MITRE ATT&CK G0034
Aliases: Telebots, Voodoo Bear, Iron Viking, Unit 74455, BlackEnergy Group
Official Attribution Source: U.S. Department of Justice Indictment (W.D. Pa.) & CISA

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
5
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0034 (Sandworm Team).
  • Linked to 1 primary court prosecution records.
  • Identified 5 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to Sandworm Team Technique frequencies extracted from verified indictments for Sandworm Team. T1485 Data Destruction 1 incidents T1190 Exploit Public-Facing Application 1 incidents T1021.002 SMB / Windows Admin Shares 1 incidents T1003 OS Credential Dumping 1 incidents T1566.001 Spearphishing Attachment 1 incidents T1055.012 Process Hollowing 1 incidents T1036.005 Match Legitimate Name or Location 1 incidents T1543.003 Windows Service 1 incidents
Technique frequencies extracted from verified indictments for Sandworm Team.
ATT&CK Techniques Mapped to Sandworm Team
Technique Frequency
T1485 Data Destruction 1 incidents
T1190 Exploit Public-Facing Application 1 incidents
T1021.002 SMB / Windows Admin Shares 1 incidents
T1003 OS Credential Dumping 1 incidents
T1566.001 Spearphishing Attachment 1 incidents
T1055.012 Process Hollowing 1 incidents
T1036.005 Match Legitimate Name or Location 1 incidents
T1543.003 Windows Service 1 incidents

Prosecution Cases Attributed to This Actor

fugitive 2020-10-15

U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)

Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.

10 techniques View case →