FlagThis
← Threat Actors
/
Russia
/
Sandworm
DOSSIER // SANDWORM
Sandworm
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Russia
Primary Aliases:
APT44
Seashell Blizzard
UNC3810
VOODOO BEAR
🔍 Adversary Rosetta Stone (27) ▾
📋 Copy All
Sponsor / State Affiliation
Russian Federation (GRU Unit 74455)
Primary Motivation
Sabotage, political disruption, and military support
Active Timeline
Unknown – Present
Confidence Rating
95% (Grounded)
Ukrainian Critical Infrastructure Sabotage, European Government Espionage and Disruption
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🛡️ MITRE ATT&CK (G0034) ↗
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(3)
CVE-2017-0144
EternalBlue SMBv1
CVSS 8.1
KEV
EPSS 97.1%
CVE-2019-19781
Citrix ADC Path Traversal
CVSS 9.8
KEV
EPSS 96.4%
CVE-2022-30190
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Energy Infrastructure
Government Services
Telecommunications
Defense Industrial Base
Transportation
Satellite Communications
Critical Infrastructure
🛡️ MITRE ATT&CK® Attack Lifecycle
(7 TTPs)
📥 Download Navigator JSON
All Stages
7
Initial Access
3
Execution
1
Credential Access & Discovery
1
Exfiltration & Impact
1
Operational Techniques
1
Initial Access
3
T1566
Spear-phishing
↗
T1566
Supply chain compromise
↗
T1566
Exploitation of public-facing edge devices
↗
Execution
1
T1059
Living-off-the-land (LotL) techniques
↗
Credential Access & Discovery
1
T1003
Credential harvesting
↗
Exfiltration & Impact
1
T1485
Wiper malware deployment (e.g., CaddyWiper, IsaacWiper)
↗
Operational Techniques
1
T1000
Industrial Control Systems (ICS/SCADA) manipulation
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Head Mare APT Exploits TrueConf Server Vulnerabilities to Deploy PhantomCore and PhantomGraph
Attacks and Vulnerabilities
2026-08-13
[DEEP DIVE]
UAC-0145 Sandworm ClickFix CAPTCHA and Ethereum-based SMARTAXE C2
Attacks and Vulnerabilities
2026-07-20
Adversary Rosetta Stone // Sandworm
×
🪟 Microsoft Threat Actor Naming
IRIDIUM
📋
Seashell Blizzard
📋
🦅 CrowdStrike Monikers
VOODOO BEAR
📋
🔍 Mandiant / Google Threat Intel
APT44
📋
TEMP.Noble
📋
UNC3810
📋
🏛️ Government / CISA / Law Enforcement
GRU
📋
Unit 74455
📋
🛡️ Other Industry Tracking Codes
ATK 14
📋
BE2
📋
BlackEnergy Lite
📋
Blue Echidna
📋
CTG-7263
📋
ELECTRUM
📋
FROZENBARENTS
📋
G0034
📋
GTsST
📋
IRON VIKING
📋
Main Center for Special Technologies
📋
PHANTOM
📋
Quedagh
📋
Sandworm Relic
📋
Storm-0816
📋
TeleBots
📋
UAC-0050
📋
UAC-0082
📋
UAC-0113
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD