Sandworm Team is a destructive Russian-based threat group attributed to Russian GRU Unit 74455 by the United States Department of Justice and United Kingdom National Cyber Security Centre. Sandworm Team's most notable activity include the 2015 and 2016 attacks on Ukrainian electrical companies and 2017's NotPetya attacks. Sandworm Team has been active since at least 2009.
Other names for this threat
Black Energy, Black Energy (Group), ELECTRUM, Iron Viking, Quedagh, Sandworm, Telebots, TEMP.Noble, VOODOO BEAR
This is a collection of rules based on the presence of indicators of compromise publicly reported as associated with this malicious actor.