news.mlab.sh
Threat intelligence
Threat actor

Sandworm Team

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Russia
Targeted countries
Russia
TLP
WHITE

Sandworm Team is a Russian cyberespionage group that has operated since approximately 2009. The group likely consists of Russian pro-hacktivists. Sandworm Team targets mainly Ukrainian entities associated with energy, industrial control systems, SCADA, government, and media. Sandworm Team has been linked to the Ukrainian energy sector attack in late 2015. This group appears to be closely associated with, or evolved into, TeleBots.

Also known as

APT 44APT44ATK 14BE2BlackEnergy (Group)Blue EchidnaCTG-7263ELECTRUMFROZENBARENTSG0034Grey TornadoIRIDIUMIron VikingQuedaghRazing UrsaSandwormSandworm TeamSeashell BlizzardTelebotsTEMP.NobleUAC-0082UAC-0113UAC-0125UAC-0133Voodoo Bear

Vulnerabilities exploited

Tooling and malware

AcidPourAcidRainBad RabbitBlackEnergyCobalt StrikeCyclops BlinkExaramel for LinuxExaramel for WindowsGreyEnergyIndustroyerIndustroyer2KapekaKillDiskNeo-reGeorgNotPetyaOlympic DestroyerP.A.S. WebshellPrestigeVPNFilterEmpireImpacketInvoke-PSImageMimikatzNetPoshC2PsExecSDelete

MITRE ATT&CK techniques

T1005 Data from Local SystemT1090 ProxyT1105 Ingress Tool TransferT1219 Remote Access ToolsT1571 Non-Standard PortT1040 Network SniffingT1539 Steal Web Session CookieT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1049 System Network Connections DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1047 Windows Management InstrumentationT1072 Software Deployment ToolsT1106 Native APIT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1485 Data DestructionT1486 Data Encrypted for ImpactT1489 Service StopT1490 Inhibit System RecoveryT1499 Endpoint Denial of ServiceT1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1199 Trusted RelationshipT1570 Lateral Tool TransferT1133 External Remote ServicesT1593 Search Open Websites/DomainsT1594 Search Victim-Owned WebsitesT1583 Acquire InfrastructureT1027 Obfuscated Files or InformationT1036 MasqueradingT1078 Valid AccountsT1140 Deobfuscate/Decode Files or Information

Coverage 15