures.
High confidenceSourcesMITRE ATT&CK -
T0831Manipulation of ControlBreaker states and operational commands were deliberately altered to disrupt the grid.
High confidenceSourcesMITRE ATT&CKESET Research
Indicator handling
Historical indicators
This dossier prioritises durable behaviour over historical campaign infrastructure. Sandworm routinely changes access infrastructure and reuses legitimate services; point-in-time indicators should remain tied to the source campaign and collection date.
This profile intentionally prioritises sourced behaviour, access paths and operational context.
Source register
Sources
Publication and update dates preserve the point-in-time context used for this review.
- MITRE ATT&CKknowledge base
Sandworm Team, Group G0034
Published 31 May 2017 ยท Updated 4 December 2024
- U.S. Department of Justicegovernment attribution
Six Russian GRU Officers Charged in Connection with Destructive Malware
Published 19 October 2020
- CISA and partner agenciesgovernment advisory
Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
Published 20 April 2022
- ESET Researchincident and malware research
Industroyer2: Industroyer reloaded
Published 12 April 2022
- Google Threat Intelligence Groupthreat research
Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm
Published 17 April 2024
- Microsoft Threat Intelligencethreat research
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation
Published 12 February 2025
- ESET Researchincident and malware research
Win32/Industroyer: A new threat for industrial control systems
Published 12 June 2017
- ESET Researchthreat research
New TeleBots backdoor: First evidence linking Industroyer to NotPetya
Published 11 October 2018
- Joe Slowik, Dragos (VB2018)incident analysis
Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE
Published 4 October 2018
- CERT-UAnational CERT advisory
Cyberattack of Sandworm group on Ukrainian energy facilities (CERT-UA#4435)
Published 12 April 2022
- Mandiant / Google Cloudincident response report
Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology
Published 9 November 2023