THREAT-WATCH logo

THREAT‑WATCH

Threat Actors

Sandworm

Voodoo Bear, APT44, Unit 74455

ActiveState-sponsored (Russia)

A Russian military intelligence (GRU) unit specifically known for destructive operations against operational technology and critical infrastructure.

Sandworm is widely attributed to some of the most consequential OT-targeted attacks on record, including the 2015 and 2016 attacks on Ukraine's power grid that caused actual blackouts, and the 2017 NotPetya malware, which caused an estimated $10 billion in global damage after spreading far beyond its apparent original target. Unlike most espionage-focused state actors, Sandworm's operations are frequently destructive by design, making it one of the most closely watched threat actors for any organization running industrial control systems.

Target Sectors

Energy grids, industrial control systems, and government/military targets, with a particular historical focus on Ukraine but demonstrated capability for broader collateral impact.

24/7 SOC Monitoring & MDR