Sandworm is a Russian state-sponsored advanced persistent threat group widely attributed to the GRU, specifically Unit 74455. It is also tracked under aliases including APT44, Voodoo Bear, Seashell Blizzard, TeleBots, Electrum, Iridium, Iron Viking, Blue Echidna, Quedagh, and UAC-0113, with some reporting distinguishing operational sub-elements such as KAMACITE as an access-focused component and ELECTRUM as an ICS-specialist component. The group is known for disruptive and destructive cyber operations, especially against Ukraine, including attacks on the Ukrainian power sector and the development or deployment of destructive malware such as BlackEnergy-associated tooling, NotPetya, Olympic Destroyer, and later OT-focused malware including Industroyer2 alongside wiper activity. Sandworm has repeatedly targeted government and critical infrastructure environments, particularly electric utilities and other operational technology networks, and has also been linked to compromises of perimeter network devices used to build botnet and command-and-control infrastructure, including VPNFilter and Cyclops Blink. Operationally, Sandworm uses spearphishing with malicious document attachments for initial access, custom malware development, credential harvesting, browser-stored password theft through tools such as CredRaptor, keylogging, PowerShell-based in-memory execution, system and account discovery, network reconnaissance, lateral movement, and data exfiltration. The group has used encoded and obfuscated command-and-control traffic, including Base64, and malware capable of decoding, decrypting, and decompressing payloads. Reporting also associates Sandworm with pushing additional tooling to compromised systems to steal credentials, move laterally, and destroy data. Its tradecraft spans enterprise and ICS environments and reflects a blend of espionage-enabling access operations and destructive effects in support of Russian military and strategic objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
28 CVEs this actor has used in observed campaigns. 28 of them exploited in the wild.
CVE-2014-6352 • bypass the patch of CVE-2014-4114 used by Sandworm
As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.
Sandworm also has demonstrated an ability to get access to the latest exploits, he says, pointing to the group's use of the NSA-developed EternalBlue exploit during its NotPetya campaign.
Sandworm Team has exploited... Microsoft Word via crafted TIFF images (CVE-2013-3906).
To date, at least eight vulnerabilities... have been exploited by this subgroup: Microsoft Exchange (CVE-2021-34473)... We have observed web shells deployed following exploitation of vulnerabilities in Microsoft Exchange (CVE-2021-34473)...
23 more CVEs tied to this actor tracked in Mallory.
167 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a separate state-sponsored actor using fake job offers to target system administrators and IT professionals in a different campaign.
Conducted a cyber campaign against Poland's energy infrastructure, including attacks on renewable energy facilities and a CHP plant, using novel OT intrusion techniques via a private APN to disrupt industrial processes and sabotage recovery.
Conducting a fake job interview campaign targeting IT professionals and system administrators, using recruiter impersonation, live video calls, and a trojanized WireGuard-based VPN client (SopraVPN) to gain access and deliver follow-on payloads.
Conducting a staged fake job interview campaign targeting system administrators and other IT specialists, using recruiter impersonation, live video calls, malicious WireGuard configurations, and a trojanized VPN client (SopraVPN) to gain access to privileged systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.