FlagThis
← Threat Actors
/
Russia
/
Sandworm Team
DOSSIER // SANDWORM-TEAM
Sandworm Team
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Russia
Primary Aliases:
APT44
Seashell Blizzard
Voodoo Bear
BlackEnergy (Group)
🔍 Adversary Rosetta Stone (11) ▾
📋 Copy All
Sponsor / State Affiliation
Russia (GRU / Unit 74455)
Primary Motivation
Strategic sabotage, geopolitical disruption, and direct military support for Russian state objectives.
Active Timeline
Unknown – Present
Confidence Rating
95% (Grounded)
BadPilot Campaign, Poland Power Grid Attack, Global OT/ICS Disruption Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(1)
CVE-2024-1709
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Energy
Water and Wastewater
Telecommunications
Transportation
Manufacturing
Government
NATO Member States
Military
Oil and Gas
Shipping
Arms Manufacturing
🛡️ MITRE ATT&CK® Attack Lifecycle
(9 TTPs)
📥 Download Navigator JSON
All Stages
9
Initial Access
1
Execution
1
Credential Access & Discovery
1
Lateral Movement & Collection
1
Command & Control
2
Exfiltration & Impact
1
Operational Techniques
2
Initial Access
1
T1566
Exploitation of misconfigured network edge devices (routers, VPN concentrators, gateways)
↗
Execution
1
T1059
Living-off-the-land (LOTL) techniques
↗
Credential Access & Discovery
1
T1003
Credential harvesting and replay attacks
↗
Lateral Movement & Collection
1
T1021
Aggressive lateral movement using legacy exploits (EternalBlue, Log4Shell)
↗
Command & Control
2
T1071
Trojanized software distribution (e.g., pirated Microsoft KMS activators)
↗
T1071
Use of hacktivist personas and false-flag operations to obscure attribution
↗
Exfiltration & Impact
1
T1485
Deployment of custom wiper malware (e.g., AcidPour)
↗
Operational Techniques
2
T1000
Targeting of OT/ICS assets (PLCs, HMIs, RTUs, Engineering workstations)
↗
T1000
Exploitation of IT remote management software (e.g., ConnectWise ScreenConnect CVE-2024-1709)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Adversary Rosetta Stone // Sandworm Team
×
🪟 Microsoft Threat Actor Naming
IRIDIUM
📋
Seashell Blizzard
📋
🦅 CrowdStrike Monikers
Voodoo Bear
📋
🔍 Mandiant / Google Threat Intel
APT44
📋
🛡️ Other Industry Tracking Codes
BlackEnergy (Group)
📋
ELECTRUM
📋
FROZENBARENTS
📋
G0034
📋
IRON VIKING
📋
Quedagh
📋
Telebots
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD