Sandworm Team, Iron Viking, Voodoo Bear

Description

Sandworm Team is a Russian cyberespionage group that has operated since approximately 2009. The group likely consists of Russian pro-hacktivists. Sandworm Team targets mainly Ukrainian entities associated with energy, industrial control systems, SCADA, government, and media. Sandworm Team has been linked to the Ukrainian energy sector attack in late 2015.

This group appears to be closely associated with, or evolved into, TeleBots.

Names

NameName-Giver
Sandworm TeamTrend Micro
SandwormESET
Iron VikingSecureWorks
CTG-7263SecureWorks
Voodoo BearCrowdStrike
QuedaghF-Secure
TEMP.NobleFireEye
ATK 14Thales
BE2Kaspersky
UAC-0082CERT-UA
UAC-0113CERT-UA
UAC-0125CERT-UA
UAC-0133CERT-UA
FROZENBARENTSGoogle
IRIDIUMMicrosoft
Seashell BlizzardMicrosoft
APT 44Mandiant
Blue EchidnaPwC
Grey Tornado?
Razing UrsaPalo Alto

Country

State-sponsored, GRU Unit 74455

Motivation

  • Sabotage and destruction

First Seen

2009

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

7f0a4e84-4c28-4f8c-a70a-3cac308bca90

Last Card Change

2025-06-30