Threat group.View on attack.mitre.org
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009.
In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory. |
| T1003.003 NTDS |
Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access. |
| T1005 Data from Local System |
Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts. |
| T1018 Remote System Discovery |
Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD. |
| T1021.002 SMB/Windows Admin Shares |
Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run |
| T1027 Obfuscated Files or Information |
Sandworm Team has used Base64 encoding within malware variants. |
| T1027.010 Command Obfuscation |
Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor. |
| T1033 System Owner/User Discovery |
Sandworm Team has collected the username from a compromised host. |
| T1036 Masquerading |
Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries. |
| T1036.005 Match Legitimate Resource Name or Location |
Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1040 Network Sniffing |
Sandworm Team has used intercepter-NG to sniff passwords in network traffic. |
| T1041 Exfiltration Over C2 Channel |
Sandworm Team has sent system information to its C2 server using HTTP. |
| T1047 Windows Management Instrumentation |
Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1049 System Network Connections Discovery |
Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1053.005 Scheduled Task |
Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.