Threat Actor Profile Sandworm
Sandworm, also commonly referred to as IRIDIUM, Sandworm Team, Voodoo Bear or Telebots, is a Russian state-sponsored advanced strategic threat group responsible for some of the most destructive cyber-attacks around the world. They are believed to be operating with the aim to advance Russia’s geopolitical position by conducting destruction, sabotage, and espionage based cyber operations. They are known to target the energy infrastructure, transportation systems, telecommunication services, government organizations, and more. Their focus has been set on Eastern nations with strategic importance to Russia, such as Georgia and Ukraine, although some of their attacks has had worldwide reach. The group has been labeled as one of the most dangerous APT groups in the world, which is why it is crucial to understand their background, motivations and techniques to prepare companies and institutions for possible future attacks.
- Aliases: Seashell Blizzard, Sandworm, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, Sandworm Team, CTG-7263, ATK 14, BE2, BlackEnergy (Group)
- Strategic motives: Destruction, Espionage, Sabotage
- Affiliation: Russian Main Intelligence Directorate (GRU)
- Cyber capabilities: ★★★★☆
- Target sectors: Energy, Telecommunications, Government
- Observed countries: 60+, including Azerbaijan, Belarus, Denmark, France, Georgia, Iran, Israel, Kazakhstan, Kyrgyzstan, Lithuania, Poland, Russia, Ukraine, Netherlands
Request a free membership to access our full research insights
Already a member? Login here
Origins, Motivations & Targets
Sandworm is confirmed to have been operating since 2009[1], although it is believed that (members of) the group were involved in cyber-attacks already during the Russian-Georgian war in 2008.[2] Moreover, they are known to deploy the malware BlackEnergy Lite, which has its origins traced back to DDoS attacks in 2007.[3] The name Sandworm by which the group is best known, was given by researchers at iSIGHT after their 2014 discovery of hidden references to the 1965 sci-fi novel Dune in their code.[4] It is generally accepted that Sandworm operates within Unit 74455 of the Main Intelligence Directorate of the Russian Federation, effectively acting as Russia’s cyber military unit.[5] This state affiliation ensures the group’s access to resources, as well as guaranteeing impunity for its members as long as they remain on Russian-controlled territory.
As stated previously, the group is generally focusing on Eastern regions, particularly countries that carry a geopolitical relevance to Russia. This includes countries that used to belong to the Soviet bloc, such as Georgia, Lithuania, Poland, or Ukraine. This tendency, however, is not exclusive, as they attempted to interfere with the 2017 French elections, as well as carried out campaigns with worldwide effects.[6] Sandworm tends to target a variety of sectors as long as the attack results in an outcome aligning with Russian state interest. Their most well-known activities involved the energy sector, the financial sector, governmental agencies, and telecommunication networks.[7]
SWOT analysis
Strengths, weaknesses, opportunities & threats
Strengths
- Significant resources available from the Russian state
- Advanced level and speed to develop new tools
- No fear from criminal prosecution
Weaknesses
- Actual effects of their attacks are fairly limited
- Difficulties carrying out long-term attacks
Opportunities
- Chances for further development to maintain access for a longer period of time in order to gain strategic advantage
- Opportunities to further develop and utilize their tools during the Russia-Ukraine conflict
Threats
- Increased attention on Russian activity in general
- Ongoing criminal proceedings against members
Campaigns Overview
January 1, 2022
16:00 PM
BlackEnergy
2014
Although it is suspected that Sandworm has been active since the 2008 Georgian attacks, their first widely reported and confirmed activity was the 2014 attacks using the BlackEnergy backdoor malware. The operation targeted Ukrainian government bodies, NATO, companies in the European energy and telecommunications sectors, and several Western governmental organizations.[8] Sandworm exploited a Windows zero-day vulnerability (CVE-2014-4114), which allowed the attackers to have the same user rights as legitimate (administrative) users.[9]
January 1, 2022
16:00 PM
BlackEnergy3
2015
A new variant of BlackEnergy was discovered to be used in the 2015 campaign against Ukrainian energy suppliers.[10] Sandworm attempted to disrupt the country’s electric infrastructure, which resulted in almost 230.000 consumers left without electricity in the Oblast region for 6 hours.[11] The disruption was caused by the malware BlackEnergy, effectively disabling the power stations’ remote management systems.[12]
January 1, 2022
16:00 PM
Industroyer Campaign
2016
Industroyer is a malware framework used in the cyberattack on Ukraine’s power grid on December 17, 2016. The attack temporarily cut power to for one hour and is thought to have been a large-scale test. Industroyer is the first known malware specifically designed to target electrical grids.
January 1, 2022
16:00 PM
French Election
2017
Prior to the 2017 French elections, phishing campaigns targeted French government agencies and political parties resulting in data breaches.[13] The attempted interference with Macron’s election campaign was aiming to provide an advantage to the opposing candidate, Marine Le Pen[14] as her anti-EU sentiment would have been beneficial to the Russian political agenda.
January 1, 2022
16:00 PM
NotPetya
2017
2017 also marked the year when Sandworm launched its most infamous and most financially damaging[15] campaign to date, releasing the NotPetya malware. The series of attacks on a variety of organizations worldwide - including in Russia - resulted in approximately ten billion dollars in damage.[16] The malware has reached 60 countries affecting thousands of businesses worldwide,[17] although it is thought that the original targets were Ukrainian; that is where the first cases were reported, including the state power company, the Kiev airport, and even the Chernobyl nuclear power plant.[18] There was a serious financial element to the attacks, and because NotPetya “prevents users from accessing their files or system and demands a ransom payment,” some may consider it ransomware.[19] However, it seems that the aim was destruction rather than financial gain, making the campaign particularly heinous. Although the financial damage was enormous, it is believed that the magnitude of it was unintentional. It was not in Russia’s best interest, for example, to compromise Danish shipping and logistics company Maersk.
January 1, 2022
16:00 PM
Olympic Destroyer
2018
In 2018, the group attempted a large-scale cyber-attack against the Winter Olympics held in PyeongChang.[20] Russia was barred from competing in the competition due to doping allegations,[21] which is undoubtedly what motivated the attacks. The sabotage attempt was caught early during the opening ceremony of the Games, and within hours basic services were restored.[22] The damage, however, could have been significantly more serious, as the “Olympic Destroyer” malware caused destruction in the entirety of the event’s network, disrupting internal communications, the ticketing system and more.[23]
January 1, 2022
16:00 PM
Georgia Attacks
2018 - 2019
In 2018 and 2019 Sandworm again turned against Russia’s political adversaries. Websites and servers in Georgia got infiltrated not only in the governmental sector, but TV-networks, NGOs, financial institutions, courts and universities also became targets.[24] The scope of the operation was vast, as it is believed that several thousand websites were defaced.[25] Intercepted websites displayed Russia-aligned political messaging for a prolonged period of time, causing unrest not only in the political sphere but in society as well. Even though the attacks lacked sophistication from a technical point of view, their scale and effects resulted in a temporary but significant disruption of life. As the US State Department put it: “These operations aim to sow division, create insecurity, and undermine democratic institutions.”[26] In that, Sandworm succeeded.
January 1, 2022
16:00 PM
Cyber warfare in Ukraine
2022 - ongoing
In 2022, Russian APTs turned their attention towards the war in Ukraine. Sandworm has played a pivotal role in this. Please see the section on Cyber Warfare in Ukraine for more detailed information.
Sandworm in the Netherlands
Sandworm had been focusing on geopolitically relevant Eastern countries before 2017, therefore the Netherlands was not an obvious target. This, however, changed with the launching of the global NotPetya attacks which affected several Dutch companies. This included container terminal operator APM, pharmaceutical company MSD, and delivery company TNT.[86] It is (publicly) unknown exactly how much damage these companies suffered.
Then in 2022, the geopolitical landscape changed. Shortly after Russia invaded Ukraine, the Dutch military intelligence agency MIVD detected Sandworm activity in the Netherlands. Thousands of routers in Dutch homes and businesses had been compromised in what the MIVD believes was a botnet operation by Sandworm.[87]
Sandworm in Ukraine
As a group known for its destructive methods, Sandworm has been part of the cyber operations against Ukraine since the war commenced in February 2022. In April it was confirmed that the group was behind the attempt to disable the functioning of a large Ukrainian energy provider. Sandworm deployed Industroyer2 against the energy provider’s industrial control system and used CaddyWiper to erase data.[88] According to discovered artifacts in Industroyer2, the attacks had been planned for weeks. The Ukrainain Computer Emergency Response Team, however, was able to prevent the group’s plan to disrupt energy supplies.
January 1, 2022
16:00 PM
May - June 2022
In May and June Sandworm was among a number of malicious actors exploiting the CVE-2022-30190 Microsoft zero-day vulnerability against Ukrainian targets in the media sector.[89] In September Sandworm was identified to be behind a series of attacks distributing commodity malware, masquerading as telecommunication providers Datagroup and EuroTransTelecom. The attacks reportedly involved payloads like Colibri loader and Warzone RAT.[90]
January 1, 2022
16:00 PM
October - November 2022
In October and November, Sandworm shifted its methods to ransomware attacks. Transportation and logistics organizations throughout Ukraine and Poland were targeted with Prestige ransomware. The attacks aimed to disrupt the military and humanitarian supply chain in Ukraine.[91] In another series of attacks, the presence of new ransomware, RansomBoggs, was identified in several Ukrainian organizations’ networks.
January 1, 2022
16:00 PM
January - August 2023
The group has been active in 2023 as well. In January, Sandworm carried out an attack against a not-yet identified but specific target in Ukraine’s public sector. According to ESET, a new data-wiping malware, SwiftSlicer, was used. The impact of the attacks is not yet reported.[92] Then in May CERT-UA warned about attacks being conducted against government networks. This included the impairment of “server equipment, automated user workplaces [and] data storage systems.”[93] The targeted environment was Windows operating systems, using RoarBat.[94] Lastly, in August 2023 Sandworm targeted the Android devices of some Ukrainian armed forces members with the "Infamous Chisel" malware.
January 1, 2022
16:00 PM
May - December 2023
In December of 2023, Ukraine's most prominent mobile network operator Kyivstar went down temporarily, resulting in millions of people being left without mobile services. The cyberattack, later attributed to Sandworm, was deemed to be the largest attack since the beginning of the war. [95] Upon investigating the attacks, Ukraine's cyber spy chief confirmed that the group had been present in their network since at least May 2023. [96]
January 1, 2022
16:00 PM
2024
Although Russia's presense in Ukrainian cyberspace remains, there is not many Sandworm attacks confirmed in relation to the Russia-Ukraine war in 2024. Most notably, in March Sandworm launched a cyberattack on Ukrainian critical infrastructure, targeting 20 sites across 10 regions. The attacks aimed to amplify the effects of missile strikes by compromising energy, heating, and water facilities. At least three supply chains were breached to deliver compromised software updates or gain access through third-party credentials. During the investigation, two new Linux backdoors, "Biasboat" and "Loadgrip," were discovered, which are variants of the previously known "Queueseed" backdoor. [97]
Indictments
Due to the inherently international nature of the operation of state-sponsored APT groups, it is extremely rare that individuals are held responsible. One crucial part of hacking is innovation, from which it follows that legal procedures to invoke criminal liability are often too slow and not well-equipped to address the rapidly evolving technology and operations that cross many jurisdictions. Even so, Sandworm has caused substantial damage and gained enough international attention that a case against them was initiated. This resulted in the 2020 indictment of six Sandworm members by a Pennsylvania grand jury on seven counts. The US Department of Justice charged the member under a number of Title 18 violations such as conspiracy, wire fraud, identity theft, and more.[95]
This indictment is not only impactful from a justice point of view, but also because this is rare occasions that, due to lenient privacy regulations in the United States, the global public gets to know the names and faces behind the malicious activities committed by APT groups. The defendants all belong to Unit 74455 of the GRU – also known as Sandworm. The identified and charged members are:
Yuriy Sergeyevich Andrienko, Sergey Vladimirovich Detistov, Pavel Valeryevich Frolov, Anatoliy Sergeyevich Kovalev, Artem Valeryevich Ochichenko, Petr Nikolayevich Pliskin.
Image 1 - GRU most wanted poster | Source: FBI
Trends
This indictment is not only impactful from a justice point of view, but also because this is rare occasions that, due to lenient privacy regulations in the United States, the global public gets to know the names and faces behind the malicious activities committed by APT groups. The defendants all belong to Unit 74455 of the GRU – also known as Sandworm. The identified and charged members are: Yuriy Sergeyevich Andrienko, Sergey Vladimirovich Detistov, Pavel Valeryevich Frolov, Anatoliy Sergeyevich Kovalev, Artem Valeryevich Ochichenko, Petr Nikolayevich Pliskin.
Conclusions and Future Implications
Sources
[1] Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure | CISA
[2] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[3] Sandworm: A tale of disruption told anew (welivesecurity.com)
[4] Sandworm: A tale of disruption told anew (welivesecurity.com)
[5] PowerPoint Presentation (hubspotusercontent-eu1.net)
[6] PowerPoint Presentation (hubspotusercontent-eu1.net) p.10
[7] Hunt & Hackett Threat Diagnostic System
[8] PowerPoint Presentation (hubspotusercontent-eu1.net) p.6.
[9] Microsoft Security Bulletin MS14-060 - Important | Microsoft Learn
[10] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[11] Compromise of a power grid in eastern Ukraine | CFR Interactives
[12] PowerPoint Presentation (hubspotusercontent-eu1.net) p. 6
[13] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[14] Liberté, égalité, securité: 4 Threats to the French Presidential Election - ReliaQuest
[15] We need to hold the Kremlin responsible for its 2018 cyberattack on the Olympics - The Washington Post
[16] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[17] NotPetya: the cyberattack that shook the world (indiatimes.com)
[18] Global ransomware attack causes turmoil - BBC News
[19] What are Petya and NotPetya Ransomware? | Malwarebytes
[20] UK and partners condemn GRU cyber attacks against Olympic... - NCSC.GOV.UK
[21] Russia Banned From Winter Olympics by I.O.C. - The New York Times (nytimes.com)
[22] We need to hold the Kremlin responsible for its 2018 cyberattack on the Olympics - The Washington Post
[23] We need to hold the Kremlin responsible for its 2018 cyberattack on the Olympics - The Washington Post
[24] Russia Banned From Winter Olympics by I.O.C. - The New York Times (nytimes.com)
[25] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[26] US and UK call out Russian hackers for Georgia attacks – Naked Security (sophos.com)
[27] Hunt & Hackett Threat Diagnostic System
[28] Hunt & Hackett Threat Diagnostic System
[29] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[30] Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE By Joe Slowik
[31] Valid Accounts, Technique T0859 - ICS | MITRE ATT&CK®
[32] Hunt & Hackett Threat Diagnostic System
[33] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[34] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[35] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[36] Server Software Component, Technique T1505 - Enterprise | MITRE ATT&CK®
[37] Abuse Elevation Control Mechanism, Technique T1548 - Enterprise | MITRE ATT&CK®
[38] Indicator Removal, Technique T1070 - Enterprise | MITRE ATT&CK®
[39] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[40] Obfuscated Files or Information, Technique T1027 - Enterprise | MITRE ATT&CK®
[41] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[42] Hunt & Hackett Threat Diagnostic System
[43] The rise of TeleBots: Analyzing disruptive KillDisk attacks (welivesecurity.com)
[44] Account Discovery, Technique T1087 - Enterprise | MITRE ATT&CK®
[45] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[46] Hunt & Hackett Threat Diagnostic System
[47] Hunt & Hackett Threat Diagnostic System
[48] Lateral Tool Transfer, Technique T1570 - Enterprise | MITRE ATT&CK®
[49] Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE By Joe Slowik p.7.
[50] Remote Services, Technique T1021 - Enterprise | MITRE ATT&CK®
[51] Remote Services, Technique T1021 - Enterprise | MITRE ATT&CK®
[52] Data from Local System, Technique T1005 - Enterprise | MITRE ATT&CK®
[53] Input Capture, Technique T1056 - Enterprise | MITRE ATT&CK®
[54] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[55] The rise of TeleBots: Analyzing disruptive KillDisk attacks (welivesecurity.com)
[56] Proxy, Technique T1090 - Enterprise | MITRE ATT&CK®
[57] The rise of TeleBots: Analyzing disruptive KillDisk attacks (welivesecurity.com)
[58] Remote Access Software, Technique T1219 - Enterprise | MITRE ATT&CK®
[59] Cyber-Attack Against Ukrainian Critical Infrastructure | CISA
[60] Hunt & Hackett Threat Diagnostic System
[61] https://attack.mitre.org/techniques/T1041/
[62] The rise of TeleBots: Analyzing disruptive KillDisk attacks (welivesecurity.com)
[63] Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign - ReliaQuest
[64] Exfiltration Over C2 Channel, Technique T1041 - Enterprise | MITRE ATT&CK®
[65] Cyber-Attack Against Ukrainian Critical Infrastructure | CISA
[66] cr4sh_0x48k: Fuck me, I'm famous (archive.ph) quoted via Google Translate
[67] BlackEnergy (Malware Family) (fraunhofer.de)
[68] Khan et al, Threat Analysis of BlackEnergy Malware for Synchrophasor based Real-time Control and Monitoring in Smart Grid (2016, BCS Learning and Development Ltd.) p.55.
[69] Khan et al, Threat Analysis of BlackEnergy Malware for Synchrophasor based Real-time Control and Monitoring in Smart Grid (2016, BCS Learning and Development Ltd.) p.55.
[70] Sandworm: A tale of disruption told anew (welivesecurity.com)
[71] Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland (welivesecurity.com)
[72] Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland (welivesecurity.com)
[73] Sandworm: A tale of disruption told anew (welivesecurity.com)
[74] BlackEnergy (Malware Family) (fraunhofer.de)
[75] Sandworm: A tale of disruption told anew (welivesecurity.com)
[76] Hunt & Hackett Threat Diagnostic System
[77] What is NotPetya Ransomware & How to Protect Against It in 2023? (comparitech.com)
[78] New Petya / NotPetya / ExPetr ransomware outbreak | Kaspersky official blog
[79] PowerPoint Presentation (hubspotusercontent-eu1.net) p.32.
[80] What is NotPetya Ransomware & How to Protect Against It in 2023? (comparitech.com)
[81] Hunt & Hackett Threat Diagnostic System
[82] PowerPoint Presentation (hubspotusercontent-eu1.net) p.32.
[83] NotPetya (2017) - International cyber law: interactive toolkit (ccdcoe.org)
[84] Oreo Giant Mondelez Settles NotPetya 'Act of War' Insurance Suit (darkreading.com)
[85] The Untold Story of NotPetya, the Most Devastating Cyberattack in History | WIRED
[86] Meet Petya: the new type of Ransomware that… | Nomios Netherlands
[87] Major Russian cyberattack globally halted by intelligence agencies in the Netherlands (securitynewspaper.com)
[88] Sandworm hackers fail to take down Ukrainian energy provider (bleepingcomputer.com)
[89] Russian Hackers Tricked Ukrainians with Fake "DoS Android Apps to Target Russia" (thehackernews.com)
[90] Russian Sandworm Hackers Impersonate Ukrainian Telecoms to Distribute Malware (thehackernews.com)
[91] Russian military hackers linked to ransomware attacks in Ukraine (bleepingcomputer.com)
[92] Russia's Sandworm hackers blamed in fresh Ukraine malware attack | CyberScoop
[95] Ukraine's top mobile operator hit by biggest cyberattack of war | Reuters
[96] Exclusive: Russian hackers were inside Ukraine telecoms giant for months | Reuters
[97] Russian Sandworm hackers targeted 20 critical orgs in Ukraine (bleepingcomputer.com)
[98] Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace: Unsealed Indictment (justice.gov)
[99] Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace: Unsealed Indictment (justice.gov) para.3.
Sint oratio at per, diam saepe dicam ei sea. At civibus appetere cum, quem habeo in. Eam modo apeirian te, ut altera iisque evertitur sit. Cu saperet inermis aliquando nam, per impetus qualisque interesset ex, vix at omittantur instructior disputationi.
