Sandworm is a Russian state-sponsored group known for destructive attacks on energy and industrial control systems.
Analyst brief
Sandworm is a Russian state-sponsored threat group primarily targeting energy, electric, industrial, and government sectors across countries like Ukraine, Georgia, Azerbaijan, and Iran. It is known for compromising industrial control systems (ICS) and uses TTPs such as Exploit Public-Facing Application, vulnerability scanning, C2 channel exfiltration, along with destructive malware like Bad Rabbit, GreyEnergy, and tools like Mimikatz and PsExec. Defenders must prioritize OT/IT network segmentation, patch management for public-facing applications, and rigorous monitoring of C2 communication channels.
Sandworm
QuedaghVOODOO BEARTEMP.Noble
activenation-state
This threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial of service, and data destruction purposes. Some believe that the threat actor is linked to the 2015 compromise of the Ukrainian electrical grid and a distributed denial of service prior to the Russian invasion of Georgia. Believed to be responsible for the 2008 DDoS attacks in Georgia and the 2015 Ukraine power grid outage
origin (suspected)
🇷🇺Russia· state-sponsoredattribution confidence: medium (50)
Detect suspicious processes that may cause Service Stop and monitor for service stop attempts.
FAQ2
What destructive malware does the Sandworm group use against industrial control systems?+
The Sandworm group uses destructive malware such as Bad Rabbit and GreyEnergy, along with the Black Energy tool, in attacks against industrial control systems.
What are the major historical cyber incidents attributed to the Sandworm group?+
The Sandworm group is believed to be responsible for the 2008 DDoS attacks in Georgia and the 2015 compromise of the Ukrainian electrical grid.