Sandworm

Actor Type Nation State
Attributed to Nation Russia
Directly Linked Intrusion Sets Seashell Blizzard , UAC-0002 , APT44 , FROZENBARENTS , ELECTRUM , UAC-0133
Associated Threat Actor GRU Unit 74455

Sandworm is a cyber threat actor reportedly linked to the Russian government and responsible for conducting numerous cyber attack campaigns. The group have been identified as being responsible for disruptive and destructive attacks against multiple targets.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

Sandworm Threat Reports

Report

KAPEKA A novel backdoor spotted in Eastern Europe

This report from researchers at WithSecure unveils a novel backdoor: 'Kapeka'. Kapeka has been used against victims in Eastern Europe ...

Report

AcidPour - New Embedded Wiper Variant of AcidRain Appears in Ukraine

This blog post by researchers at SentinelLabs describes a new variant of the AcidRain malware which they call AcidPour. The report includes ...

References

MITRE ATT&CK Techniques

MITRE ATT&CK techniques observed in use by this intrusion set.