All actors

Sandworm Team

Also reported as IRIDIUM, Seashell Blizzard, Quedagh, FROZENBARENTS, APT44 and 39 other names. Sources disagree on the origin.

Reports
528
Last reported
Known CVEs
185
Techniques in ATT&CK
85
Origin
Iran, Russia
ID
G0034
Merge evidence
65 alias matches

Reports per quarter

  1. 2007 Q4: 1 report
  2. 2008 Q1: no reports
  3. 2008 Q2: no reports
  4. 2008 Q3: no reports
  5. 2008 Q4: no reports
  6. 2009 Q1: no reports
  7. 2009 Q2: no reports
  8. 2009 Q3: no reports
  9. 2009 Q4: no reports
  10. 2010 Q1: 1 report
  11. 2010 Q2: no reports
  12. 2010 Q3: 1 report
  13. 2010 Q4: no reports
  14. 2011 Q1: no reports
  15. 2011 Q2: no reports
  16. 2011 Q3: no reports
  17. 2011 Q4: no reports
  18. 2012 Q1: no reports
  19. 2012 Q2: no reports
  20. 2012 Q3: no reports
  21. 2012 Q4: no reports
  22. 2013 Q1: no reports
  23. 2013 Q2: no reports
  24. 2013 Q3: no reports
  25. 2013 Q4: no reports
  26. 2014 Q1: no reports
  27. 2014 Q2: no reports
  28. 2014 Q3: 1 report
  29. 2014 Q4: 12 reports
  30. 2015 Q1: 2 reports
  31. 2015 Q2: 1 report
  32. 2015 Q3: 3 reports
  33. 2015 Q4: 1 report
  34. 2016 Q1: 12 reports
  35. 2016 Q2: no reports
  36. 2016 Q3: 4 reports
  37. 2016 Q4: 10 reports
  38. 2017 Q1: 4 reports
  39. 2017 Q2: 23 reports
  40. 2017 Q3: 15 reports
  41. 2017 Q4: 9 reports
  42. 2018 Q1: 4 reports
  43. 2018 Q2: 1 report
  44. 2018 Q3: 3 reports
  45. 2018 Q4: 8 reports
  46. 2019 Q1: 13 reports
  47. 2019 Q2: 8 reports
  48. 2019 Q3: 5 reports
  49. 2019 Q4: 3 reports
  50. 2020 Q1: 8 reports
  51. 2020 Q2: 13 reports
  52. 2020 Q3: 8 reports
  53. 2020 Q4: 17 reports
  54. 2021 Q1: 10 reports
  55. 2021 Q2: 7 reports
  56. 2021 Q3: 8 reports
  57. 2021 Q4: 5 reports
  58. 2022 Q1: 71 reports
  59. 2022 Q2: 51 reports
  60. 2022 Q3: 12 reports
  61. 2022 Q4: 12 reports
  62. 2023 Q1: 18 reports
  63. 2023 Q2: 9 reports
  64. 2023 Q3: 6 reports
  65. 2023 Q4: 10 reports
  66. 2024 Q1: 3 reports
  67. 2024 Q2: 15 reports
  68. 2024 Q3: 8 reports
  69. 2024 Q4: 6 reports
  70. 2025 Q1: 8 reports
  71. 2025 Q2: 5 reports
  72. 2025 Q3: 4 reports
  73. 2025 Q4: 3 reports
  74. 2026 Q1: 7 reports
  75. 2026 Q2: 57 reports
  76. 2026 Q3: 2 reports
Dated reports, 2007 Q4 to 2026 Q3.

Techniques seen in the last two years

Show all 294 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 24 techniques Show fewer

CVEs named in reports

Show all 185 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. DCRat (Malware Family)

    date ORKL added it fromORKL

Show all 528 reports Show fewer
  1. CyclopsBlink (Malware Family)

    date ORKL added it fromORKL

  2. HermeticWiper (Malware Family)

    date ORKL added it fromORKL

  3. Olympic Destroyer (Malware Family)

    date ORKL added it fromORKL

  4. Sandworm Team, Iron Viking, Voodoo Bear

    date ORKL added it fromORKL

  5. BlackEnergy (Malware Family)

    date ORKL added it fromORKL

  6. EternalPetya (Malware Family)

    date ORKL added it fromORKL

  7. Sandworm Zero Day Vulnerability | iSIGHT Partners

    date ORKL added it fromORKL

  8. BlackEnergy

    date ORKL added it fromORKL

  9. Research, News, and Perspectives

    date ORKL added it fromORKL

  10. VPNFilter (Malware Family)

    date ORKL added it fromORKL

  11. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  12. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  13. PartyTicket (Malware Family)

    date ORKL added it fromORKL

  14. APT44 Report

    Malpedia library date Selin Uğurlu fromORKL

  15. CERT-UA

    Malpedia library date fromORKL

  16. Ukraine remains Russia’s biggest cyber focus in 2023

    date in the title fromORKL

  17. Microsoft Security Compliance and Identity

    Malpedia library date Microsoft fromORKL

  18. SwiftSlicer- New destructive wiper malware strikes Ukraine

    date in the title fromORKL

  19. CERT-UA

    Malpedia library date fromORKL

  20. Unpacking Colibri Loader- A Russian APT linked Campaign

    date in the title fromORKL

  21. Space Invaders- Cyber Threats That Are Out Of This World

    date in the title fromORKL

  22. Continued cyber activity in Eastern Europe observed by TAG

    date in the title fromORKL

  23. CERT-UA

    Malpedia library date fromORKL

  24. Deep Analysis of Snake Keylogger

    date in the title fromORKL

  25. CERT-UA

    Malpedia library date fromORKL

  26. eset_threat_report_t12022

    file creation date fromORKL

  27. Network Footprints of Gamaredon Group

    date in the title fromORKL

  28. BE2 custom plugins, router abuse, and target profiles.pdf

    file creation date fromORKL

  29. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  30. Black Energy – Analysis.pdf

    file creation date fromORKL

  31. Industroyer2 in Perspective

    date in the title fromORKL

  32. Industroyer2 in Perspective

    date in the title fromORKL

  33. Russian State-Sponsored and Criminal Cyber .pdf

    file creation date fromORKL

  34. Industroyer2- Industroyer reloaded

    date in the title fromORKL

  35. Industroyer2 Industroyer Reloaded

    date in the title fromORKL

  36. CERT-UA

    Malpedia library date fromORKL

  37. Industroyer2- Industroyer reloaded

    date in the title fromORKL

  38. Ukraine CyberWar Overview

    date in the title fromORKL

  39. AcidRain: A Modem Wiper Rains Down on Europe

    date in the CCS '25 data Sentinelone fromORKLCCS '25 data

  40. AcidRain - A Modem Wiper Rains Down on Europe

    date in the title fromORKL

  41. Who is EMBER BEAR-

    date in the title fromORKL

  42. New Sandworm Malware Cyclops Blink Replaces VPNFilter

    date in the CCS '25 data CISA fromCCS '25 data

  43. Sandworm- A tale of disruption told anew

    date in the title fromORKL

  44. Cyclops Blink malware sets up shop in ASUS routers

    date in the title fromORKL

  45. Cyclops Blink Sets Sights on Asus Routers

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  46. Cyclops Blink Sets Sights on Asus Routers

    date in the title fromORKL

  47. New CaddyWiper data wiping malware hits Ukrainian networks

    date in the title fromORKL

  48. HermeticWiper and PartyTicket Targeting Computers in Ukraine

    date in the CCS '25 data RecordedFuture fromCCS '25 data

  49. Cyber threat activity in Ukraine- analysis and resources

    date in the title fromORKL

  50. Russia or Ukraine- Hacking groups take sides

    date in the title fromORKL

  51. Threat Update – Ukraine & Russia conflict

    date in the title fromORKL

  52. Shadowserver Special Reports – Cyclops Blink

    date in the title fromORKL

  53. New Sandworm malware Cyclops Blink replaces VPNFilter

    date in the title fromORKL

  54. eset_threat_report_t32021

    file creation date fromORKL

  55. Deep Analysis Agent Tesla Malware

    date in the title fromORKL

  56. Anticipating Cyber Threats as the Ukraine Crisis Escalates

    date in the title fromORKL

  57. Anticipating and Preparing for Russian Cyber Activity

    date in the title fromORKL

  58. Technical Analysis of the WhisperGate Malicious Bootloader

    date in the title fromORKL

  59. Deep analysis agent tesla malware

    date in the title fromORKL

  60. UNC1151_Assessed-with-High-Confidence-to-have-Links-to-Belarus_Mandiant

    date in the CCS '25 data Mandiant fromORKLCCS '25 data

  61. eset_threat_report_t22021

    file creation date fromORKL

  62. The Ghostwriter Scenario (UNC1151)

    date in the title fromORKL

  63. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  64. Technical report of AgentTesla

    date in the title fromORKL

  65. Centreon to Exim and Back- On the Trail of Sandworm

    date in the title fromORKL

  66. France Ties Russia's Sandworm to a Multiyear Hacking Spree

    date in the title fromORKL

  67. What Is the Point of These Nation-State Indictments-

    date in the title fromORKL

  68. The Devil’s in the Details- SUNBURST Attribution

    date in the title fromORKL

  69. Russian cyber attack campaigns and actors

    date in the title fromORKL

  70. Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  71. Extrapolating Adversary Intent Through Infrastructure

    date in the title fromORKL

  72. The Enigmatic Energetic Bear

    date in the title fromORKL

  73. Revisited- Fancy Bear's New Faces...and Sandworms' too

    date in the title fromORKL

  74. Attribution- A Puzzle

    date in the title fromORKL

  75. ESET_Threat_Report_Q22020

    file creation date fromORKL

  76. Russia's GRU Hackers Hit US Government and Energy Targets

    date in the title fromORKL

  77. Probable Sandworm Infrastructure

    date in the title fromORKL

  78. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  79. NSA- Russia's Sandworm Hackers Have Hijacked Mail Servers

    date in the title fromORKL

  80. Silos of Excellence

    date in the title fromORKL

  81. ESET_Turla_ComRAT

    Malpedia library date ESET fromORKLCCS '25 data

  82. ESET_Threat_Report_Q12020

    date in the CCS '25 data ESET fromORKLCCS '25 data

  83. UK condemns Russia's GRU over Georgia cyber-attacks

    date in the title fromORKL

  84. North American Electric Cyber Threat Perspective

    Malpedia library date fromORKL

  85. Operation Ghost

    Malpedia library date ESET fromORKLCCS '25 data

  86. Zebrocy Multilanguage Malware Salad

    date in the CCS '25 data EFF fromORKLCCS '25 data

  87. Zebrocy’s Multilanguage Malware Salad

    date in the title fromORKL

  88. Malware Against the C Monoculture

    date in the title fromORKL

  89. ESET-LightNeuron

    Malpedia library date fromORKL

  90. rpt-mtrends-2019.pdf

    file creation date fromORKL

  91. Report2019GlobalThreatReport

    file creation date fromORKL

  92. rpt-mtrends-2019

    file creation date fromORKL

  93. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  94. BLACK ENERGY – Analysis

    date in the title fromORKL

  95. ESET_GreyEnergy

    Malpedia library date ESET fromORKLCCS '25 data

  96. BfV Cyber-Brief Nr. 02/2018

    file creation date Bundesamt für Verfassungsschutz fromORKL

  97. Industrial Control System Threats

    Malpedia library date Dragos fromORKL

  98. blog

    file creation date fromORKL

  99. TeleBots are back_ supply-chain attacks against Ukraine

    file creation date fromORKL

  100. Cyberattacks Against Ukrainian ICS

    file creation date Sentryo fromORKL

  101. Casting a Light on BlackEnergy

    date in the title fromORKL

  102. Analysis of TeleBots’ cunning backdoor

    date in the title fromORKL

  103. Industroyer

    Malpedia library date fromORKL

  104. Industroyer

    date in the title fromORKL

  105. From BlackEnergy to ExPetr - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  106. TeleBots are back- Supply‑chain attacks against Ukraine

    date in the title fromORKL

  107. CrashOverride_revised091118

    Malpedia library date fromORKL

  108. Open Source Malware - Sharing is caring?

    Malpedia library date fromORKL

  109. Open Source Malware - Sharing is caring-

    date in the title fromORKL

  110. CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations

    date in the CCS '25 data Dragos fromORKLCCS '25 data

  111. Enhanced Analysis of GRIZZLY STEPPE Activity

    file creation date US-CERT fromORKL

  112. GRIZZLY STEPPE - Russian Malicious Cyber Activity

    date in the CCS '25 data US-CERT fromORKLCCS '25 data

  113. The rise of TeleBots: Analyzing disruptive KillDisk attacks

    date in the CCS '25 data RSA fromORKLCCS '25 data

  114. It's Parliamentary: KeyBoy and the targeting of the Tibetan Community

    date in the CCS '25 data Citizen Lab fromORKLCCS '25 data

  115. Industrial Cybersecurity Threat Briefing

    file creation date Booz Allen fromORKL

  116. Fireeye - ICS Vulnerability Trend Report - 2016.pdf

    file creation date fromORKL

  117. Unveiling Patchwork

    file creation date fromORKL

  118. Unveiling Patchwork the Copy Paste APT

    date in the CCS '25 data Cymmetria fromORKLCCS '25 data

  119. Ongoing Sophisticated Malware Campaign Compromising ICS (Update C) | ICS-CERT

    date in the CCS '25 data ICS-CERT fromORKLCCS '25 data

  120. BlackEnergy3_WP_012716_1c

    file creation date fromORKL

  121. New wave of cyberattacks against Ukrainian power industry

    date in the CCS '25 data ESET fromORKLCCS '25 data

  122. Operation Potao Express: Analysis Of A Cyber-Espionage Toolkit

    Malpedia library date ESET fromORKLCCS '25 data

  123. rpt-m-trends-2015.pdf

    file creation date fromORKL

  124. Korplug military targeted attacks: Afghanistan & Tajikistan

    date in the CCS '25 data ESET fromORKLCCS '25 data

  125. Timeline of Sandworm Attacks

    date in the title fromORKL

  126. BE2 Custom Plugins, Router Abuse, and Target Profiles - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  127. BE2 custom plugins, router abuse, and target profiles

    date in the title fromORKL

  128. Sandworm Briefing Deck

    date in the CCS '25 data iSight Partners fromORKLCCS '25 data

  129. BlackEnergy & Quedagh: The convergence of crimeware and APT attacks

    date in the CCS '25 data F-Secure fromORKLCCS '25 data

  130. Black Energy Crypto

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.