🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS    ◆    🔴 [LATEST] BREACHFORUMS ADMIN: HASANBROKER WAS A PREDATOR? DARK WEB FORUM WARS EXPLODE

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
SANDWORM

/actor/sandworm/  ·  1 intel report

Year Established
2009
Attribution
Russia (GRU Unit 74455)
Motivation
Espionage, Sabotage, Destructive Attacks
Modus Operandi (MO)
Critical infrastructure attacks, destructive wiper malware, supply chain compromise, election interference
Primary Aliases
VOODOO BEAR, IRIDIUM, Telebots, BlackEnergy Group, APT44

Sandworm is one of the most destructive nation-state threat actors in recorded cyber history, attributed with high confidence to Russia's GRU (General Staff's Main Intelligence Directorate), specifically Unit 74455 also known as the Main Centre for Special Technologies (GTsST). Active since at least 2009, the group is uniquely distinguished by its willingness to conduct destructive, sabotage-oriented cyber operations rather than purely espionage-focused intrusions.

Sandworm is responsible for some of the most impactful cyberattacks ever documented: the 2015 and 2016 attacks on Ukraine's power grid , the first confirmed cyberattacks to cause power outages for civilian populations , the deployment of the NotPetya wiper malware in 2017, which caused an estimated $10 billion USD in global damages and is widely considered the most destructive cyberattack in history, and the Olympic Destroyer attack targeting the 2018 Pyeongchang Winter Olympics.

The group maintains an extensive custom malware arsenal including BlackEnergy, Industroyer/CRASHOVERRIDE, NotPetya, Cyclops Blink, and Industroyer2, the latter specifically engineered to disrupt industrial control systems (ICS) managing electrical grid infrastructure. Their operations against Ukraine have intensified significantly since the 2022 Russian invasion.

Sandworm's operational mandate from GRU appears to extend beyond intelligence collection to active support of Russian military objectives through kinetic-effect cyber operations, making them a uniquely dangerous actor in the contemporary threat landscape.

Sandworm is a Russian military intelligence cluster (GRU Unit 74455), not a volunteer DDoS channel. Historical operations include destructive wipers and electric-sector incidents in Ukraine. Any 2026 card that slaps the Sandworm name on a simple website flood should be treated with suspicion. Reserve the label for tooling, infrastructure, or government attribution that actually matches the unit.

OT owners: ICS protocol visibility, immutable backups of engineering workstations, and an assumption that living-off-the-land in Windows is more likely than a cartoon wiper splash screen.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (1)

> cd ../articles