logo

apt44-unearthing-sandworm.pdf

ID: 93842a63-9b33-4a42-8f79-eaa3109ac050

STIX ID: report--93842a63-9b33-4a42-8f79-eaa3109ac050

Threat Score

95/100

Uploaded: 2026-08-14

Published Date: 2024-04-16

Last Modified Date: 2024-04-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Mandiant report, “APT44: Unearthing Sandworm,” attributes a wide range of espionage, disruptive (wiper) and influence operations to APT44 (Unit 74455/GRU), documents its global targeting mandate and wartime focus on Ukraine, catalogs extensive custom and commodity malware families and hunting rules, outlines observed TTPs (edge exploitation, LOTL, supply‑chain compromise, OT targeting), and provides IOCs and mitigation guidance; the report assesses APT44 as a highly capable, state‑sponsored actor responsible for destructive attacks against critical infrastructure and election/information operations.