Sandworm Explained: TTPs, IOCs and How to Defend in 2026
Table of contents
- 1. Who is Sandworm?
- Sandworm is not APT28
- The alias problem
- 2. Sandworm in numbers
- 3. The Sandworm timeline
- 4. BadPilot: the part that determines whether you are exposed
- The supply chain route
- 5. Poland, December 2025: the attack that failed
- 6. The destructive toolkit
- The hacktivist front
- 7. Are you a Sandworm target?
- 8. Defending against Sandworm
- Know what you have exposed, then patch it
- Assume the wiper will be delivered by Group Policy
- Build backups for destruction, not for ransomware
- Segment operational technology properly
- Watch the credentials, not just the perimeter
- Endpoint protection is not futile here
- FAQs
- Over to you
What does it take to become a Sandworm target?
Less than you would hope, and the answer has very little to do with who you are. For a subgroup that Microsoft calls BadPilot, it is enough to run an internet-facing appliance with an unpatched vulnerability. Selection happens afterwards.
That distinction matters, because almost everything written about Sandworm is about the destructive end of its operations: the Ukrainian blackouts, NotPetya, the wipers. Those events are real and they are the reason the group matters. But they are the last five minutes of an operation that started months earlier on a server nobody remembered was exposed.
In late December 2025, the group attempted to wipe Poland’s power infrastructure. It was stopped at execution. That attack is the clearest illustration available of both halves of this problem, and we will come back to it.
This guide covers who Sandworm is, how it differs from APT28, what it has actually done in 2025 and 2026, how the access pipeline works, and what defences apply to an adversary whose objective is destruction rather than profit.
1. Who is Sandworm?
Sandworm is a cyber sabotage unit of Russian military intelligence. The US and UK governments formally attribute it to Unit 74455 of the GRU, and the group has been active since around 2009.
In April 2024, Mandiant took the unusual step of promoting it to a numbered advanced persistent threat, APT44, on the grounds that it is responsible for nearly all of the disruptive and destructive operations against Ukraine over the past decade. Mandiant’s assessment was blunt: no other Russian state-backed group has played a more central role in supporting Russia’s military campaign.
What separates Sandworm from most of what this blog covers is intent. Ransomware groups want money and will negotiate. Espionage groups want to stay hidden and will retreat rather than be caught. Sandworm exists to break things, and its operations have repeatedly been timed to coincide with conventional military activity such as kinetic strikes.
Sandworm is not APT28
This is the single most common error in reporting on Russian state activity, and it produces defensive priorities that make no sense.
Both groups sit within the GRU’s Information Operations Troops. They are different units with different missions. APT28 is assessed as Unit 26165 and runs intelligence collection, prioritising quiet persistence inside diplomatic and government networks. Sandworm is Unit 74455 and runs sabotage. Mandiant separated them explicitly when it created the APT44 designation, precisely because the two had been conflated for years.
If you are building detections or briefing an executive, work from the unit rather than the vendor codename.
The alias problem
Sandworm is also tracked as APT44, Seashell Blizzard, Voodoo Bear, Iron Viking, TeleBots, ELECTRUM, FROZENBARENTS, IRIDIUM, Blue Echidna, TEMP.Noble, Quedagh, BlackEnergy Group, and by CERT-UA under several UAC designations including UAC-0002, UAC-0082, UAC-0113, UAC-0125 and UAC-0133.
That is not trivia. If your threat intelligence platform ingests a Microsoft bulletin on Seashell Blizzard, a CERT-UA advisory on UAC-0133 and an ESET paper on Sandworm, you have three records describing one organization, and correlation depends entirely on whether someone maintained the alias mapping.
2. Sandworm in numbers
Here are 6 insights into the scale of what this group has done.
- Around $10 billion: the estimated global cost of NotPetya in 2017, still the most expensive cyberattack on record. It was aimed at Ukraine and spread worldwide, which is the definitive example of collateral damage from a targeted operation.
- Approximately 230,000 people: left without power in the December 2015 attack on Ukraine’s grid, the first confirmed case of a cyberattack causing a blackout.
- Roughly 17 years of operation: active since around 2009, through multiple governments, sanctions regimes and indictments.
- At least 18 distinct malware families publicly attributed, from BlackEnergy and Industroyer through to the 2026 wipers.
- Six operational phases in Mandiant’s analysis of the group’s wartime activity, from pre-positioning before the 2022 invasion through successive disruption campaigns to a more recent shift toward intelligence collection.
- Since late 2021: how long the BadPilot subgroup has been running opportunistic access operations against internet-facing infrastructure, well beyond Eastern Europe.
3. The Sandworm timeline
Here’s a rundown of the group’s activity.
- December 2015: BlackEnergy and KillDisk cut power to around 230,000 people in Ukraine.
- December 2016: Industroyer, purpose-built to manipulate electricity substation systems, used against Kyiv.
- June 2017: NotPetya, delivered by hijacking the update mechanism of Ukrainian accounting software M.E.Doc and pushed to all users simultaneously.
- February 2018: Olympic Destroyer disrupts the Pyeongchang Winter Olympics opening ceremony, with false flags planted to misdirect attribution.
- February 2022: AcidRain bricks modems in a satellite communications provider on the day of the invasion, with knock-on effects across Europe.
- April 2022: Industroyer2 deployed against a Ukrainian electricity provider, alongside CaddyWiper.
- October 2022: IT and operational technology systems disrupted at a power distribution entity, timed with Russia’s winter campaign of strikes against the grid.
- December 2023: Kyivstar, Ukraine’s largest mobile operator, taken offline. SwiftSlicer deployed.
- January 2024: FrostyGoop, ICS malware, cuts heating to hundreds of apartment buildings in Lviv in winter. One of very few known cases of operational technology malware directly affecting civilians.
- April 2024: Mandiant publishes its APT44 report.
- February 2025: Microsoft details the BadPilot subgroup and its multi-year initial access campaign.
- Through 2025: the ZEROLOT, Sting and ZOV wipers deployed against Ukrainian government, energy, logistics and grain-sector organizations. ESET assessed the objective as weakening the Ukrainian economy.
- 29 to 30 December 2025: DynoWiper deployed against Polish energy infrastructure.
- August 2026: CERT-UA ties subgroup UAC-0145 to fake job interviews delivering a trojanised WireGuard VPN client capable of running arbitrary commands.
4. BadPilot: the part that determines whether you are exposed
In February 2025, Microsoft documented a subgroup within Sandworm dedicated solely to obtaining initial access. It has been running since at least late 2021.
BadPilot does not conduct targeted reconnaissance against selected victims. It exploits known vulnerabilities in internet-facing systems opportunistically, at scale, and works out afterwards which of the resulting footholds are worth keeping. Microsoft describes the victimology as having expanded well beyond the group’s traditional Eastern European focus into North America, multiple European countries, and a long list of others including Australia, India, Egypt, Nigeria, Turkey and Kazakhstan.
The exploited vulnerabilities are a roll-call of edge and collaboration software:
- ConnectWise ScreenConnect (CVE-2024-1709)
- Fortinet FortiClient EMS (CVE-2023-48788)
- Microsoft Exchange (ProxyShell)
- Zimbra Collaboration, OpenFire, JetBrains TeamCity and Outlook
Every one of those is an n-day, not a zero-day. The patches existed. The advantage was speed against slow patch cycles and, more often, against assets nobody had inventoried.
This is the practical consequence for a reader outside government or defence. You do not get selected as a Sandworm target and then attacked. You get collected by an opportunistic access operation that does not know or care who you are, and selection happens later, from the pool. Persistence is established ahead of any destructive activity, sometimes by years.
The supply chain route
Mandiant documented a case where access to a software developer resulted in the downstream compromise of critical infrastructure networks across Eastern Europe and Central Asia, followed by wiper deployment against a selected victim.
NotPetya worked the same way. Sandworm did not breach thousands of organizations individually in 2017. It compromised one accounting software vendor and let the update mechanism do the distribution. If you supply software or managed services to organizations in scope, your customers’ threat model is yours.
5. Poland, December 2025: the attack that failed
On 29 and 30 December 2025, a wiper called DynoWiper was deployed against Polish energy infrastructure. Polish officials said the attack targeted two combined heat and power plants and a management system for renewably generated electricity.
Three things about this are worth sitting with.
It was a NATO and EU member state. Not Ukraine. Poland’s grid is interconnected with the wider European network, which makes this the closest a Sandworm destructive operation has come to Western European energy infrastructure.
The timing was almost certainly deliberate. It fell almost exactly ten years after the December 2015 attack on Ukraine’s grid. This group has a documented history of timing operations for symbolic effect.
It was stopped. Endpoint protection blocked execution of the wiper, significantly limiting the impact. That deserves more attention than it received. The overwhelming majority of coverage of this group describes attacks that succeeded, which produces a quiet fatalism about whether anything works. Something worked here.
One caveat belongs in any honest account: ESET attributes DynoWiper to Sandworm with medium confidence, in contrast to the ZOV wiper which it attributes with high confidence. That hedge is in the source material and should stay in the retelling.
6. The destructive toolkit
Sandworm’s malware divides into categories with quite different defensive implications.
- Fast IT wipers: CaddyWiper, SwiftSlicer, ZEROLOT, Sting, ZOV and DynoWiper. Rapid destruction of files, systems and volumes, frequently distributed through Group Policy, which means the attacker already holds domain control by the time they run.
- Slow wipers: LazyWiper, a PowerShell-based implementation observed from 2025 using a slower destruction model.
- ICS and OT malware: Industroyer, Industroyer2 and FrostyGoop. This is the category that turns a network incident into a physical one.
- Embedded and telecom destructive tooling: AcidRain and AcidPour, capable of bricking modems, routers and storage devices.
- Persistence and espionage tooling: Cyclops Blink, Kapeka, Infamous Chisel and the Biasboat and Loadgrip backdoors seen against Ukrainian energy and water sites.
The Group Policy detail in that first bullet is the one to take away. Wipers are not an intrusion. They are the final action of an intrusion that has already succeeded completely. By the time a wiper executes, detection has failed at every earlier stage.
The hacktivist front
Mandiant identified close ties between Sandworm and CyberArmyofRussia_Reborn, a persona presenting itself as hacktivist. It has claimed attacks on US and Polish water utilities and a French dam, and in at least one case a local US official confirmed a system malfunction causing a tank to overflow at a claimed victim.
The pattern matters for how you read incident claims. Activity presented as amateur ideological hacking may be a state unit operating behind a deniable front, and small municipal utilities with exposed control systems are the softest available targets for demonstrating capability.
7. Are you a Sandworm target?
For the destructive operations, almost certainly not. Sandworm’s wipers land on Ukrainian government, energy, logistics and grain organizations, and on infrastructure in states directly supporting Ukraine. The selection criteria are strategic, not commercial.
For the access operations, the answer is different and less comfortable, because BadPilot does not select. Three exposure routes are worth checking honestly:
- You run one of the affected products on the internet. ScreenConnect, FortiClient EMS, Exchange, Zimbra, TeamCity. Opportunistic exploitation does not check your sector first.
- You are in the energy, water, transport or logistics chain, including as a supplier, contractor or maintenance provider. European critical infrastructure has been in scope since at least 2021 according to independent assessments by Microsoft and Amazon.
- You are collateral. NotPetya is the permanent argument here. Organizations with no connection to Ukraine lost hundreds of millions of dollars because they used one piece of Ukrainian accounting software, or were connected to someone who did.
8. Defending against Sandworm
You cannot deter a military unit. What you can do is remove the openings its access operation depends on, and make sure the destructive stage has somewhere to fail.
Know what you have exposed, then patch it
BadPilot’s entire entry method is n-day exploitation of internet-facing systems. Not novel vulnerabilities. Known ones, on assets that were either unpatched or unknown.
The unknown ones are the harder half of that. Remote management consoles installed by a supplier, a mail server from an acquisition, a collaboration platform stood up by a regional office. Attack Surface Management maps your internet-facing estate from the outside, which is the same vantage point the access operation is working from.
Assume the wiper will be delivered by Group Policy
If the fast wipers arrive through GPO, then domain controller integrity is the control that matters most. Tiered administration, restricted GPO edit rights, alerting on new or modified policies linked to broad scopes, and monitoring for scheduled tasks pushed estate-wide.
Build backups for destruction, not for ransomware
The distinction is real. Against ransomware there is a decryption key in existence somewhere and a counterparty who wants payment. Against a wiper there is nothing to buy. Offline, offsite, immutable copies with a tested restore path are not a mitigation here, they are the recovery plan in full.
Segment operational technology properly
FrostyGoop and Industroyer2 required a path from IT into OT. If you run industrial control systems, the controls that matter are the ones preventing an ordinary corporate compromise from reaching them: genuine network separation, no shared credentials, monitored one-way paths.
Watch the credentials, not just the perimeter
Lateral movement in these intrusions runs on PsExec, stolen credentials and remote management tooling rather than exploits. Credential Intelligence surfaces exposed credentials tied to your domains before somebody uses them to move.
Endpoint protection is not futile here
It blocked DynoWiper in Poland. Against an adversary with this reputation it is easy to conclude that ordinary controls are pointless, and the Polish case is the evidence that they are not.
FAQs
No. Both belong to the GRU’s Information Operations Troops, but Sandworm is assessed as Unit 74455 and APT28 as Unit 26165. Sandworm conducts sabotage and destruction. APT28 conducts espionage and prioritises remaining undetected. Mandiant created the APT44 designation partly to end the conflation of the two.
Ransomware encrypts data reversibly and the operator wants payment, which means a counterparty exists. A wiper destroys data with no recovery path and no negotiation. Some Sandworm operations have been disguised as ransomware, including NotPetya, which displayed a ransom note despite having no functional mechanism to restore files.
Yes. NotPetya spread globally in 2017 causing billions in damage to Western companies. The December 2025 DynoWiper attack targeted Polish energy infrastructure directly. Microsoft and Amazon have both reported sustained targeting of Western critical infrastructure, and the BadPilot access campaign covers North America and multiple European countries.
A subgroup within Sandworm, documented by Microsoft in February 2025, dedicated to gaining initial access rather than conducting attacks. It has exploited n-day vulnerabilities in internet-facing systems since at least late 2021, including ConnectWise ScreenConnect and Fortinet FortiClient EMS, establishing persistence that can precede destructive operations by a considerable margin.
It has done so, twice in Ukraine, in 2015 and 2016, and disrupted a power distribution entity again in October 2022. It also cut heating to hundreds of apartment buildings in Lviv in January 2024 using FrostyGoop. That capability is demonstrated rather than theoretical, though every documented success required a path from IT systems into operational technology.
Over to you
Sandworm is the most consequential destructive cyber actor of the past decade, and for almost every organization reading this, that is not the relevant fact about it.
The relevant fact is that its access operation has been indiscriminately exploiting known vulnerabilities in internet-facing infrastructure since 2021, across every continent, without checking who owns the server first. That pool is where victims come from. Everything destructive happens afterwards, to a subset chosen for reasons that have nothing to do with how easy you were to compromise.
Which makes the useful question a mundane one. Not whether you are a target, but what of yours is reachable from the internet right now, and whether you know about all of it.
