Cyber threat actor
Sandworm
Russian GRU Unit 74455 · active since 2009
GRU military intelligence unit responsible for destructive attacks including the Ukrainian power-grid outages, NotPetya, and the Olympic Destroyer wiper.
Aliases
Voodoo BearAPT44Seashell BlizzardIridium
Primary targets
Energy grids Ukrainian government Allied critical infrastructure Industrial control systems
MITRE ATT&CK techniques
0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
No MITRE ATT&CK mapping available yet for Sandworm.
Curated incidents
- 2017-06-27·Cross-sector·Global (US multinationals affected)NotPetya wiper attributed to Sandworm causes global billions in damage
Disguised as ransomware, the wiper spread via Ukrainian tax software and disrupted Maersk, Merck, and FedEx subsidiary TNT Express.