What is Sandworm?

Sandworm (also APT44) is a Russian state-sponsored hacking group run by the GRU military intelligence service, unit 74455, and is held responsible for the most consequential cyberattacks on industrial control systems to date, including two power outages in Ukraine and the global NotPetya attack. Active since at least 2009, the group mixes espionage, sabotage and influence operations. Where most APT groups are after data, Sandworm is after disruption: switching off electricity, wiping systems and taking communications offline. For anyone running critical infrastructure, Sandworm is therefore the reference scenario for a targeted OT attack.


🧠 Who is behind Sandworm?

Sandworm is attributed to the GRU’s Main Center for Special Technologies (GTsST), known as military unit 74455. That attribution is unusually well documented:

  • US indictment, October 2020 — on 19 October 2020 the US Department of Justice unsealed charges against six officers of unit 74455 for attacks between November 2015 and October 2019, covering the Ukrainian power grid, NotPetya, the 2017 French elections and the 2018 Winter Olympics.
  • Joint advisories — in February 2022 the UK NCSC, CISA, NSA and FBI jointly warned about Cyclops Blink, the successor to the VPNFilter router malware, naming the GTsST explicitly.
  • Mandiant, April 2024 — Mandiant gave the group the formal designation APT44, judging its activity long-running and consistent enough to be treated as a single threat actor.

🏷️ Which names do vendors use for Sandworm?

Every security vendor has its own naming scheme. If you read threat intelligence reports, you need to be able to map these names onto each other:

Organisation Name Note
Mandiant / Google APT44 (formerly FROZENBARENTS) Formal APT designation since 2024
Microsoft Seashell Blizzard (formerly IRIDIUM) Follows Microsoft’s weather-based taxonomy
CrowdStrike Voodoo Bear ”Bear” denotes Russia
ESET Sandworm / TeleBots TeleBots refers to the NotPetya era
Dragos ELECTRUM OT-focused cluster, related but not always identical
CERT-UA UAC-0002, UAC-0133 Sub-clusters per campaign
MITRE ATT&CK Sandworm Team (G0034) Reference for TTP mapping

🗓️ Which attacks are attributed to Sandworm?

The timeline shows how the group moved from hands-on sabotage to automated OT malware and, eventually, to attacks that need no custom malware at all.

Date Operation Target and effect
23 Dec 2015 BlackEnergy + KillDisk Three Ukrainian distribution companies; about 225,000 customers without power for 1 to 6 hours
17 Dec 2016 Industroyer (CrashOverride) Pivnichna substation near Kyiv; roughly a fifth of Kyiv without power for about an hour
27 Jun 2017 NotPetya Wiper spread via an M.E.Doc update; around USD 10 billion of damage worldwide
Feb 2018 Olympic Destroyer IT of the PyeongChang Winter Olympics; false flags pointing to North Korea
8 Apr 2022 Industroyer2 + CaddyWiper High-voltage substations of a Ukrainian energy company; foiled in time
10 Oct 2022 MicroSCADA attack Power outage in a Ukrainian city during missile strikes, without custom OT malware
Dec 2023 Kyivstar Ukraine’s largest mobile operator; around 24 million subscribers without service for days
Mar 2024 UAC-0133 Prepared sabotage at almost 20 energy, water and heating suppliers in Ukraine

Two incidents are often mentioned but remain disputed. In May 2023, 22 Danish energy companies were attacked through a vulnerability in Zyxel firewalls; SektorCERT saw a possible link to Sandworm, but Forescout later questioned it. On 29 and 30 December 2025, a wiper attack hit more than thirty wind and solar farms, a combined heat and power plant and a manufacturer in Poland, without causing a power cut. ESET attributes that attack to Sandworm with medium confidence and Dragos to the related ELECTRUM cluster, whereas CERT Polska points to Static Tundra (Berserk Bear), a group linked to Russia’s FSB security service.


🔧 How does a Sandworm attack on OT work?

Sandworm follows a recognisable pattern that maps well onto MITRE ATT&CK for ICS:

  • Initial access via phishing and the perimeter — Office attachments with macros (2015), vulnerable internet-facing systems, VPN appliances and firewalls without MFA; see also internet-exposed OT
  • Months of preparation — for Industroyer2 the group was inside by February 2022 at the latest, at Kyivstar since May 2023
  • Taking over Active Directory — wipers such as CaddyWiper were pushed across the entire domain at once via Group Policy
  • Speaking industrial protocols directly — Industroyer used IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA; Industroyer2 used only IEC 104 with a hard-coded configuration per target
  • Living Off The Land in OT — in 2022 the group used an ISO image to run the legitimate MicroSCADA binary scilc.exe and open circuit breakers
  • Sabotaging recovery — overwriting the firmware of serial-to-Ethernet converters (2015) and deploying wipers after the OT action to destroy evidence and systems

The key insight is that attacks are getting cheaper. Industroyer took years to develop, whereas the 2022 attack relied solely on the victim’s own SCADA software. An attacker with access to an engineering station no longer needs malware.


🧭 How does Sandworm map onto MITRE ATT&CK for ICS?

Tactic Technique (ID) Sandworm example
Initial Access Spearphishing Attachment (T0865) Office attachments with macros that installed BlackEnergy, 2015
Initial Access External Remote Services (T0822) Grid operators’ VPN, accessed with stolen domain accounts, 2015
Persistence / Lateral Movement Valid Accounts (T0859) Stolen domain accounts used to reach the OT network
Execution Scripting (T0853) VBS and batch script that invoked scilc.exe, 2022
Evasion System Binary Proxy Execution (T0894) Legitimate MicroSCADA binary scilc.exe sent SCADA commands to substations
Inhibit Response Function Device Restart/Shutdown (T0816) UPS units for data and telephone servers shut down remotely, 2015
Impact Denial of Control (T0813) Overwritten firmware on serial-to-Ethernet converters cut operators off from field devices, 2015
Impact Loss of Availability (T0826) Opened breakers left households and businesses without power for hours

Use this mapping to test whether your detection sees the early stages. Almost every Sandworm operation was visible in the IT phase, weeks or months before the impact.


🛡️ What should Dutch and European asset owners do?

Sandworm is not only a Ukrainian problem: NotPetya shut down container terminals on the Maasvlakte in Rotterdam in 2017, and the Polish attack shows that EU energy companies are targets too. A practical five-step approach:

  1. Map your perimeter — inventory firewalls, VPN gateways and remote access; enforce MFA everywhere and replace default passwords on OT equipment, exactly the weaknesses exploited in Poland.
  2. Segment IT and OT strictly — network segmentation with a DMZ ensures a compromised domain does not automatically reach the SCADA network; ideally keep OT out of the corporate domain.
  3. Detect abuse of legitimate tools — monitor IEC 104 and IEC 61850 traffic for unusual commands, log the use of engineering software and run regular threat hunting for Sandworm TTPs.
  4. Keep offline, immutable backups — immutable backups of servers, project files and PLC and RTU configurations let you recover after a wiper; test that recovery every year.
  5. Rehearse your incident response plan — including manual operation of installations and a scenario in which IT has been wiped completely.

Organisations covered by the Dutch Cybersecurity Act, the national transposition of NIS2 in force since 15 August 2026, must be able to demonstrate these measures and send an early warning of a significant incident to the competent CSIRT within 24 hours.


❓ Frequently asked questions

Is Sandworm the same as APT28 or Fancy Bear?

No, Sandworm and APT28 are two different GRU units. Sandworm is unit 74455 and focuses mainly on sabotage and destructive attacks, while APT28 (unit 26165) is known for espionage and hack-and-leak operations.

Why is the group called Sandworm?

The name Sandworm comes from researchers at iSight Partners, who in 2014 found references to the science fiction novel Dune in the group’s malware. The sandworms of Dune thus gave the group its name, which the industry later adopted widely.

Has Sandworm attacked the Netherlands?

There is no publicly known Sandworm attack aimed specifically at the Netherlands. However, Sandworm’s NotPetya attack in 2017 hit Dutch operations of companies such as Maersk and TNT Express, halting container terminals in Rotterdam for days.

Which malware does Sandworm use?

Sandworm’s toolset includes BlackEnergy, KillDisk, Industroyer, Industroyer2, NotPetya, Olympic Destroyer, Cyclops Blink, CaddyWiper and Kapeka. Increasingly, Sandworm avoids custom malware altogether and abuses legitimate tools and the victim’s own SCADA software instead.

How can you detect a Sandworm attack in an OT network?

A Sandworm attack is best detected in the preparation phase: unusual login attempts on VPNs and firewalls, new Group Policy objects and unexpected connections from IT to OT. Within the OT network itself, passive monitoring that flags anomalous IEC 104 commands and unexpected use of engineering software is the most effective control.

Is Sandworm still active?

Yes, Sandworm has become more active since Russia’s full-scale invasion of Ukraine in 2022, attacking energy, telecoms and water. Mandiant regards APT44 as one of the most dangerous threat actors in the world for critical infrastructure.


📌 In summary

Sandworm (APT44) is GRU unit 74455, the only known actor to have repeatedly caused power outages through cyberattacks, and it increasingly operates without custom malware by abusing legitimate OT software. To prepare, start with MFA and patching at the perimeter, strict separation of IT and OT, detection of engineering-tool abuse and offline backups that survive a wiper.