Mapping MITRE ATT&CK to SandWorm APTâs Global Campaign
ID: 340c8768-55a2-5baa-8482-853d5f055914
STIX ID: report--340c8768-55a2-5baa-8482-853d5f055914
Feed Name: ReliaQuest Blog
Threat Score
SandWorm (an APT attributed to Russia’s GRU) is the focus of a DoJ indictment of six military officers; the report reviews the group’s historical disruptive campaigns (NotPetya, Ukrainian power-grid outages, Olympic Destroyer, website defacements), maps their techniques to MITRE ATT&CK (phishing, PowerShell, credential dumping, lateral movement, destructive malware), and discusses the limited practical impact of indictments versus operational disruption and sanctions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
