Threat Intelligence / Actor / Sandworm

Sandworm

As of 2026-09-09, Sandworm is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 11 threats spanning ics scada, malware, threat intel. Also known as Seashell Blizzard, Static Tundra, Void Manticore, Red Sandstorm. ATT&CK coverage spans 192 techniques across 25 tactics in 11 of 11 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1005 (Data from Local System), T1036 (Masquerading).

Nation: Russia · 11 tracked threat(s) · Categories: ICS_SCADA, MALWARE, THREAT_INTEL, APT, VULNERABILITY, CAMPAIGN

Also known as: Seashell Blizzard, Static Tundra, Void Manticore, Red Sandstorm, DragonForce, APT44, Sandworm Team - G0034, Blue Echidna, ELECTRUM, FROZENBARENTS, G0034, IRIDIUM

ATT&CK techniques observed

192 techniques observed across 11 of 11 tracked threats · Impact (22), Defense Evasion (18), Initial Access (18), Execution (16), Persistence (16), Collection (15)

Tracked threats

Related CVEs

3 CVEs referenced by tracked Sandworm activity

CVE-2026-21509, CVE-2024-2617, CVE-2014-4114

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence