Skip to content
← All Threat Actors
Nation-State critical Russia

Sandworm

Russian state-sponsored (GRU Unit 74455) · Destructive / disruptive attacks / pre-positioning in critical infrastructure

Reports 1
Active Since 2009
Last Reported 27 May 2026
Sectors Targeted critical-infrastructure, ot-ics, government, communications, transport

Tactics, Techniques & Procedures (TTPs)

  • ICS-targeting malware development (Industroyer, Industroyer2, CrashOverride) speaking native OT protocols
  • Wiper malware deployment at scale (HermeticWiper, CaddyWiper, IsaacWiper, WhisperGate, Prestige)
  • Supply chain compromise for mass distribution (NotPetya via M.E.Doc accounting software)
  • Spear-phishing for initial IT network access followed by OT pivot
  • Web shell deployment for persistent server-side access
  • False flag operations to mislead attribution (Olympic Destroyer)
  • Pre-positioning reconnaissance within Western CNI

Known Targets

Ukrainian power grid (2015, 2016, 2022)Global logistics and shipping (Maersk, TNT -- NotPetya collateral)Ukrainian government ministries, media, and financial institutionsPolish logistics operators (Prestige campaign)Olympic Games infrastructure (2018)European critical infrastructure (pre-positioning)

Analyst Notes

GRU Unit 74455, the Main Centre for Special Technologies. Assessed by Mandiant, NCSC, and Five Eyes intelligence services as the most dangerous offensive cyber actor currently operating. Responsible for the only confirmed cyberattacks to cause power outages (2015, 2016, 2022 -- all Ukraine), NotPetya (the most destructive cyberattack in history, $10B+ in damages), and Olympic Destroyer. Continuous wiper campaigns against Ukraine since February 2022 have demonstrated a pace of novel malware development unmatched by any other actor. The ICS protocols Industroyer targets -- IEC 60870-5-101, IEC 60870-5-104, IEC 61850 -- are used in power infrastructure globally. The capability is portable beyond Ukraine.

Also Known As

APT44Voodoo BearIRIDIUMSeashell BlizzardTeleBots