Sandworm Team
Also known as: apt44, blackenergy (group), blue echidna, electrum, frozenbarents, g0034, iridium, iron viking, quedagh, sandworm, sandworm relic, seashell blizzard
Profile
Sandworm Team is a threat group known for destructive operations against critical infrastructure, particularly in the energy sector. Its documented activity dates back at least to December 2015, when an attack on Ukraine's power grid caused a blackout affecting roughly 230,000 people. According to ESET, in late 2025 the group was behind a cyberattack on Poland's power grid using DynoWiper, malware designed to erase data. What sets the group apart is its use of wiper malware for sabotage rather than financial gain, together with an apparent symbolic use of timing: the Poland attack fell on the tenth anniversary of the Ukrainian incident. BlackEnergy is also among the tools associated with the group's campaigns against the electricity sector.
Active since: 2015
Tools
DynoWiper (wiper), BlackEnergy
What defenders should watch
- Pay particular attention to operational technology (OT/ICS) environments in the energy sector, the group's recurring documented target in Ukraine and Poland.
- Prepare detection and response for wiper malware such as DynoWiper: keep offline, verified backups and test restoration procedures, since the goal is data destruction rather than extortion.
- Review historical indicators associated with BlackEnergy in power-grid networks and segment industrial environments from the corporate network to limit spread.
- Increase monitoring and response readiness around significant dates or anniversaries of earlier incidents, as the Poland campaign coincided with the tenth anniversary of the 2015 Ukraine attack.
- Available sources do not specify the initial access vector used; maintain broad baseline controls (remote access, credentials, third-party suppliers) until more specific information is available.
Most affected countries
No data yet.
Most affected sectors
No data yet.
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- User Account Management (17 techniques covered)
- User Training (15 techniques covered)
- Network Intrusion Prevention (11 techniques covered)
- Privileged Account Management (10 techniques covered)
- Execution Prevention (9 techniques covered)
- Behavior Prevention on Endpoint (9 techniques covered)
- Restrict Web-Based Content (8 techniques covered)
- Multi-factor Authentication (8 techniques covered)
MITRE ATT&CK techniques
Recent victims
No data yet.
Sources analysed
- ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 (ESET WeLiveSecurity, 1/23/2026)
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.