Sandworm
Threat Actor
Sandworm is a very active espionage threat group linked to Russia's GRU (armed forces). The attackers have focused on Ukraine throughout 2023, using phishing lures, Android malware, and data-wipers.
Incidents Associated with this Threat
- December 29, 2025: Polish Power Plant Shut Down
- April 19, 2024: Cyberattack at Indiana Water Plant
- January 9, 2024: Cyberattack on Multiple Rural Texas Water Facilities
- December 12, 2023: Sandworm Linked Group Sabotages Major Ukrainian Communications Provider Affecting Millions of Customers
- May 1, 2023: ‘Sandworm’ Attack Interrupts Service at 11 Telcom Providers in Ukraine
- October 12, 2022: Russian Sandworm Behind Operational Disruption of Ukraine Energy Facility in October 2022
- December 13, 2016: Ukrainian Railway Company Ukrzaliznytsia Hit by Cyberattack
Malware Used by this Threat Actor
No malware identified for this threat actor.
