Sandworm Team
Aliases: ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.
Open interactive actor investigation
ATT&CK techniques
Upload MalwareT1588.006
VulnerabilitiesT1040
Network SniffingT1027.010
Command ObfuscationT1595.002
Vulnerability ScanningT1585.001
Social Media AccountsT1586.001
Social Media AccountsT1132.001
Standard EncodingT1213
Data from Information RepositoriesT1539
Steal Web Session CookieT1059.001
PowerShellT1090
ProxyT1203
Exploitation for Client ExecutionT1041
Exfiltration Over C2 ChannelT1053.005
Scheduled TaskT1190
Exploit Public-Facing ApplicationT1078.002
Domain AccountsT1003.003
NTDST1036
MasqueradingT1598.003
Spearphishing LinkT1133
External Remote ServicesT1587.001
MalwareT1072
Software Deployment ToolsT1584.005
BotnetT1566.002
Spearphishing LinkT1018
Remote System DiscoveryT1589.003
Employee NamesT1078
Valid AccountsT1566.001
Spearphishing AttachmentT1204.002
Malicious FileT1106
Native APIT1588.002
ToolT1583.004
ServerT1590.001
Domain PropertiesT1083
File and Directory DiscoveryT1049
System Network Connections DiscoveryT1555.003
Credentials from Web BrowsersT1489
Service StopT1571
Non-Standard PortT1070.004
File DeletionT1047
Windows Management InstrumentationT1087.003
Email AccountT1021.002
SMB/Windows Admin SharesT1204.001
Malicious LinkT1505.003
Web ShellT1218.011
Rundll32T1499
Endpoint Denial of ServiceT1195.002
Compromise Software Supply ChainT1199
Trusted RelationshipT1056.001
KeyloggingT1561.002
Disk Structure WipeT1486
Data Encrypted for ImpactT1592.002
SoftwareT1491.002
External DefacementT1583
Acquire InfrastructureT1219
Remote Access SoftwareT1584.004
ServerT1003.001
LSASS MemoryT1594
Search Victim-Owned WebsitesT1570
Lateral Tool TransferT1027
Obfuscated Files or InformationT1591.002
Business RelationshipsT1585.002
Email AccountsT1102.002
Bidirectional CommunicationT1490
Inhibit System RecoveryT1583.001
DomainsT1140
Deobfuscate/Decode Files or InformationT1485
Data DestructionT1059.005
Visual BasicT1105
Ingress Tool TransferT1033
System Owner/User DiscoveryT1589.002
Email AddressesT1071.001
Web ProtocolsT1087.002
Domain AccountT1082
System Information DiscoveryT1005
Data from Local SystemT1195
Supply Chain CompromiseT1593
Search Open Websites/DomainsT1036.005
Match Legitimate Name or LocationT1136.002
Domain AccountT1110.003
Password SprayingT1059.003
Windows Command ShellT1505.001
SQL Stored ProceduresT1098
Account ManipulationT1016
System Network Configuration DiscoveryT1136
Create AccountT1027.002
Software PackingT1562.002
Disable Windows Event Logging
Correlated CTI and IR reports
1200km CTI repository · explicit report mentionBlue-Team IOC Tables — Consolidated
1200km CTI repository · explicit report mentionCTI
1200km CTI repository · explicit report mentionCTI Research Template
1200km CTI repository · explicit report mentionCTI Research: Sandworm / APT44
1200km CTI repository · explicit report mentionCTI Research: Sandworm / APT44
1200km CTI repository · explicit report mentionCTI Research: Sandworm / APT44
1200km CTI repository · explicit report mentionGitHub repo: description and short description
1200km CTI repository · explicit report mentionIOC Tables — Sandworm / APT44 (Seashell Blizzard)
1200km CTI repository · explicit report mentionCTI Research Sandworm APT44
1200km Medium · authored report mention