Skip to main content
QUIETLYTIC
Threat Actor

Sandworm Team

Destructive threat group attributed by MITRE ATT&CK to Russia's GRU military unit 74455, active since at least 2009 and linked to Ukrainian power-grid attacks and the 2017 NotPetya worm.

Threat Level
CRITICAL
Attribution
Russian GRU Main Center for Special Technologies (GTsST), military unit 74455 — per US indictment cited in MITRE ATT&CK's group profile
Also Known As
ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44
Targets
Ukrainian electrical companies and government organizations, 2017 French presidential campaign, 2018 Winter Olympic Games (Olympic Destroyer)

Overview

Sandworm Team (MITRE ATT&CK ID G0034) is a destructive threat group MITRE ATT&CK attributes to Russia’s General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST), military unit 74455, active since at least 2009. In October 2020, per MITRE’s documentation, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against Georgia in 2018-2019. MITRE notes some of these operations were conducted with the assistance of GRU Unit 26165, tracked separately as APT28.

Known tools and malware (per MITRE ATT&CK relationship data)

Our ingested data links Sandworm Team to some of the most consequential malware in MITRE’s knowledge base by real-world impact: NotPetya, BlackEnergy, Industroyer and Industroyer2, Olympic Destroyer, KillDisk, Bad Rabbit, Cyclops Blink, VPNFilter, AcidRain, AcidPour, Prestige, and Kapeka — alongside GreyEnergy, Exaramel for Windows/Linux, and dual-use tools Cobalt Strike, Mimikatz, and Empire.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to Sandworm Team in our data include Acquire Infrastructure (T1583), Botnet (T1584.005), Business Relationships (T1591.002), Compromise Software Supply Chain (T1195.002), Credentials from Web Browsers (T1555.003), and Data Destruction (T1485) — the last a signature of the group’s documented history of destructive, not just espionage-focused, operations.

Per MITRE ATT&CK’s relationship data, Sandworm Team is linked to the 2015, 2016, and 2022 Ukraine Electric Power Attack campaigns — a documented, repeated targeting of the same critical-infrastructure sector across multiple years.

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2009” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What is Sandworm Team? A destructive Russian GRU-attributed threat group (military unit 74455), per MITRE ATT&CK, linked to the 2015-16 Ukrainian power-grid attacks and the 2017 NotPetya worm.

Is Sandworm Team the same as APT28? No — MITRE ATT&CK tracks them as separate groups (GRU units 74455 and 26165 respectively), though MITRE’s documentation notes some operations were conducted jointly.

What malware is Sandworm Team linked to? Per MITRE ATT&CK’s relationship data: NotPetya, BlackEnergy, Industroyer/Industroyer2, Olympic Destroyer, Cyclops Blink, VPNFilter, and AcidRain, among others.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0034, aggregated August 31, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools