Overview 771 indicators
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.
| ipv4 | 394 | G0034.json |
| domain | 303 | G0034-domain.txt |
| url | 58 | G0034.json |
| url_path | 16 | G0034.json |
Techniques 82 ATT&CK
Open in ATT&CK Navigator → or download the layer (82 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.003 NTDS
- T1005 Data from Local System
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1027 Obfuscated Files or Information
- T1027.010 Command Obfuscation
- T1033 System Owner/User Discovery
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1040 Network Sniffing
- T1041 Exfiltration Over C2 Channel
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1056.001 Keylogging
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1072 Software Deployment Tools
- T1078 Valid Accounts
- T1078.002 Domain Accounts
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1087.003 Email Account
- T1090 Proxy
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1132.001 Standard Encoding
- T1133 External Remote Services
- T1140 Deobfuscate/Decode Files or Information
- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1195.002 Compromise Software Supply Chain
- T1199 Trusted Relationship
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1213.006 Databases
- T1218.011 Rundll32
- T1219 Remote Access Tools
- T1409 Stored Application Data
- T1485 Data Destruction
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491.002 External Defacement
- T1499 Endpoint Denial of Service
- T1505.003 Web Shell
- T1539 Steal Web Session Cookie
- T1555.003 Credentials from Web Browsers
- T1561.002 Disk Structure Wipe
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1570 Lateral Tool Transfer
- T1571 Non-Standard Port
- T1583 Acquire Infrastructure
- T1583.001 Domains
- T1583.004 Server
- T1584.004 Server
- T1584.005 Botnet
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1586.001 Social Media Accounts
- T1587.001 Malware
- T1588.002 Tool
- T1588.006 Vulnerabilities
- T1589.002 Email Addresses
- T1589.003 Employee Names
- T1590.001 Domain Properties
- T1591.002 Business Relationships
- T1592.002 Software
- T1593 Search Open Websites/Domains
- T1594 Search Victim-Owned Websites
- T1595.002 Vulnerability Scanning
- T1598.003 Spearphishing Link
- T1608.001 Upload Malware
- T1660 Phishing
- T1676 Linked Devices
Software 28
- Mimikatz
- PsExec
- Net
- BlackEnergy
- Cobalt Strike
- SDelete
- Invoke-PSImage
- GreyEnergy
- Exaramel for Windows
- Impacket
- Empire
- Olympic Destroyer
- NotPetya
- PoshC2
- Exaramel for Linux
- CHEMISTGAMES
- P.A.S. Webshell
- Industroyer
- Bad Rabbit
- KillDisk
- Cyclops Blink
- VPNFilter
- Prestige
- Industroyer2
- AcidRain
- AcidPour
- Neo-reGeorg
- Kapeka
Principal sources 64 reports
Ranked by how many of this actor's indicators each report brought in.
- 189trendmicro.com/en_us/research/22/c/cyclops-blink-sets-…
- 189otx.alienvault.com/pulse/623319918d3021c70ec8f396
- 179cert.gov.ua/article/6318437
- 176ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Re…
- 35x.com/byrne_emmy12099/status/1856178461515362…
- 35x.com/DaveLikesMalwre/status/1893691921995878…
- 35x.com/Cyber0verload/status/1893952471342428182
- 35cert.gov.ua/article/6282517
Related groups 9
What the sources have in common — not a claim that these are the same actor. See the whole graph.
1 more in the relationship graph.
Timeline 771 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 771. Complete: G0034.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
1o.cdn-googel.com 365softupdate.com 389424.xyz 445600.xyz 4b.cdn-banamex.com ads.tolinkhub.com aiads.best akamaizes.com allserve.xyz api-to-now.allserve.xyz api.beesapp.top api.budandan.com api.chaboshi.cc api.click2mine.top api.degendogs.top api.fastrig.top api.globalsimc.com api.gmc-doge.top api.jackpotsure.win api.luckytonspin.top api.omgton.xyz api.plantton.top api.powerdigger.top api.powerton.top api.surewinsgjackpot.com api.tonblastrun.top api.tonchainer.top api.toncore.top api.tondaily.top api.tondrillx.top api.tonengine.top api.tonfarmers.top api.tonforgex.top api.tonhive.top api.tonmineplus.top api.tonow.top api.tonrushgo.top api.tonvaultchain.top api.tribikauction.co.id api.urvega.com api.xmtk01.xyz api.xsms.ng api.yangsany.cn apiali.huangma188.cc app.chaboshi.cc backup.yuhspace.top bbxgames.top beesapp.top bitooex.com bot.swapbot.ru botservice.tgtool.org budandan.com cdn-banamex.com cdn-googel.com cdn-health-service.com cdn-images-world.com cdn-javascript-source.com cdn-sat.com cfaccount.ccwu.cc chaboshi.cc checknetworkstatus.com checknetwstatus.com click2mine.top codvya.cc cohpoint.com cols.melfordco.com convoai.club ctulocal1.com dashboard.viktor.id.vn datasafereader.com degendogs.top delta.smartlinkupload.com deploynewcdn.com dev-api-ton-mine-x.bbxgames.top dev-tg-clound.jsxgate.xyz devcr.cc diagnostics-monitoring.com dimsumshop.goodomensplus.com do5.net ealingbikes.com email.jsxgate.xyz entouchnetworks.com f16auto.com fastrig.top feirobot.youdianfuli.com fileprotectloader.com freezeblank.online fullycap.com globalsimc.com gmc-doge.top goodomensplus.com goodsmatch.goodomensplus.com h5.xincheng.baby horse-fun.com hp.do5.net htrjhb.npm.ng huangma188.cc i2.cdn-images-world.com ios2026.top ivoryhire.com jackpotsure.win jsxgate.xyz jw.445600.xyz kf.pezxdf.cn lantian123.xyz lc2023.com luckytonspin.top magic.horse-fun.com may.convoai.club melfordco.com mixu.ai msoayvri.com nefzawa.net new-activity.tgtool.org nn.cdn-health-service.com node3-cdn.com offlce366.com omgton.xyz opennetworkconnect.com oq.codvya.cc pack.softpacker.org pezxdf.cn plantton.top platform.mixu.ai powerdigger.top powerton.top s.akamaizes.com sealisten.jsxgate.xyz sjuosdt.top skewertime.goodomensplus.com smartlinkupload.com soft.softchecker.org softchecker.org softpacker.org softupdater.org static.diagnostics-monitoring.com static.opennetworkconnect.com status.ealingbikes.com surewinsgjackpot.com swapbot.ru t3.cdn-sat.com tailchat.lc2023.com tapakweb.my thedatingadvise.com tolinkhub.com tonblastrun.top tonchainer.top toncore.top tondaily.top tondrillx.top tonengine.top tonfarmers.top tonforgex.top tonhive.top tonmineplus.top tonow.top tonrushgo.top tonvaultchain.top tribikauction.co tx.chaboshi.cc update-requirements.com uploader.social urvega.com utm.checknetwstatus.com vb.bitooex.com viktor.id.vn wd.sjuosdt.top web-v2.yunmx.com webman.vip well-sold.com xg.cdn-javascript-source.com xincheng.baby xmtk01.xyz yangsany.cn yf.aiads.best youdianfuli.com yuhspace.top yv.msoayvri.com zz.ios2026.top -
x.com/RexorVc0/status/2036703151303065880 · mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508035…
domain apidocs.ataas.cl domain checksystem.nl domain deltaexchange.net domain dontgivedamn.com domain dontgivefuck.com domain i2rgcvog6cypjohfzfzw3d5kqgoobkzlbchsdxx4gm7lyaxn5nfp6bid.onion domain massgrave.link domain mscloudedge.com domain n6b6j4vlkc4ak343j4fmuwmosxtwrft6bph5s5562lefji4a475smuad.onion domain ovhphpmyadmin.xtreme-vision.net domain smartscreenua.com domain sumbur.net domain xtreme-vision.net ipv4 146.59.116.226:50845 ipv4 57.128.59.134:24102 -
x.com/byrne_emmy12099/status/1856178461515362… · x.com/DaveLikesMalwre/status/1893691921995878… · x.com/Cyber0verload/status/1893952471342428182 · cert.gov.ua/article/6282517 · virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44… · virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e… · virustotal.com/gui/file/baa76590f0917782ca070401feb83c… · virustotal.com/gui/file/9507beb5f00ae19cbd3fc3ac74d761… · virustotal.com/gui/file/05285298ae543665503ab888020460… · virustotal.com/gui/file/0a2a18aac9f5683d4a65e402e22503… · virustotal.com/gui/file/4a302c0ed3c47231bc7c34cf2d41bc…
domain cdnauthsoft.com domain documentreader.net domain documents-reader.com domain object-storage-service.com ipv4 91.232.31.178:873 url adobeprotectcheck.com/Downloads/zayavka.lnk url annualgieconferenceinmunich2024.com/Downloads/ url dobeprotectcheck.com/Downloads/ url ertel-audit.com/wp-includes/GIE_Annual_Conference_2024_Participant_Form.pdf url ertel-audit.com/wp-includes/Zayava_pro_vitik_gasu.pdf url ertel-audit.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php url ertel-audit.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php url furqaanenergy.com/wp-includes/Text/November/ url furqaanenergy.com/wp-includes/Text/November2/ url gieannualconferenceinmunich.com/Downloads/ url gurt.duna.ua/programy-nauczania/arst.dll url helpdesk.katolik.bydgoszcz.pl/eliot.php url http://212.237.217.78 url http://51.222.43.200 url http://66.63.187.79 url http://91.232.31.178 url protectraid.com/Downloads/ url protectraid.com/Downloads/Resume.lnk url protectraid.com/Downloads/Resume.pdf.lnk url protectraid.com/Downloads/VASY.lnk url_path /b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php url_path /b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php url_path /wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php url_path /wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php -
x.com/WhichbufferArda/status/1972012355983720… · virustotal.com/gui/file/6472d2f027e25639b98381affdeb69… · virustotal.com/gui/file/a1b41f7ee862ee9703afda7793d227…
esetpremium.com -
x.com/TLP_R3D/status/1892221224094445666 · cloud.google.com/blog/topics/threat-intelligence/russia-…
150.107.31.194:18000 -
x.com/TLP_R3D/status/1889627590970757502 · app.validin.com/detail?find=a78dda24e41edb22c214a4d5db1… · app.validin.com/detail?find=dca40e790cd76198c6748dc8d5c… · blog.eclecticiq.com/sandworm-apt-targets-ukrainian-users-wi…
2zilmiystfbjib2k4hvhpnv2uhni4ax5ce4xlpb7swkjimfnszxbkaid.onion -
x.com/Now_on_VT/status/1889750562230407235 · x.com/BaoshengbinCumt/status/1889865641223659… · microsoft.com/en-us/security/blog/2025/02/12/the-badp…
ipv4 103.201.129.130:443 url http://103.201.129.130 -
x.com/TLP_R3D/status/1889627590970757502 · app.validin.com/detail?find=a78dda24e41edb22c214a4d5db1… · app.validin.com/detail?find=dca40e790cd76198c6748dc8d5c… · blog.eclecticiq.com/sandworm-apt-targets-ukrainian-users-wi…
domain activationsmicrosoft.com domain kalambur.net domain kms-win11-update.net domain kmsupdate2023.com domain onedrivestandaloneupdater.com domain ratiborus2023.com domain windowsdrivepack.com domain windowsupdatesystem.org url http://5.255.101.146 url http://5.255.114.16 url http://5.255.119.183 url http://5.255.119.195 url http://5.255.121.218 url http://5.255.122.118 url http://5.255.99.169 -
x.com/Now_on_VT/status/1889750562230407235 · x.com/BaoshengbinCumt/status/1889865641223659… · microsoft.com/en-us/security/blog/2025/02/12/the-badp…
cloud-sync.org hwupdates.com -
x.com/StrikeReadyLabs/status/1869210151439253… · x.com/StrikeReadyLabs/status/1869359670290468… · virustotal.com/gui/file/d2049157980b7ee0a54948d4def4ab…
aplusdesktop.workers.dev aplusmodgovua.workers.dev armylpus.workers.dev armyplus-desktop.workers.dev beta-0-110.armyplus-desktop.workers.dev beta-0-2237.desktopapluscom.workers.dev desktopaplus.workers.dev desktopapluscom.workers.dev old-lab-1001.armyplus-desktop.workers.dev wvtmsouaa2gt6jmcuxj5hkfrqdss5lhecoqijt5dl7gfruueu3i5mkad.onion yellow-butterfly-6fcd.armyplus-desktop.workers.dev -
x.com/StrikeReadyLabs/status/1847329950443184… · strikeready.com/blog/ru-apt-targeting-energy-infrastruc… · virustotal.com/gui/file/b8d97d29e99e1f96e06836468db568… · virustotal.com/gui/file/806b5269e7aa9c2c82ce247b30a3e9…
domain adobeprotectcheck.com domain annualgieconferenceinmunich2024.com domain antimailspam.com domain gieannualconferenceinmunich.com domain login.antimailspam.com domain protectconnections.com domain protectraid.com url gurt.duna.ua/programy-nauczania/ url gurt.duna.ua/programy-nauczania/GIEAnnualConferenceStage2 url gurt.duna.ua/programy-nauczania/GTSvitikgasuStage5 url gurt.duna.ua/programy-nauczania/ssowoface.dll -
x.com/StrikeReadyLabs/status/1847329950443184… · strikeready.com/blog/ru-apt-targeting-energy-infrastruc… · virustotal.com/gui/file/b8d97d29e99e1f96e06836468db568… · virustotal.com/gui/file/806b5269e7aa9c2c82ce247b30a3e9… · x.com/byrne_emmy12099/status/1856178461515362… · x.com/DaveLikesMalwre/status/1893691921995878… · x.com/Cyber0verload/status/1893952471342428182 · cert.gov.ua/article/6282517 · virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44… · virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e… · virustotal.com/gui/file/baa76590f0917782ca070401feb83c… · virustotal.com/gui/file/9507beb5f00ae19cbd3fc3ac74d761… · virustotal.com/gui/file/05285298ae543665503ab888020460… · virustotal.com/gui/file/0a2a18aac9f5683d4a65e402e22503… · virustotal.com/gui/file/4a302c0ed3c47231bc7c34cf2d41bc…
afi-ukraine.org/wp-includes/bestone.php calendar.stib.com.ua/bestone.php ertel-audit.com/wp-includes/caramel.php helpdesk.katolik.bydgoszcz.pl/bydgoszcz.php -
x.com/byrne_emmy12099/status/1856178461515362… · x.com/DaveLikesMalwre/status/1893691921995878… · x.com/Cyber0verload/status/1893952471342428182 · cert.gov.ua/article/6282517 · virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44… · virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e… · virustotal.com/gui/file/baa76590f0917782ca070401feb83c… · virustotal.com/gui/file/9507beb5f00ae19cbd3fc3ac74d761… · virustotal.com/gui/file/05285298ae543665503ab888020460… · virustotal.com/gui/file/0a2a18aac9f5683d4a65e402e22503… · virustotal.com/gui/file/4a302c0ed3c47231bc7c34cf2d41bc…
furqaanenergy.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php furqaanenergy.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php -
x.com/DailyDarkWeb/status/1802234656039051511 · services.google.com/fh/files/misc/apt44-unearthing-sandworm…
account-check.hostapp.link account.adfs.kyivstar.online accounts.google-account-settings.spdup.art adfs.kyivstar.online claud.in cloue.link darksea.ddns.net drive.google.com.filepreview.auth.userarea.click filepreview.auth.userarea.click google-account-settings.spdup.art i.ua.account-check.hostapp.link kyivstar.me kyivstar.online login.adfs.kyivstar.online login.kyivstar.online me-cloud.link nalog.in outlook.adfs.kyivstar.online solntsepek.com spdup.art telegramweb.us tgcloud.link tgeo.link tgme.contact tgset.click ua.account-check.hostapp.link ukrnet24.com · 2 more in this batch, in the JSON
Further reading 79
- 2017-2021.state.gov/the-united-states-condemns-russian-cybe…
- attack.mitre.org/groups/G0034
- blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/Bla…
- blog.google/threat-analysis-group/ukraine-remains-r…
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- services.google.com/fh/files/misc/apt44-unearthing-sandworm…
- crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the…
- dragos.com/resource/electrum
- fireeye.com/blog/threat-research/2016/01/ukraine-an…
- gov.uk/government/news/uk-exposes-series-of-ru…
- infosecurity-magazine.com/news/microsoft-zero-day-traced-russian
- justice.gov/opa/page/file/1098481/download
- justice.gov/opa/press-release/file/1328521/download
- microsoft.com/en-us/security/blog/2022/10/14/new-pres…
- ncsc.gov.uk/news/ncsc-supports-sandworm-advisory
- secureworks.com/research/threat-profiles/iron-viking
- cert.gov.ua/article/6278706 (# UAC-0133)
- virustotal.com/gui/file/25497816b84a44be526c4cf048b53f…
- x.com/Now_on_VT/status/1889750562230407235
- x.com/StrikeReadyLabs/status/1847329950443184…
- cert.gov.ua/article/160530 (Ukrainian)
- welivesecurity.com/2018/10/11/new-telebots-backdoor-linkin…
- ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Re…
- welivesecurity.com/2016/01/20/new-wave-attacks-ukrainian-p…
- twitter.com/kyleehmke/status/1267222198588145664
- cert.gov.ua/article/39518 (Ukranian)
- virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e…
- x.com/StrikeReadyLabs/status/1869210151439253…
- virustotal.com/gui/file/806b5269e7aa9c2c82ce247b30a3e9…
- virustotal.com/gui/file/a1b41f7ee862ee9703afda7793d227…
- twitter.com/RecordedFuture/status/15719468034274140…
- mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508035…
- x.com/byrne_emmy12099/status/1856178461515362…
- twitter.com/Des00464472/status/1590213508423352320
- virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44…
- virustotal.com/gui/file/d2049157980b7ee0a54948d4def4ab…
- x.com/StrikeReadyLabs/status/1869359670290468…
- media.defense.gov/2020/May/28/2002306626/-1/-1/0/CSA%20Sa…
- threatconnect.com/blog/threatconnect-research-roundup-pro…
- virustotal.com/gui/file/0bb5e98f77e69d85bf5068bcbc5b58…
39 more, and the report behind every indicator, in G0034.json.