Threat Intelligence / Actor / Sandworm
Sandworm
As of 2026-09-09, Sandworm is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 11 threats spanning ics scada, malware, threat intel. Also known as Seashell Blizzard, Static Tundra, Void Manticore, Red Sandstorm. ATT&CK coverage spans 192 techniques across 25 tactics in 11 of 11 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1005 (Data from Local System), T1036 (Masquerading).
Also known as: Seashell Blizzard, Static Tundra, Void Manticore, Red Sandstorm, DragonForce, APT44, Sandworm Team - G0034, Blue Echidna, ELECTRUM, FROZENBARENTS, G0034, IRIDIUM
ATT&CK techniques observed
- T1003 OS Credential Dumping — Credential Access — observed in 7 of 11 tracked threats
- T1005 Data from Local System — Collection — observed in 7 of 11 tracked threats
- T1036 Masquerading — Defense Evasion — observed in 7 of 11 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 7 of 11 tracked threats
- T1485 Data Destruction — Impact — observed in 7 of 11 tracked threats
- T1566 Phishing — Initial Access — observed in 7 of 11 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 6 of 11 tracked threats
- T1133 External Remote Services — Persistence — observed in 6 of 11 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 5 of 11 tracked threats
- T1053 Scheduled Task/Job — Execution — observed in 5 of 11 tracked threats
- T1070 Indicator Removal — Defense Evasion — observed in 5 of 11 tracked threats
- T1071 Application Layer Protocol — Command And Control — observed in 5 of 11 tracked threats
- T1078 Valid Accounts — Defense Evasion — observed in 5 of 11 tracked threats
- T1110 Brute Force — Credential Access — observed in 5 of 11 tracked threats
- T1489 Service Stop — Impact — observed in 5 of 11 tracked threats
Tracked threats
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry — HIGH
- Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver Trojanized WireGuard VPN Client (SopraVPN) — HIGH
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC — INFO
- Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC Exploitation — CRITICAL
- State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151) — HIGH
- Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities — CRITICAL
- IPIDEA Residential Proxy Botnet Disruption by Google — HIGH
- CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against Ukraine — CRITICAL
- Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms — CRITICAL
- Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper — CRITICAL
- Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure — CRITICAL
Related CVEs
CVE-2026-21509, CVE-2024-2617, CVE-2014-4114
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →