Threat actor profile
Sandworm (APT44) aka APT44, Seashell Blizzard, FROZENBARENTS, GRU Unit 74455
Sandworm is attributed to the Main Center for Special Technologies of Russia's GRU, military unit 74455, and has been active since at least 2009. It is also tracked as APT44 and Seashell Blizzard. It is linked to the 2015 and 2016 attacks on Ukraine's power grid, the 2017 NotPetya outbreak, Olympic Destroyer in 2018 and the Industroyer2 attack on Ukrainian power systems in 2022. In October 2020 the US indicted six GRU officers associated with the unit. Its operations focus on disruption and destruction rather than espionage alone.
LatestESET attributed, with medium confidence, a late-December 2025 attempt to deploy a new wiper, DynoWiper, against Poland's energy sector to Sandworm, and said it was not aware of any successful disruption (23 January 2026). Amazon reported in December 2025 on a GRU-linked campaign against Western energy and infrastructure that abused misconfigured network edge devices to harvest and replay credentials.
Timeline
From December 2015 to December 2016, attacks on Ukraine's power grid, Ministry of Finance and State Treasury used BlackEnergy, Industroyer and KillDisk.
NotPetya destructive malware spread worldwide; three victims named by US prosecutors lost nearly $1 billion.
Olympic Destroyer hit IT systems during the PyeongChang Winter Olympics opening ceremony.
The US unsealed charges against six officers of GRU Unit 74455.
A planned Industroyer2 attack on a Ukrainian energy provider was disrupted with CERT-UA's help, ESET reported.
ESET Research — Industroyer2: Industroyer reloaded (12 Apr 2022)
Mandiant designated Sandworm as APT44, describing it as sponsored by GRU Unit 74455.
Amazon described a GRU-linked campaign against Western energy and infrastructure abusing misconfigured edge devices.
ESET attributed a late-December 2025 attempt to deploy the DynoWiper wiper against Poland's energy sector to Sandworm, with medium confidence.
ESET Research — Sandworm behind cyberattack on Poland's power grid in late 2025 (23 Jan 2026)
Who is exposed, and what holds
Who is exposed
- Energy utilities, grid operators and other critical infrastructure in Ukraine, Europe and North America
- Organisations with misconfigured or exposed routers, VPN concentrators and management interfaces
- Telecommunications and cloud providers that can offer onward access
Recommended controls
- Audit edge devices for exposed management interfaces and unexpected packet-capture tools
- Segment IT from OT networks and isolate device management planes
- Maintain offline backups and tested recovery plans for destructive attacks
Sources
- ESET Research — Sandworm behind cyberattack on Poland's power grid in late 2025 (23 Jan 2026)
- Amazon Threat Intelligence — Russian cyber threat group targeting Western critical infrastructure (15 Dec 2025)
- MITRE ATT&CK — Sandworm Team, G0034
- US DOJ — Six Russian GRU officers charged in connection with worldwide deployment of destructive malware (19 Oct 2020)
- Mandiant/Google — APT44: Unearthing Sandworm (17 Apr 2024)