Sandworm Team is a Russian military cyber unit operated by the GRU's Main Center for Special Technologies (GTsST, military unit 74455), and is assessed by multiple governments and private-sector researchers to be the most destructive nation-state cyber actor documented to date. Active since at least 2009 and elevated by Mandiant to full named-APT status as APT44 in April 2024 (Mandiant/Google Cloud, "APT44: Unearthing Sandworm," Apr 2024), the group is the only actor tracked in this project's roster with a confirmed, repeated record of using cyber intrusions to cause physical disruption to critical infrastructure — the December 2015 and December 2016 Ukrainian power grid attacks, and the April 2022 Industroyer2 operation against a Ukrainian transmission substation during the ongoing invasion.
The group matters acutely right now because it remains one of the most operationally active pieces of Russia's war effort against Ukraine. Independent OT telemetry from Nozomi Networks identified 29 confirmed Sandworm-linked incidents across ten industrial organizations in seven countries between July 2025 and January 2026 (Nozomi Networks, "Sandworm Activity in Industrial Environments," 2026), and the group sustained a wiper campaign against Ukrainian energy, logistics, and grain-sector organizations from October 2024 through at least March 2025 using a new destructive tool tracked as ZEROLOT. Separately, Fieldeffect and other researchers documented a 2025 tactical shift away from expensive zero-day exploitation toward compromising misconfigured or end-of-life edge devices — VPN concentrators, enterprise routers, remote-access gateways — against North American and European energy-sector targets, a shift significant enough that CISA issued a mandatory federal order to identify and replace unsupported edge devices in response (Fieldeffect, 2025; Federal News Network, 2026).
Sandworm is the direct originator of the Industroyer malware family — the first and, to date, only malware demonstrated to have caused an electrical blackout through purpose-built, ICS-protocol-native code rather than generic IT destruction — and its NotPetya wiper remains the single most expensive cyberattack in recorded history, with White House and industry loss estimates exceeding $10 billion globally despite the malware never having functioned as real ransomware. A full case-file account of NotPetya's impact on one victim organization, Maersk, is documented in this project's companion incident card (see incident card: Maersk NotPetya, 2017-06-27), which this profile treats as authoritative on that specific operation and does not duplicate here.
Operationally, nearly everything Sandworm has done since February 2022 sits inside the context of Russia's full-scale invasion of Ukraine — the group functions as a forward-deployed cyber-sabotage arm supporting battlefield and economic-pressure objectives, and its targeting has expanded in step with the war's phases, from initial destructive wiper waves at the invasion's outset, to sustained grid and logistics targeting through 2024–2025, to a 2025–2026 pivot toward pre-positioning inside Western critical infrastructure that several governments now assess as preparation for potential future leverage rather than purely Ukraine-focused activity.
[HIGH] — this identity rests on an unusually dense stack of independent, high-confidence corroboration for a nation-state APT: a named U.S. federal criminal indictment identifying six specific GRU officers by name and unit; formal UK NCSC attribution statements naming GTsST/Unit 74455 directly (Georgia, 2019/2020); coordinated multi-government attribution of NotPetya (Feb 2018); and a stable, continuously-tracked technical cluster followed independently by ESET (as Telebots/BlackEnergy since ~2014), Dragos (ELECTRUM), CrowdStrike (Voodoo Bear), and Microsoft (Seashell Blizzard) that converges on the same infrastructure and toolset lineage. Mandiant's April 2024 decision to graduate the cluster to APT44 status was itself a confirmation of this convergence rather than a new attribution claim. The one area of genuine attribution nuance is discussed in Section 08: several 2022 wiper incidents (notably WhisperGate) have been attributed by different vendors to an adjacent-but-distinct GRU-linked cluster (Cadet Blizzard/Ember Bear), and this profile does not fold that activity into Sandworm's core record.
Sandworm's entry vectors have shifted materially across its operational lifetime without ever fully abandoning earlier techniques. The 2014–2016 grid-attack era relied on spearphishing with malicious Office macros against energy-sector staff, followed by long-dwell lateral movement into ICS-adjacent networks before any destructive action (SANS/E-ISAC, 2016). NotPetya (2017) used a software supply-chain compromise instead — a hijacked update mechanism for Ukrainian tax software M.E.Doc — demonstrating the group's willingness to weaponize trusted software distribution channels for indiscriminate, self-propagating impact (see incident card: Maersk NotPetya). Since 2025, the dominant entry vector has become opportunistic exploitation of internet-exposed, misconfigured, or end-of-life edge devices — VPN concentrators, routers, remote-access gateways — reached through exposed management interfaces rather than novel vulnerability research (Fieldeffect, 2025).
The group's toolchain splits cleanly into two tiers. For IT-layer access, lateral movement, and credential theft, Sandworm relies on a largely dual-use, commodity-adjacent kit — Cobalt Strike, Impacket, Mimikatz-derived credential dumping, PsExec/WMI for lateral tool transfer — indistinguishable at the tooling level from many other intrusion sets. For the OT/ICS layer, by contrast, the group has repeatedly demonstrated a rare, resource-intensive capability to build purpose-specific malware: Industroyer and Industroyer2 contain protocol-native modules for IEC 60870-5-101/104, IEC 61850, and OPC DA that issue what look like entirely legitimate operator commands directly to substation relays and RTUs, rather than exploiting a software vulnerability. Industroyer2 in particular was compiled specifically for one victim's exact substation configuration only weeks before its April 2022 deployment (ESET, 2022) — a level of target-specific OT engineering investment that most nation-state actors do not undertake.
Command and control has evolved from conventional web-protocol beaconing toward more resilient, harder-to-attribute infrastructure: Cyclops Blink, disclosed by NCSC/CISA in February 2022, embeds directly in WatchGuard Firebox and ASUS router firmware as a successor to the earlier VPNFilter botnet, giving the group a distributed, edge-device-resident C2 mesh that survives conventional endpoint remediation because it never touches the monitored host OS. Persistence at the IT layer uses account manipulation, scheduled tasks, and legitimate-service masquerading (the Exaramel backdoor registers as an ordinary Windows service). Exfiltration is comparatively limited and secondary to the group's core destructive/sabotage mission — data theft, where observed, appears oriented toward operational reconnaissance for follow-on targeting rather than bulk collection. The defining signature of Sandworm's most severe operations is the deliberate pairing of an ICS-impact payload with an anti-forensic wiper timed to detonate shortly afterward — Industroyer2 was followed roughly ten minutes later by CaddyWiper specifically to erase evidence of the substation-layer attack before defenders could triage it (ESET, 2022).
| Type | Value / Description | Source | Date |
|---|---|---|---|
| MALWARE | NotPetya (aka ExPetr / "GoldenEye" variant) | DOJ indictment | 2020-10-15 |
| MALWARE | Industroyer2 | ESET WeLiveSecurity | 2022-04-12 |
| MALWARE | Cyclops Blink (WatchGuard/ASUS firmware implant) | NCSC / CISA Joint Advisory | 2022-02-23 |
| CVE | CVE-2017-0144 (EternalBlue) — NotPetya lateral-spread mechanism | DOJ indictment / ESET | 2020-10-15 |
| PROTOCOL | IEC 60870-5-104 (TCP/2404) — abused for Industroyer2 substation command injection | ESET WeLiveSecurity | 2022-04-12 |
| MALWARE | ZEROLOT / Sting wiper family | ESET APT Activity Report | 2025-Q1 |
| NOTE | Specific network indicators (C2 IPs/domains) for the active 2025–2026 edge-device campaign were not captured in this research pass — consult current CISA/joint advisory bulletins for operational indicator sets as of compile date. | — | 2026-09-02 |
Sandworm is assessed at CRITICAL threat level on the strength of a record no other actor in this project's roster can match: it is the only group with confirmed, repeated success causing physical infrastructure disruption through cyber means (2015, 2016, and the foiled-but-otherwise-complete 2022 grid attacks), and it authored the single most expensive cyberattack in recorded history by direct and indirect cost. The most dangerous capability is not any single tool but the demonstrated willingness and engineering capacity to build victim-specific ICS protocol malware — Industroyer2's substation-specific compilation just weeks before use reflects an investment of OT-engineering effort that most nation-state actors, even sophisticated ones, do not undertake for a single target.
The clearest analytical gap in this profile is real-time indicator visibility. Open-source reporting through early 2026 documents the 2025 tactical shift toward edge-device compromise and credential-replay lateral movement in rich methodological detail, but the specific C2 infrastructure, IPs, and domains behind that campaign were not surfaced in this research pass — likely because the campaign is still active and current indicator sets are being managed operationally through CISA/vendor advisory channels rather than static public writeups. This is a meaningful limitation for anyone using this card for near-term defensive tuning; consult current advisories directly for that layer.
One attribution nuance deserves explicit flagging rather than silent smoothing-over: WhisperGate, deployed against Ukrainian government systems in January 2022, has been attributed with varying confidence to different clusters — CrowdStrike names Ember Bear, Microsoft names Cadet Blizzard, while ESET's broader assessment credits Sandworm with the majority of 2022 Ukraine wiper activity without necessarily including WhisperGate specifically in that count. This profile treats Cadet Blizzard/Ember Bear as an adjacent-but-distinct GRU-linked cluster and does not fold WhisperGate into Sandworm's confirmed record — a competing hypothesis exists that these are the same operators using deliberately inconsistent tradecraft, but the independent tracking convergence that supports Sandworm's core identity (Section 01) does not extend cleanly to this specific incident.
A separate non-finding is worth recording for anyone cross-referencing recent news: a self-replicating npm supply-chain worm publicly named "SANDWORM_MODE" was disclosed by Socket Research Team in February 2026, targeting JavaScript developer tooling and AI coding assistants. No source reviewed in this research pass provides a confirmed attribution link between that campaign and GRU Unit 74455 — the name appears to be a thematic reference (in the lineage of the "Shai-Hulud" npm worm, itself a Dune reference) rather than an attributed Sandworm operation, and this profile deliberately excludes it from Section 06 to avoid manufacturing a false attribution through name-matching alone. Forward trajectory: the group's 2025–2026 activity pattern — slower new-victim acquisition per Nozomi's OT telemetry, combined with a pivot toward lower-cost, higher-persistence edge-device and credential-based access — reads as a shift toward sustainable long-war positioning rather than a capability decline, consistent with an actor settling in for prolonged conflict rather than seeking rapid, high-visibility effects.