Skip to actor profile
activeTLP:CLEARHigh confidence

State-sponsored destructive threat group

Sandworm Team

A Russian GRU Unit 74455 threat group responsible for destructive global operations and multiple attacks that produced or attempted operational effects in Ukraine's electric grid.

Primary focus
Espionage, disruption, destructive operations and cyber-physical effects
State alignment
Russia
Microsoft family
Blizzard
Sandworm Team
2009
Publicly attributed OT disruption
2015
Last reviewed
2026-07-19

Designations

Aliases and related groups

The same activity is tracked under several vendor names. Each designation is listed separately below.

PrimaryHigh confidence

MITRE ATT&CK

Sandworm Team

G0034

The primary public group record used for this dossier.

SourcesMITRE ATT&CK

Note: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.

Key assessment

Key judgements

High confidence

Sandworm has demonstrated the full path from enterprise intrusion to deliberate physical-process disruption, combining patient access, legitimate operator functionality, purpose-built ICS malware and destructive recovery inhibition.

SourcesMITRE ATT&CKU.S. Department of JusticeESET Research
High confidence

BadPilot illustrates the access layer behind destructive capability: scalable perimeter exploitation and persistent access may precede a later high-impact operation by months or years.

SourcesMicrosoft Threat IntelligenceMITRE ATT&CK
High confidence

Sandworm's OT effect tooling is trending toward less code and faster deployment: a four-protocol framework in 2016, a single IEC-104 binary with hardcoded targets in 2022, then native SCADA functionality with no custom ICS malware in October 2022.

SourcesESET ResearchESET ResearchMandiant / Google Cloud
Medium confidence

Initial access is the least evidenced phase of the grid campaigns. Only 2015 has a confirmed vector (spearphishing with macro-bearing Office documents); 2016 is assessed as likely phishing, and neither 2022 intrusion has a publicly identified vector. Dossier claims about entry for those campaigns are inference, not confirmation.

SourcesJoe Slowik, Dragos (VB2018)CERT-UAMandiant / Google Cloud
Medium confidence

Dwell time between enterprise access and OT impact is measured in months: roughly six months in 2015, between two and eleven months in 2016, and around four months in October 2022, where Mandiant assessed the attacker may have held SCADA access for up to three months and developed the OT capability as late as three weeks before the outage.

SourcesJoe Slowik, Dragos (VB2018)Mandiant / Google CloudMITRE ATT&CK
High confidence

ESET's 2018 discovery of the Exaramel backdoor supplied the first code-level link between Industroyer and the TeleBots activity behind BlackEnergy and NotPetya, consolidating separate campaigns under one operator.

SourcesESET Research

Targeting

Regions, sectors and technology

Technology

Campaign chronology

Timeline

  1. December 2015High confidence

    Sandworm / associated Ukraine operation

    2015 Ukraine electric-power attack

    Spearphishing emails carrying macro-bearing Microsoft Office documents installed the BlackEnergy 3 toolkit at three electricity distribution companies. Months of enterprise access and credential harvesting culminated on 23 December in remote use of operator workstations to open breakers at roughly 30 substations, overwrite serial-to-Ethernet device firmware and inhibit recovery. This is the only grid campaign with a publicly confirmed initial access vector.

    Operational consequence: Approximately 225,000 customers lost power; operators restored service manually while call centers and remote control were disrupted.

    SourcesMITRE ATT&CKU.S. Department of JusticeCISA and partner agencies
  2. December 2016High confidence

    Sandworm / ELECTRUM overlap

    2016 Ukraine electric-power attack

    Industroyer/CrashOverride automated interaction with electric-grid protocols and issued commands to a transmission substation in Kyiv on 17 December. Initial access was never publicly confirmed; the intrusion may have begun with phishing as early as January 2016, with IT network access evidenced no later than October 2016. The attackers used valid accounts, living-off-the-land techniques, PsExec and Mimikatz to traverse the enterprise, pivoted into the ICS network via a likely dual-homed host, and reached Windows Server 2003 SQL Server systems assessed as data historians before reaching equipment-facing hosts.

    Operational consequence: Part of Kyiv lost power for roughly an hour, and the operation demonstrated reusable, protocol-aware ICS attack capability.

    SourcesMITRE ATT&CKU.S. Department of JusticeCISA and partner agenciesJoe Slowik, Dragos (VB2018)ESET Research
  3. June 2017High confidence

    GRU Unit 74455 attributed operation

    NotPetya

    A compromised M.E.Doc update distributed a destructive wiper disguised as ransomware, which propagated rapidly through enterprise networks.

    Operational consequence: Global collateral damage disrupted shipping, logistics, pharmaceuticals and other sectors; the U.S. indictment cites nearly one billion dollars in losses among three victims alone.

    SourcesU.S. Department of JusticeCISA and partner agenciesMITRE ATT&CK
  4. April 2022High confidence

    Sandworm

    Industroyer2 attempt

    A targeted IEC-104 payload built from the original Industroyer source was scheduled against Ukrainian high-voltage substations alongside Windows, Linux and Solaris wipers. Target IP addresses, ASDU addresses and information object addresses were hardcoded into the binary rather than read from a configuration file. CERT-UA reported the initial compromise occurred no later than February 2022; the entry vector was not identified publicly.

    Operational consequence: Defenders disrupted the attempt before the planned power interruption; the operation showed refined, target-specific ICS execution.

    SourcesESET ResearchCERT-UAMITRE ATT&CK
  5. October 2022High confidence

    Sandworm

    October 2022 MicroSCADA living-off-the-land outage

    No custom ICS malware was used. The attacker executed a native MicroSCADA binary, scilc.exe, from an ISO image mounted on the hypervisor hosting the victim's SCADA management instance, issuing commands that opened breakers. The intrusion began on or before June 2022, with SCADA access assessed as possibly held for up to three months and the OT capability potentially developed as late as three weeks before execution. Mandiant could not identify the initial access vector.

    Operational consequence: An unscheduled power outage at a Ukrainian substation, timed to coincide with Russian missile strikes on Ukrainian cities; CaddyWiper was deployed across the IT estate two days later to compound disruption and destroy forensic evidence.

    SourcesMandiant / Google Cloud
  6. Late 2021 onwardHigh confidence

    Seashell Blizzard access subgroup

    BadPilot global access operation

    A multiyear access campaign exploited perimeter products at scale, established persistence, harvested credentials and expanded from Ukraine to organisations across several continents.

    Operational consequence: Long-lived access provides espionage value and can establish the conditions for later destructive operations.

    SourcesMicrosoft Threat IntelligenceMITRE ATT&CK

Capabilities and malware

Capabilities and tooling

High confidenceSandworm / ELECTRUM overlap

Operate industrial processes through intended functionality

Use SCADA interfaces and protocol-valid commands to manipulate breakers and deny operator control.

SourcesMITRE ATT&CKESET Research
High confidenceSandworm / ELECTRUM overlap

Develop purpose-built ICS malware

Create reusable frameworks and target-specific payloads that communicate with electric-power equipment.

SourcesESET ResearchU.S. Department of Justice
High confidenceOctober 2022 Ukraine campaign

Cause OT impact with native platform tooling

Execute vendor-supplied SCADA binaries and scripting interfaces already present on control hosts, removing the need for custom ICS malware and shrinking the detectable footprint.

SourcesMandiant / Google Cloud
High confidenceUkraine electric-power campaigns

Pivot from enterprise IT into control networks

Traverse the corporate estate with valid accounts, credential dumping and living-off-the-land tooling, then cross into OT through dual-homed hosts, shared domain identity or remote access paths.

SourcesJoe Slowik, Dragos (VB2018)CISA and partner agencies
Medium confidenceSandworm

Sustain long pre-impact dwell in OT environments

Hold access for months while learning the process environment and equipment addressing, then build or configure an effect capability specific to the plant shortly before execution.

SourcesMandiant / Google CloudJoe Slowik, Dragos (VB2018)
High confidenceSeashell Blizzard access subgroup

Acquire persistent access at scale

Exploit exposed perimeter products, deploy web shells and remote tools, and collect credentials for later tasking.

SourcesMicrosoft Threat Intelligence

Sandworm-associated activity

High confidence

BlackEnergy 3 and KillDisk

Enterprise intrusion and destructive components used around the 2015 Ukraine power operation.

SourcesMITRE ATT&CKCISA and partner agencies

Sandworm / ELECTRUM overlap

High confidence

Industroyer / CrashOverride

A modular ICS framework with four protocol payloads (IEC-101, IEC-104, IEC-61850 and OPC DA), a main backdoor, a second backdoor hidden in a trojanised Notepad application and a wiper component, capable of automating operational disruption at substation equipment.

SourcesU.S. Department of JusticeCISA and partner agenciesESET Research

Sandworm / TeleBots overlap

High confidence

Exaramel

A backdoor whose code-level similarity to Industroyer's main backdoor gave the first public evidence tying Industroyer to the TeleBots group behind BlackEnergy and NotPetya.

SourcesESET Research

October 2022 Ukraine campaign

High confidence

scilc.exe (native MicroSCADA utility)

A legitimate vendor binary abused to run SCIL commands against substation equipment in October 2022, delivered via an ISO mounted on the SCADA host's hypervisor.

Scope caveat: Not attacker-authored. Detection must key on anomalous invocation of trusted platform tooling rather than file reputation.

SourcesMandiant / Google Cloud

Sandworm

High confidence

Industroyer2

A streamlined IEC-104 payload configured for a targeted 2022 attempt against Ukrainian substations.

SourcesESET Research

Sandworm

High confidence

CaddyWiper / ORCSHRED / SOLOSHRED / AWFULSHRED

Destructive payloads for Windows, Linux and Solaris coordinated with the Industroyer2 attempt, with CaddyWiper reused across the IT estate two days after the October 2022 outage to compound disruption and destroy forensic evidence.

SourcesESET ResearchMandiant / Google Cloud

Tactics, techniques and procedures

Mapped ATT&CK techniques

Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.

Enterprise ATT&CK

Enterprise access and manipulation

Download Navigator layer

ICS ATT&CK

ICS effects and access

Download Navigator layer

Indicator handling

Historical indicators

Historical, not current infrastructure.

This dossier prioritises durable behaviour over historical campaign infrastructure. Sandworm routinely changes access infrastructure and reuses legitimate services; point-in-time indicators should remain tied to the source campaign and collection date.

No point-in-time indicators published.

This profile intentionally prioritises sourced behaviour, access paths and operational context.

Source register

Sources

Publication and update dates preserve the point-in-time context used for this review.

  1. MITRE ATT&CKknowledge base

    Sandworm Team, Group G0034

    Published 31 May 2017 ยท Updated 4 December 2024

  2. U.S. Department of Justicegovernment attribution

    Six Russian GRU Officers Charged in Connection with Destructive Malware

    Published 19 October 2020

  3. CISA and partner agenciesgovernment advisory

    Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure

    Published 20 April 2022

  4. ESET Researchincident and malware research

    Industroyer2: Industroyer reloaded

    Published 12 April 2022

  5. Google Threat Intelligence Groupthreat research

    Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm

    Published 17 April 2024

  6. Microsoft Threat Intelligencethreat research

    The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation

    Published 12 February 2025

  7. ESET Researchincident and malware research

    Win32/Industroyer: A new threat for industrial control systems

    Published 12 June 2017

  8. ESET Researchthreat research

    New TeleBots backdoor: First evidence linking Industroyer to NotPetya

    Published 11 October 2018

  9. Joe Slowik, Dragos (VB2018)incident analysis

    Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE

    Published 4 October 2018

  10. CERT-UAnational CERT advisory

    Cyberattack of Sandworm group on Ukrainian energy facilities (CERT-UA#4435)

    Published 12 April 2022

  11. Mandiant / Google Cloudincident response report

    Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology

    Published 9 November 2023