# APT44

> As of 2026-09-09, APT44 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 9 threats spanning ics scada, malware, threat intel. Also known as ELECTRUM, Sandworm Team - G0034. ATT&CK coverage spans 159 techniques across 26 tactics in 9 of 9 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1133 (External Remote Services), T1003 (OS Credential Dumping).

- **Nation:** Russia
- **Tracked threats:** 9
- **Categories:** ICS_SCADA, MALWARE, THREAT_INTEL, APT
- **Also known as:** ELECTRUM, Sandworm Team - G0034
- **As of:** 2026-09-09

## ATT&CK techniques observed

159 techniques observed across 9 of 9 tracked threats. Tactics: Stealth (formerly Defense Evasion) (12), Impact (11), Resource Development (11), Initial Access (10), Collection (9), Execution (9).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 5 of 9 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 5 of 9 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 4 of 9 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 4 of 9 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 9 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 9 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 4 of 9 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 9 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 3 of 9 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 3 of 9 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 9 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 9 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 9 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 3 of 9 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 9 tracked threats

## Tracked threats

- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry](https://intel.threadlinqs.com/threat/TL-2026-2420) — HIGH
- [Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver Trojanized WireGuard VPN Client (SopraVPN)](https://intel.threadlinqs.com/threat/TL-2026-1988) — HIGH
- [UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign impersonating Sopra Steria Bulgaria](https://intel.threadlinqs.com/threat/TL-2026-1973) — HIGH
- [ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilities](https://intel.threadlinqs.com/threat/TL-2026-1883) — CRITICAL
- [Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC](https://intel.threadlinqs.com/threat/TL-2026-1730) — INFO
- [UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against Ukraine](https://intel.threadlinqs.com/threat/TL-2026-1527) — HIGH
- [Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0125) — CRITICAL
- [State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)](https://intel.threadlinqs.com/threat/TL-2026-0111) — HIGH
- [Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities](https://intel.threadlinqs.com/threat/TL-2026-0053) — CRITICAL

## Related CVEs

2 CVEs referenced by tracked APT44 activity.

- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT44
