DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-26
groupactive

Sandworm (Unit 74455 / Main Center for Special Technologies)

KNOWN ALIASES: Unit 74455 · APT44 · BlackEnergy Group · TeleBots · Voodoo Bear · Seashell Blizzard
EXECUTIVE INTELLIGENCE SUMMARY

The Russian military intelligence agency’s premier cyber-sabotage unit, notorious for devastating wiper malware, power grid blackouts, and NotPetya.

Specializes in destructive kinetic-equivalent cyberattacks, SCADA/ICS disruption, supply chain compromises, and multi-stage wiper deployments in support of Russian military operations and geopolitical warfare.

MAJOR ATTRIBUTED OPERATIONS
2024 · Operation Microgrid Relay SabotageTARGET: Substation Protection Relays

Targeted IEC 60870-5-104 industrial protocol commands sent to trigger regional circuit trips.

2017 · NotPetya Global Supply Chain OutbreakTARGET: M.E.Doc Accounting Software Supply Chain

PsExec/EternalBlue worm causing over $10 Billion in global shipping, logistics, and pharmaceutical damages.

2015 · Ukrainian Power Grid BlackoutTARGET: Kyivoblenergo & Prykarpattyaoblenergo

First documented cyberattack in history to successfully disconnect power substations and disable UPS backup batteries.

SOURCE CITATIONS & ATTESTATIONS (1)
Mandiant Special Report: APT44 UnmaskedMandiant Intelligence

APT44: Active Russian Military Cyber Warfare

TELEMETRY CARDID: group-sandworm
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
Russian Federation (GRU)
INDEXED TAGS
#apt#gru#scada_disruption#wiper#notpetya#grid_attacks