LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 This group has been active since at least 2009.CitationiSIGHT Sandworm 2014CitationCrowdStrike VOODOO BEARCitationUSDOJ Sandworm Feb 2020CitationNCSC Sandworm Feb 2020

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.CitationUS District Court Indictment GRU Oct 2018

EnterpriseG0034GroupObject v4.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Sandworm Team matters because ATT&CK records it as a destructive group associated with major public incidents, including Ukrainian electric power attacks, NotPetya, and Olympic Destroyer. For leaders, the decision value is not “track one actor,” but validate whether the organization can withstand destructive operations that combine credential theft, administrative tooling, backdoors, wipers, and—in power-sector contexts—SCADA disruption paths.

Executive priority

Prioritize this as a resilience and crisis-readiness reference case: confirm identity controls, privileged administration monitoring, backup/restore confidence, incident communications, and enterprise-to-ICS segmentation where relevant. The ATT&CK relationships show repeated links to electric power campaigns and destructive malware, so risk owners should ask whether continuity plans and audit evidence cover destructive Windows-centric events, legitimate admin tool abuse, and cyber-physical escalation paths.

Technical view

ATT&CK provides no official detection text and no tactics for this group object, so defenders should derive coverage validation from the related software and campaigns. Confirm monitoring for Windows credential dumping and administrative execution patterns associated with Mimikatz, PsExec, Net, Impacket, PowerShell-based frameworks, Cobalt Strike, Empire, PoshC2, backdoors such as GreyEnergy and Exaramel, and destructive tooling such as SDelete, Olympic Destroyer, NotPetya, CaddyWiper-related campaign context, BlackEnergy, and KillDisk-related campaign context. For utilities or OT-connected environments, validate visibility across enterprise systems, jump hosts, SCADA administration paths, and command activity that could affect substations.

Likely telemetry

  • Windows security events for logon activity, privileged account use, service creation, remote execution, and account/group changes
  • Endpoint process, command-line, PowerShell, script, and file deletion telemetry
  • EDR or host logs for credential access tools, post-exploitation frameworks, backdoors, and wiper-like behavior
  • Network telemetry for SMB/Windows administration, remote service execution, command-and-control indicators, and unusual protocol use from administrative hosts
  • Identity telemetry for abnormal privileged access, lateral movement, and credential reuse

Detection direction

  • Treat alias matching alone as weak; validate behavior-based detections mapped to the related tools and campaigns instead.
  • Tune separately for legitimate administration tools such as PsExec, Net, SDelete, Impacket, PowerShell frameworks, and Cobalt Strike-like activity because false positives are likely in administrator workflows.
  • Prioritize detection chains that combine credential access, remote execution, lateral movement, payload staging, and destructive file or disk activity.
  • For electric utility or OT environments, test whether enterprise detections can be correlated with SCADA access paths and unauthorized command activity described in the related 2022 Ukraine Electric Power Attack context.
  • Because ATT&CK provides no official detection field for this group, require local validation through purple-team tests, incident retrospectives, or control evidence rather than assuming vendor coverage.

Mitigation priorities

  • Harden privileged identity first: reduce standing admin rights, monitor privileged sessions, and enforce strong authentication where applicable.
  • Restrict and monitor remote administration paths, especially PsExec-like execution, SMB administration, PowerShell, and Python-based tooling that can be used across Windows, Linux, and macOS environments.
  • Segment enterprise and ICS networks where relevant, with controlled jump paths and logging for SCADA administration.
  • Maintain tested offline or protected backups and recovery procedures suitable for destructive malware scenarios.
  • Build response playbooks for wiper/destructive events, including rapid isolation, credential reset sequencing, evidence preservation, and business continuity decision points.
Additional notes and limits

The supplied ATT&CK object identifies Sandworm Team aliases, destructive public operations, GRU attribution from official descriptions, and relationships to campaigns and software. The strongest defensive value comes from the relationship context: electric power campaigns, Windows-heavy tooling, cross-platform post-exploitation frameworks, credential dumping, backdoors, legitimate admin tools, and destructive malware.

The group object does not specify platforms, tactics, or official detection guidance. Related software provides platform context, but local exposure, sector relevance, telemetry availability, and control effectiveness must be validated in the organization’s own environment. This take does not assert current activity or customer-specific targeting.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 This group has been active since at least 2009.CitationiSIGHT Sandworm 2014CitationCrowdStrike VOODOO BEARCitationUSDOJ Sandworm Feb 2020CitationNCSC Sandworm Feb 2020

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.CitationUS District Court Indictment GRU Unit 74455 October 2020CitationUK NCSC Olympic Attacks October 2020 Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.CitationUS District Court Indictment GRU Oct 2018

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
4.2
Created
Modified
Raw hash
781b69323a748c81...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.