logo svg
logo

September 7, 2026

Updated: September 7, 2026

Sandworm (APT44): Ukraine, Wipers & Grid Attacks

The rare threat group that turns network access into physical consequence: two grid blackouts, the costliest cyberattack ever, and a steady supply of wipers.

Abdalla Mohamed

Featured Image

Updated: September 2026

The quick answer

Sandworm is Russia's most destructive cyberwar unit, tied to military intelligence (GRU) Unit 74455 and tracked in MITRE ATT&CK as G0034. Active since at least 2009, it is also called APT44, Seashell Blizzard, Voodoo Bear, and Telebots. Sandworm is unique for causing real-world physical harm: it caused the first cyberattack-driven power blackouts in Ukraine (2015 and 2016), unleashed the NotPetya worm that did roughly $10 billion in global damage (2017), and still deploys data-wiping malware against critical infrastructure across Ukraine and Europe today.

What is Sandworm?

What is Sandworm?

Sandworm is a Russian state-sponsored threat group that specializes in disruptive and destructive attacks rather than quiet espionage. It is attributed to Unit 74455 of the GRU, specifically the Main Centre for Special Technologies (GTsST), and it is the sharpest edge of Russia's cyber operations in Ukraine. In 2024, Mandiant elevated the group to a full APT designation, APT44, reflecting its status as one of the most active and dangerous nation-state actors in the world.

What sets Sandworm apart is a rare willingness to cross from data theft into kinetic effect. Most nation-state groups, including Russia's own APT28 (Fancy Bear) and APT29 (Cozy Bear), focus on intelligence collection. Sandworm targets the industrial control systems (ICS) and operational technology (OT) that run power grids, heating plants, and water systems, and it is comfortable turning the lights off. That makes it a defining actor in the state-sponsored APT landscape and a permanent fixture on any list of the world's most dangerous hacking groups.

Its targets span government, military, energy, water, telecommunications, transportation and logistics, media, and even the grain sector, concentrated in Ukraine but reaching NATO countries, the United States, and beyond.

The many names of Sandworm

Sandworm carries one of the longest alias lists in threat intelligence because vendors, governments, and Ukraine's CERT-UA all track it under different labels.

AliasAssigned by
Sandworm / Sandworm TeamCommunity (MITRE G0034)
APT44Mandiant (current designation)
Seashell BlizzardMicrosoft
Voodoo BearCrowdStrike
TelebotsESET
Iron VikingSecureworks
ELECTRUMDragos (ICS activity)
BlackEnergy Group / Quedaghearly reporting
UAC-0002, UAC-0113, UAC-0145CERT-UA (activity clusters)

The name to anchor on is Sandworm, but a Microsoft report on Seashell Blizzard, a Mandiant report on APT44, and a CERT-UA advisory on UAC-0145 can all describe the same GRU unit.

What makes Sandworm different: destruction over espionage

The reason Sandworm gets its own profile is intent. It is a cyber-physical sabotage unit whose job is to disrupt, destroy, and destabilize in support of Russian strategic goals. Where espionage groups want to stay hidden and keep stealing, Sandworm frequently wants systems down and data gone, and it accepts the attention that causes.

That mission shows up in its tooling. Sandworm is the pioneer of grid-attacking ICS malware and the most prolific user of wiper malware, software designed to erase drives and render systems unbootable so recovery means rebuilding from backups. It has also blended sabotage with information operations, disguising attacks as ransomware or hacktivism to muddy attribution. For defenders, the practical implication is that a Sandworm intrusion is not just a data-loss risk, it is an availability and safety risk to physical operations.

Major Sandworm attacks

Sandworm's history reads like a timeline of the most damaging cyber operations ever recorded.

2015: the first blackout (BlackEnergy and KillDisk)

On December 23, 2015, Sandworm used spear-phishing to breach three Ukrainian energy companies, stole SCADA credentials with the BlackEnergy malware, remotely opened circuit breakers, and cut power to around 230,000 people in the Ivano-Frankivsk region. It then wiped systems with KillDisk and flooded call centers to slow the response. It was the first confirmed cyberattack to cause a power blackout.

2016: Industroyer hits Kyiv

A year later, on December 17, 2016, Sandworm struck a transmission substation in Kyiv with Industroyer, also called CRASHOVERRIDE, the first malware ever purpose-built to attack electric grids. It could speak native ICS protocols to control substation switches directly, a major escalation over the manual 2015 attack.

2017: NotPetya, the most costly cyberattack in history

On June 27, 2017, Sandworm pushed the NotPetya worm through a hijacked update of M.E.Doc, a Ukrainian accounting program, in a textbook software supply chain attack. Using the EternalBlue exploit and credential theft to spread automatically, NotPetya masqueraded as ransomware but was designed to be irreversible. It escaped Ukraine and hit Maersk, Merck, FedEx subsidiary TNT Express, and the Heritage Valley Health System, causing roughly $10 billion in global damage. This is why treating a ransomware note as the whole story is a mistake, and why groups that pose as ransomware operators deserve scrutiny.

2018 to 2019: Olympic Destroyer and Georgia

In February 2018, Sandworm sabotaged the PyeongChang Winter Olympics opening ceremony with Olympic Destroyer, planting false flags to frame North Korea. It also targeted the OPCW investigation into the Novichok poisoning, and in October 2019 defaced roughly 15,000 websites in Georgia.

2020: the US indictment

In October 2020, the US Department of Justice indicted six GRU Unit 74455 officers by name for the 2015 and 2016 blackouts, NotPetya, the French election targeting, and Olympic Destroyer, calling the campaign among the most destructive in history. The charges named the unit publicly but did not slow it down.

2022: full-scale war

After Russia's invasion, Sandworm attempted a fresh grid attack with Industroyer2, disrupted Viasat KA-SAT satellite modems with the AcidRain wiper, ran the Prestige fake-ransomware campaign against Ukrainian and Polish logistics, and maintained the Cyclops Blink botnet on network devices, the successor to its earlier VPNFilter platform.

2023 to 2024: telecom, mobile, and heating

Sandworm knocked out Kyivstar, Ukraine's largest mobile operator, in December 2023, deployed the SwiftSlicer wiper, and used the Infamous Chisel malware to steal data from Android devices belonging to the Ukrainian military. In January 2024 it used the FrostyGoop ICS malware to cut heating to hundreds of apartment buildings in Lviv during winter, one of the few known cases of OT malware directly affecting civilian services.

2025 to 2026: BadPilot and a new wave of wipers

In February 2025, Microsoft detailed BadPilot, a Sandworm subgroup running a multi-year initial-access campaign by exploiting n-day vulnerabilities in internet-facing systems (including ConnectWise ScreenConnect, CVE-2024-1709, and Fortinet FortiClient EMS, CVE-2023-48788) to establish persistence ahead of destructive attacks. Through 2025 and into 2026, Sandworm kept deploying wipers such as ZEROLOT, Sting, and ZOV, and in late December 2025 it attempted to wipe Poland's power grid with new malware named DynoWiper, almost exactly ten years after the first Ukraine blackout. In August 2026, CERT-UA tied the subgroup UAC-0145 to fake job interviews that pushed a trojanized WireGuard VPN client capable of running arbitrary commands.

Sandworm tactics, malware, and MITRE ATT&CK techniques

Sandworm's MITRE ATT&CK group ID is G0034. Searching for Sandworm MITRE surfaces the full catalog; the techniques below recur across its campaigns and map to its destructive playbook.

TechniqueATT&CK IDHow Sandworm uses it
Phishing: spear-phishing attachmentT1566.001Initial access to energy and government networks
Exploit public-facing applicationT1190BadPilot n-day exploitation for persistence
Supply chain compromiseT1195.002Trojanized M.E.Doc update delivering NotPetya
Valid accountsT1078Stolen SCADA and domain credentials
Data destruction / disk wipeT1485, T1561KillDisk, AcidRain, SwiftSlicer, ZEROLOT, DynoWiper
Inhibit system recoveryT1490Rendering systems unbootable
Block command message (ICS)T0803Cutting operator control of substations
Device restart / shutdown (ICS)T0816Opening breakers to cause outages

Its malware ecosystem includes BlackEnergy, KillDisk, Industroyer and Industroyer2, NotPetya, Olympic Destroyer, Cyclops Blink, AcidRain, Prestige, SwiftSlicer, Infamous Chisel, FrostyGoop, and the newer ZEROLOT, ZOV, and DynoWiper wipers, alongside legitimate tools it abuses for stealth.

A Sandworm grid attack, step by step

The 2015 Ukraine blackout remains the clearest public model of a Sandworm cyber-physical operation.

  1. Spear-phishing. Sandworm sent booby-trapped Office documents to staff at three regional energy companies, delivering the BlackEnergy backdoor when macros were enabled.
  2. Foothold and recon. From the corporate IT network it harvested credentials, mapped the environment, and identified the path into the SCADA systems that control the grid.
  3. Cross into OT. Using stolen valid accounts and remote-access tools, it pivoted from IT into the operational technology network, the boundary that should never be easy to cross.
  4. Physical impact. Operators watched as the intruders remotely opened circuit breakers across substations, cutting power to around 230,000 people.
  5. Slow the recovery. Sandworm overwrote firmware on serial-to-ethernet converters, wiped workstations with KillDisk, and launched a telephone denial-of-service flood against call centers to delay restoration.

The attack combined living off the land with targeted destruction, and it showed that the IT-to-OT boundary is the decisive terrain in grid defense.

How to defend against Sandworm

Sandworm wins by crossing from IT into OT, moving fast on new vulnerabilities, and destroying rather than stealing, so defenses should harden that boundary, shorten exposure, and make recovery survivable. Validate each control with real testing rather than assuming it holds.

Segment and defend IT from OT

Rigorously segment operational technology from corporate IT, enforce strict access control and monitoring at the boundary, and require phishing-resistant multifactor authentication for any remote access into control networks. Most Sandworm grid operations begin in IT and pivot to OT, so the crossing point is where detection pays off most. Power and utility operators should treat power-sector cyber defense as a distinct discipline, informed by energy-sector attack data.

Patch internet-facing systems fast

The BadPilot campaign shows Sandworm exploiting n-day flaws in VPNs, email servers, and remote-management tools to gain a foothold. Prioritize rapid patch management on everything internet-facing and reduce your attack surface so there are fewer doors to force. Watch for abuse of legitimate remote-management tools like Atera and Splashtop, which the group uses to blend in.

Build wiper and supply chain resilience

Because Sandworm destroys data, assume a wiper will succeed somewhere and plan for it: maintain tested, offline, immutable backups, and rehearse full rebuilds. Vet third-party software updates and service providers, since NotPetya proved a trusted update can be the delivery vehicle. A well-practiced incident response plan built for destructive, availability-first attacks is not optional against this actor.

Test your defenses like an adversary would

Assumptions about IT-to-OT segmentation, patch speed, and backup recovery are exactly what Sandworm exploits. Regular penetration testing and red team exercises prove whether a phishing foothold could really reach your control systems, and whether you could actually recover from a wiper, before the GRU tests it for you.

Why this matters for security teams

Sandworm broke the assumption that cyberattacks stay in cyberspace. It has turned off power in winter, halted global shipping through Maersk, disrupted an Olympics, and cut heating to homes, using code to produce physical consequences. For any organization running critical infrastructure or industrial systems, it is the clearest proof that IT security and physical safety are now the same problem.

Even organizations that will never be targeted by the GRU should learn from Sandworm's methods, because n-day exploitation, wiper malware, supply chain compromise, and IT-to-OT pivots are spreading to criminal and hacktivist actors. Building resilience against destruction, not just against theft, is the lesson Sandworm keeps teaching, and it applies to nearly every industry attackers target.

FAQ

What is Sandworm?

Sandworm is a Russian state-sponsored hacking group specializing in destructive cyberattacks, attributed to GRU military intelligence Unit 74455 and tracked as MITRE ATT&CK G0034. Active since at least 2009, it is also known as APT44, Seashell Blizzard, Voodoo Bear, and Telebots, and it is best known for attacking critical infrastructure.

Who is behind Sandworm?

Sandworm is Unit 74455 of Russia's GRU, its military intelligence agency, specifically the Main Centre for Special Technologies. In 2020 the US Department of Justice indicted six named GRU officers from the unit for attacks including the Ukraine blackouts, NotPetya, and Olympic Destroyer.

What is Sandworm's MITRE ATT&CK ID?

Sandworm Team's MITRE ATT&CK group identifier is G0034. The catalog maps it to techniques including spear-phishing (T1566.001), supply chain compromise (T1195.002), data destruction (T1485), and ICS techniques for blocking control messages and shutting down devices.

Is Sandworm the same as APT44?

Yes. APT44 is the designation Mandiant assigned to Sandworm in 2024 when it elevated the group to a formal advanced persistent threat. Sandworm, APT44, Seashell Blizzard, and Voodoo Bear all refer to the same GRU Unit 74455.

What was NotPetya?

NotPetya was a destructive worm Sandworm released in June 2017 through a hijacked update of Ukrainian accounting software. Disguised as ransomware but built to be irreversible, it spread worldwide and caused roughly $10 billion in damage, making it the most costly cyberattack in history.

How is Sandworm different from APT28?

Both are GRU units, but APT28 (Unit 26165, Fancy Bear) focuses on espionage and hack-and-leak operations, while Sandworm (Unit 74455) specializes in destructive and disruptive attacks on critical infrastructure. They have occasionally supported the same operations but have distinct missions.

Running critical infrastructure or industrial systems? DeepStrike's penetration testing and red team services stress-test your IT-to-OT boundary, patch speed, and wiper recovery the way Sandworm would. Explore our penetration testing services to find the gaps before an adversary does.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us