Sandworm
Actor Type | Nation State |
---|---|
Attributed to Nation | Russia |
Directly Linked Intrusion Sets | Seashell Blizzard , UAC-0002 , APT44 , FROZENBARENTS , ELECTRUM , UAC-0133 |
Associated Threat Actor | GRU Unit 74455 |
Sandworm is a cyber threat actor reportedly linked to the Russian government and responsible for conducting numerous cyber attack campaigns. The group have been identified as being responsible for disruptive and destructive attacks against multiple targets.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph
Sandworm Threat Reports
Report
KAPEKA A novel backdoor spotted in Eastern Europe
This report from researchers at WithSecure unveils a novel backdoor: 'Kapeka'. Kapeka has been used against victims in Eastern Europe ...
Report
AcidPour - New Embedded Wiper Variant of AcidRain Appears in Ukraine
This blog post by researchers at SentinelLabs describes a new variant of the AcidRain malware which they call AcidPour. The report includes ...
References
services.google.com
https://services.google.com/fh/files/blogs/google_fog_of_war_research_report.pdfwww.dragos.com
https://www.dragos.com/threat/electrum/www.justice.gov
https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-andwww.cisa.gov
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-110alabs.withsecure.com
https://labs.withsecure.com/content/dam/labs/docs/WithSecure-Research-Kapeka.pdfwww.mandiant.com
https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technologywww.microsoft.com
https://www.microsoft.com/en-us/security/blog/2025/02/12/the-badpilot-campaign-seashell-blizzard-subgroup-conducts-multiyear-global-access-operation/www.welivesecurity.com
https://www.welivesecurity.com/2022/03/21/sandworm-tale-disruption-told-anew/www.mandiant.com
https://www.mandiant.com/resources/blog/ukraine-and-sandworm-teamservices.google.com
https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdfwww.sentinelone.com
https://www.sentinelone.com/labs/acidpour-new-embedded-wiper-variant-of-acidrain-appears-in-ukraine/cert.gov.ua
https://cert.gov.ua/article/6278706MITRE ATT&CK Techniques
MITRE ATT&CK techniques observed in use by this intrusion set.