LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

EnterpriseG0034GroupObject v4.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0034: Sandworm Team describes [Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC S...

Executive priority

G0034: Sandworm Team is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0034: Sandworm Team by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0034: Sandworm Team appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

57 rows
DomainIDNameRelationship / procedure
EnterpriseT1608.001Upload MalwareSub-technique

Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user.[8]

EnterpriseT1588.006VulnerabilitiesSub-technique

In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport.[1]

EnterpriseT1040Network Sniffing

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.CitationESET Telebots Dec 2016

EnterpriseT1027.010Command ObfuscationSub-technique

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.CitationESET Telebots Dec 2016

EnterpriseT1595.002Vulnerability ScanningSub-technique

Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning.[1]

EnterpriseT1585.001Social Media AccountsSub-technique

Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data.[1]

EnterpriseT1586.001Social Media AccountsSub-technique

Sandworm Team creates credential capture webpages to compromise existing, legitimate social media accounts.CitationSlowik Sandworm 2021

EnterpriseT1132.001Standard EncodingSub-technique

Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server.CitationESET Telebots Dec 2016

EnterpriseT1213.006DatabasesSub-technique

Sandworm Team exfiltrates data of interest from enterprise databases using Adminer.[10]

EnterpriseT1539Steal Web Session Cookie

Sandworm Team used information stealer malware to collect browser session cookies.[10]

EnterpriseT1059.001PowerShellSub-technique

Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.[1]CitationDragos Crashoverride 2018

EnterpriseT1090Proxy

Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally.CitationESET Telebots Dec 2016

EnterpriseT1203Exploitation for Client Execution

Sandworm Team has exploited vulnerabilities in Microsoft PowerPoint via OLE objects (CVE-2014-4114) and Microsoft Word via crafted TIFF images (CVE-2013-3906).CitationiSight Sandworm Oct 2014CitationTrendMicro Sandworm October 2014CitationMcAfee Sandworm November 2013

EnterpriseT1041Exfiltration Over C2 Channel

Sandworm Team has sent system information to its C2 server using HTTP.CitationESET Telebots Dec 2016

EnterpriseT1053.005Scheduled TaskSub-technique

Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines.[8]

EnterpriseT1190Exploit Public-Facing Application

Sandworm Team exploits public-facing applications for initial access and to acquire infrastructure, such as exploitation of the EXIM mail transfer agent in Linux systems.CitationNSA Sandworm 2020[10]

EnterpriseT1078.002Domain AccountsSub-technique

Sandworm Team has used stolen credentials to access administrative accounts within the domain.[1][11]

EnterpriseT1003.003NTDSSub-technique

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.[11]

EnterpriseT1036Masquerading

Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries.[10]

EnterpriseT1598.003Spearphishing LinkSub-technique

Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials.[1]

EnterpriseT1133External Remote Services

Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users.CitationESET BlackEnergy Jan 2016CitationESET Telebots June 2017CitationANSSI Sandworm January 2021[8]

EnterpriseT1587.001MalwareSub-technique

Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.[1]

EnterpriseT1072Software Deployment Tools

Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution.[11]

EnterpriseT1584.005BotnetSub-technique

Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.CitationNCSC Cyclops Blink February 2022

EnterpriseT1566.002Spearphishing LinkSub-technique

Sandworm Team has crafted phishing emails containing malicious hyperlinks.[1]

EnterpriseT1018Remote System Discovery

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD.CitationESET Telebots Dec 2016CitationDragos Crashoverride 2018

EnterpriseT1589.003Employee NamesSub-technique

Sandworm Team's research of potential victim organizations included the identification and collection of employee information.[1]

EnterpriseT1078Valid Accounts

Sandworm Team have used previously acquired legitimate credentials prior to attacks.CitationUS-CERT Ukraine Feb 2016

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.CitationiSight Sandworm Oct 2014CitationUS-CERT Ukraine Feb 2016CitationESET Telebots Dec 2016[1]CitationGoogle_WinRAR_vuln_2023[8]

EnterpriseT1204.002Malicious FileSub-technique

Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files.CitationESET Telebots Dec 2016[1]

EnterpriseT1106Native API

Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`.[11]

EnterpriseT1588.002ToolSub-technique

Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations.[1][11] Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2.[8]

EnterpriseT1583.004ServerSub-technique

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.[1]

EnterpriseT1590.001Domain PropertiesSub-technique

Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack.[1]

EnterpriseT1083File and Directory Discovery

Sandworm Team has enumerated files on a compromised host.[1]CitationDragos Crashoverride 2018

EnterpriseT1049System Network Connections Discovery

Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured.[1]CitationDragos Crashoverride 2018

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.CitationESET Telebots Dec 2016

EnterpriseT1489Service Stop

Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files.[11]

EnterpriseT1571Non-Standard Port

Sandworm Team has used port 6789 to accept connections on the group's SSH server.CitationESET BlackEnergy Jan 2016

EnterpriseT1070.004File DeletionSub-technique

Sandworm Team has used backdoors that can delete files used in an attack from an infected system.CitationESET Telebots Dec 2016CitationESET Telebots July 2017CitationMandiant-Sandworm-Ukraine-2022

EnterpriseT1047Windows Management Instrumentation

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.CitationDragos Crashoverride 2018[11]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run net use to connect to network shares.CitationDragos Crashoverride 2018[11]

EnterpriseT1204.001Malicious LinkSub-technique

Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.[1]

EnterpriseT1505.003Web ShellSub-technique

Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks.CitationANSSI Sandworm January 2021

EnterpriseT1218.011Rundll32Sub-technique

Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe.CitationESET Telebots July 2017

EnterpriseT1499Endpoint Denial of Service

Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019.[1]

EnterpriseT1195.002Compromise Software Supply ChainSub-technique

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.CitationSecureworks NotPetya June 2017CitationESET Telebots June 2017[1]

EnterpriseT1199Trusted Relationship

Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization.[1] Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity.[8]

EnterpriseT1056.001KeyloggingSub-technique

Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function.CitationESET Telebots Dec 2016

EnterpriseT1561.002Disk Structure WipeSub-technique

Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.CitationUS-CERT Ukraine Feb 2016CitationESET Telebots June 2017

EnterpriseT1486Data Encrypted for Impact

Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland.[11]

EnterpriseT1592.002SoftwareSub-technique

Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts.[1]

EnterpriseT1491.002External DefacementSub-technique

Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019.[1][2]

EnterpriseT1583Acquire Infrastructure

Sandworm Team used various third-party email campaign management services to deliver phishing emails.[10]

EnterpriseT1219Remote Access Tools

Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers.CitationUS-CERT Ukraine Feb 2016[11]

EnterpriseT1584.004ServerSub-technique

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.CitationNSA Sandworm 2020[10]

EnterpriseT1003.001LSASS MemorySub-technique

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.CitationESET Telebots Dec 2016CitationESET Telebots June 2017[11]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S1058: Prestige

Prestige ransomware has been used by Sandworm Team since at least March 2022, including against transportation and related logistics industries in Ukraine and Poland in October 2022.[1]

Windows
MalwareEnterprise

S1167: AcidPour

AcidPour is a variant of AcidRain designed to impact a wider range of x86 architecture Linux devices. AcidPour is an x86 ELF binary that expands on the targeted devices and locations in AcidRain by including items such as Unsorted Block Image (UBI), Deice Mapper (DM), and various flash memory references. Based on this expanded targeting, AcidPour can impact a variety of device types including IoT, networking, and ICS embedded device types.[1] AcidPour is a wiping payload associated with the Sandworm Team threat actor, and potentially linked to attacks against Ukrainian internet service providers (ISPs) in 2023.[2]

Linux
MalwareEnterprise

S1010: VPNFilter

VPNFilter is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber attack operations. VPNFilter modules such as its packet sniffer ('ps') can collect traffic that passes through an infected device, allowing the theft of website credentials and monitoring of Modbus SCADA protocols. [1] [2] VPNFilter was assessed to be replaced by Sandworm Team with Cyclops Blink starting in 2019.[3]

Network DevicesLinux
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
4.2
Created
Modified
Raw hash
02538aad071aa4bc...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.24.2Current bundle02538aad071a…
19.14.2Older bundle781b69323a74…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  2. [2]
    UK NCSC Olympic Attacks October 2020

    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

    Open source URL
  3. [3]
    iSIGHT Sandworm 2014

    Hultquist, J.. (2016, January 7). Sandworm Team and the Ukrainian Power Authority Attacks. Retrieved October 6, 2017.

    Open source URL
  4. [4]
    CrowdStrike VOODOO BEAR

    Meyers, A. (2018, January 19). Meet CrowdStrike’s Adversary of the Month for January: VOODOO BEAR. Retrieved May 22, 2018.

    Open source URL
  5. [5]
    USDOJ Sandworm Feb 2020

    Pompeo, M. (2020, February 20). The United States Condemns Russian Cyber Attack Against the Country of Georgia. Retrieved September 12, 2024.

    Open source URL
  6. [6]
    NCSC Sandworm Feb 2020

    NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020.

    Open source URL
  7. [7]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  8. [8]
    mandiant_apt44_unearthing_sandworm

    Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024.

    Open source URL
  9. [9]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  10. [10]
    Leonard TAG 2023

    Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.

    Open source URL
  11. [11]
    Microsoft Prestige ransomware October 2022

    MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.

    Open source URL
  12. [12]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  13. [13]
    APT44

    (Citation: mandiant_apt44_unearthing_sandworm)

  14. [14]
    BlackEnergy (Group)

    (Citation: NCSC Sandworm Feb 2020)(Citation: UK NCSC Olympic Attacks October 2020)

  15. [15]
    Dragos ELECTRUM

    Dragos. (2017, January 1). ELECTRUM Threat Profile. Retrieved June 10, 2020.

    Open source URL
  16. [16]
    ELECTRUM

    (Citation: Dragos ELECTRUM)(Citation: UK NCSC Olympic Attacks October 2020)

  17. [17]
    FROZENBARENTS

    (Citation: Leonard TAG 2023)

  18. [18]
    IRIDIUM

    (Citation: Microsoft Prestige ransomware October 2022)

  19. [19]
    IRON VIKING

    (Citation: Secureworks IRON VIKING )(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020)

  20. [20]
    InfoSecurity Sandworm Oct 2014

    Muncaster, P.. (2014, October 14). Microsoft Zero Day Traced to Russian ‘Sandworm’ Hackers. Retrieved October 6, 2017.

    Open source URL
  21. [21]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  22. [22]
    Quedagh

    (Citation: iSIGHT Sandworm 2014) (Citation: F-Secure BlackEnergy 2014)(Citation: UK NCSC Olympic Attacks October 2020)

  23. [23]
    Sandworm Team

    (Citation: iSIGHT Sandworm 2014) (Citation: F-Secure BlackEnergy 2014) (Citation: InfoSecurity Sandworm Oct 2014)(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020)

  24. [24]
    Seashell Blizzard

    (Citation: Microsoft Threat Actor Naming July 2023)

  25. [25]
    Telebots

    (Citation: NCSC Sandworm Feb 2020)(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020)

  26. [26]
    Voodoo Bear

    (Citation: CrowdStrike VOODOO BEAR)(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020)

  27. [27]
    mitre-attackG0034
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.