Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
Sandworm Team
Also tracked as APT44 · BlackEnergy (Group) · ELECTRUM · FROZENBARENTS · IRIDIUM · IRON VIKING · Quedagh · Seashell Blizzard · Telebots · Voodoo Bear
[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with [Sandworm Team](https://attack.mitre.org/groups/G0034) for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide [NotPetya](https://attack.mitre.org/software/S0368) attack, targeting of the 2017 French presidential campaign, the 2018 [Olympic Destroyer](https://attack.mitre.org/software/S0365) attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as [APT28](https://attack.mitre.org/groups/G0007).(Citation: US District Court Indictment GRU Oct 2018)
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0034- ATT&CK record
- G0034
- Record version
- 4.2
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 04
- Mapped events
- 13
- Evidence gates
- 15
- Defensive analytics
- 06
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/8
Failed gates
0/8
Pending
8/8
Coverage gaps
0/8
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
Technique context retained
T1195.002 is highlighted below. Public group behavior remains separate from synthetic replay evidence.
PATH 01
T1070.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E14 to E28
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E1413:00Build interpositionFile integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
BLD-WIN-03
- E1615:00Build interpositionFile integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
BLD-WIN-03
- E2824:30InvestigationFile integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
BLD-WIN-03
PATH 02
T1071.001
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1071.001 Application Layer Protocol: Web Protocols. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E23 to E23
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E2322:00Downstream signalEgress proxy
Egress proxy records a first-seen destination from the build tier
One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.
BLD-WIN-03
PATH 03
T1195.002
Compromise Software Supply Chain
Initial Access · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E08 to E29
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0807:00Build accessCI orchestrator
The adversary waits for a legitimate build
Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.
- E1110:00Build interpositionEndpoint telemetry
The helper observes the compiler invocation
The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.
BLD-WIN-03
- E11A10:30Build interpositionCI orchestrator
Selectivity check — correct product and expected source version
Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.
BLD-WIN-03
- E1514:00Build interpositionCI orchestrator
Produced binary hash differs from the reproducible reference
Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.
BLD-WIN-03
- E1716:00Trusted releaseCI orchestrator
Trusted release — the ordinary workflow accepts the artifact
Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.
- E2019:00Trusted releaseRelease system
Provenance record lacks the compile-input attestation
The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.
- E2422:30Downstream signalEndpoint telemetry
Marker string observed in the released artifact inventory
Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.
- E2925:00InvestigationRelease system
Provenance gap documented as the failed boundary
Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.
PATH 04
T1591.002
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1591.002 Gather Victim Org Information: Business Relationships. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E03 to E03
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0302:00ReconnaissanceEgress proxy
Release cadence is public
Published release notes disclose a predictable weekly gateway-agent release and the name of the build toolchain. Public information alone narrows where trust is concentrated.