ThreatBox · Threat Actor Attribution
Sandworm
a.k.a. Voodoo Bear, Iron Viking, TeleBots, GRU Unit 74455, Seashell Blizzard
Destructive espionage / Sabotage (state-sponsored) Russia (GRU Unit 74455) First seen 2009
Sandworm is Russia's most destructive GRU cyber unit, responsible for the two Ukraine power-grid blackouts (2015 BlackEnergy, 2016 Industroyer/CrashOverride) and the 2017 NotPetya wiper — the most damaging cyberattack in history (~$10B in global damage). Post-2022 they have run continuous destructive campaigns against Ukrainian civilian infrastructure (AcidRain wiper on Viasat, WhisperGate, HermeticWiper, CaddyWiper, Industroyer2). Considered the highest-tier ICS/OT adversary.
Targeted sectors
Energy gridGovernmentMediaFinancialUkraine infrastructure
Targeted regions
UkraineNATO countriesGlobal (NotPetya spread)
Known TTPs (4)
T1485Data Destruction (wipers)
T1195.002Supply Chain Compromise (M.E.Doc)
T0800ICS attacks (Industroyer)
T1078Valid Accounts
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2015-12Ukraine power grid attack #1 (BlackEnergy)
- 2016-12Ukraine power grid attack #2 (Industroyer)
- 2017-06NotPetya global outbreak via M.E.Doc supply chain
- 2022-02AcidRain wiper on Viasat KA-SAT modems (Ukraine invasion H-hour)
- 2022-04Industroyer2 attempt on Ukraine energy provider (thwarted)
References
End of dossier · Sandworm
Back to ThreatBox