{
  "id": "case-sandworm-notpetya",
  "slug": "sandworm-notpetya-olympic-destroyer",
  "title": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)",
  "summary": "Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.",
  "case_number": "2:20-cr-00316",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "United States",
  "opened_at": "2020-10-15",
  "status": "fugitive",
  "victim_sector": "Energy, Healthcare, Government, Transportation",
  "victim_country": "Ukraine, United States, France, South Korea",
  "loss_amount_usd": 10000000000,
  "loss_amount_note": "Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.",
  "first_seen_at": "2015-12-23T15:00:00Z",
  "last_updated_at": "2026-09-20T12:00:00Z",
  "actor_slug": "sandworm-team",
  "defendant_slugs": [
    "yuriy-andrienko",
    "sergey-detistov",
    "pavel-frolov",
    "anatoliy-kovalev",
    "artem-ochichenko",
    "petr-pliskin"
  ],
  "cves": [
    "CVE-2017-0144"
  ],
  "techniques": [
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware.",
      "evidence_locator": "Indictment \u00b6 44, Page 22",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary.",
      "evidence_locator": "Indictment \u00b6 38, Page 19",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1021.002",
      "evidence_excerpt": "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention.",
      "evidence_locator": "Indictment \u00b6 47, Page 24",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA17-181A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
      "technique_name": "SMB / Windows Admin Shares",
      "tactic": "Lateral Movement"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators.",
      "evidence_locator": "Indictment \u00b6 46, Page 23",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators.",
      "evidence_locator": "Indictment \u00b6 15, Page 7",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1055.012",
      "evidence_excerpt": "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity.",
      "evidence_locator": "Indictment \u00b6 52, Page 27",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Process Hollowing",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1036.005",
      "evidence_excerpt": "NotPetya named its primary payload dllhost.dat inside C:\\Windows\\ to blend in with legitimate host process binaries.",
      "evidence_locator": "Indictment \u00b6 45, Page 23",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Match Legitimate Name or Location",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1543.003",
      "evidence_excerpt": "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type.",
      "evidence_locator": "CISA Advisory ICS-ALERT-14-281-01B",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA ICS Advisory",
      "source_url": "https://www.cisa.gov/news-events/ics-advisories",
      "technique_name": "Windows Service",
      "tactic": "Persistence"
    },
    {
      "technique_id": "T1499",
      "evidence_excerpt": "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops.",
      "evidence_locator": "Indictment \u00b6 54, Page 28",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Endpoint Denial of Service",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1124",
      "evidence_excerpt": "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps.",
      "evidence_locator": "CISA Advisory AA17-181A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA17-181A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
      "technique_name": "System Time Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2020-10-15",
      "description": "Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage."
    },
    {
      "event_type": "sanction",
      "event_date": "2021-04-15",
      "description": "U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities."
    },
    {
      "event_type": "advisory",
      "event_date": "2022-02-23",
      "description": "CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A)."
    }
  ]
}