Sandworm is a Russian state-sponsored threat actor associated with GRU Unit 74455 and widely tracked under aliases including IRIDIUM, APT44, Seashell Blizzard, Voodoo Bear, TeleBots, Iron Viking, Blue Echidna, PHANTOM, BE2, UAC-0113, and BlackEnergy Lite. It is one of Russia’s most disruptive cyber units and has been linked to espionage, sabotage, destructive attacks, and operations conducted in parallel with broader Russian military objectives. The group is best known for long-running operations against Ukraine, especially critical infrastructure and government-related targets. Its activity has included compromises of Ukrainian energy infrastructure, attacks on news media, local government and other public-sector entities, and intrusions affecting logistics and grain-sector organizations. Sandworm has also targeted digital infrastructure and public administration in Europe, and has been attributed in incidents affecting water utilities in the United States. Reported targeting extends to energy companies and critical infrastructure in Poland as well. Sandworm has used and developed multiple notable malware and destructive toolsets over time, including BlackEnergy, KillDisk, GreyEnergy, NotPetya, AcidRain, and ZEROLOT. BlackEnergy operations in Ukraine involved malicious documents with macros for initial compromise, use of the malware as a backdoor, and delivery of the destructive KillDisk component. KillDisk variants were used to destroy files, render systems unbootable, delete event logs, and in some cases target processes associated with industrial environments. GreyEnergy has been assessed as a successor framework to BlackEnergy, with a modular architecture, stealth-focused operations, selective module deployment, fileless execution, use of stolen code-signing certificates, and targeting of ICS-related systems and SCADA workstations. GreyEnergy has also been linked to an early NotPetya precursor. The actor has repeatedly demonstrated capability against operational technology and industrial control environments. It has been tied to the 2015 Ukrainian power-grid attack, later disruptive activity against Ukrainian energy infrastructure, and deployment of wipers through weaknesses in Active Directory Group Policy. Sandworm has also been associated with supply-chain compromise, most notably delivery of NotPetya through the ME/doc update mechanism, one of the most consequential software supply-chain attacks recorded. Operationally, Sandworm combines custom malware with pragmatic tradecraft. Reported techniques include spearphishing, exploitation of public-facing servers and unpatched vulnerabilities, webshell deployment, use of backdoored remote-access services for persistence, credential theft, internal proxying, lateral movement with administrative tools, reconnaissance with network-scanning utilities, and extensive living-off-the-land activity using native Windows tooling and PowerShell. The group has also shown strong defense-evasion discipline through selective payload deployment, secure wiping of components, and low-footprint post-compromise operations. Sandworm is assessed as a state-directed actor whose dominant purpose is espionage and strategic sabotage in support of Russian interests, with a particular emphasis on disruptive operations against Ukrainian and other critical infrastructure targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sandworm is known for conducting coordinated cyberattacks, including data-wiping malware campaigns, against Ukrainian critical infrastructure, often in tandem with Russian military strikes. Their operations target energy, logistics, government, and grain sectors to destabilize Ukraine's wartime economy.
Sandworm is a Russian state-linked threat actor known for targeting Ukrainian organizations using legitimate tools for cyberattacks.
Sandworm is a Russian military hacking unit known for disruptive cyberattacks, including power grid blackouts in Ukraine and the AcidRain malware attack on Viasat satellite modems. In this incident, they are suspected of breaching Ukrainian entities using living-off-the-land techniques and webshells, with minimal use of custom malware.
Sandworm is known for state-sponsored cyberattacks targeting critical infrastructure, particularly power grids, with the intent to cause physical disruption. They have been implicated in attacks on Ukraine's power grid.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.