« All threats

APT groupMITRE G0034

Sandworm Team

Also known as: apt44, blackenergy (group), blue echidna, electrum, frozenbarents, g0034, iridium, iron viking, quedagh, sandworm, sandworm relic, seashell blizzard

Profile

Sandworm Team is a threat group known for destructive operations against critical infrastructure, particularly in the energy sector. Its documented activity dates back at least to December 2015, when an attack on Ukraine's power grid caused a blackout affecting roughly 230,000 people. According to ESET, in late 2025 the group was behind a cyberattack on Poland's power grid using DynoWiper, malware designed to erase data. What sets the group apart is its use of wiper malware for sabotage rather than financial gain, together with an apparent symbolic use of timing: the Poland attack fell on the tenth anniversary of the Ukrainian incident. BlackEnergy is also among the tools associated with the group's campaigns against the electricity sector.

Active since: 2015

Tools

DynoWiper (wiper), BlackEnergy

What defenders should watch

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. User Account Management (17 techniques covered)
  2. User Training (15 techniques covered)
  3. Network Intrusion Prevention (11 techniques covered)
  4. Privileged Account Management (10 techniques covered)
  5. Execution Prevention (9 techniques covered)
  6. Behavior Prevention on Endpoint (9 techniques covered)
  7. Restrict Web-Based Content (8 techniques covered)
  8. Multi-factor Authentication (8 techniques covered)

MITRE ATT&CK techniques

T1608.001 · Upload MalwareT1588.006 · VulnerabilitiesT1040 · Network SniffingT1027.010 · Command ObfuscationT1595.002 · Vulnerability ScanningT1585.001 · Social Media AccountsT1586.001 · Social Media AccountsT1132.001 · Standard EncodingT1213.006 · DatabasesT1539 · Steal Web Session CookieT1059.001 · PowerShellT1090 · ProxyT1203 · Exploitation for Client ExecutionT1041 · Exfiltration Over C2 ChannelT1053.005 · Scheduled TaskT1190 · Exploit Public-Facing ApplicationT1078.002 · Domain AccountsT1003.003 · NTDST1036 · MasqueradingT1598.003 · Spearphishing LinkT1133 · External Remote ServicesT1587.001 · MalwareT1072 · Software Deployment ToolsT1584.005 · BotnetT1566.002 · Spearphishing LinkT1018 · Remote System DiscoveryT1589.003 · Employee NamesT1078 · Valid AccountsT1566.001 · Spearphishing AttachmentT1204.002 · Malicious FileT1106 · Native APIT1588.002 · ToolT1583.004 · ServerT1590.001 · Domain PropertiesT1083 · File and Directory DiscoveryT1049 · System Network Connections DiscoveryT1555.003 · Credentials from Web BrowsersT1489 · Service StopT1571 · Non-Standard PortT1070.004 · File DeletionT1047 · Windows Management InstrumentationT1021.002 · SMB/Windows Admin SharesT1204.001 · Malicious LinkT1505.003 · Web ShellT1218.011 · Rundll32T1499 · Endpoint Denial of ServiceT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1056.001 · KeyloggingT1561.002 · Disk Structure WipeT1486 · Data Encrypted for ImpactT1592.002 · SoftwareT1491.002 · External DefacementT1583 · Acquire InfrastructureT1219 · Remote Access ToolsT1584.004 · ServerT1003.001 · LSASS MemoryT1594 · Search Victim-Owned WebsitesT1570 · Lateral Tool TransferT1027 · Obfuscated Files or Information

Recent victims

No data yet.

Sources analysed

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.