🇷🇺Sandworm
🇷🇺 Sandworm is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: State. We map 26 detection use cases to this actor across 121 MITRE ATT&CK techniques, with 12 threat-intel articles citing them. Active in our corpus from 2025-11-06 to 2026-05-28.
crit 9high 3
26Use cases
12Articles
121Techniques
14IOCs
Known aliases
SandwormVoodoo BearTeleBotsBlackEnergy GroupIron VikingSeashell BlizzardGRU Unit 74455Sandworm TeamELECTRUMTelebotsIRON VIKINGBlackEnergy (Group)QuedaghIRIDIUMFROZENBARENTSAPT44
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1003.007 · Proc FilesystemT1005 · Data from Local SystemT1018 · Remote System DiscoveryT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.009 · Embedded PayloadsT1027.010 · Command ObfuscationT1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.005 · Match Legitimate Resource Name or LocationT1040 · Network SniffingT1041 · Exfiltration Over C2 ChannelT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1056.001 · KeyloggingT1059 · Command and Scripting InterpreterT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1072 · Software Deployment ToolsT1078 · Valid AccountsT1078.002 · Domain AccountsT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.002 · Domain AccountT1087.003 · Email AccountT1090 · ProxyT1090.001 · Internal ProxyT1090.002 · External ProxyT1098.001 · Additional Cloud CredentialsT1102.002 · Bidirectional CommunicationT1102.003 · One-Way CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1124 · System Time DiscoveryT1132.001 · Standard EncodingT1133 · External Remote ServicesT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1195 · Supply Chain CompromiseT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1213.006 · DatabasesT1218 · System Binary Proxy ExecutionT1218.011 · Rundll32T1219 · Remote Access ToolsT1485 · Data DestructionT1486 · Data Encrypted for ImpactT1489 · Service StopT1490 · Inhibit System RecoveryT1491.002 · External DefacementT1498 · Network Denial of ServiceT1499 · Endpoint Denial of ServiceT1505.003 · Web ShellT1528 · Steal Application Access TokenT1529 · System Shutdown/RebootT1539 · Steal Web Session CookieT1543.001 · Launch AgentT1543.002 · Systemd ServiceT1546 · Event Triggered ExecutionT1546.016 · Installer PackagesT1547.001 · Registry Run Keys / Startup FolderT1552.001 · Credentials In FilesT1554 · Compromise Host Software BinaryT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1558 · Steal or Forge Kerberos TicketsT1561.001 · Disk Content WipeT1561.002 · Disk Structure WipeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.004 · Spearphishing VoiceT1567 · Exfiltration Over Web ServiceT1567.002 · Exfiltration to Cloud StorageT1568 · Dynamic ResolutionT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1571 · Non-Standard PortT1572 · Protocol TunnelingT1574.002 · T1574.002T1583 · Acquire InfrastructureT1583.001 · DomainsT1583.003 · Virtual Private ServerT1583.004 · ServerT1584.004 · ServerT1584.005 · BotnetT1585.001 · Social Media AccountsT1585.002 · Email AccountsT1586.001 · Social Media AccountsT1587.001 · MalwareT1588.002 · ToolT1588.006 · VulnerabilitiesT1589.002 · Email AddressesT1589.003 · Employee NamesT1590.001 · Domain PropertiesT1591.002 · Business RelationshipsT1592.002 · SoftwareT1593 · Search Open Websites/DomainsT1594 · Search Victim-Owned WebsitesT1595.002 · Vulnerability ScanningT1598.003 · Spearphishing LinkT1608.001 · Upload MalwareT1680 · Local Storage Discovery
Detection use cases (26)
Sandworm GPO-Deployed Wiper via Task Scheduler Fan-Out from SYSVOL / C:\Windows Root HermeticWiper / Sandworm EaseUS Partition Driver Loaded by Non-Vendor Process NoName057(16) DDoSia client check-in (/client/login, /client/get_targets) World Cup 2026 themed lookalike / typosquat domain resolution by corporate hosts Beaconing — periodic outbound to small set of destinations Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement 1Password impossible-travel sign-in Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Developer package install spawning script-host with non-registry C2 within 5 minutes Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 MinutesThreat-intel articles (12)
crit ESET APT Activity Report Q4 2025–Q1 2026 · 2026-05-28
crit Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account · 2026-05-18
crit TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages · 2026-05-12
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages · 2026-04-29
high Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm · 2026-04-23
crit ESET APT Activity Report Q2 2025–Q3 2025 · 2025-11-06
Tracked indicators
Domains (11)
api.masscan.cloud audit.checkmarx.cx esetremover.com esetscanner.com esetsmart.com filev2.getsession.org git-tanstack.com litter.catbox.moe m-kosche.com progamevl.ru t.m-kosche.comIP addresses (3)
185.95.159.32 31.172.71.5 83.142.209.194CVEs (3)
CVE-2024-42009 CVE-2025-8088 CVE-2026-45321