logo

Mapping MITRE ATT&CK to SandWorm APT’s Global Campaign

ID: 340c8768-55a2-5baa-8482-853d5f055914

STIX ID: report--340c8768-55a2-5baa-8482-853d5f055914

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2020-10-28

Date Updated: 2026-04-29

...
...

SandWorm (an APT attributed to Russia’s GRU) is the focus of a DoJ indictment of six military officers; the report reviews the group’s historical disruptive campaigns (NotPetya, Ukrainian power-grid outages, Olympic Destroyer, website defacements), maps their techniques to MITRE ATT&CK (phishing, PowerShell, credential dumping, lateral movement, destructive malware), and discusses the limited practical impact of indictments versus operational disruption and sanctions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.