Back to ThreatBox
ThreatBox · Threat Actor Attribution

Sandworm

a.k.a. Voodoo Bear, Iron Viking, TeleBots, GRU Unit 74455, Seashell Blizzard
Destructive espionage / Sabotage (state-sponsored) Russia (GRU Unit 74455) First seen 2009

Sandworm is Russia's most destructive GRU cyber unit, responsible for the two Ukraine power-grid blackouts (2015 BlackEnergy, 2016 Industroyer/CrashOverride) and the 2017 NotPetya wiper — the most damaging cyberattack in history (~$10B in global damage). Post-2022 they have run continuous destructive campaigns against Ukrainian civilian infrastructure (AcidRain wiper on Viasat, WhisperGate, HermeticWiper, CaddyWiper, Industroyer2). Considered the highest-tier ICS/OT adversary.

Targeted sectors
Energy gridGovernmentMediaFinancialUkraine infrastructure
Targeted regions
UkraineNATO countriesGlobal (NotPetya spread)

Known TTPs (4)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2015-12
    Ukraine power grid attack #1 (BlackEnergy)
  2. 2016-12
    Ukraine power grid attack #2 (Industroyer)
  3. 2017-06
    NotPetya global outbreak via M.E.Doc supply chain
  4. 2022-02
    AcidRain wiper on Viasat KA-SAT modems (Ukraine invasion H-hour)
  5. 2022-04
    Industroyer2 attempt on Ukraine energy provider (thwarted)

References

End of dossier · Sandworm
Back to ThreatBox

Made with Emergent