Sandworm, also tracked as UAC-0002, APT44, and Seashell Blizzard, is a Russian state-linked threat actor associated with disruptive and espionage-oriented cyber operations, particularly against Ukraine. UAC-0145 has been identified as a subcluster of this actor. The group has conducted sustained campaigns against Ukrainian targets, including critical infrastructure, government entities, military-related users, telecom and IT personnel, and other organizations of strategic value. Observed operations attributed to this cluster include social-engineering campaigns against job seekers and IT specialists, distribution of trojanized software installers, messenger-based lures, and ClickFix-style fake CAPTCHA delivery chains. In one campaign, operators impersonated recruiters and technology companies, moved conversations to messaging and video platforms, and delivered a trojanized VPN client derived from WireGuard. That malware decrypted and executed hidden payloads from configuration data and then retrieved additional payloads on both Windows and Linux. Other activity involved malicious tools delivered through Signal under false security pretexts, including fake antivirus or protective software. The malware ecosystem associated with this cluster includes GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, and the Android backdoor COWARDDUCK, as well as previously linked tooling such as KALAMBUR, SUMBUR, and TAMBUR. These tools have supported reconnaissance, payload delivery, persistence, remote access, theft of messaging data, and exfiltration. The actor has also used legitimate utilities including OpenSSH, Tor, and rsync to maintain unauthorized access, tunnel traffic, and move stolen data. CERT-UA reporting further indicates that access obtained through trojanized installers was used for persistence and lateral movement inside an organization, creating conditions for a destructive cyberattack against a central executive authority in Ukraine. Tradecraft attributed to this actor includes sophisticated social engineering, spoofing of trusted organizations, use of compromised websites for staged delivery, PowerShell-based execution, scheduled-task persistence, abuse of startup mechanisms, Android surveillance tooling, and dynamic infrastructure retrieval techniques. The actor has demonstrated capability for reconnaissance, credential- and data-focused collection from messaging platforms, exfiltration, persistence, lateral movement, and destructive follow-on operations. The overall pattern is consistent with a mature, state-backed operator focused primarily on Russian strategic objectives in Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the parent/subcluster associated with UAC-0145 in this campaign.
Named subcluster associated in the report with UAC-0145 and identified as the broader Sandworm/APT44/Seashell Blizzard activity set behind the described campaigns against Ukraine.
Referenced as a separate CERT-UA tracked cluster previously observed using XLL files in targeted attacks against Ukrainian critical infrastructure; mentioned for differentiation from UAC-0245 rather than as the primary actor in this report.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.