Not part of a guided workflow —
Next best move:Open the platform atlas Atlas

Official ATT&CK groups · sourced comparison

Documented group behavior. Independent vehicle evidence.

Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.

Behavioral overlap is not attributionSIMULATION — NO LIVE ACTIONS
G0034ATT&CK groupLive catalogue

Sandworm Team

Also tracked as APT44 · BlackEnergy (Group) · ELECTRUM · FROZENBARENTS · IRIDIUM · IRON VIKING · Quedagh · Seashell Blizzard · Telebots · Voodoo Bear

[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with [Sandworm Team](https://attack.mitre.org/groups/G0034) for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide [NotPetya](https://attack.mitre.org/software/S0368) attack, targeting of the 2017 French presidential campaign, the 2018 [Olympic Destroyer](https://attack.mitre.org/software/S0365) attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as [APT28](https://attack.mitre.org/groups/G0007).(Citation: US District Court Indictment GRU Oct 2018)

Attribution boundary

Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.

Official identity source

MITRE ATT&CK · G0034
ATT&CK record
G0034
Record version
4.2
Created
Unknown
Last modified
Unknown
Catalogue release
19.2
Replay fixture
AL-BUILD-TRUST-1.1.0
Technique overlaps
04
Mapped events
13
Evidence gates
15
Defensive analytics
06
Documented groupSandworm TeamT1591.002

Operational sequence assessment

The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1591.002 Gather Victim Org Information: Business Relationships. Consult the official group record for its cited procedure examples.

Public behavior is a comparison lens · Northstar events below are synthetic · no attribution

Synthetic replay lane · not VIN evidence

Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.

NO VIN

Independent VIN gates

Reached

0/1

Failed gates

0/1

Pending

1/1

Coverage gaps

0/1

0/1 evaluated
  1. 1

Select a VIN to build this group’s full evidence path.

A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.

Select VIN

Exact ATT&CK joins

Public behavior mapped to fixture observations

Full technique playbook

Technique context retained

T1591.002 is highlighted below. Public group behavior remains separate from synthetic replay evidence.

  1. PATH 01

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E14 to E28

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E1413:00Build interpositionFile integrity

      Workspace restored to the committed state

      The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.

      BLD-WIN-03

    2. E1615:00Build interpositionFile integrity

      Short-lived file mutation recorded, not alerted

      File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.

      BLD-WIN-03

    3. E2824:30InvestigationFile integrity

      Transient workspace mutation recovered from raw records

      The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.

      BLD-WIN-03

  2. PATH 02

    T1071.001

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1071.001 Application Layer Protocol: Web Protocols. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E23 to E23

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E2322:00Downstream signalEgress proxy

      Egress proxy records a first-seen destination from the build tier

      One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.

      BLD-WIN-03

  3. PATH 03

    T1195.002

    Compromise Software Supply Chain

    Initial Access · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E08 to E29

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E0807:00Build accessCI orchestrator

      The adversary waits for a legitimate build

      Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.

    2. E1110:00Build interpositionEndpoint telemetry

      The helper observes the compiler invocation

      The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.

      BLD-WIN-03

    3. E11A10:30Build interpositionCI orchestrator

      Selectivity check — correct product and expected source version

      Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.

      BLD-WIN-03

    4. E1514:00Build interpositionCI orchestrator

      Produced binary hash differs from the reproducible reference

      Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.

      BLD-WIN-03

    5. E1716:00Trusted releaseCI orchestrator

      Trusted release — the ordinary workflow accepts the artifact

      Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.

    6. E2019:00Trusted releaseRelease system

      Provenance record lacks the compile-input attestation

      The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.

    7. E2422:30Downstream signalEndpoint telemetry

      Marker string observed in the released artifact inventory

      Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.

    8. E2925:00InvestigationRelease system

      Provenance gap documented as the failed boundary

      Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.

  4. PATH 04

    T1591.002

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps Sandworm Team to T1591.002 Gather Victim Org Information: Business Relationships. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E03 to E03

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E0302:00ReconnaissanceEgress proxy

      Release cadence is public

      Published release notes disclose a predictable weekly gateway-agent release and the name of the build toolchain. Public information alone narrows where trust is concentrated.