Sandworm
QuedaghVOODOO BEARTEMP.NobleIRON VIKINGG0034ELECTRUMTeleBotsIRIDIUMBlue EchidnaFROZENBARENTSUAC-0113Seashell BlizzardUAC-0082APT44SANDWORM RELICUAC-0145
This threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial of service, and data destruction purposes. Some believe that the threat actor is linked to the 2015 compromise of the Ukrainian electrical grid and a distributed denial of service prior to the Russian invasion of Georgia. Believed to be… Fuente: MISP
País atribuido: RU según MISP
Actividad en Jábega · 12 semanas
1 noticias · vista por primera vez el 14 sept 2026 · la última, el 14 sept 2026
Noticias
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 14 sept 2026
Aparece junto a
Técnicas MITRE ATT&CK
Reconocimiento
T1589.002Email Addresses 1 reglas SigmaT1589.003Employee NamesT1590.001Domain Properties 1 reglas SigmaT1591.002Business RelationshipsT1592.002SoftwareT1593Search Open Websites/Domains 2 reglas SigmaT1594Search Victim-Owned WebsitesT1595.002Vulnerability Scanning 1 reglas SigmaT1598.003Spearphishing Link
Preparación de recursos
T1583Acquire InfrastructureT1583.001DomainsT1583.004ServerT1584.004ServerT1584.005BotnetT1585.001Social Media AccountsT1585.002Email AccountsT1586.001Social Media AccountsT1587.001Malware 10 reglas SigmaT1588.002Tool 7 reglas SigmaT1588.006VulnerabilitiesT1608.001Upload Malware
Acceso inicial
T1078Valid Accounts 82 reglas SigmaT1078.002Domain Accounts 3 reglas SigmaT1133External Remote Services 17 reglas SigmaT1190Exploit Public-Facing Application 40 reglas SigmaT1195Supply Chain Compromise 19 reglas SigmaT1195.002Compromise Software Supply Chain 17 reglas SigmaT1199Trusted Relationship 1 reglas SigmaT1566.001Spearphishing Attachment 21 reglas SigmaT1566.002Spearphishing Link 3 reglas Sigma
Ejecución
T1047Windows Management Instrumentation 40 reglas SigmaT1053.005Scheduled Task 40 reglas SigmaT1059.001PowerShell 40 reglas SigmaT1059.005Visual Basic 28 reglas SigmaT1072Software Deployment Tools 4 reglas SigmaT1106Native API 12 reglas SigmaT1203Exploitation for Client Execution 31 reglas SigmaT1204.001Malicious Link 4 reglas SigmaT1204.002Malicious File 32 reglas Sigma
Persistencia
Acceso a credenciales
T1003.001LSASS Memory 40 reglas SigmaT1003.003NTDS 23 reglas SigmaT1040Network Sniffing 7 reglas SigmaT1056.001Keylogging 3 reglas SigmaT1539Steal Web Session Cookie 2 reglas SigmaT1555.003Credentials from Web Browsers 6 reglas Sigma
Descubrimiento
T1018Remote System Discovery 9 reglas SigmaT1033System Owner/User Discovery 26 reglas SigmaT1049System Network Connections Discovery 2 reglas SigmaT1082System Information Discovery 18 reglas SigmaT1083File and Directory Discovery 17 reglas SigmaT1087.002Domain Account 19 reglas SigmaT1087.003Email Account
Movimiento lateral
Recopilación
Mando y control
T1071.001Web Protocols 39 reglas SigmaT1090Proxy 31 reglas SigmaT1102.002Bidirectional Communication 3 reglas SigmaT1105Ingress Tool Transfer 40 reglas SigmaT1132.001Standard Encoding 4 reglas SigmaT1219Remote Access Tools 46 reglas SigmaT1571Non-Standard Port 5 reglas Sigma
Exfiltración
Impacto
T1485Data Destruction 15 reglas SigmaT1486Data Encrypted for Impact 14 reglas SigmaT1489Service Stop 13 reglas SigmaT1490Inhibit System Recovery 26 reglas SigmaT1491.002External DefacementT1499Endpoint Denial of Service 7 reglas SigmaT1561.002Disk Structure Wipe 1 reglas Sigma
Stealth
T1027Obfuscated Files or Information 61 reglas SigmaT1027.010Command Obfuscation 8 reglas SigmaT1036Masquerading 88 reglas SigmaT1036.005Match Legitimate Resource Name or Location 20 reglas SigmaT1070.004File Deletion 9 reglas SigmaT1140Deobfuscate/Decode Files or Information 17 reglas SigmaT1218.011Rundll32 40 reglas Sigma
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗