Threat Actor Profile

Sandworm

Aliases
  • Unit 74455
  • Voodoo Bear
  • TeleBots
Origin
Russia
Active Since
2009
Motivation
Disruption, Strategic impact against critical infrastructure
Cause
Nation State
Recent Activity

On December 29, 2025, coordinated destructive attacks targeted Poland’s energy sector, including more than 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant. CERT Polska reported no disruption to electricity production or heat supply.

Primary Targets
  • Ukraine power grid
  • Viasat satellite communications
  • European infrastructure providers
Target Locations
  • Ukraine
  • Eastern Europe
  • Broader Europe
  • Poland
Target Sectors
  • Energy
  • Utilities
  • Government
  • Telecommunications
  • Technology
  • Finance
  • Transportation

How Bitsight Helps

Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.

Request threat intel demo