U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Energy, Healthcare, Government, Transportation.
- Documented Financial Loss: $10.0 billion.
- 9 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Supply-chain compromise of Ukrainian tax accounting software M.E.Doc (Intellect Service). Threat actors infiltrated the vendor's update infrastructure and backdoored the routine update binary ezvit.exe to deploy a malicious loader across thousands of corporate networks.
Operational & Financial Fallout
Exceeded $10 billion in global economic damages. Paralyzed A.P. Moller-Maersk (shutting down 76 shipping terminals worldwide), FedEx TNT Express (permanently destroying tracking databases and causing $400M in losses), Merck Pharmaceuticals ($870M in losses), and Heritage Valley Health System (disrupting patient surgical suites and emergency rooms).
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Supply-chain compromise of Ukrainian tax accounting software M.E.Doc (Intellect Service). Threat actors infiltrated the vendor's update infrastructure and backdoored the routine update binary ezvit.exe to deploy a malicious loader across thousands of corporate networks.
Adversary Kill Chain Flow
5 Documented PhasesRussian GRU operatives breached the internal update server of Intellect Service in Ukraine, replacing the legitimate ezvit.exe update binary with a backdoored variant that executed silently on client systems during tax report synchronization.
Upon execution, a bundled custom Mimikatz module extracted plaintext passwords and Kerberos tickets directly from Local Security Authority Subsystem Service (LSASS) memory to acquire domain administrator access.
NotPetya leveraged EternalBlue (CVE-2017-0144) alongside legitimate PsExec and Windows Management Instrumentation (WMI) utilities to automatically infect every accessible Windows host across local and peered RFC 1918 subnets.
The malware wrote its secondary payload into C:\Windows\dllhost.dat, imitating the legitimate Microsoft Component Object Model surrogate host process to avoid endpoint detection.
NotPetya scrambled the Master File Table (MFT) with Salsa20 and overwrote the Master Boot Record (MBR) with a custom bootloader that displayed a fake Bitcoin ransom screen. The decryption key was deliberately unrecoverable, permanently destroying victim data.
Exceeded $10 billion in global economic damages. Paralyzed A.P. Moller-Maersk (shutting down 76 shipping terminals worldwide), FedEx TNT Express (permanently destroying tracking databases and causing $400M in losses), Merck Pharmaceuticals ($870M in losses), and Heritage Valley Health System (disrupting patient surgical suites and emergency rooms).
Procedural & Incident Timeline
Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage.
U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities.
CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A).
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Yuriy Sergeyevich Andrienko | Russian Federation | fugitive | Pending | None | GRU Unit 74455 military officer who developed components of the NotPetya and Olympic Destroyer malware. |
| Sergey Vladimirovich Detistov | Russian Federation | fugitive | Pending | None | GRU Unit 74455 officer who conducted spearphishing campaigns targeting the 2018 PyeongChang Winter Olympic Games. |
| Pavel Valeryevich Frolov | Russian Federation | fugitive | Pending | None | GRU Unit 74455 malware engineer who developed KillDisk wiper payloads. |
| Artem Valeryevich Ochichenko | Russian Federation | fugitive | Pending | None | GRU Unit 74455 officer responsible for reconnaissance and technical exploitation of French political parties. |
| Petr Nikolayevich Pliskin | Russian Federation | fugitive | Pending | None | GRU Unit 74455 military officer who assisted in the deployment of Olympic Destroyer malware. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1485 | Data Destruction Impact | "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware." | Indictment ¶ 44, Page 22 | reviewed |
| T1190 | Exploit Public-Facing Application Initial Access | "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary." | Indictment ¶ 38, Page 19 | reviewed |
| T1021.002 | SMB / Windows Admin Shares Lateral Movement | "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention." | Indictment ¶ 47, Page 24 | reviewed |
| T1003 | OS Credential Dumping Credential Access | "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators." | Indictment ¶ 46, Page 23 | reviewed |
| T1055.012 | Process Hollowing Defense Evasion | "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity." | Indictment ¶ 52, Page 27 | reviewed |
| T1036.005 | Match Legitimate Name or Location Defense Evasion | "NotPetya named its primary payload dllhost.dat inside C:\Windows\ to blend in with legitimate host process binaries." | Indictment ¶ 45, Page 23 | reviewed |
| T1543.003 | Windows Service Persistence | "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type." | CISA Advisory ICS-ALERT-14-281-01B | reviewed |
| T1499 | Endpoint Denial of Service Impact | "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops." | Indictment ¶ 54, Page 28 | reviewed |
| T1124 | System Time Discovery Discovery | "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps." | CISA Advisory AA17-181A | reviewed |
View 1 Proposed / Unverified Mapping Candidates
"Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators."