← Back to all threat actors

Sandworm Team

Also known as ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44
Tracked as G0034

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
RU
Sectors
energy, transportation, government, critical-infrastructure
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: APT44

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0034

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: ELECTRUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Telebots

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: IRON VIKING

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BlackEnergy (Group)

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Quedagh

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Voodoo Bear

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: IRIDIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Seashell Blizzard

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: FROZENBARENTS

Reviewed identity mapping approved on this date.

Last observed
Campaign2022 Ukraine Electric Power Attack

The 2022 Ukraine Electric Power Attack was a Sandworm Team campaign that used a combination of GOGETTER, Neo-REGEORG, CaddyWiper, and living of the lan…

Last observed
Campaign2016 Ukraine Electric Power Attack

2016 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used Industroyer malware to target and disrupt distribution substatio…

Last observed
Campaign2015 Ukraine Electric Power Attack

2015 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used BlackEnergy (specifically BlackEnergy3) and [KillDisk](https://a…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Sandworm TeamCanonical Name
APT44Alias
BlackEnergy (Group)Alias
ELECTRUMAlias
FROZENBARENTSAlias
IRIDIUMAlias
IRON VIKINGAlias
QuedaghAlias
Seashell BlizzardAlias
TelebotsAlias
Voodoo BearAlias
G0034Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...