MITRE ATT&CK G0034
Sandworm Team
View MITRE Group Page ↗
Aliases: Telebots, Voodoo Bear, Iron Viking, Unit 74455, BlackEnergy Group
Official Attribution Source: U.S. Department of Justice Indictment (W.D. Pa.) & CISA
Key Facts
Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
5
Indicted individuals
Sanctions
0
OFAC designations
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G0034 (Sandworm Team).
- Linked to 1 primary court prosecution records.
- Identified 5 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1485 Data Destruction | 1 incidents |
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1021.002 SMB / Windows Admin Shares | 1 incidents |
| T1003 OS Credential Dumping | 1 incidents |
| T1566.001 Spearphishing Attachment | 1 incidents |
| T1055.012 Process Hollowing | 1 incidents |
| T1036.005 Match Legitimate Name or Location | 1 incidents |
| T1543.003 Windows Service | 1 incidents |
Prosecution Cases Attributed to This Actor
fugitive 2020-10-15
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.
10 techniques
View case →