Threat actor · all actors
Sandworm TeamG0034 state
🇷🇺 RU · GRU · Unit 74455
aka Sandworm Team, ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44, Sandworm, TEMP.Noble, G0034, Blue Echidna, UAC-0113, UAC-0082, SANDWORM RELIC, UAC-0145
Last updated: 2026-08-22
About this actor
[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with [Sandworm Team](https://attack.mitre.org/groups/G0034) for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide [NotPetya](https://attack.mitre.org/software/S0368) attack, targeting of the 2017 French presidential campaign, the 2018 [Olympic Destroyer](https://attack.mitre.org/software/S0365) attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as [APT28](https://attack.mitre.org/groups/G0007).(Citation: US District Court Indictment GRU Oct 2018)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
MandiantTEMP temporary cluster
Secureworkscolour-metal names
DragosICS mineral names
CERT-UAUAC cluster id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 109 ATT&CK techniques on file.
- Named victims
- 1 extracted from reporting.
Thin data: Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
- 2022 — 1 KEV added
- 2010 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2010-3333 KEV | 8.5 | 7.8 | 0.9740 | 2010-11-10 | see CVE |
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.003NTDS ↗T1005Data from Local System ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.002SMB/Windows Admin Shares ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1040Network Sniffing ↗T1041Exfiltration Over C2 Channel ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1056Input Capture ↗T1056.001Keylogging ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.005Visual Basic ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1072Software Deployment Tools ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1087.003Email Account ↗T1090Proxy ↗T1102Web Service ↗T1102.002Bidirectional Communication ↗T1105Ingress Tool Transfer ↗T1106Native API ↗T1132Data Encoding ↗T1132.001Standard Encoding ↗T1133External Remote Services ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1195Supply Chain Compromise ↗T1195.002Compromise Software Supply Chain ↗T1199Trusted Relationship ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1213Data from Information Repositories ↗T1213.006Databases ↗T1218System Binary Proxy Execution ↗T1218.011Rundll32 ↗T1219Remote Access Tools ↗T1485Data Destruction ↗T1486Data Encrypted for Impact ↗T1489Service Stop ↗T1490Inhibit System Recovery ↗T1491Defacement ↗T1491.002External Defacement ↗T1499Endpoint Denial of Service ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1539Steal Web Session Cookie ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1561Disk Wipe ↗T1561.002Disk Structure Wipe ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1570Lateral Tool Transfer ↗T1571Non-Standard Port ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1583.004Server ↗T1584Compromise Infrastructure ↗T1584.004Server ↗T1584.005Botnet ↗T1585Establish Accounts ↗T1585.001Social Media Accounts ↗T1585.002Email Accounts ↗T1586Compromise Accounts ↗T1586.001Social Media Accounts ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.006Vulnerabilities ↗T1589Gather Victim Identity Information ↗T1589.002Email Addresses ↗T1589.003Employee Names ↗T1590Gather Victim Network Information ↗T1590.001Domain Properties ↗T1591Gather Victim Org Information ↗T1591.002Business Relationships ↗T1592Gather Victim Host Information ↗T1592.002Software ↗T1593Search Open Websites/Domains ↗T1594Search Victim-Owned Websites ↗T1595Active Scanning ↗T1595.002Vulnerability Scanning ↗T1598Phishing for Information ↗T1598.003Spearphishing Link ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 64 / 109 | 59% |
CM-6 | 53 / 109 | 49% |
CM-2 | 50 / 109 | 46% |
SI-3 | 47 / 109 | 43% |
AC-3 | 42 / 109 | 39% |
CA-7 | 42 / 109 | 39% |
CM-7 | 40 / 109 | 37% |
AC-6 | 39 / 109 | 36% |
AC-4 | 32 / 109 | 29% |
SC-7 | 30 / 109 | 28% |
SI-7 | 30 / 109 | 28% |
AC-2 | 28 / 109 | 26% |
IA-2 | 21 / 109 | 19% |
AC-5 | 20 / 109 | 18% |
CM-5 | 19 / 109 | 17% |
Co-occurring actors
- Scarlet Mimic 1 shared CVEs
- Aoqin Dragon 1 shared CVEs
- Transparent Tribe 1 shared CVEs
- Naikon 1 shared CVEs
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
Similar actors
Similar TTPs
- Magic Hound 0.42
- APT32 0.35
- Lazarus Group 0.34
- Kimsuky 0.33
- OilRig 0.33
Active in same years
- APT29 3.00
- Threat Group-3390 3.00
- Naikon 2.00
- Equation 2.00
- Scarlet Mimic 2.00
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00