Overview
Sandworm Team (MITRE ATT&CK ID G0034) is a destructive threat group MITRE ATT&CK attributes to Russia’s General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST), military unit 74455, active since at least 2009. In October 2020, per MITRE’s documentation, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against Georgia in 2018-2019. MITRE notes some of these operations were conducted with the assistance of GRU Unit 26165, tracked separately as APT28.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested data links Sandworm Team to some of the most consequential malware in MITRE’s knowledge base by real-world impact: NotPetya, BlackEnergy, Industroyer and Industroyer2, Olympic Destroyer, KillDisk, Bad Rabbit, Cyclops Blink, VPNFilter, AcidRain, AcidPour, Prestige, and Kapeka — alongside GreyEnergy, Exaramel for Windows/Linux, and dual-use tools Cobalt Strike, Mimikatz, and Empire.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to Sandworm Team in our data include Acquire Infrastructure (T1583), Botnet (T1584.005), Business Relationships (T1591.002), Compromise Software Supply Chain (T1195.002), Credentials from Web Browsers (T1555.003), and Data Destruction (T1485) — the last a signature of the group’s documented history of destructive, not just espionage-focused, operations.
Related campaigns
Per MITRE ATT&CK’s relationship data, Sandworm Team is linked to the 2015, 2016, and 2022 Ukraine Electric Power Attack campaigns — a documented, repeated targeting of the same critical-infrastructure sector across multiple years.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2009” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What is Sandworm Team? A destructive Russian GRU-attributed threat group (military unit 74455), per MITRE ATT&CK, linked to the 2015-16 Ukrainian power-grid attacks and the 2017 NotPetya worm.
Is Sandworm Team the same as APT28? No — MITRE ATT&CK tracks them as separate groups (GRU units 74455 and 26165 respectively), though MITRE’s documentation notes some operations were conducted jointly.
What malware is Sandworm Team linked to? Per MITRE ATT&CK’s relationship data: NotPetya, BlackEnergy, Industroyer/Industroyer2, Olympic Destroyer, Cyclops Blink, VPNFilter, and AcidRain, among others.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0034, aggregated August 31, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.