Sandworm Team
G00344 reportsAnalyst assessment — key judgments
- Signature techniques: T1593.001 (Social Media), AML.T0016.002 (Generative AI), T1684 (Social Engineering).
- Primary targeting: RU, US, UA, CN.
- Steady activity: 2 report(s) in last 30d vs 1 prior (+100%).
- Recent movement: 17 new technique(s), 7 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 68% of 22 observed techniques (7 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
Movement — last 30 days
Overview
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020)
In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.(Citation: US District Court Indictment GRU Oct 2018)
ATT&CK technique matrix
- T1593.001 · Social Mediaconf 602
- AML.T0016.002 · Generative AIconf 602
- T1684 · Social Engineeringconf 652
- T1036 · Masqueradingconf 652
- AML.T0074 · Masqueradingconf 652
- T1589.001 · Credentialsconf 652
- T1590.004 · Network Topologyconf 601
- T1588.007 · Artificial Intelligenceconf 601
- T1590.005 · IP Addressesconf 601
- T1059.007 · JavaScriptconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1195 · Supply Chain Compromiseconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|