Sandworm is a Russian state-sponsored cyber threat actor associated with the Russian military intelligence service, the GRU, and specifically Unit 74455. It is also tracked as APT44, Sandworm Team, Seashell Blizzard, Voodoo Bear, FROZENBARENTS, IRIDIUM, TeleBots, BlackEnergy Group, and ELECTRUM. The group conducts disruptive and destructive cyber operations, with Ukraine a prominent target, and has attacked electricity infrastructure, software supply chains, and international sporting events. Sandworm distributed NotPetya by compromising the Ukrainian accounting software M.E.Doc and substituting a malicious software update. Its operations include the 2016 Ukraine electric power attack and preparations for the attack against the 2018 Winter Olympics. It has also deployed Prestige ransomware, copying payloads to an Active Directory domain controller and distributing them through Group Policy. Initial-access methods include spearphishing with malicious links and Microsoft Office attachments, compromised software updates, previously acquired legitimate credentials, and VPN connections through compromised software-provider infrastructure into customer networks. The group scans network infrastructure for vulnerabilities and queries Active Directory through LDAP to discover systems. It steals Windows credentials from memory using a modified Mimikatz tool and transfers tools and payloads between compromised hosts and network shares. Sandworm maintains access through newly created domain accounts, account manipulation, web shells including P.A.S. Webshell, and a backdoored Dropbear SSH service. Its backdoors use encoding, encryption, and compression to conceal payloads and communications, including Base64, ROT13, AES, Triple DES, GZip, and zlib. It combines custom malware with publicly available tools, including Invoke-PSImage for encrypted command-and-control communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
76 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
39 malware families attributed to this actor across reporting.
34 additional families tracked in Mallory.
31 CVEs this actor has used in observed campaigns. 31 of them exploited in the wild.
Sandworm Team has exploited vulnerabilities in Microsoft PowerPoint via OLE objects (CVE-2014-4114) and Microsoft Word via crafted TIFF images (CVE-2013-3906).
As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.
The first intrusion cluster exploits CVE-2026-20079 and places a malicious web shell in the CSM Tomcat webroot directory, which is then used to place a malicious JAR file in the same directory.
The third one, suspected to be the work of a Qilin ransomware operator, starts with the attackers logging in with the static credentials (CVE-2026-20316), then performing network and endpoint reconnaissance, stealing credentials, establishing additional access, deploying AV killers, and delivering the ransomware.
The Shadow Brokers leak included EternalBlue, an exploit for Windows SMB. The content links it to WannaCry and to the Sandworm-attributed NotPetya attack, and states that Microsoft released MS17-010 in March 2017.
26 more CVEs tied to this actor tracked in Mallory.
313 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat actor linked to Russian military intelligence that ESET identifies as a possible recipient of initial access provided by UAC-0099. The content does not establish this relationship or attribute the described malware campaign directly to Sandworm.
Russian military-intelligence-linked threat actor associated with destructive attacks against Ukrainian power grids and other infrastructure. The article identifies it as a possible recipient of initial access supplied by UAC-0099, without establishing its direct involvement in the MatchBoil campaign.
Russian advanced persistent threat group known for destructive attacks against Ukraine. Its connection to the reported activity is ESET's assessment that UAC-0099 can provide it with initial access; the article does not establish Sandworm's direct participation in the ASHVEIN attacks.
Russia-aligned threat group identified as a historical beneficiary of initial access supplied by UAC-0099. The article does not establish Sandworm's involvement in the specific MATCHBOIL infections described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.