Sandworm, also tracked as APT44 and Seashell Blizzard, is a Russian GRU-linked threat actor associated with Military Unit 74455. Active since at least 2013, it has conducted disruptive and destructive cyber operations against governments, critical infrastructure, and energy-sector organizations, with particularly prominent operations against Ukraine and Western targets. The group has been associated with malware including KillDisk, FoxBlade, NotPetya, and Prestige. Sandworm has targeted exposed and misconfigured network-edge infrastructure, harvested credentials from intercepted traffic, and used acquired access for lateral movement and persistence. Its operations have included intelligence collection as well as destructive activity affecting Windows-based operational-technology environments, industrial control devices, and remote-management capabilities. Sandworm has been linked to major attacks including Ukraine power-grid incidents, NotPetya, the 2018 Winter Olympics disruption, and targeting connected with French electoral activity. Reports of a separate self-propagating supply-chain worm called “Mini Shai-Hulud” using the name Sandworm are not sufficient to establish it as the same entity as the GRU-linked actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group deployed a specialized malware variant designated as the “Sandworm” (Mini Shai-Hulud). This particular malware functions as a virulent worm, possessing self-replication and propagation capabilities.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-replicating supply-chain worm reportedly used to poison the npm ecosystem and propagate through infected developer environments and packages.
GRU-linked offensive cyber capability described here as deploying destructive wiper malware against Poland’s energy grid to cause physical disruption.
Russian GRU-linked hacking group associated with Unit 74455 and destructive cyber-attacks including against Ukraine’s power grid and other high-profile targets.
Named Russia-linked activity clusters are referenced for attribution overlap; the content does not name any specific malware family/tool used by these actors beyond generic 'custom wipers' and destructive scripts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.