{
  "id": "case-sandworm-notpetya",
  "slug": "sandworm-notpetya-olympic-destroyer",
  "title": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)",
  "summary": "Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.",
  "case_number": "2:20-cr-00316",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "United States",
  "opened_at": "2020-10-15",
  "status": "fugitive",
  "victim_sector": "Energy, Healthcare, Government, Transportation",
  "victim_country": "Ukraine, United States, France, South Korea",
  "loss_amount_usd": 10000000000,
  "loss_amount_note": "Estimated global worldwide economic damage exceeding $10 billion, including $1 billion across Heritage Valley Health System, FedEx TNT Express, and Merck.",
  "first_seen_at": "2015-12-23T15:00:00Z",
  "last_updated_at": "2026-09-20T12:00:00Z",
  "actor_slug": "sandworm-team",
  "defendant_slugs": [
    "yuriy-andrienko",
    "sergey-detistov",
    "pavel-frolov",
    "anatoliy-kovalev",
    "artem-ochichenko",
    "petr-pliskin"
  ],
  "cves": [
    "CVE-2017-0144"
  ],
  "techniques": [
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware.",
      "evidence_locator": "Indictment \u00b6 44, Page 22",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary.",
      "evidence_locator": "Indictment \u00b6 38, Page 19",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1021.002",
      "evidence_excerpt": "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention.",
      "evidence_locator": "Indictment \u00b6 47, Page 24",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA17-181A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
      "technique_name": "SMB / Windows Admin Shares",
      "tactic": "Lateral Movement"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators.",
      "evidence_locator": "Indictment \u00b6 46, Page 23",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators.",
      "evidence_locator": "Indictment \u00b6 15, Page 7",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1055.012",
      "evidence_excerpt": "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity.",
      "evidence_locator": "Indictment \u00b6 52, Page 27",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Process Hollowing",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1036.005",
      "evidence_excerpt": "NotPetya named its primary payload dllhost.dat inside C:\\Windows\\ to blend in with legitimate host process binaries.",
      "evidence_locator": "Indictment \u00b6 45, Page 23",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Andrienko et al.",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Match Legitimate Name or Location",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1543.003",
      "evidence_excerpt": "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type.",
      "evidence_locator": "CISA Advisory ICS-ALERT-14-281-01B",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA ICS Advisory",
      "source_url": "https://www.cisa.gov/news-events/ics-advisories",
      "technique_name": "Windows Service",
      "tactic": "Persistence"
    },
    {
      "technique_id": "T1499",
      "evidence_excerpt": "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops.",
      "evidence_locator": "Indictment \u00b6 54, Page 28",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware",
      "technique_name": "Endpoint Denial of Service",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1124",
      "evidence_excerpt": "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps.",
      "evidence_locator": "CISA Advisory AA17-181A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA17-181A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a",
      "technique_name": "System Time Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2020-10-15",
      "description": "Grand jury returns indictment charging six GRU officers with seven counts of computer conspiracy, wire fraud, and intentional damage."
    },
    {
      "event_type": "sanction",
      "event_date": "2021-04-15",
      "description": "U.S. Department of the Treasury sanctions GRU Unit 74455 and associated military intelligence facilities."
    },
    {
      "event_type": "advisory",
      "event_date": "2022-02-23",
      "description": "CISA and international partners publish joint advisory on Sandworm wiper deployments (AA22-054A)."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Supply-chain compromise of Ukrainian tax accounting software M.E.Doc (Intellect Service). Threat actors infiltrated the vendor's update infrastructure and backdoored the routine update binary ezvit.exe to deploy a malicious loader across thousands of corporate networks.",
    "blast_radius": "Exceeded $10 billion in global economic damages. Paralyzed A.P. Moller-Maersk (shutting down 76 shipping terminals worldwide), FedEx TNT Express (permanently destroying tracking databases and causing $400M in losses), Merck Pharmaceuticals ($870M in losses), and Heritage Valley Health System (disrupting patient surgical suites and emergency rooms).",
    "kill_chain": [
      {
        "phase": "Initial Infiltration",
        "title": "Software Supply Chain Compromise",
        "description": "Russian GRU operatives breached the internal update server of Intellect Service in Ukraine, replacing the legitimate ezvit.exe update binary with a backdoored variant that executed silently on client systems during tax report synchronization.",
        "technical_artifacts": [
          "ezvit.exe",
          "M.E.Doc update package",
          "BKDR_HERLOK.A"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Credential Dumping",
        "title": "In-Memory LSASS Credential Harvesting",
        "description": "Upon execution, a bundled custom Mimikatz module extracted plaintext passwords and Kerberos tickets directly from Local Security Authority Subsystem Service (LSASS) memory to acquire domain administrator access.",
        "technical_artifacts": [
          "Mimikatz memory dumper",
          "LSASS.exe memory read"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Lateral Traversal",
        "title": "Automated SMB and PsExec Subnet Propagation",
        "description": "NotPetya leveraged EternalBlue (CVE-2017-0144) alongside legitimate PsExec and Windows Management Instrumentation (WMI) utilities to automatically infect every accessible Windows host across local and peered RFC 1918 subnets.",
        "technical_artifacts": [
          "EternalBlue (MS17-010)",
          "PsExec.exe",
          "WMI command execution"
        ],
        "mitre_technique_id": "T1021.002"
      },
      {
        "phase": "Defense Evasion",
        "title": "Legitimate Process Masquerading",
        "description": "The malware wrote its secondary payload into C:\\Windows\\dllhost.dat, imitating the legitimate Microsoft Component Object Model surrogate host process to avoid endpoint detection.",
        "technical_artifacts": [
          "C:\\Windows\\dllhost.dat",
          "Process masquerading"
        ],
        "mitre_technique_id": "T1036.005"
      },
      {
        "phase": "Destruction & Impact",
        "title": "Irreversible Disk Wiper Detonation",
        "description": "NotPetya scrambled the Master File Table (MFT) with Salsa20 and overwrote the Master Boot Record (MBR) with a custom bootloader that displayed a fake Bitcoin ransom screen. The decryption key was deliberately unrecoverable, permanently destroying victim data.",
        "technical_artifacts": [
          "Salsa20 encryption",
          "MBR overwrite",
          "shutdown.exe /r /t 60"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Disable SMBv1 across all operating systems and restrict internal SMB (port 445) traversal between workstation subnets.",
      "Enforce cryptographically verified, out-of-band code signing for third-party software updates.",
      "Tier Active Directory administration to ensure domain credentials are never cached on endpoints.",
      "Maintain immutable, air-gapped Master Boot Record and Active Directory state backups."
    ]
  }
}