Sandworm
MITRE G0034Also known as Unit 74455, APT44, UAC-0145, Seashell Blizzard, APT34, HEXANE, Voodoo Bear, IRON BARK
Reports
14
First seen
Nov 6, 2025
Last seen
Aug 11, 2026
Motivation
Sabotage, Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×2×3
Ukraine×3
Poland×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×10T1486 Data Encrypted for Impact ×7T1190 Exploit Public-Facing Application ×7T1561 Disk Wipe ×6T1598 Phishing for Information ×4T1204 User Execution ×4T1041 Exfiltration Over C2 Channel ×4T1105 Ingress Tool Transfer ×4T1003 OS Credential Dumping ×3T1059.001 PowerShell ×3T1195 Supply Chain Compromise ×3T1005 Data from Local System ×3
Indicators
cve ×12filename ×12domain ×10url ×3hash_sha1 ×1ip_v4 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High