September 7, 2026
Updated: September 7, 2026
The rare threat group that turns network access into physical consequence: two grid blackouts, the costliest cyberattack ever, and a steady supply of wipers.
Abdalla Mohamed

Updated: September 2026
Sandworm is Russia's most destructive cyberwar unit, tied to military intelligence (GRU) Unit 74455 and tracked in MITRE ATT&CK as G0034. Active since at least 2009, it is also called APT44, Seashell Blizzard, Voodoo Bear, and Telebots. Sandworm is unique for causing real-world physical harm: it caused the first cyberattack-driven power blackouts in Ukraine (2015 and 2016), unleashed the NotPetya worm that did roughly $10 billion in global damage (2017), and still deploys data-wiping malware against critical infrastructure across Ukraine and Europe today.

Sandworm is a Russian state-sponsored threat group that specializes in disruptive and destructive attacks rather than quiet espionage. It is attributed to Unit 74455 of the GRU, specifically the Main Centre for Special Technologies (GTsST), and it is the sharpest edge of Russia's cyber operations in Ukraine. In 2024, Mandiant elevated the group to a full APT designation, APT44, reflecting its status as one of the most active and dangerous nation-state actors in the world.
What sets Sandworm apart is a rare willingness to cross from data theft into kinetic effect. Most nation-state groups, including Russia's own APT28 (Fancy Bear) and APT29 (Cozy Bear), focus on intelligence collection. Sandworm targets the industrial control systems (ICS) and operational technology (OT) that run power grids, heating plants, and water systems, and it is comfortable turning the lights off. That makes it a defining actor in the state-sponsored APT landscape and a permanent fixture on any list of the world's most dangerous hacking groups.
Its targets span government, military, energy, water, telecommunications, transportation and logistics, media, and even the grain sector, concentrated in Ukraine but reaching NATO countries, the United States, and beyond.
Sandworm carries one of the longest alias lists in threat intelligence because vendors, governments, and Ukraine's CERT-UA all track it under different labels.
| Alias | Assigned by |
|---|---|
| Sandworm / Sandworm Team | Community (MITRE G0034) |
| APT44 | Mandiant (current designation) |
| Seashell Blizzard | Microsoft |
| Voodoo Bear | CrowdStrike |
| Telebots | ESET |
| Iron Viking | Secureworks |
| ELECTRUM | Dragos (ICS activity) |
| BlackEnergy Group / Quedagh | early reporting |
| UAC-0002, UAC-0113, UAC-0145 | CERT-UA (activity clusters) |
The name to anchor on is Sandworm, but a Microsoft report on Seashell Blizzard, a Mandiant report on APT44, and a CERT-UA advisory on UAC-0145 can all describe the same GRU unit.
The reason Sandworm gets its own profile is intent. It is a cyber-physical sabotage unit whose job is to disrupt, destroy, and destabilize in support of Russian strategic goals. Where espionage groups want to stay hidden and keep stealing, Sandworm frequently wants systems down and data gone, and it accepts the attention that causes.
That mission shows up in its tooling. Sandworm is the pioneer of grid-attacking ICS malware and the most prolific user of wiper malware, software designed to erase drives and render systems unbootable so recovery means rebuilding from backups. It has also blended sabotage with information operations, disguising attacks as ransomware or hacktivism to muddy attribution. For defenders, the practical implication is that a Sandworm intrusion is not just a data-loss risk, it is an availability and safety risk to physical operations.
Sandworm's history reads like a timeline of the most damaging cyber operations ever recorded.
On December 23, 2015, Sandworm used spear-phishing to breach three Ukrainian energy companies, stole SCADA credentials with the BlackEnergy malware, remotely opened circuit breakers, and cut power to around 230,000 people in the Ivano-Frankivsk region. It then wiped systems with KillDisk and flooded call centers to slow the response. It was the first confirmed cyberattack to cause a power blackout.
A year later, on December 17, 2016, Sandworm struck a transmission substation in Kyiv with Industroyer, also called CRASHOVERRIDE, the first malware ever purpose-built to attack electric grids. It could speak native ICS protocols to control substation switches directly, a major escalation over the manual 2015 attack.
On June 27, 2017, Sandworm pushed the NotPetya worm through a hijacked update of M.E.Doc, a Ukrainian accounting program, in a textbook software supply chain attack. Using the EternalBlue exploit and credential theft to spread automatically, NotPetya masqueraded as ransomware but was designed to be irreversible. It escaped Ukraine and hit Maersk, Merck, FedEx subsidiary TNT Express, and the Heritage Valley Health System, causing roughly $10 billion in global damage. This is why treating a ransomware note as the whole story is a mistake, and why groups that pose as ransomware operators deserve scrutiny.
In February 2018, Sandworm sabotaged the PyeongChang Winter Olympics opening ceremony with Olympic Destroyer, planting false flags to frame North Korea. It also targeted the OPCW investigation into the Novichok poisoning, and in October 2019 defaced roughly 15,000 websites in Georgia.
In October 2020, the US Department of Justice indicted six GRU Unit 74455 officers by name for the 2015 and 2016 blackouts, NotPetya, the French election targeting, and Olympic Destroyer, calling the campaign among the most destructive in history. The charges named the unit publicly but did not slow it down.
After Russia's invasion, Sandworm attempted a fresh grid attack with Industroyer2, disrupted Viasat KA-SAT satellite modems with the AcidRain wiper, ran the Prestige fake-ransomware campaign against Ukrainian and Polish logistics, and maintained the Cyclops Blink botnet on network devices, the successor to its earlier VPNFilter platform.
Sandworm knocked out Kyivstar, Ukraine's largest mobile operator, in December 2023, deployed the SwiftSlicer wiper, and used the Infamous Chisel malware to steal data from Android devices belonging to the Ukrainian military. In January 2024 it used the FrostyGoop ICS malware to cut heating to hundreds of apartment buildings in Lviv during winter, one of the few known cases of OT malware directly affecting civilian services.
In February 2025, Microsoft detailed BadPilot, a Sandworm subgroup running a multi-year initial-access campaign by exploiting n-day vulnerabilities in internet-facing systems (including ConnectWise ScreenConnect, CVE-2024-1709, and Fortinet FortiClient EMS, CVE-2023-48788) to establish persistence ahead of destructive attacks. Through 2025 and into 2026, Sandworm kept deploying wipers such as ZEROLOT, Sting, and ZOV, and in late December 2025 it attempted to wipe Poland's power grid with new malware named DynoWiper, almost exactly ten years after the first Ukraine blackout. In August 2026, CERT-UA tied the subgroup UAC-0145 to fake job interviews that pushed a trojanized WireGuard VPN client capable of running arbitrary commands.
Sandworm's MITRE ATT&CK group ID is G0034. Searching for Sandworm MITRE surfaces the full catalog; the techniques below recur across its campaigns and map to its destructive playbook.
| Technique | ATT&CK ID | How Sandworm uses it |
|---|---|---|
| Phishing: spear-phishing attachment | T1566.001 | Initial access to energy and government networks |
| Exploit public-facing application | T1190 | BadPilot n-day exploitation for persistence |
| Supply chain compromise | T1195.002 | Trojanized M.E.Doc update delivering NotPetya |
| Valid accounts | T1078 | Stolen SCADA and domain credentials |
| Data destruction / disk wipe | T1485, T1561 | KillDisk, AcidRain, SwiftSlicer, ZEROLOT, DynoWiper |
| Inhibit system recovery | T1490 | Rendering systems unbootable |
| Block command message (ICS) | T0803 | Cutting operator control of substations |
| Device restart / shutdown (ICS) | T0816 | Opening breakers to cause outages |
Its malware ecosystem includes BlackEnergy, KillDisk, Industroyer and Industroyer2, NotPetya, Olympic Destroyer, Cyclops Blink, AcidRain, Prestige, SwiftSlicer, Infamous Chisel, FrostyGoop, and the newer ZEROLOT, ZOV, and DynoWiper wipers, alongside legitimate tools it abuses for stealth.
The 2015 Ukraine blackout remains the clearest public model of a Sandworm cyber-physical operation.
The attack combined living off the land with targeted destruction, and it showed that the IT-to-OT boundary is the decisive terrain in grid defense.
Sandworm wins by crossing from IT into OT, moving fast on new vulnerabilities, and destroying rather than stealing, so defenses should harden that boundary, shorten exposure, and make recovery survivable. Validate each control with real testing rather than assuming it holds.
Rigorously segment operational technology from corporate IT, enforce strict access control and monitoring at the boundary, and require phishing-resistant multifactor authentication for any remote access into control networks. Most Sandworm grid operations begin in IT and pivot to OT, so the crossing point is where detection pays off most. Power and utility operators should treat power-sector cyber defense as a distinct discipline, informed by energy-sector attack data.
The BadPilot campaign shows Sandworm exploiting n-day flaws in VPNs, email servers, and remote-management tools to gain a foothold. Prioritize rapid patch management on everything internet-facing and reduce your attack surface so there are fewer doors to force. Watch for abuse of legitimate remote-management tools like Atera and Splashtop, which the group uses to blend in.
Because Sandworm destroys data, assume a wiper will succeed somewhere and plan for it: maintain tested, offline, immutable backups, and rehearse full rebuilds. Vet third-party software updates and service providers, since NotPetya proved a trusted update can be the delivery vehicle. A well-practiced incident response plan built for destructive, availability-first attacks is not optional against this actor.
Assumptions about IT-to-OT segmentation, patch speed, and backup recovery are exactly what Sandworm exploits. Regular penetration testing and red team exercises prove whether a phishing foothold could really reach your control systems, and whether you could actually recover from a wiper, before the GRU tests it for you.
Sandworm broke the assumption that cyberattacks stay in cyberspace. It has turned off power in winter, halted global shipping through Maersk, disrupted an Olympics, and cut heating to homes, using code to produce physical consequences. For any organization running critical infrastructure or industrial systems, it is the clearest proof that IT security and physical safety are now the same problem.
Even organizations that will never be targeted by the GRU should learn from Sandworm's methods, because n-day exploitation, wiper malware, supply chain compromise, and IT-to-OT pivots are spreading to criminal and hacktivist actors. Building resilience against destruction, not just against theft, is the lesson Sandworm keeps teaching, and it applies to nearly every industry attackers target.
Sandworm is a Russian state-sponsored hacking group specializing in destructive cyberattacks, attributed to GRU military intelligence Unit 74455 and tracked as MITRE ATT&CK G0034. Active since at least 2009, it is also known as APT44, Seashell Blizzard, Voodoo Bear, and Telebots, and it is best known for attacking critical infrastructure.
Sandworm is Unit 74455 of Russia's GRU, its military intelligence agency, specifically the Main Centre for Special Technologies. In 2020 the US Department of Justice indicted six named GRU officers from the unit for attacks including the Ukraine blackouts, NotPetya, and Olympic Destroyer.
Sandworm Team's MITRE ATT&CK group identifier is G0034. The catalog maps it to techniques including spear-phishing (T1566.001), supply chain compromise (T1195.002), data destruction (T1485), and ICS techniques for blocking control messages and shutting down devices.
Yes. APT44 is the designation Mandiant assigned to Sandworm in 2024 when it elevated the group to a formal advanced persistent threat. Sandworm, APT44, Seashell Blizzard, and Voodoo Bear all refer to the same GRU Unit 74455.
NotPetya was a destructive worm Sandworm released in June 2017 through a hijacked update of Ukrainian accounting software. Disguised as ransomware but built to be irreversible, it spread worldwide and caused roughly $10 billion in damage, making it the most costly cyberattack in history.
Both are GRU units, but APT28 (Unit 26165, Fancy Bear) focuses on espionage and hack-and-leak operations, while Sandworm (Unit 74455) specializes in destructive and disruptive attacks on critical infrastructure. They have occasionally supported the same operations but have distinct missions.
Running critical infrastructure or industrial systems? DeepStrike's penetration testing and red team services stress-test your IT-to-OT boundary, patch speed, and wiper recovery the way Sandworm would. Explore our penetration testing services to find the gaps before an adversary does.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us