Sandworm is a destructive Russia-linked GRU group responsible for some of the most damaging cyberattacks in history, including NotPetya and attacks on Ukraine’s power grid.
Key facts
- Attributed to Russia’s GRU and known for destructive wiper malware.
- Behind NotPetya (2017) and multiple attacks on Ukraine’s electricity grid.
- Through 2025, deployed wiper malware against Ukrainian government, energy, logistics and grain sectors.
- Focuses on disruption and destruction rather than data theft.
Why it matters
Sandworm demonstrates cyberattacks as instruments of disruption and war. Critical-infrastructure operators must detect intrusions and exposed access before wipers are deployed.
How DarkThreatX helps
DarkThreatX tracks threat-actor activity, leaked credentials and exposed data across the dark web so security teams can act on early warning. Run a free dark web scan or explore the platform.