logo

'Sandworm' Group Is Russia's Primary Cyberattack Unit in Ukraine

ID: 7c74a6e9-a7cf-54c5-9783-772714c680b6

STIX ID: report--7c74a6e9-a7cf-54c5-9783-772714c680b6

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-04-17

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Mandiant attributes a broad, highly capable Russian GRU-linked actor known as Sandworm (APT44) with sustained espionage and destructive operations since 2022 — including attacks on Ukraine's infrastructure, the NotPetya outbreak, ransomware targeting a NATO-country logistics provider, and demonstrations against water/hydroelectric facilities — noting the group's global targeting, exploitation of edge devices and living‑off‑the‑land techniques, and use of front personas (e.g., CyberArmyofRussia_Reborn) to advance Russian military and political objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.