Sandworm is a Russian state-sponsored threat actor widely attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), specifically Unit 74455. It is one of the most prominent and destructive cyber operators associated with Russia and has been linked to cyber sabotage, disruptive attacks, espionage, influence operations, and preparatory access activity in support of Russian military and geopolitical objectives. Common aliases include APT44, Seashell Blizzard, TeleBots, Electrum, Voodoo Bear, Iridium, Iron Viking, Blue Echidna, BlackEnergy, and Unit 74455. Reporting has also associated sub-clusters such as UAC-0113, UAC-0145, and BadPilot with Sandworm activity. Sandworm is best known for high-impact destructive and disruptive operations, particularly against Ukraine. The group has been linked to attacks on Ukrainian electric power infrastructure, including the 2015 power-grid attack and later industrial-control-focused activity involving Industroyer. It has also been associated with the compromise of Ukrainian software supply chains that enabled the NotPetya outbreak, one of the most consequential destructive malware incidents globally. Additional operations attributed to Sandworm include WhisperGate, CaddyWiper-related activity, Olympic Destroyer, attacks on satellite communications infrastructure at the outset of Russia’s full-scale invasion of Ukraine, and other campaigns involving wipers and disruptive malware timed to coincide with military operations or coercive state objectives. The actor consistently targets government, military, critical infrastructure, telecommunications, logistics, energy, and other strategically significant sectors, with a sustained emphasis on Ukrainian organizations and entities relevant to wartime command, communications, and civil resilience. Sandworm has also been tied to operations affecting Europe more broadly and to incidents with global spillover. Its activity reflects a pattern of using cyber operations not merely for access or collection, but to degrade availability, disrupt operations, create psychological pressure, and amplify broader state campaigns. Sandworm’s tradecraft spans spearphishing, supply-chain compromise, abuse of trusted software distribution, credential theft, living-off-the-land techniques, destructive malware deployment, and tailored tooling for persistence, reconnaissance, and lateral movement. The group has demonstrated capability against both enterprise IT and operational technology environments, including malware designed to interact with industrial control protocols. It has also used false personas and information operations in some campaigns, and has shown an ability to combine technical intrusion with strategic timing and narrative effects. Recent reporting indicates Sandworm has adapted its initial-access methods against Ukrainian targets by adopting ClickFix-style social engineering. In these campaigns, compromised websites present fake verification or CAPTCHA prompts that trick victims into executing malicious commands, leading to deployment of custom malware and follow-on tooling. Associated malware and tools reported in Sandworm-linked activity include BlackEnergy, Industroyer, KillDisk, NotPetya, WhisperGate, CaddyWiper, DynoWiper, FreakyPoll, GhettoVibe, ScoutCurl, FluidLeech, LoadLoop, and COWARDDUCK. The group has also used trojanized installers, messaging-app-based social engineering, and Android malware disguised as security software. Overall, Sandworm is assessed as a premier Russian offensive cyber unit specializing in disruptive and destructive operations aligned with GRU objectives. Its history, targeting, and operational tempo make it one of the clearest examples of cyber capability being used as an instrument of state power in support of military action, coercion, and strategic destabilization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
40 malware families attributed to this actor across reporting.
35 additional families tracked in Mallory.
27 CVEs this actor has used in observed campaigns. 27 of them exploited in the wild.
CVE-2014-6352 is a vulnerability that was the result of an insufficient fix for CVE-2014-4114, the vulnerability that was exploited by Sandworm.
As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.
Sandworm also has demonstrated an ability to get access to the latest exploits, he says, pointing to the group's use of the NSA-developed EternalBlue exploit during its NotPetya campaign.
Sandworm Team has exploited... Microsoft Word via crafted TIFF images (CVE-2013-3906).
To date, at least eight vulnerabilities... have been exploited by this subgroup: Microsoft Exchange (CVE-2021-34473)... We have observed web shells deployed following exploitation of vulnerabilities in Microsoft Exchange (CVE-2021-34473)...
22 more CVEs tied to this actor tracked in Mallory.
97 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the broader threat actor activity with which UAC-0145 is associated.
Referenced as the parent threat actor organization containing UAC-0145, which is attributed with the campaign targeting Ukrainian victims.
Russian GRU unit known for destructive attacks against Ukraine's energy sector and use of wipers.
Russian state-backed use of ClickFix social-engineering to compromise sensitive organizations in Ukraine, leading to at least one network compromise and deployment of FreakyPoll.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.