← All actors Recent activity

Sandworm Team G0034

SANDWORM · TELEBOTS · KALAMBUR backdoor · apt44 · blackenergy · iron viking · quedagh · seashell blizzard · temp.noble · voodoo bear

Indicators
771
Source reports
64
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-07-15
20162026

Overview 771 indicators

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019. Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.

ipv4394G0034.json
domain303G0034-domain.txt
url58G0034.json
url_path16G0034.json

Techniques 82 ATT&CK

Open in ATT&CK Navigator → or download the layer (82 techniques, layer 4.5)

Software 28

Principal sources 64 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

1 more in the relationship graph.

Timeline 771 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

Showing the 300 most recent of 771. Complete: G0034.json.

  1. 179 domainthis year

    cert.gov.ua/article/6318437

    1o.cdn-googel.com
    365softupdate.com
    389424.xyz
    445600.xyz
    4b.cdn-banamex.com
    ads.tolinkhub.com
    aiads.best
    akamaizes.com
    allserve.xyz
    api-to-now.allserve.xyz
    api.beesapp.top
    api.budandan.com
    api.chaboshi.cc
    api.click2mine.top
    api.degendogs.top
    api.fastrig.top
    api.globalsimc.com
    api.gmc-doge.top
    api.jackpotsure.win
    api.luckytonspin.top
    api.omgton.xyz
    api.plantton.top
    api.powerdigger.top
    api.powerton.top
    api.surewinsgjackpot.com
    api.tonblastrun.top
    api.tonchainer.top
    api.toncore.top
    api.tondaily.top
    api.tondrillx.top
    api.tonengine.top
    api.tonfarmers.top
    api.tonforgex.top
    api.tonhive.top
    api.tonmineplus.top
    api.tonow.top
    api.tonrushgo.top
    api.tonvaultchain.top
    api.tribikauction.co.id
    api.urvega.com
    api.xmtk01.xyz
    api.xsms.ng
    api.yangsany.cn
    apiali.huangma188.cc
    app.chaboshi.cc
    backup.yuhspace.top
    bbxgames.top
    beesapp.top
    bitooex.com
    bot.swapbot.ru
    botservice.tgtool.org
    budandan.com
    cdn-banamex.com
    cdn-googel.com
    cdn-health-service.com
    cdn-images-world.com
    cdn-javascript-source.com
    cdn-sat.com
    cfaccount.ccwu.cc
    chaboshi.cc
    checknetworkstatus.com
    checknetwstatus.com
    click2mine.top
    codvya.cc
    cohpoint.com
    cols.melfordco.com
    convoai.club
    ctulocal1.com
    dashboard.viktor.id.vn
    datasafereader.com
    degendogs.top
    delta.smartlinkupload.com
    deploynewcdn.com
    dev-api-ton-mine-x.bbxgames.top
    dev-tg-clound.jsxgate.xyz
    devcr.cc
    diagnostics-monitoring.com
    dimsumshop.goodomensplus.com
    do5.net
    ealingbikes.com
    email.jsxgate.xyz
    entouchnetworks.com
    f16auto.com
    fastrig.top
    feirobot.youdianfuli.com
    fileprotectloader.com
    freezeblank.online
    fullycap.com
    globalsimc.com
    gmc-doge.top
    goodomensplus.com
    goodsmatch.goodomensplus.com
    h5.xincheng.baby
    horse-fun.com
    hp.do5.net
    htrjhb.npm.ng
    huangma188.cc
    i2.cdn-images-world.com
    ios2026.top
    ivoryhire.com
    jackpotsure.win
    jsxgate.xyz
    jw.445600.xyz
    kf.pezxdf.cn
    lantian123.xyz
    lc2023.com
    luckytonspin.top
    magic.horse-fun.com
    may.convoai.club
    melfordco.com
    mixu.ai
    msoayvri.com
    nefzawa.net
    new-activity.tgtool.org
    nn.cdn-health-service.com
    node3-cdn.com
    offlce366.com
    omgton.xyz
    opennetworkconnect.com
    oq.codvya.cc
    pack.softpacker.org
    pezxdf.cn
    plantton.top
    platform.mixu.ai
    powerdigger.top
    powerton.top
    s.akamaizes.com
    sealisten.jsxgate.xyz
    sjuosdt.top
    skewertime.goodomensplus.com
    smartlinkupload.com
    soft.softchecker.org
    softchecker.org
    softpacker.org
    softupdater.org
    static.diagnostics-monitoring.com
    static.opennetworkconnect.com
    status.ealingbikes.com
    surewinsgjackpot.com
    swapbot.ru
    t3.cdn-sat.com
    tailchat.lc2023.com
    tapakweb.my
    thedatingadvise.com
    tolinkhub.com
    tonblastrun.top
    tonchainer.top
    toncore.top
    tondaily.top
    tondrillx.top
    tonengine.top
    tonfarmers.top
    tonforgex.top
    tonhive.top
    tonmineplus.top
    tonow.top
    tonrushgo.top
    tonvaultchain.top
    tribikauction.co
    tx.chaboshi.cc
    update-requirements.com
    uploader.social
    urvega.com
    utm.checknetwstatus.com
    vb.bitooex.com
    viktor.id.vn
    wd.sjuosdt.top
    web-v2.yunmx.com
    webman.vip
    well-sold.com
    xg.cdn-javascript-source.com
    xincheng.baby
    xmtk01.xyz
    yangsany.cn
    yf.aiads.best
    youdianfuli.com
    yuhspace.top
    yv.msoayvri.com
    zz.ios2026.top

  2. 13 domain, 2 ipv4this year

    x.com/RexorVc0/status/2036703151303065880 · mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508035…

    domainapidocs.ataas.cl
    domainchecksystem.nl
    domaindeltaexchange.net
    domaindontgivedamn.com
    domaindontgivefuck.com
    domaini2rgcvog6cypjohfzfzw3d5kqgoobkzlbchsdxx4gm7lyaxn5nfp6bid.onion
    domainmassgrave.link
    domainmscloudedge.com
    domainn6b6j4vlkc4ak343j4fmuwmosxtwrft6bph5s5562lefji4a475smuad.onion
    domainovhphpmyadmin.xtreme-vision.net
    domainsmartscreenua.com
    domainsumbur.net
    domainxtreme-vision.net
    ipv4146.59.116.226:50845
    ipv457.128.59.134:24102

  3. or earlier 4 domain, 1 ipv4, 20 url, 4 url_paththis year

    x.com/byrne_emmy12099/status/1856178461515362… · x.com/DaveLikesMalwre/status/1893691921995878… · x.com/Cyber0verload/status/1893952471342428182 · cert.gov.ua/article/6282517 · virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44… · virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e… · virustotal.com/gui/file/baa76590f0917782ca070401feb83c… · virustotal.com/gui/file/9507beb5f00ae19cbd3fc3ac74d761… · virustotal.com/gui/file/05285298ae543665503ab888020460… · virustotal.com/gui/file/0a2a18aac9f5683d4a65e402e22503… · virustotal.com/gui/file/4a302c0ed3c47231bc7c34cf2d41bc…

    domaincdnauthsoft.com
    domaindocumentreader.net
    domaindocuments-reader.com
    domainobject-storage-service.com
    ipv491.232.31.178:873
    urladobeprotectcheck.com/Downloads/zayavka.lnk
    urlannualgieconferenceinmunich2024.com/Downloads/
    urldobeprotectcheck.com/Downloads/
    urlertel-audit.com/wp-includes/GIE_Annual_Conference_2024_Participant_Form.pdf
    urlertel-audit.com/wp-includes/Zayava_pro_vitik_gasu.pdf
    urlertel-audit.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php
    urlertel-audit.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php
    urlfurqaanenergy.com/wp-includes/Text/November/
    urlfurqaanenergy.com/wp-includes/Text/November2/
    urlgieannualconferenceinmunich.com/Downloads/
    urlgurt.duna.ua/programy-nauczania/arst.dll
    urlhelpdesk.katolik.bydgoszcz.pl/eliot.php
    urlhttp://212.237.217.78
    urlhttp://51.222.43.200
    urlhttp://66.63.187.79
    urlhttp://91.232.31.178
    urlprotectraid.com/Downloads/
    urlprotectraid.com/Downloads/Resume.lnk
    urlprotectraid.com/Downloads/Resume.pdf.lnk
    urlprotectraid.com/Downloads/VASY.lnk
    url_path/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php
    url_path/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php
    url_path/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php
    url_path/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php

  4. or earlier 1 domainthis year

    x.com/WhichbufferArda/status/1972012355983720… · virustotal.com/gui/file/6472d2f027e25639b98381affdeb69… · virustotal.com/gui/file/a1b41f7ee862ee9703afda7793d227…

    esetpremium.com

  5. or earlier 1 ipv4this year

    x.com/TLP_R3D/status/1892221224094445666 · cloud.google.com/blog/topics/threat-intelligence/russia-…

    150.107.31.194:18000

  6. or earlier 1 domainthis year

    x.com/TLP_R3D/status/1889627590970757502 · app.validin.com/detail?find=a78dda24e41edb22c214a4d5db1… · app.validin.com/detail?find=dca40e790cd76198c6748dc8d5c… · blog.eclecticiq.com/sandworm-apt-targets-ukrainian-users-wi…

    2zilmiystfbjib2k4hvhpnv2uhni4ax5ce4xlpb7swkjimfnszxbkaid.onion

  7. 1 ipv4, 1 url1 yr ago

    x.com/Now_on_VT/status/1889750562230407235 · x.com/BaoshengbinCumt/status/1889865641223659… · microsoft.com/en-us/security/blog/2025/02/12/the-badp…

    ipv4103.201.129.130:443
    urlhttp://103.201.129.130

  8. 8 domain, 7 url1 yr ago

    x.com/TLP_R3D/status/1889627590970757502 · app.validin.com/detail?find=a78dda24e41edb22c214a4d5db1… · app.validin.com/detail?find=dca40e790cd76198c6748dc8d5c… · blog.eclecticiq.com/sandworm-apt-targets-ukrainian-users-wi…

    domainactivationsmicrosoft.com
    domainkalambur.net
    domainkms-win11-update.net
    domainkmsupdate2023.com
    domainonedrivestandaloneupdater.com
    domainratiborus2023.com
    domainwindowsdrivepack.com
    domainwindowsupdatesystem.org
    urlhttp://5.255.101.146
    urlhttp://5.255.114.16
    urlhttp://5.255.119.183
    urlhttp://5.255.119.195
    urlhttp://5.255.121.218
    urlhttp://5.255.122.118
    urlhttp://5.255.99.169

  9. 2 domain1 yr ago

    x.com/Now_on_VT/status/1889750562230407235 · x.com/BaoshengbinCumt/status/1889865641223659… · microsoft.com/en-us/security/blog/2025/02/12/the-badp…

    cloud-sync.org
    hwupdates.com

  10. 11 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1869210151439253… · x.com/StrikeReadyLabs/status/1869359670290468… · virustotal.com/gui/file/d2049157980b7ee0a54948d4def4ab…

    aplusdesktop.workers.dev
    aplusmodgovua.workers.dev
    armylpus.workers.dev
    armyplus-desktop.workers.dev
    beta-0-110.armyplus-desktop.workers.dev
    beta-0-2237.desktopapluscom.workers.dev
    desktopaplus.workers.dev
    desktopapluscom.workers.dev
    old-lab-1001.armyplus-desktop.workers.dev
    wvtmsouaa2gt6jmcuxj5hkfrqdss5lhecoqijt5dl7gfruueu3i5mkad.onion
    yellow-butterfly-6fcd.armyplus-desktop.workers.dev

  11. 7 domain, 4 url2 yrs ago

    x.com/StrikeReadyLabs/status/1847329950443184… · strikeready.com/blog/ru-apt-targeting-energy-infrastruc… · virustotal.com/gui/file/b8d97d29e99e1f96e06836468db568… · virustotal.com/gui/file/806b5269e7aa9c2c82ce247b30a3e9…

    domainadobeprotectcheck.com
    domainannualgieconferenceinmunich2024.com
    domainantimailspam.com
    domaingieannualconferenceinmunich.com
    domainlogin.antimailspam.com
    domainprotectconnections.com
    domainprotectraid.com
    urlgurt.duna.ua/programy-nauczania/
    urlgurt.duna.ua/programy-nauczania/GIEAnnualConferenceStage2
    urlgurt.duna.ua/programy-nauczania/GTSvitikgasuStage5
    urlgurt.duna.ua/programy-nauczania/ssowoface.dll

  12. 4 url2 yrs ago

    x.com/StrikeReadyLabs/status/1847329950443184… · strikeready.com/blog/ru-apt-targeting-energy-infrastruc… · virustotal.com/gui/file/b8d97d29e99e1f96e06836468db568… · virustotal.com/gui/file/806b5269e7aa9c2c82ce247b30a3e9… · x.com/byrne_emmy12099/status/1856178461515362… · x.com/DaveLikesMalwre/status/1893691921995878… · x.com/Cyber0verload/status/1893952471342428182 · cert.gov.ua/article/6282517 · virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44… · virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e… · virustotal.com/gui/file/baa76590f0917782ca070401feb83c… · virustotal.com/gui/file/9507beb5f00ae19cbd3fc3ac74d761… · virustotal.com/gui/file/05285298ae543665503ab888020460… · virustotal.com/gui/file/0a2a18aac9f5683d4a65e402e22503… · virustotal.com/gui/file/4a302c0ed3c47231bc7c34cf2d41bc…

    afi-ukraine.org/wp-includes/bestone.php
    calendar.stib.com.ua/bestone.php
    ertel-audit.com/wp-includes/caramel.php
    helpdesk.katolik.bydgoszcz.pl/bydgoszcz.php

  13. 2 url2 yrs ago

    x.com/byrne_emmy12099/status/1856178461515362… · x.com/DaveLikesMalwre/status/1893691921995878… · x.com/Cyber0verload/status/1893952471342428182 · cert.gov.ua/article/6282517 · virustotal.com/gui/file/36db27f5eb3343cfc72d261d78da44… · virustotal.com/gui/file/d0a6c1f647ae9f21789bc12f88f00e… · virustotal.com/gui/file/baa76590f0917782ca070401feb83c… · virustotal.com/gui/file/9507beb5f00ae19cbd3fc3ac74d761… · virustotal.com/gui/file/05285298ae543665503ab888020460… · virustotal.com/gui/file/0a2a18aac9f5683d4a65e402e22503… · virustotal.com/gui/file/4a302c0ed3c47231bc7c34cf2d41bc…

    furqaanenergy.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEK.php
    furqaanenergy.com/wp-includes/b1tuZmhqZXJbaGZkYmdhbmFkZmhyZmEKb1.php

  14. 29 domain2 yrs ago

    x.com/DailyDarkWeb/status/1802234656039051511 · services.google.com/fh/files/misc/apt44-unearthing-sandworm…

    account-check.hostapp.link
    account.adfs.kyivstar.online
    accounts.google-account-settings.spdup.art
    adfs.kyivstar.online
    claud.in
    cloue.link
    darksea.ddns.net
    drive.google.com.filepreview.auth.userarea.click
    filepreview.auth.userarea.click
    google-account-settings.spdup.art
    i.ua.account-check.hostapp.link
    kyivstar.me
    kyivstar.online
    login.adfs.kyivstar.online
    login.kyivstar.online
    me-cloud.link
    nalog.in
    outlook.adfs.kyivstar.online
    solntsepek.com
    spdup.art
    telegramweb.us
    tgcloud.link
    tgeo.link
    tgme.contact
    tgset.click
    ua.account-check.hostapp.link
    ukrnet24.com

    · 2 more in this batch, in the JSON

Further reading 79

39 more, and the report behind every indicator, in G0034.json.