Cyber overview
Cyber threat actor

Sandworm

Russian GRU Unit 74455 · active since 2009

GRU military intelligence unit responsible for destructive attacks including the Ukrainian power-grid outages, NotPetya, and the Olympic Destroyer wiper.

Aliases
Voodoo BearAPT44Seashell BlizzardIridium
Primary targets
Energy grids Ukrainian government Allied critical infrastructure Industrial control systems

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for Sandworm.

Curated incidents

  1. 2017-06-27·Cross-sector·Global (US multinationals affected)
    NotPetya wiper attributed to Sandworm causes global billions in damage

    Disguised as ransomware, the wiper spread via Ukrainian tax software and disrupted Maersk, Merck, and FedEx subsidiary TNT Express.