ATT&CKGroupsSandworm Team

Sandworm Team

G0034

Threat group.View on attack.mitre.org

About this group

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009.

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.

Techniques used79

Procedure examples79

TechniqueProcedure example
T1003.001
LSASS Memory

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.

T1003.003
NTDS

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.

T1005
Data from Local System

Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.

T1018
Remote System Discovery

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD.

T1021.002
SMB/Windows Admin Shares

Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run net use to connect to network shares.

T1027
Obfuscated Files or Information

Sandworm Team has used Base64 encoding within malware variants.

T1027.010
Command Obfuscation

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.

T1033
System Owner/User Discovery

Sandworm Team has collected the username from a compromised host.

T1036
Masquerading

Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries.

T1036.005
Match Legitimate Resource Name or Location

Sandworm Team has avoided detection by naming a malicious binary explorer.exe.

T1040
Network Sniffing

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.

T1041
Exfiltration Over C2 Channel

Sandworm Team has sent system information to its C2 server using HTTP.

T1047
Windows Management Instrumentation

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.

T1049
System Network Connections Discovery

Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured.

T1053.005
Scheduled Task

Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines.

View all 79 procedure examples

Software27

Show 3 more

Campaigns3

References7

  1. CrowdStrike VOODOO BEAR Open source
    Meyers, A. (2018, January 19). Meet CrowdStrike’s Adversary of the Month for January: VOODOO BEAR. Retrieved May 22, 2018.
  2. NCSC Sandworm Feb 2020 Open source
    NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020.
  3. UK NCSC Olympic Attacks October 2020 Open source
    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.
  4. US District Court Indictment GRU Oct 2018 Open source
    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.
  5. US District Court Indictment GRU Unit 74455 October 2020 Open source
    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.
  6. USDOJ Sandworm Feb 2020 Open source
    Pompeo, M. (2020, February 20). The United States Condemns Russian Cyber Attack Against the Country of Georgia. Retrieved September 12, 2024.
  7. iSIGHT Sandworm 2014 Open source
    Hultquist, J.. (2016, January 7). Sandworm Team and the Ukrainian Power Authority Attacks. Retrieved October 6, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.