CASE DOSSIER
fugitive
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
Docket: 2:20-cr-00316 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2020-10-15 Sector: Energy, Healthcare, Government, Transportation
Key Facts
Status
FUGITIVE
Legal disposition
Loss Amount
$10.0 billion
Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.
Techniques
9
Verified mappings
Defendants
5
Named in charges
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Energy, Healthcare, Government, Transportation.
- Documented Financial Loss: $10.0 billion.
- 9 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.
Procedural & Incident Timeline
2020-10-15 indictment
Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage.
2021-04-15 sanction
U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities.
2022-02-23 advisory
CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A).
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Yuriy Sergeyevich Andrienko | Russian Federation | fugitive | Pending | None | GRU Unit 74455 military officer who developed components of the NotPetya and Olympic Destroyer malware. |
| Sergey Vladimirovich Detistov | Russian Federation | fugitive | Pending | None | GRU Unit 74455 officer who conducted spearphishing campaigns targeting the 2018 PyeongChang Winter Olympic Games. |
| Pavel Valeryevich Frolov | Russian Federation | fugitive | Pending | None | GRU Unit 74455 malware engineer who developed KillDisk wiper payloads. |
| Artem Valeryevich Ochichenko | Russian Federation | fugitive | Pending | None | GRU Unit 74455 officer responsible for reconnaissance and technical exploitation of French political parties. |
| Petr Nikolayevich Pliskin | Russian Federation | fugitive | Pending | None | GRU Unit 74455 military officer who assisted in the deployment of Olympic Destroyer malware. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1485 | Data Destruction Impact | "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware." | Indictment ¶ 44, Page 22 | reviewed |
| T1190 | Exploit Public-Facing Application Initial Access | "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary." | Indictment ¶ 38, Page 19 | reviewed |
| T1021.002 | SMB / Windows Admin Shares Lateral Movement | "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention." | Indictment ¶ 47, Page 24 | reviewed |
| T1003 | OS Credential Dumping Credential Access | "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators." | Indictment ¶ 46, Page 23 | reviewed |
| T1055.012 | Process Hollowing Defense Evasion | "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity." | Indictment ¶ 52, Page 27 | reviewed |
| T1036.005 | Match Legitimate Name or Location Defense Evasion | "NotPetya named its primary payload dllhost.dat inside C:\Windows\ to blend in with legitimate host process binaries." | Indictment ¶ 45, Page 23 | reviewed |
| T1543.003 | Windows Service Persistence | "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type." | CISA Advisory ICS-ALERT-14-281-01B | reviewed |
| T1499 | Endpoint Denial of Service Impact | "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops." | Indictment ¶ 54, Page 28 | reviewed |
| T1124 | System Time Discovery Discovery | "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps." | CISA Advisory AA17-181A | reviewed |
View 1 Proposed / Unverified Mapping Candidates
T1566.001: Spearphishing Attachment Proposed by rule
"Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators."
CISA Cybersecurity Advisories
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455), No. 2:20-cr-00316 (U.S. District Court for the Western District of Pennsylvania 2020), https://cyberattackcaselibrary.pages.dev/cases/sandworm-notpetya-olympic-destroyer/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/sandworm-notpetya-olympic-destroyer" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>