Menu
Browse

Sandworm

Primary URL Location Industry
Undetermined
Country Russia
Government - National Icon
Government - National
Profile

Sandworm is an alias used for a cyber threat actor group. The group’s headquarters is located in Russia. Sandworm has been identified as a Russian military‑linked organization. It is known for carrying out the NotPetya cyberattack in 2017. The group’s activities have been linked to operations targeting Ukrainian entities.

On June 27, 2017, Sandworm executed the NotPetya cyberattack by compromising the update mechanism of a widely used Ukrainian tax software. The malware was disguised as ransomware but was designed to cause irreversible data destruction. NotPetya exploited the EternalBlue and Mimikatz vulnerabilities to propagate across networks. The attack primarily targeted Ukrainian critical infrastructure, including banks, government ministries, energy firms, and the Chernobyl nuclear plant’s radiation monitoring system. It also spread globally, affecting multinational corporations such as Maersk, Merck, and FedEx. The incident resulted in billions of dollars in damages due to operational disruption and permanent data loss. Despite ransom demands, decryption was impossible because of the malware’s destructive core functionality. Attribution by multiple governments and cybersecurity firms identified Sandworm as responsible. The attack was leveraged to destabilize Ukraine amid ongoing geopolitical tensions. The attack is documented in multiple public sources, including the Wikipedia article on the 2017 Ukraine ransomware attacks.

Incidents
Linked incidents available to members
1 incident