Adversary-emulation profile for Sandworm Team (Voodoo Bear / Seashell Blizzard / APT44 / ELECTRUM), Russia's GRU Unit 74455 destructive ICS/OT and influence actor (ATT&CK G0034).
60
70%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/sandworm-team/SKILL.mdSandworm Team (MITRE ATT&CK G0034; also tracked as APT44, Voodoo Bear, Seashell Blizzard, ELECTRUM, Telebots, IRON VIKING, IRIDIUM, FROZENBARENTS, and historically BlackEnergy/Quedagh) is a destructive Russian state threat group attributed to the GRU's Main Center for Special Technologies (GTsST), military unit 74455, active since at least 2009. Unlike espionage-focused peers, Sandworm is the GRU's premier sabotage and influence unit: it pairs conventional intrusion tradecraft with bespoke ICS/OT attack capability, disk wipers, fake ransomware, hacktivist-persona leaks, and disruptive operations timed to geopolitical and kinetic events. It is the only actor publicly documented to have triggered electric-grid blackouts via cyberattack (Ukraine, 2015 and 2016) and later repeated an OT grid attack in 2022. This profile maps Sandworm's signature TTPs to ATT&CK so Decepticon can emulate them within an authorized engagement and so the blue cell can anticipate detection.
a.iso) → lun.vbs → n.bat → native MicroSCADA scilc.exe (SCIL-API) to issue unauthorized breaker commands (Oct 10), followed two days later by CaddyWiper deployed via GPO. (Google Cloud / Mandiant)xp_cmdshell, and VBScript/VBA (e.g., lun.vbs, vba_macro.exe).explorer.exe, executables as .txt, and accounts as admin/система.rundll32.exe.comsvcs.dll, plainpwd), NTDS extraction via ntdsutil.exe, keylogging (SetWindowsHookEx), RPC brute force, browser session-cookie and saved-password theft (CredRaptor), and network sniffing (intercepter-NG, BlackEnergy sniffer). Also alters OWA sign-in pages to capture credentials in real time (BadPilot).net use; lateral tool transfer (e.g., copying Prestige to the DC via GPO, ICS payload staging).svchost.exe, and ingress tool transfer.scilc.exe / SCIL-API, ATT&CK ICS T1692.001/T0831), serial-to-ethernet firmware overwrite to block OT messages (T1693.001/T1691), causing loss of control/availability and ~6-hour regional blackouts.| Family | ATT&CK | Type | Role |
|---|---|---|---|
| BlackEnergy | S0089 | Custom | Modular backdoor/keylogger/sniffer; original grid-attack platform |
| KillDisk | S0607 | Custom | Disk/MBR wiper used to hamper recovery |
| Industroyer / Industroyer2 | S0604 | Custom | ICS/SCADA malware that automates breaker manipulation |
| NotPetya | S0368 | Custom | Self-propagating wiper masquerading as ransomware (supply-chain) |
| Olympic Destroyer | S0365 | Custom | Disruptive wiper with false-flag artifacts |
| Bad Rabbit | S0606 | Custom | Ransomware-style outbreak |
| CaddyWiper | S0693 | Custom | Wiper deployed via GPO (2022 Ukraine ops) |
| AcidRain / AcidPour | S1125 / S1167 | Custom | Wipers (AcidRain bricked Viasat modems) |
| Cyclops Blink | S0687 | Custom | Botnet/router implant (SOHO devices) |
| Prestige | S1058 | Custom | Ransomware against Ukraine/Poland logistics |
| P.A.S. Webshell | S0598 | Custom/shared | Web shell for persistence |
| CHEMISTGAMES | S0555 | Custom | Mobile backdoor |
| GOGETTER / TANKTRAP / SHARPIVORY / CredRaptor / plainpwd | — | Custom | Tunneler, PowerShell deployer, dropper, browser-cred stealer, LSASS dumper |
| Mimikatz / Impacket / Cobalt Strike / Empire / PoshC2 / Invoke-PSImage / SDelete / RemoteExec / Adminer / Neo-REGEORG / intercepter-NG | S0002 / S0357 / S0154 / S0363 / S0378 / S0231 / S0195 / — | Public | Off-the-shelf cred theft, lateral movement, C2, sniffing, exfil, wiping |
Authorized use only: every action below is destructive-capable and must run strictly inside the documented engagement scope, on approved targets, with rules-of-engagement sign-off and (for any wipe/encrypt/OT step) explicit written authorization and reversible/lab-only execution. Never touch real ICS/OT or production data outside an isolated test range.
ntdsutil/comsvcs.dll), and reach Domain Admin — Sandworm's defining pivot is GPO-based mass deployment, so practice pushing a benign payload domain-wide via GPO.explorer.exe, система), disable event logging, and clean up artifacts — then verify the blue cell catches them.net use, Impacket WMIexec, and GPO/RemoteExec-style mass execution to mirror Sandworm's DC-to-fleet propagation.ntdsutil.exe, LSASS access, and comsvcs.dll MiniDump (T1003).wscript.exe/cscript.exe spawning batch files, mounted ISO autoruns, xp_cmdshell enablement, rundll32.exe proxy execution (T1218.011), and PowerShell that loads code in memory; baseline native SCADA utilities (e.g., scilc.exe) and alert on any unexpected invocation.svchost.exe injection; alert on Windows event-log clearing/disabling (T1685.001) and mass file deletion.vssadmin/wbadmin misuse, mass service stops (T1489), and rapid multi-host file overwrite (T1485). Segment IT from OT; restrict and monitor HMI/ICS-client access and serial-to-ethernet device firmware integrity.0cf691e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.