G0034: Sandworm Team
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 This group has been active since at least 2009.CitationiSIGHT Sandworm 2014CitationCrowdStrike VOODOO BEARCitationUSDOJ Sandworm Feb 2020CitationNCSC Sandworm Feb 2020
In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.CitationUS District Court Indictment GRU Oct 2018
Security context for executives and security teams
Sandworm Team matters because ATT&CK records it as a destructive group associated with major public incidents, including Ukrainian electric power attacks, NotPetya, and Olympic Destroyer. For leaders, the decision value is not “track one actor,” but validate whether the organization can withstand destructive operations that combine credential theft, administrative tooling, backdoors, wipers, and—in power-sector contexts—SCADA disruption paths.
Executive priority
Prioritize this as a resilience and crisis-readiness reference case: confirm identity controls, privileged administration monitoring, backup/restore confidence, incident communications, and enterprise-to-ICS segmentation where relevant. The ATT&CK relationships show repeated links to electric power campaigns and destructive malware, so risk owners should ask whether continuity plans and audit evidence cover destructive Windows-centric events, legitimate admin tool abuse, and cyber-physical escalation paths.
Technical view
ATT&CK provides no official detection text and no tactics for this group object, so defenders should derive coverage validation from the related software and campaigns. Confirm monitoring for Windows credential dumping and administrative execution patterns associated with Mimikatz, PsExec, Net, Impacket, PowerShell-based frameworks, Cobalt Strike, Empire, PoshC2, backdoors such as GreyEnergy and Exaramel, and destructive tooling such as SDelete, Olympic Destroyer, NotPetya, CaddyWiper-related campaign context, BlackEnergy, and KillDisk-related campaign context. For utilities or OT-connected environments, validate visibility across enterprise systems, jump hosts, SCADA administration paths, and command activity that could affect substations.
Likely telemetry
- Windows security events for logon activity, privileged account use, service creation, remote execution, and account/group changes
- Endpoint process, command-line, PowerShell, script, and file deletion telemetry
- EDR or host logs for credential access tools, post-exploitation frameworks, backdoors, and wiper-like behavior
- Network telemetry for SMB/Windows administration, remote service execution, command-and-control indicators, and unusual protocol use from administrative hosts
- Identity telemetry for abnormal privileged access, lateral movement, and credential reuse
Detection direction
- Treat alias matching alone as weak; validate behavior-based detections mapped to the related tools and campaigns instead.
- Tune separately for legitimate administration tools such as PsExec, Net, SDelete, Impacket, PowerShell frameworks, and Cobalt Strike-like activity because false positives are likely in administrator workflows.
- Prioritize detection chains that combine credential access, remote execution, lateral movement, payload staging, and destructive file or disk activity.
- For electric utility or OT environments, test whether enterprise detections can be correlated with SCADA access paths and unauthorized command activity described in the related 2022 Ukraine Electric Power Attack context.
- Because ATT&CK provides no official detection field for this group, require local validation through purple-team tests, incident retrospectives, or control evidence rather than assuming vendor coverage.
Mitigation priorities
- Harden privileged identity first: reduce standing admin rights, monitor privileged sessions, and enforce strong authentication where applicable.
- Restrict and monitor remote administration paths, especially PsExec-like execution, SMB administration, PowerShell, and Python-based tooling that can be used across Windows, Linux, and macOS environments.
- Segment enterprise and ICS networks where relevant, with controlled jump paths and logging for SCADA administration.
- Maintain tested offline or protected backups and recovery procedures suitable for destructive malware scenarios.
- Build response playbooks for wiper/destructive events, including rapid isolation, credential reset sequencing, evidence preservation, and business continuity decision points.
Additional notes and limits
The supplied ATT&CK object identifies Sandworm Team aliases, destructive public operations, GRU attribution from official descriptions, and relationships to campaigns and software. The strongest defensive value comes from the relationship context: electric power campaigns, Windows-heavy tooling, cross-platform post-exploitation frameworks, credential dumping, backdoors, legitimate admin tools, and destructive malware.
The group object does not specify platforms, tactics, or official detection guidance. Related software provides platform context, but local exposure, sector relevance, telemetry availability, and control effectiveness must be validated in the organization’s own environment. This take does not assert current activity or customer-specific targeting.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Sandworm Team
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 This group has been active since at least 2009.CitationiSIGHT Sandworm 2014CitationCrowdStrike VOODOO BEARCitationUSDOJ Sandworm Feb 2020CitationNCSC Sandworm Feb 2020
In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.CitationUS District Court Indictment GRU Oct 2018
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
