Sandworm is a Russian state-linked threat actor associated with GRU Unit 74455 and also tracked under names including Razing Ursa and Voodoo Bear. The group is known for disruptive and destructive cyber operations, particularly against critical infrastructure, communications technology, and high-visibility geopolitical or public-event targets. It has been publicly linked to the Olympic Destroyer attack that disrupted services during the 2018 Pyeongchang Winter Olympics, including connectivity and event-support systems, demonstrating a willingness to conduct sabotage operations timed for maximum public impact. The actor has also been linked to destructive Linux wiper malware including AcidRain and the newer AcidPour variant. These malware families are associated with data destruction and operational disruption across Linux-based and embedded environments, including network devices, storage systems, and industrial-control-related platforms. Reported Sandworm-linked tooling and tradecraft indicate a focus on destructive post-compromise effects rather than purely covert collection. Sandworm is widely regarded as a Russian military intelligence actor whose operations align with Russian state interests. Its activity profile includes destructive attacks, post-exploitation in Linux environments, and targeting that can affect government, communications, and infrastructure-dependent organizations. Known aliases include Razing Ursa and Voodoo Bear, and the group is associated with GRU Unit 74455.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian state-linked actor attributed with destructive Olympic-related operations including Olympic Destroyer and later reconnaissance/disruption activity around Tokyo 2020/21.
Razing Ursa is a Russian threat actor known for deploying destructive wiper malware (AcidRain, AcidPour) against infrastructure, including modems, routers, storage arrays, and industrial control systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.