RussiaFormally attributedActiveMITRE G0034

Sandworm

Coverage omission — Eastern

Russia-attributed threat group operated by GRU Unit 74455. Responsible for the most destructive cyberattacks on record including the 2015 and 2016 Ukrainian power grid attacks, NotPetya, and attacks on the 2018 Winter Olympics.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
8.1
Moderate signal strength
Mentions11
Sources2
High conf.6
Last seenJun 2026
First observed
2009
Last active
Active
Origin
Russia — attributed by US, UK governments to GRU Unit 74455
Aliases
9
Techniques
79
Campaigns
8
Russia — attributed by US, UK governments to GRU Unit 74455consensus confidence
TargetsEnergyGovernmentMediaCritical Infrastructure
RegionsUaEuUsNato

Attribution signals

11 mentions · 2 sources
#1commonly attributedmoderate
HUMINT
eset
May 2026

"The group is commonly attributed to Unit 74455 of the Russian Main Intelligence Directorate (GRU)."

#2attributed byhigh
Malware
curated-intel
Jun 2026

"The Sandworm group (aka VoodooBear) has been attributed by the UK NCSC to a new Internet-of-Things (IoT) malware dubbed CyclopsBlink"

#3attributedhigh
InfrastructureTTP match
infosecurity-magazine
Jun 2026

"ESET has also previously attributed an attack against the Polish energy sector in December 2025 to Sandworm activity."

#4we attributehigh
TTP match
eset
May 2026

"which we attribute to Sandworm with high confidence"

Campaign: ZOV wiper
#5foundhigh
TTP matchMalware
eset
May 2026

"ESET Research has now found that the attack was the work of the notorious Russia-aligned APT group Sandworm."

#6capturedhigh
MalwareTTP match
wechat-qax-ti
May 2026

"captured multiple malicious samples from APT-C-13 (Sandworm) organization conducting targeted attacks"

#7tied tohigh
Unspecified
infosecurity-magazine
Jun 2026

"Google's threat analysts have separately tied to Sandworm, Turla and other Russian operators"

#8we attributemoderate
TTP matchMalware
eset
May 2026

"Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed"

#9we attributemoderate
TTP matchVictimology
eset
May 2026

"We attribute DynoWiper to Sandworm with medium confidence"

Campaign: DynoWiper
#10linked tomoderate
MalwareVictimology
wired-security
May 2026

"Some have graduated and joined both Fancy Bear and the notorious Sandworm group, which has been linked to attacks on Ukraine's power grid, the Winter Olympics, and the NotPetya malware that caused billions of damage around the world"

#11unspecified
Unspecified
eset
May 2026

Hedge terms observed

attributedattributed bycapturedcommonly attributedfoundlinked totied towe attribute