Sandworm Team
Also tracked as ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.
- Known attack methods
- 79
- Origin
- Russia
- Motive
- Sabotage
- First seen
- 2009
- Last seen
- 2022-10
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 8 used
Resource Development
9 techniques · 7 used
Initial Access
11 techniques · 4 used
Execution
20 techniques · 7 used
Persistence
22 techniques · 2 used
Privilege Escalation
13 techniques
Stealth
30 techniques · 6 used
Defense Impairment
18 techniques
Credential Access
17 techniques · 4 used
Discovery
34 techniques · 6 used
Lateral Movement
9 techniques · 2 used
Collection
17 techniques · 3 used
Command and Control
18 techniques · 7 used
Exfiltration
9 techniques · 1 used
Impact
15 techniques · 7 used
Reconnaissance9
Resource development12
Initial access6
Execution9
Persistence2
Stealth9
Credential access5
Discovery7
Lateral movement2
Command and control7
Exfiltration1
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.