RussiaFormally attributedActiveMITRE G0034

Sandworm

Coverage omission — Eastern

Russia-attributed threat group operated by GRU Unit 74455. Responsible for the most destructive cyberattacks on record including the 2015 and 2016 Ukrainian power grid attacks, NotPetya, and attacks on the 2018 Winter Olympics.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
5.3
Moderate signal strength
Mentions8
Sources2
High conf.3
Last seenMay 2026
First observed
2009
Last active
Active
Origin
Russia — attributed by US, UK governments to GRU Unit 74455
Aliases
9
Techniques
79
Campaigns
0
Russia — attributed by US, UK governments to GRU Unit 74455consensus confidence
TargetsEnergyGovernmentMediaCritical Infrastructure
RegionsUaEuUsNato

Attribution signals

8 mentions · 2 sources
#1commonly attributedmoderate
HUMINT
eset
May 2026

"The group is commonly attributed to Unit 74455 of the Russian Main Intelligence Directorate (GRU)."

#2foundhigh
TTP matchMalware
eset
May 2026

"ESET Research has now found that the attack was the work of the notorious Russia-aligned APT group Sandworm."

#3capturedhigh
MalwareTTP match
wechat-qax-ti
May 2026

"captured multiple malicious samples from APT-C-13 (Sandworm) organization conducting targeted attacks"

#4we attributehigh
TTP match
eset
May 2026

"which we attribute to Sandworm with high confidence"

Campaign: ZOV wiper
#5linked tomoderate
MalwareVictimology
wired-security
May 2026

"Some have graduated and joined both Fancy Bear and the notorious Sandworm group, which has been linked to attacks on Ukraine's power grid, the Winter Olympics, and the NotPetya malware that caused billions of damage around the world"

#6we attributemoderate
TTP matchMalware
eset
May 2026

"Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed"

#7we attributemoderate
TTP matchVictimology
eset
May 2026

"We attribute DynoWiper to Sandworm with medium confidence"

Campaign: DynoWiper
#8unspecified
Unspecified
eset
May 2026

Hedge terms observed

capturedcommonly attributedfoundlinked towe attribute