RESEARCH ARTICLE

Walkthrough of a Well-Documented Case: Sandworm and NotPetya

Published: 2026-09-21 • Author: Cyberattack Case Library Research Team

Key Facts

  • Published on 2026-09-21 by Cyberattack Case Library Research Team.
  • Focus topic: Walkthrough of a Well-Documented Case: Sandworm and NotPetya.
  • Documented from primary government and court records.

On October 15, 2020, a federal grand jury in the Western District of Pennsylvania returned an indictment charging six officers of the Main Intelligence Directorate (GRU) of the General Staff of the Armed Forces of the Russian Federation. The indictment (*United States v. Yuriy Sergeyevich Andrienko, et al.*) provides one of the most comprehensive primary records of state-sponsored destructive cyber warfare ever published.

The Threat Actor: GRU Unit 74455

The defendants were assigned to GRU Military Unit 74455, commonly tracked by security researchers as the Sandworm Team, Telebots, or Voodoo Bear. The indictment documents years of coordinated operations targeting critical infrastructure in Ukraine, international chemical weapons inspectors in the Netherlands, and hospitals worldwide.

Initial Access: The M.E.Doc Supply Chain Compromise

The indictment establishes that the June 27, 2017 NotPetya malware outbreak was initiated through a software supply chain compromise (MITRE ATT&CK T1195.002).

According to paragraphs 53 through 58 of the indictment, the conspirators repeatedly accessed the server infrastructure of an accounting software developer in Kyiv, Ukraine that produced M.E.Doc, the country's dominant tax reporting software. By modifying an official software update package, the conspirators distributed a malicious backdoor that automatically executed on thousands of client networks across Ukraine and international corporations with Ukrainian subsidiaries.

Internal Propagation: Mimikatz and EternalBlue

Once inside a victim network, NotPetya did not rely on external command and control servers. As detailed in paragraph 61:

  • The malware extracted credentials from memory using a custom implementation of Mimikatz (ATT&CK T1003.001).
  • It scanned local subnets for open SMB ports and propagated using the EternalBlue exploit (CVE-2017-0144 / ATT&CK T1210).
  • It leveraged PsExec and Windows Management Instrumentation (WMI / ATT&CK T1047) using harvested credentials to compromise adjacent servers within minutes.

Destruction Masquerading as Ransomware

Although NotPetya displayed a ransom demand demanding $300 in Bitcoin, the indictment proves that the malware was engineered solely as a destructive wiper (ATT&CK T1485 and T1486). The malware intentionally scrambled the Master Boot Record (MBR) and encryption keys in memory, ensuring that data recovery was mathematically impossible even if a payment was made.

The indictment documents over $1 billion in total damages to international shipping firms, pharmaceutical manufacturers, and healthcare networks, cementing NotPetya as the costliest cyber incident in modern history.