![]() Organizational structure of Russian Intelligence Service (RIS). The Sandworm group operates under GRU. | |
Formation | c. 2004–2007[1] |
---|---|
Type | Advanced persistent threat |
Purpose | Cyberespionage, cyberwarfare |
Headquarters | 22 Kirova Street Khimki, Russia |
Region | Russia |
Methods | Zero-days, spearphishing, malware |
Official language | Russian |
Parent organization | GRU |
Affiliations | Fancy Bear |
Formerly called | Voodoo Bear [1] Iron Viking [2] Telebots [2] |
Sandworm is an advanced persistent threat operated by MUN 74455, a cyberwarfare unit of the GRU, Russia's military intelligence service.[3] Other names for the group, given by cybersecurity researchers, include APT44,[4] Telebots, Voodoo Bear, IRIDIUM, Seashell Blizzard,[5] and Iron Viking.[6][7][8]
The team is believed to be behind the December 2015 Ukraine power grid cyberattack,[9][10][11] the 2017 cyberattacks on Ukraine using the NotPetya malware,[12] various interference efforts in the 2017 French presidential election,[6] and the cyberattack on the 2018 Winter Olympics opening ceremony.[13][14] Then-United States Attorney for the Western District of Pennsylvania Scott Brady described the group's cyber campaign as "representing the most destructive and costly cyber-attacks in history."[6]
© MMXXIII Rich X Search. We shall prevail. All rights reserved. Rich X Search