Sandworm

☆ pin
MITRE G0034Also known as Unit 74455, APT44, UAC-0145, Seashell Blizzard, APT34, HEXANE, Voodoo Bear, IRON BARK
Reports
14
First seen
Nov 6, 2025
Last seen
Aug 11, 2026
Motivation
Sabotage, Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×2
×3
Ukraine×3
Poland×2

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×10T1486 Data Encrypted for Impact ×7T1190 Exploit Public-Facing Application ×7T1561 Disk Wipe ×6T1598 Phishing for Information ×4T1204 User Execution ×4T1041 Exfiltration Over C2 Channel ×4T1105 Ingress Tool Transfer ×4T1003 OS Credential Dumping ×3T1059.001 PowerShell ×3T1195 Supply Chain Compromise ×3T1005 Data from Local System ×3

Indicators

cve ×12filename ×12domain ×10url ×3hash_sha1 ×1ip_v4 ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

Sandworm targets IT professionals with trojanized WireGuard VPN client in fake job offers

Bleeping Computer
High

Russian Military Hackers Pose as Recruiters to Target Ukrainian IT Workers

The Record (Recorded Future News)
High

Sandworm uses fake CAPTCHA ClickFix attacks against Ukrainian targets

The Record (Recorded Future News)
High

EU and UK sanction Russian GRU military hackers over coordinated cyberattacks

Bleeping Computer
High

Threats to the 2026 FIFA World Cup: Physical Security, Cyber, and Influence Operations Risk Assessment

Recorded Future Insikt
High

ESET APT Activity Report Q4 2025–Q1 2026

ESET WeLiveSecurity
High

ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits

The Hacker News
Critical

Preparing for Russia's New Generation Warfare in NATO Territory

Recorded Future Insikt
High

CERT-EU Cyber Brief January 2026 – Espionage, Ransomware, and Critical Vulnerabilities

CERT-EU Threat Intel
High

DynoWiper: New data-wiping malware attributed to Sandworm targeting Polish energy company

ESET WeLiveSecurity
High

ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025

ESET WeLiveSecurity
High

Cyber Brief November 2025: Operation Endgame, Sandworm Wipers, China AI Espionage

CERT-EU Threat Intel
High

APT Activity Report Q2–Q3 2025: State-Aligned Groups Target Government and Corporate Systems

ESET WeLiveSecurity
High

ESET APT Activity Report Q2 2025–Q3 2025

ESET WeLiveSecurity

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.