Sandworm is a Russian state-sponsored advanced persistent threat group widely attributed to the GRU, particularly Unit 74455. It is also tracked under aliases including APT44, Seashell Blizzard, Voodoo Bear, TeleBots, Electrum, Iridium, Iron Viking, Blue Echidna, BlackEnergy, and UAC-0113, though some of these names have also been used to describe overlapping clusters, sub-teams, or reporting-era linkages rather than a perfectly identical scope. Sandworm is best known for disruptive and destructive cyber operations, especially against Ukraine, including attacks on the Ukrainian power grid in 2015 and 2016 and later operations using destructive malware such as NotPetya, Olympic Destroyer, CaddyWiper, and Industroyer2. The group has repeatedly targeted critical infrastructure and operational technology environments, particularly electric-sector organizations, and has also conducted broader campaigns affecting government and other strategic sectors. Operational reporting has described Sandworm as using a multi-team structure in some intrusions, with access-focused elements and ICS-specialist components. KAMACITE has been assessed as an access team associated with Electrum/Sandworm activity, while TeleBots has been linked to Sandworm in destructive operations. The actor has demonstrated capability across the intrusion lifecycle, including spearphishing with malicious Office attachments for initial access, credential harvesting, browser-stored password theft through tools such as CredRaptor, keylogging, PowerShell-based in-memory execution, system and network discovery, lateral movement, and deployment of additional tooling after compromise. Sandworm has also used encoded and obfuscated command-and-control traffic, including Base64-based mechanisms, and malware capable of decoding, decrypting, and decompressing payload data. Beyond enterprise intrusions, Sandworm has operated large botnet infrastructure, including VPNFilter and its successor Cyclops Blink, compromising perimeter network devices and using them as command-and-control infrastructure. U.S. government actions have publicly disrupted these botnets. Sandworm’s history shows a strong emphasis on disruptive and destructive effects in support of Russian military and strategic objectives, particularly in wartime and coercive contexts, making espionage-supporting access and persistence subordinate to a broader mission of sabotage and operational impact.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
28 CVEs this actor has used in observed campaigns. 28 of them exploited in the wild.
CVE-2014-6352 • bypass the patch of CVE-2014-4114 used by Sandworm
As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.
Sandworm also has demonstrated an ability to get access to the latest exploits, he says, pointing to the group's use of the NSA-developed EternalBlue exploit during its NotPetya campaign.
Sandworm Team has exploited... Microsoft Word via crafted TIFF images (CVE-2013-3906).
To date, at least eight vulnerabilities... have been exploited by this subgroup: Microsoft Exchange (CVE-2021-34473)... We have observed web shells deployed following exploitation of vulnerabilities in Microsoft Exchange (CVE-2021-34473)...
23 more CVEs tied to this actor tracked in Mallory.
167 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of historical background on Russian cyber operations against Ukraine, including power grid attacks.
Mentioned as a separate state-sponsored actor using fake job offers to target system administrators and IT professionals in a different campaign.
Conducted a cyber campaign against Poland's energy infrastructure, including attacks on renewable energy facilities and a CHP plant, using novel OT intrusion techniques via a private APN to disrupt industrial processes and sabotage recovery.
Conducting a fake job interview campaign targeting IT professionals and system administrators, using recruiter impersonation, live video calls, and a trojanized WireGuard-based VPN client (SopraVPN) to gain access and deliver follow-on payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.