TLP:CLEAR
⚠ NATION-STATE · GRU / MAIN INTELLIGENCE DIRECTORATE · RUSSIA
// Threat Actor Profile — Military Intelligence Cyber-Sabotage & ICS/OT Destruction Unit

SANDWORM TEAM

PROFILE COMPILED: 2026-09-02  |  SOURCES: MITRE ATT&CK, DOJ, U.S. Treasury, UK NCSC, CISA, Mandiant/Google Cloud, ESET, Dragos, Microsoft, CrowdStrike, Nozomi Networks, AttackIQ
Status: ACTIVE
Threat Level: CRITICAL
Primary Motive: Sabotage / Military Advantage / Coercion
Active Since: ≥2009 (assessed)
MITRE ATT&CK: G0034
Also Tracked As: APT44 (Mandiant)
$10B+
NotPetya global damage est. — White House, 2018
6
GRU Unit 74455 officers indicted — DOJ, Oct 2020
3
Confirmed cyber-caused grid disruptions — 2015 / 2016 / 2022
19+
Custom malware/tool families tracked — MITRE ATT&CK G0034
00
Overview

Sandworm Team is a Russian military cyber unit operated by the GRU's Main Center for Special Technologies (GTsST, military unit 74455), and is assessed by multiple governments and private-sector researchers to be the most destructive nation-state cyber actor documented to date. Active since at least 2009 and elevated by Mandiant to full named-APT status as APT44 in April 2024 (Mandiant/Google Cloud, "APT44: Unearthing Sandworm," Apr 2024), the group is the only actor tracked in this project's roster with a confirmed, repeated record of using cyber intrusions to cause physical disruption to critical infrastructure — the December 2015 and December 2016 Ukrainian power grid attacks, and the April 2022 Industroyer2 operation against a Ukrainian transmission substation during the ongoing invasion.

The group matters acutely right now because it remains one of the most operationally active pieces of Russia's war effort against Ukraine. Independent OT telemetry from Nozomi Networks identified 29 confirmed Sandworm-linked incidents across ten industrial organizations in seven countries between July 2025 and January 2026 (Nozomi Networks, "Sandworm Activity in Industrial Environments," 2026), and the group sustained a wiper campaign against Ukrainian energy, logistics, and grain-sector organizations from October 2024 through at least March 2025 using a new destructive tool tracked as ZEROLOT. Separately, Fieldeffect and other researchers documented a 2025 tactical shift away from expensive zero-day exploitation toward compromising misconfigured or end-of-life edge devices — VPN concentrators, enterprise routers, remote-access gateways — against North American and European energy-sector targets, a shift significant enough that CISA issued a mandatory federal order to identify and replace unsupported edge devices in response (Fieldeffect, 2025; Federal News Network, 2026).

Sandworm is the direct originator of the Industroyer malware family — the first and, to date, only malware demonstrated to have caused an electrical blackout through purpose-built, ICS-protocol-native code rather than generic IT destruction — and its NotPetya wiper remains the single most expensive cyberattack in recorded history, with White House and industry loss estimates exceeding $10 billion globally despite the malware never having functioned as real ransomware. A full case-file account of NotPetya's impact on one victim organization, Maersk, is documented in this project's companion incident card (see incident card: Maersk NotPetya, 2017-06-27), which this profile treats as authoritative on that specific operation and does not duplicate here.

Operationally, nearly everything Sandworm has done since February 2022 sits inside the context of Russia's full-scale invasion of Ukraine — the group functions as a forward-deployed cyber-sabotage arm supporting battlefield and economic-pressure objectives, and its targeting has expanded in step with the war's phases, from initial destructive wiper waves at the invasion's outset, to sustained grid and logistics targeting through 2024–2025, to a 2025–2026 pivot toward pre-positioning inside Western critical infrastructure that several governments now assess as preparation for potential future leverage rather than purely Ukraine-focused activity.

01
Identity & Attribution
Primary NameSandworm Team
Sponsor / ParentRussian GRU — Main Center for Special Technologies (GTsST), Military Unit 74455
Actor TypeNation-State Military Intelligence Unit
Primary MotivationSabotage, military advantage, political coercion; secondary espionage
Active SinceAt least 2009 (assessed); BlackEnergy-linked activity traced from ~2014
Last ObservedOngoing — OT intrusions through Jan 2026 (Nozomi Networks)
MITRE G-IDG0034
Legal StatusUnder U.S. DOJ indictment (6 named officers, E.D. Pa., Oct 15 2020)
Formal AttributionUS, UK NCSC, EU, Australia, Canada, NZ — coordinated statements (NotPetya, Feb 2018; Georgia, 2020)
Tracking Aliases
Sandworm Team APT44 (Mandiant) ELECTRUM (Dragos) Telebots (ESET) IRON VIKING BlackEnergy Group Quedagh Voodoo Bear (CrowdStrike) IRIDIUM (Microsoft, legacy) Seashell Blizzard (Microsoft, current) FROZENBARENTS UAC-0082 (CERT-UA)
Attribution Confidence

[HIGH] — this identity rests on an unusually dense stack of independent, high-confidence corroboration for a nation-state APT: a named U.S. federal criminal indictment identifying six specific GRU officers by name and unit; formal UK NCSC attribution statements naming GTsST/Unit 74455 directly (Georgia, 2019/2020); coordinated multi-government attribution of NotPetya (Feb 2018); and a stable, continuously-tracked technical cluster followed independently by ESET (as Telebots/BlackEnergy since ~2014), Dragos (ELECTRUM), CrowdStrike (Voodoo Bear), and Microsoft (Seashell Blizzard) that converges on the same infrastructure and toolset lineage. Mandiant's April 2024 decision to graduate the cluster to APT44 status was itself a confirmation of this convergence rather than a new attribution claim. The one area of genuine attribution nuance is discussed in Section 08: several 2022 wiper incidents (notably WhisperGate) have been attributed by different vendors to an adjacent-but-distinct GRU-linked cluster (Cadet Blizzard/Ember Bear), and this profile does not fold that activity into Sandworm's core record.

02
Campaign & Operational Timeline
2014–2015
BlackEnergy3 Pre-Positioning
Spearphishing with macro-laced Office documents delivers BlackEnergy3 against Ukrainian energy-sector personnel; long-dwell reconnaissance and credential harvesting inside ICS-adjacent IT networks precedes any destructive action (ESET; SANS/E-ISAC report, 2016).
Dec 2015
First Ukraine Grid Attack
Coordinated intrusion into three regional Ukrainian power distribution companies; operators' own SCADA workstations are hijacked in real time to open breakers, and KillDisk wipes systems and corrupts the master boot record afterward. ~230,000 customers lose power for 1–6 hours — the first publicly confirmed cyberattack to cause a blackout (CISA IR-ALERT-H-16-056-01; SANS/E-ISAC, 2016).
Dec 2016
Second Grid Attack — Industroyer Debut
A Kyiv transmission substation is disrupted using Industroyer, the first malware framework built with native, protocol-specific modules (IEC 60870-5-101/104, IEC 61850, OPC DA) to directly command grid hardware — a qualitatively different capability from 2015's manual-hijack approach (MITRE ATT&CK, Campaign C0025; Dragos).
Jun 2017
NotPetya Global Wiper
A hijacked update to Ukrainian tax software M.E.Doc delivers a wiper disguised as ransomware that self-propagates via EternalBlue/EternalRomance and Mimikatz-derived credential theft, causing an estimated $10B+ in global collateral damage across dozens of countries (DOJ indictment, Oct 2020). Full case study: (see incident card: Maersk NotPetya, 2017-06-27).
Feb 2018
Olympic Destroyer
Destructive malware disrupts IT systems supporting the PyeongChang Winter Olympics opening ceremony, deliberately salted with false-flag artifacts pointing toward North Korean and Chinese threat actors — among the most sophisticated attribution-deception operations publicly documented for this group (DOJ indictment, Oct 2020).
2018–2020
Georgia, OPCW & France Operations
Large-scale website defacement and disruption of Georgian government, court, media, and business sites (Oct 2019, UK NCSC formal attribution, 2020); targeting of the Organisation for the Prohibition of Chemical Weapons following the Novichok poisoning investigation; and operations against the 2017 French presidential campaign (DOJ indictment, Oct 2020).
Feb–Apr 2022
Invasion-Phase Wiper Wave & Industroyer2
Coinciding with the February 2022 invasion, Sandworm and adjacent GRU-linked clusters deploy a rotating cast of wipers (CaddyWiper among those confirmed to Sandworm; WhisperGate attributed with lower confidence to an adjacent cluster — see Section 08) against Ukrainian government and infrastructure targets. On 8 April 2022, ESET and CERT-UA jointly disclose and help foil a planned Industroyer2 attack against a high-voltage substation, purpose-compiled for the victim's exact IEC-104 configuration just weeks earlier and sequenced with CaddyWiper for anti-forensic cleanup (ESET WeLiveSecurity, Apr 2022).
2022–2025
Sustained Destructive Campaign Against Ukraine
ESET documents Sandworm as responsible for the majority of wiper attacks against Ukraine throughout 2022 (ESET, "A Year of Wiper Attacks in Ukraine," Feb 2023). From October 2024 through March 2025, the group deploys a new wiper tracked as ZEROLOT against Ukrainian energy, logistics, and grain-sector organizations, extending destructive targeting beyond the power grid into the broader economic war effort.
2025–2026
Pivot to Edge Devices & Western Critical Infrastructure
Researchers document a tactical shift away from costly zero-day exploitation toward compromising misconfigured or end-of-life edge devices (VPN concentrators, enterprise routers, remote-access gateways) at North American and European energy organizations, using exposed management interfaces and credential-replay attacks to pivot into cloud-hosted environments (Fieldeffect, 2025). CISA responds with a mandatory federal order to identify and replace unsupported edge devices. Independent OT telemetry (Nozomi Networks) confirms 29 Sandworm-linked industrial incidents across seven countries between Jul 2025–Jan 2026, though the rate of new-victim acquisition slowed roughly 2.2x over that window.
03
Attack Lifecycle From spearphishing pre-positioning to purpose-built ICS sabotage

Sandworm's entry vectors have shifted materially across its operational lifetime without ever fully abandoning earlier techniques. The 2014–2016 grid-attack era relied on spearphishing with malicious Office macros against energy-sector staff, followed by long-dwell lateral movement into ICS-adjacent networks before any destructive action (SANS/E-ISAC, 2016). NotPetya (2017) used a software supply-chain compromise instead — a hijacked update mechanism for Ukrainian tax software M.E.Doc — demonstrating the group's willingness to weaponize trusted software distribution channels for indiscriminate, self-propagating impact (see incident card: Maersk NotPetya). Since 2025, the dominant entry vector has become opportunistic exploitation of internet-exposed, misconfigured, or end-of-life edge devices — VPN concentrators, routers, remote-access gateways — reached through exposed management interfaces rather than novel vulnerability research (Fieldeffect, 2025).

The group's toolchain splits cleanly into two tiers. For IT-layer access, lateral movement, and credential theft, Sandworm relies on a largely dual-use, commodity-adjacent kit — Cobalt Strike, Impacket, Mimikatz-derived credential dumping, PsExec/WMI for lateral tool transfer — indistinguishable at the tooling level from many other intrusion sets. For the OT/ICS layer, by contrast, the group has repeatedly demonstrated a rare, resource-intensive capability to build purpose-specific malware: Industroyer and Industroyer2 contain protocol-native modules for IEC 60870-5-101/104, IEC 61850, and OPC DA that issue what look like entirely legitimate operator commands directly to substation relays and RTUs, rather than exploiting a software vulnerability. Industroyer2 in particular was compiled specifically for one victim's exact substation configuration only weeks before its April 2022 deployment (ESET, 2022) — a level of target-specific OT engineering investment that most nation-state actors do not undertake.

Command and control has evolved from conventional web-protocol beaconing toward more resilient, harder-to-attribute infrastructure: Cyclops Blink, disclosed by NCSC/CISA in February 2022, embeds directly in WatchGuard Firebox and ASUS router firmware as a successor to the earlier VPNFilter botnet, giving the group a distributed, edge-device-resident C2 mesh that survives conventional endpoint remediation because it never touches the monitored host OS. Persistence at the IT layer uses account manipulation, scheduled tasks, and legitimate-service masquerading (the Exaramel backdoor registers as an ordinary Windows service). Exfiltration is comparatively limited and secondary to the group's core destructive/sabotage mission — data theft, where observed, appears oriented toward operational reconnaissance for follow-on targeting rather than bulk collection. The defining signature of Sandworm's most severe operations is the deliberate pairing of an ICS-impact payload with an anti-forensic wiper timed to detonate shortly afterward — Industroyer2 was followed roughly ten minutes later by CaddyWiper specifically to erase evidence of the substation-layer attack before defenders could triage it (ESET, 2022).

04
TTPs — MITRE ATT&CK Mapping Enterprise + ICS frameworks
Reconnaissance
T1595.002
Active Scanning: Vulnerability Scanning
[HIGH] Systematic scanning of internet-facing edge devices (VPN concentrators, routers) preceding the 2025 intrusion wave against North American/European energy targets (Fieldeffect, 2025).
Initial Access
T1566.001
Spearphishing Attachment
[HIGH] Macro-laced Office documents delivered BlackEnergy3 against Ukrainian energy-sector staff ahead of the 2015 grid attack (SANS/E-ISAC, 2016).
Initial Access
T1133
External Remote Services
[HIGH] 2025 shift toward abusing exposed management interfaces on misconfigured/EOL VPN and remote-access gateways rather than 0-day exploitation (Fieldeffect, 2025).
Execution
T1059.001
Command and Scripting Interpreter: PowerShell
[MEDIUM] Used across post-exploitation tooling and NotPetya's spreader logic alongside native Windows utilities.
Persistence
T1543.003
Create/Modify System Process: Windows Service
[HIGH] The Exaramel backdoor installs and masquerades as a legitimate Windows service to blend into normal service inventories (ESET, TeleBots research).
Defense Evasion
T1036.005
Masquerading: Match Legitimate Name or Location
[HIGH] Backdoors and droppers named/positioned to resemble legitimate system components; Olympic Destroyer additionally salted with false-flag artifacts implicating other nation-states (DOJ indictment, 2020).
Credential Access
T1003.001
OS Credential Dumping: LSASS Memory
[HIGH] Mimikatz-derived credential theft is the standard mechanism enabling lateral spread in both NotPetya and the earlier grid intrusions.
Lateral Movement
T1210
Exploitation of Remote Services
[HIGH] EternalBlue/EternalRomance (CVE-2017-0144/-0145) drove NotPetya's self-propagating worm behavior (DOJ indictment, 2020). No dedicated vuln card exists yet for the underlying CVE — flagged as an open cross-link gap.
Command & Control
T1071.001
Application Layer Protocol: Web Protocols
[HIGH] Cyclops Blink's modular C2 embedded in WatchGuard/ASUS firmware, successor to VPNFilter (NCSC/CISA joint advisory, Feb 2022).
Impact
T1561.002
Disk Wipe: Disk Structure Wipe
[HIGH] NotPetya overwrites the master boot record and encrypts the MFT with no functional decryption path — destructive by design, ransomware only in appearance (DOJ indictment, 2020).
Impact
T1485
Data Destruction
[HIGH] CaddyWiper and the ZEROLOT wiper family deployed against Ukrainian energy, logistics, and grain-sector organizations, Oct 2024–Mar 2025.
ATT&CK FOR ICS
Impair Process Control
T0831
Manipulation of Control
[HIGH] Industroyer2 issues properly-formatted IEC-104 protocol commands directly to substation relays to trip circuit breakers — the defining capability distinguishing this group from generic IT-destructive actors (ESET, Apr 2022).
ATT&CK FOR ICS
Impact
T0816
Device Restart/Shutdown
[HIGH] Industroyer's protocol-specific modules (IEC 101/104, IEC 61850, OPC DA) issued restart/shutdown commands to substation RTUs in the Dec 2016 Kyiv attack (Dragos; MITRE ATT&CK C0025).
ATT&CK FOR ICS
Inhibit Response Function
T0813
Denial of Control
[MEDIUM] Industroyer2 was designed to disable circuit-breaker failure-protection functions ahead of the intended April 2022 disruption, per ESET's technical analysis.
05
Targeting Profile
Sector Targeting
Energy & Critical Infrastructure
PRIMARY
Government & Public Sector
HIGH
Logistics, Grain & Transportation
MED
Media, Telecom & Financial
LOW
GeographiesUkraine (primary, sustained since 2014); Georgia; France (2017 election); South Korea (2018 Olympics); expanding NATO/Western Europe & North America (2025–2026); global collateral via NotPetya's 65+ country spread
Victim ProfileEnergy transmission/distribution operators, government agencies, defense-adjacent logistics; increasingly cloud-hosted enterprise environments reached via edge-device pivot
Preferred EntryHistorically spearphishing + software supply chain (M.E.Doc); since 2025, internet-exposed misconfigured/EOL edge devices
Target DoctrineHybrid directed/opportunistic — destructive strikes timed to military and political events, paired with opportunistic pre-positioning inside Western infrastructure for potential future leverage
06
Tools, Malware & Infrastructure
NOTPETYA WIPER · CUSTOM
MBR/MFT-destroying wiper disguised as Petya ransomware; self-propagates via EternalBlue/EternalRomance (CVE-2017-0144/-0145 — no dedicated vuln card on file yet, cross-link gap) plus Mimikatz-derived credential theft for PsExec/WMIC-based lateral spread. Generates a random installation ID that cannot map to any valid decryption key, confirming no functional ransomware capability was ever intended (DOJ indictment, 2020). Full incident treatment: (see incident card: Maersk NotPetya).
INDUSTROYER / INDUSTROYER2 ICS MALWARE · CUSTOM
Modular malware with protocol-native payload components for IEC 60870-5-101/104, IEC 61850, and OPC DA that issue legitimate-looking commands directly to substation RTUs and protection relays. Industroyer2 (2022) was purpose-compiled for a single victim's exact IEC-104 configuration weeks before deployment and paired with CaddyWiper for anti-forensic cleanup ~10 minutes post-execution (ESET, Apr 2022).
CADDYWIPER / ZEROLOT / STING WIPER FAMILY · CUSTOM
A rotating cast of destructive wipers deployed against Ukraine 2022–2025. CaddyWiper was sequenced immediately after Industroyer2 to erase attack evidence (ESET, 2022); ZEROLOT and Sting were deployed against energy, logistics, and grain-sector targets Oct 2024–Mar 2025 (ESET APT Activity Report, 2025).
CYCLOPS BLINK FIRMWARE IMPLANT / BOTNET · CUSTOM
Modular malware embedded in WatchGuard Firebox and ASUS router firmware, successor to VPNFilter. Provides a distributed, resilient C2 mesh resident below the monitored host OS layer, complicating conventional endpoint-based detection and remediation (NCSC/CISA joint advisory, Feb 2022).
EXARAMEL BACKDOOR · CUSTOM
TeleBots-era backdoor, functional successor to Industroyer's backdoor component. Installs and masquerades as a legitimate Windows service for durable persistence (ESET, TeleBots research).
P.A.S. WEBSHELL WEBSHELL · DUAL-USE
PHP webshell used for persistent access to compromised web infrastructure; included as an emulated component in MITRE CTID's published Sandworm adversary emulation plan (see Section 12).
COBALT STRIKE / IMPACKET / MIMIKATZ COTS / DUAL-USE TOOLKIT
Standard post-exploitation toolkit for lateral movement, credential access, and IT-layer persistence across intrusions — largely indistinguishable at the tooling level from many other intrusion sets; the group's distinguishing capability sits at the OT/ICS layer, not here.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
MALWARENotPetya (aka ExPetr / "GoldenEye" variant)DOJ indictment2020-10-15
MALWAREIndustroyer2ESET WeLiveSecurity2022-04-12
MALWARECyclops Blink (WatchGuard/ASUS firmware implant)NCSC / CISA Joint Advisory2022-02-23
CVECVE-2017-0144 (EternalBlue) — NotPetya lateral-spread mechanismDOJ indictment / ESET2020-10-15
PROTOCOLIEC 60870-5-104 (TCP/2404) — abused for Industroyer2 substation command injectionESET WeLiveSecurity2022-04-12
MALWAREZEROLOT / Sting wiper familyESET APT Activity Report2025-Q1
NOTESpecific network indicators (C2 IPs/domains) for the active 2025–2026 edge-device campaign were not captured in this research pass — consult current CISA/joint advisory bulletins for operational indicator sets as of compile date.2026-09-02
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH
TrajectoryEscalating & diversifying — IT/OT sabotage expanding into edge-infrastructure prepositioning
Most Dangerous CapabilityPurpose-built ICS protocol manipulation (Industroyer family)
Primary Intel GapReal-time IOC visibility into current (2025–2026) edge-device C2 infrastructure
Ecosystem / Affiliated Clusters
GTsST / Unit 74455 (parent) Cadet Blizzard / UNC2589 (adjacent, distinct) APT28 / Fancy Bear (sister GRU unit)

Sandworm is assessed at CRITICAL threat level on the strength of a record no other actor in this project's roster can match: it is the only group with confirmed, repeated success causing physical infrastructure disruption through cyber means (2015, 2016, and the foiled-but-otherwise-complete 2022 grid attacks), and it authored the single most expensive cyberattack in recorded history by direct and indirect cost. The most dangerous capability is not any single tool but the demonstrated willingness and engineering capacity to build victim-specific ICS protocol malware — Industroyer2's substation-specific compilation just weeks before use reflects an investment of OT-engineering effort that most nation-state actors, even sophisticated ones, do not undertake for a single target.

The clearest analytical gap in this profile is real-time indicator visibility. Open-source reporting through early 2026 documents the 2025 tactical shift toward edge-device compromise and credential-replay lateral movement in rich methodological detail, but the specific C2 infrastructure, IPs, and domains behind that campaign were not surfaced in this research pass — likely because the campaign is still active and current indicator sets are being managed operationally through CISA/vendor advisory channels rather than static public writeups. This is a meaningful limitation for anyone using this card for near-term defensive tuning; consult current advisories directly for that layer.

One attribution nuance deserves explicit flagging rather than silent smoothing-over: WhisperGate, deployed against Ukrainian government systems in January 2022, has been attributed with varying confidence to different clusters — CrowdStrike names Ember Bear, Microsoft names Cadet Blizzard, while ESET's broader assessment credits Sandworm with the majority of 2022 Ukraine wiper activity without necessarily including WhisperGate specifically in that count. This profile treats Cadet Blizzard/Ember Bear as an adjacent-but-distinct GRU-linked cluster and does not fold WhisperGate into Sandworm's confirmed record — a competing hypothesis exists that these are the same operators using deliberately inconsistent tradecraft, but the independent tracking convergence that supports Sandworm's core identity (Section 01) does not extend cleanly to this specific incident.

A separate non-finding is worth recording for anyone cross-referencing recent news: a self-replicating npm supply-chain worm publicly named "SANDWORM_MODE" was disclosed by Socket Research Team in February 2026, targeting JavaScript developer tooling and AI coding assistants. No source reviewed in this research pass provides a confirmed attribution link between that campaign and GRU Unit 74455 — the name appears to be a thematic reference (in the lineage of the "Shai-Hulud" npm worm, itself a Dune reference) rather than an attributed Sandworm operation, and this profile deliberately excludes it from Section 06 to avoid manufacturing a false attribution through name-matching alone. Forward trajectory: the group's 2025–2026 activity pattern — slower new-victim acquisition per Nozomi's OT telemetry, combined with a pivot toward lower-cost, higher-persistence edge-device and credential-based access — reads as a shift toward sustainable long-war positioning rather than a capability decline, consistent with an actor settling in for prolonged conflict rather than seeking rapid, high-visibility effects.

09
Defensive Recommendations
01
Enforce IT/OT segmentation with unidirectional gateways at ICS boundaries so that IT-layer compromise cannot reach protocol-level control of substation hardware.
Counters: T0831, T0816 (ICS)
02
Identify and replace end-of-life edge devices (VPN concentrators, routers, remote-access gateways) per CISA's 2026 mandatory federal order; disable exposed management interfaces on any device that must remain in service.
Counters: T1133, T1595.002
03
Disable SMBv1 and maintain aggressive patch cadence for remote-service exploitation vectors, given this group's history of worm-enabled lateral spread.
Counters: T1210
04
Maintain offline, immutable, regularly-tested backups across both IT and OT domains with verified restore procedures — assume any online backup target is in scope for a wiper.
Counters: T1561.002, T1485
05
Deploy ICS-protocol-aware monitoring capable of flagging anomalous IEC-104/61850/OPC-DA command sequences at substation boundaries, not just generic network IDS.
Counters: T0831, T0813 (ICS)
06
Enforce replay-resistant MFA (FIDO2/hardware-token-based rather than OTP/push alone) given the 2025 shift toward credential-harvesting and replay attacks against cloud-hosted environments.
Counters: T1110, credential replay
07
Harden software-supply-chain ingestion (dependency pinning, provenance verification, update-mechanism integrity checks) — the tradecraft class this group pioneered with the M.E.Doc/NotPetya compromise remains broadly relevant to the current supply-chain threat landscape.
Counters: supply-chain-class initial access
08
Rehearse a coordinated IT+OT incident response plan including pre-authorized manual grid-operation fallback procedures, so that a destructive event does not require improvising manual control under pressure.
Counters: overall Impact-tactic techniques
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
Cyclops Blink's firmware-resident design lets the group repurpose already-compromised WatchGuard/ASUS edge devices as a resilient, distributed C2 mesh rather than depending on freshly-registered attacker-owned domains — reducing the reusable registration-pattern signature that typically aids infrastructure tracking (NCSC/CISA, 2022).
Living-off-the-Land Ratio [MEDIUM]
Bifurcated approach: standard commodity/dual-use tooling (PsExec, WMI, Impacket, Mimikatz) for IT-layer lateral movement and credential access, but almost entirely native, protocol-legitimate commands at the OT layer — Industroyer2's substation commands are indistinguishable from valid operator traffic at the protocol level, which is a more extreme form of "living off the land" than binary-level LOLBin abuse.
Anti-Forensics Routines [HIGH]
Deliberate, well-documented wiper-chaining sequence: CaddyWiper execution was timed roughly ten minutes after Industroyer2's payload specifically to destroy host-level forensic evidence of the ICS-layer attack before defenders could triage it (ESET, Apr 2022) — this is a repeatable operational pattern, not incidental cleanup.
Timing & Operational Patterns [LOW]
Source material documents destructive operations timed to geopolitical and military milestones (invasion phases, the 2018 Olympics) rather than describing victim-timezone-based beaconing or dwell-time patterns — no specific beacon jitter or working-hours data was identified in this research pass; flagged as a genuine gap rather than inferred.
Tooling Hygiene [MEDIUM]
Victim-specific malware compilation for high-value OT targets — Industroyer2 was compiled specifically for one victim's exact substation configuration only weeks before deployment (ESET, 2022) — reflects deliberate minimization of reusable detection signatures for the group's highest-stakes operations, in contrast to the more standardized commodity toolkit used for routine IT-layer access.
11
Detection Evasion Specific techniques, protocol abuse, EDR bypass patterns
Legitimate ICS Protocol Abuse T0831 (ICS)
NETWORK IEC-104
Industroyer2 issues properly-formatted IEC-104 protocol commands that are indistinguishable from legitimate SCADA/operator traffic at the protocol level, defeating signature-based network detection that isn't ICS-protocol-aware (ESET, Apr 2022).
Specific command sequences/payload byte structures not publicly documented beyond protocol-family identification as of 2026-09-02.
Anti-Forensic Wiper Chaining T1561.002
EDR SIEM
CaddyWiper deployment sequenced approximately ten minutes after Industroyer2 execution specifically to destroy host-level evidence before defenders could complete triage (ESET, Apr 2022).
Approx. 10-minute delay between Industroyer2 execution and CaddyWiper detonation, per ESET's incident timeline reconstruction.
Legitimate-Service Masquerading T1036.005
EDR
The Exaramel backdoor installs itself as, and is named to resemble, a legitimate Windows service — blending into normal service-inventory review rather than relying on process-hiding techniques (ESET, TeleBots research).
Specific service names/binary paths used per-campaign not consistently publicly documented as of 2026-09-02.
Firmware-Resident Persistence T1601-adjacent (firmware implant)
EDR NETWORK
Cyclops Blink embeds directly in WatchGuard Firebox and ASUS router firmware rather than the host OS, placing it below the layer conventional endpoint EDR monitors and surviving typical remediation steps that don't include a full firmware reflash (NCSC/CISA joint advisory, Feb 2022).
Full reverse-engineered module/command set not entirely public as of the joint advisory's release; some modules documented, others withheld from public disclosure.
Credential Replay Against Cloud Environments T1110-adjacent (credential replay)
SIEM
The 2025 tactic shift uses harvested credentials for replay-based lateral movement into cloud-hosted environments, blending with legitimate authentication patterns and evading detection tuned to malware execution rather than valid-credential misuse (Fieldeffect, 2025).
Specific tooling/commands used for the replay mechanism not publicly documented as of 2026-09-02.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — ADVERSARY EMULATION PLAN Sandworm
MITRE Center for Threat-Informed Defense publishes a full Sandworm plan in its Adversary Emulation Library, built around the group's 2015 Ukraine grid attack and NotPetya. The plan comprises a nine-step Detection Scenario and a three-test Protection Scenario, emulating five components of the group's documented toolset: the P.A.S. webshell, the Exaramel backdoor, NotPetya itself, an OraDump/LaZagne-variant credential harvester, and a Win64/Spy.KeyLogger.G-class keylogger. The repository includes an Intelligence Summary, Operations Flow diagrams, source code and password-protected executables for the emulated malware, file hashes, and YARA rules.
Detection Scenario (9 steps) Protection Scenario (3 tests) P.A.S. Webshell Exaramel Backdoor NotPetya Wiper Credential Harvesting
Additional Emulation Resources
AttackIQ
Vendor-published emulation plan · Accessed: 2026-09-02
Gap Note
No Sandworm-specific Atomic Red Team test bundle or dedicated SigmaHQ-tagged rule set was confirmed in this research pass. Generic technique-level atomics (e.g., for T1561, T1003) may apply but are not actor-specific — stated explicitly rather than fabricating a coverage claim.
Accessed: 2026-09-02
13
References URLs are NOT defanged — navigate directly
MITRE ATT&CK
Accessed: 2026-09-02
Mandiant / Google Cloud
Apr 2024 · Accessed: 2026-09-02
UK NCSC / FCDO
2020 · Accessed: 2026-09-02
ESET WeLiveSecurity
Apr 12, 2022 · Accessed: 2026-09-02
NCSC / CISA
Feb 23, 2022 · Accessed: 2026-09-02
SANS / E-ISAC
2016 · Accessed: 2026-09-02
ESET WeLiveSecurity
Feb 24, 2023 · Accessed: 2026-09-02
Nozomi Networks
2026 · Accessed: 2026-09-02
Kodem Security
Feb 2026 · Accessed: 2026-09-02 (cited for naming-collision non-finding only, see Section 08)
AttackIQ
Nov 14, 2025 · Accessed: 2026-09-02
MITRE CTID
Accessed: 2026-09-02