Sandworm
Sandworm (APT)
Sandworm (APT-Gruppe)
Sandworm is a state-attributed adversary group held responsible for some of the most consequential attacks on critical infrastructure — including the power outages in Ukraine in 2015 and 2016 as well as the Industroyer2 attack in 2022. The group is attributed to Russian military intelligence (GRU). It exemplifies the threat posed by a patient, well-resourced actor (APT).
History & facts. Sandworm is associated with a series of grave operations: the Ukrainian power grid attack in 2015 (with the BlackEnergy malware family), the automated 2016 attack with Industroyer / CrashOverride (Industroyer)/CrashOverride and the Industroyer2 attempt in 2022. Public attributions place the group with a unit of the Russian GRU. The name goes back to references to Frank Herbert's novel „Dune“ found in its malware.
Outlook & recommendation. Sandworm illustrates the Advanced Persistent Threat (APT) profile in its purest form: clear strategic objectives, long-term persistence and the willingness to attack critical infrastructure directly. Against such an adversary, no single product protects, but rather end-to-end visibility across IT and Operational Technology (OT), rehearsed incident response and the assumption of already being in the crosshairs. For KRITIS operators under Network and Information Security Directive 2 (NIS2) this threat is no abstract scenario but documented reality — and a reason to prepare detection and restart seriously.