Sandworm is a Russian state-sponsored threat actor widely linked to the GRU, most commonly identified with Unit 74455. It is one of the most prominent Russian offensive cyber operators and is known for combining espionage, disruptive, destructive, and cyber-physical operations in support of Russian strategic and military objectives, especially against Ukraine and other European targets. Common aliases include APT44, Sandworm Team, Seashell Blizzard, TeleBots, Electrum, IRIDIUM, Voodoo Bear, Blue Echidna, Iron Viking, Quedagh, BE2, BlackEnergy, and Unit 74455. Sandworm has a long record of high-impact operations against critical infrastructure, government, telecommunications, and private-sector organizations. It is strongly associated with attacks on the Ukrainian power sector, including the 2015 Ukraine Electric Power Attack, and with later wartime disruptive activity against Ukrainian energy and telecom environments. The group is also broadly associated with destructive malware and wiper operations, including activity tied to CaddyWiper and reporting that linked it to attempted deployment of DynoWiper in attacks on Polish power-grid organizations. Sandworm was also publicly tied to the Viasat KA-SAT satellite network attack at the outset of Russia’s full-scale invasion of Ukraine. The group is especially notorious for the 2017 NotPetya operation, a destructive supply-chain attack in which operators compromised the update mechanism of Ukrainian accounting software to distribute malware that masqueraded as ransomware but functioned as a wiper. That campaign caused massive global collateral damage and remains a canonical example of state-directed destructive cyber activity spilling far beyond the intended theater. Operationally, Sandworm is assessed as a mature GRU actor that integrates network intrusion, malware deployment, destructive effects, and influence or deception elements. Reporting characterizes it as a central Russian destructive cyber-physical actor, particularly in the Russia-Ukraine conflict. The group has been observed using techniques such as process injection, system information discovery, registry modification, and web-shell deployment, and has historically used malware families and tooling associated with BlackEnergy-era operations as well as later wipers and bespoke intrusion capabilities. Sandworm has also been linked to efforts to lower host defenses or alter system settings prior to payload execution, including registry-based changes during the 2015 Ukraine power attack. It has used backdoors to enumerate victim operating-system details and has demonstrated the ability to conduct coordinated attacks against operational technology and enterprise environments alike. Some reporting notes operational relationships between Sandworm and pro-Russian hacktivist or proxy ecosystems, including loose or indirect links to CyberArmy of Russia Reborn. Such relationships are best understood as adjacent or cooperative rather than evidence that those groups are synonymous with Sandworm itself. High-confidence attribution supports Sandworm as a GRU-linked actor centered on disruptive and destructive operations, with Ukraine and critical infrastructure remaining among its most significant target sets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
27 CVEs this actor has used in observed campaigns. 27 of them exploited in the wild.
CVE-2014-6352 is a vulnerability that was the result of an insufficient fix for CVE-2014-4114, the vulnerability that was exploited by Sandworm.
As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.
Sandworm also has demonstrated an ability to get access to the latest exploits, he says, pointing to the group's use of the NSA-developed EternalBlue exploit during its NotPetya campaign.
Sandworm Team has exploited... Microsoft Word via crafted TIFF images (CVE-2013-3906).
To date, at least eight vulnerabilities... have been exploited by this subgroup: Microsoft Exchange (CVE-2021-34473)... We have observed web shells deployed following exploitation of vulnerabilities in Microsoft Exchange (CVE-2021-34473)...
22 more CVEs tied to this actor tracked in Mallory.
64 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed with a cyberattack against Poland's power grid and attempted deployment of destructive wiper malware against operational technology environments.
Mentioned as a Russian military intelligence unit previously linked to wiper attacks and Ukrainian power disruptions, as background comparison for the Poland attribution.
Initially but incorrectly attributed by some cybersecurity firms to the Poland energy-grid attack before the activity was linked to an FSB cluster.
Groupe étatique russe mentionné comme étant indirectement associé à CyberArmy of Russia Reborn.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.