CASE DOSSIER fugitive

U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)

Docket: 2:20-cr-00316 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2020-10-15 Sector: Energy, Healthcare, Government, Transportation

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$10.0 billion
Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.
Techniques
9
Verified mappings
Defendants
5
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Energy, Healthcare, Government, Transportation.
  • Documented Financial Loss: $10.0 billion.
  • 9 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Supply-chain compromise of Ukrainian tax accounting software M.E.Doc (Intellect Service). Threat actors infiltrated the vendor's update infrastructure and backdoored the routine update binary ezvit.exe to deploy a malicious loader across thousands of corporate networks.

Operational & Financial Fallout

Exceeded $10 billion in global economic damages. Paralyzed A.P. Moller-Maersk (shutting down 76 shipping terminals worldwide), FedEx TNT Express (permanently destroying tracking databases and causing $400M in losses), Merck Pharmaceuticals ($870M in losses), and Heritage Valley Health System (disrupting patient surgical suites and emergency rooms).

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Supply-chain compromise of Ukrainian tax accounting software M.E.Doc (Intellect Service). Threat actors infiltrated the vendor's update infrastructure and backdoored the routine update binary ezvit.exe to deploy a malicious loader across thousands of corporate networks.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Infiltration Software Supply Chain Compromise
MITRE ATT&CK T1190 →

Russian GRU operatives breached the internal update server of Intellect Service in Ukraine, replacing the legitimate ezvit.exe update binary with a backdoored variant that executed silently on client systems during tax report synchronization.

Artifacts & Tooling: ezvit.exe M.E.Doc update package BKDR_HERLOK.A
2
Credential Dumping In-Memory LSASS Credential Harvesting
MITRE ATT&CK T1003 →

Upon execution, a bundled custom Mimikatz module extracted plaintext passwords and Kerberos tickets directly from Local Security Authority Subsystem Service (LSASS) memory to acquire domain administrator access.

Artifacts & Tooling: Mimikatz memory dumper LSASS.exe memory read
3
Lateral Traversal Automated SMB and PsExec Subnet Propagation
MITRE ATT&CK T1021.002 →

NotPetya leveraged EternalBlue (CVE-2017-0144) alongside legitimate PsExec and Windows Management Instrumentation (WMI) utilities to automatically infect every accessible Windows host across local and peered RFC 1918 subnets.

Artifacts & Tooling: EternalBlue (MS17-010) PsExec.exe WMI command execution
4
Defense Evasion Legitimate Process Masquerading
MITRE ATT&CK T1036.005 →

The malware wrote its secondary payload into C:\Windows\dllhost.dat, imitating the legitimate Microsoft Component Object Model surrogate host process to avoid endpoint detection.

Artifacts & Tooling: C:\Windows\dllhost.dat Process masquerading
5
Destruction & Impact Irreversible Disk Wiper Detonation
MITRE ATT&CK T1485 →

NotPetya scrambled the Master File Table (MFT) with Salsa20 and overwrote the Master Boot Record (MBR) with a custom bootloader that displayed a fake Bitcoin ransom screen. The decryption key was deliberately unrecoverable, permanently destroying victim data.

Artifacts & Tooling: Salsa20 encryption MBR overwrite shutdown.exe /r /t 60
Real-World Blast Radius & Operational Fallout

Exceeded $10 billion in global economic damages. Paralyzed A.P. Moller-Maersk (shutting down 76 shipping terminals worldwide), FedEx TNT Express (permanently destroying tracking databases and causing $400M in losses), Merck Pharmaceuticals ($870M in losses), and Heritage Valley Health System (disrupting patient surgical suites and emergency rooms).

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Disable SMBv1 across all operating systems and restrict internal SMB (port 445) traversal between workstation subnets.
✓ Enforce cryptographically verified, out-of-band code signing for third-party software updates.
✓ Tier Active Directory administration to ensure domain credentials are never cached on endpoints.
✓ Maintain immutable, air-gapped Master Boot Record and Active Directory state backups.

Procedural & Incident Timeline

2020-10-15 indictment

Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage.

2021-04-15 sanction

U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities.

2022-02-23 advisory

CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A).

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Yuriy Sergeyevich Andrienko Russian Federation fugitive Pending None GRU Unit 74455 military officer who developed components of the NotPetya and Olympic Destroyer malware.
Sergey Vladimirovich Detistov Russian Federation fugitive Pending None GRU Unit 74455 officer who conducted spearphishing campaigns targeting the 2018 PyeongChang Winter Olympic Games.
Pavel Valeryevich Frolov Russian Federation fugitive Pending None GRU Unit 74455 malware engineer who developed KillDisk wiper payloads.
Artem Valeryevich Ochichenko Russian Federation fugitive Pending None GRU Unit 74455 officer responsible for reconnaissance and technical exploitation of French political parties.
Petr Nikolayevich Pliskin Russian Federation fugitive Pending None GRU Unit 74455 military officer who assisted in the deployment of Olympic Destroyer malware.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1485 Data Destruction
Impact
"The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware." Indictment ¶ 44, Page 22 reviewed
T1190 Exploit Public-Facing Application
Initial Access
"Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary." Indictment ¶ 38, Page 19 reviewed
T1021.002 SMB / Windows Admin Shares
Lateral Movement
"NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention." Indictment ¶ 47, Page 24 reviewed
T1003 OS Credential Dumping
Credential Access
"The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators." Indictment ¶ 46, Page 23 reviewed
T1055.012 Process Hollowing
Defense Evasion
"Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity." Indictment ¶ 52, Page 27 reviewed
T1036.005 Match Legitimate Name or Location
Defense Evasion
"NotPetya named its primary payload dllhost.dat inside C:\Windows\ to blend in with legitimate host process binaries." Indictment ¶ 45, Page 23 reviewed
T1543.003 Windows Service
Persistence
"The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type." CISA Advisory ICS-ALERT-14-281-01B reviewed
T1499 Endpoint Denial of Service
Impact
"Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops." Indictment ¶ 54, Page 28 reviewed
T1124 System Time Discovery
Discovery
"NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps." CISA Advisory AA17-181A reviewed
View 1 Proposed / Unverified Mapping Candidates
T1566.001: Spearphishing Attachment Proposed by rule

"Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators."

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455), No. 2:20-cr-00316 (U.S. District Court for the Western District of Pennsylvania 2020), https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/sandworm-notpetya-olympic-destroyer" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>