CASE DOSSIER fugitive

U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)

Docket: 2:20-cr-00316 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2020-10-15 Sector: Energy, Healthcare, Government, Transportation

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$10.0 billion
Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.
Techniques
9
Verified mappings
Defendants
5
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Energy, Healthcare, Government, Transportation.
  • Documented Financial Loss: $10.0 billion.
  • 9 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.

Procedural & Incident Timeline

2020-10-15 indictment

Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage.

2021-04-15 sanction

U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities.

2022-02-23 advisory

CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A).

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Yuriy Sergeyevich Andrienko Russian Federation fugitive Pending None GRU Unit 74455 military officer who developed components of the NotPetya and Olympic Destroyer malware.
Sergey Vladimirovich Detistov Russian Federation fugitive Pending None GRU Unit 74455 officer who conducted spearphishing campaigns targeting the 2018 PyeongChang Winter Olympic Games.
Pavel Valeryevich Frolov Russian Federation fugitive Pending None GRU Unit 74455 malware engineer who developed KillDisk wiper payloads.
Artem Valeryevich Ochichenko Russian Federation fugitive Pending None GRU Unit 74455 officer responsible for reconnaissance and technical exploitation of French political parties.
Petr Nikolayevich Pliskin Russian Federation fugitive Pending None GRU Unit 74455 military officer who assisted in the deployment of Olympic Destroyer malware.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1485 Data Destruction
Impact
"The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware." Indictment ¶ 44, Page 22 reviewed
T1190 Exploit Public-Facing Application
Initial Access
"Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary." Indictment ¶ 38, Page 19 reviewed
T1021.002 SMB / Windows Admin Shares
Lateral Movement
"NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention." Indictment ¶ 47, Page 24 reviewed
T1003 OS Credential Dumping
Credential Access
"The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators." Indictment ¶ 46, Page 23 reviewed
T1055.012 Process Hollowing
Defense Evasion
"Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity." Indictment ¶ 52, Page 27 reviewed
T1036.005 Match Legitimate Name or Location
Defense Evasion
"NotPetya named its primary payload dllhost.dat inside C:\Windows\ to blend in with legitimate host process binaries." Indictment ¶ 45, Page 23 reviewed
T1543.003 Windows Service
Persistence
"The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type." CISA Advisory ICS-ALERT-14-281-01B reviewed
T1499 Endpoint Denial of Service
Impact
"Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops." Indictment ¶ 54, Page 28 reviewed
T1124 System Time Discovery
Discovery
"NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps." CISA Advisory AA17-181A reviewed
View 1 Proposed / Unverified Mapping Candidates
T1566.001: Spearphishing Attachment Proposed by rule

"Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators."

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455), No. 2:20-cr-00316 (U.S. District Court for the Western District of Pennsylvania 2020), https://cyberattackcaselibrary.pages.dev/cases/sandworm-notpetya-olympic-destroyer/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/sandworm-notpetya-olympic-destroyer" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>