Files

22 lines
1.3 KiB
YAML

name: Sandworm Tools
id: 54146850-9d26-4877-a611-2db33231e63e
version: 2
creation_date: '2023-04-12'
modification_date: '2026-05-13'
author: Teoderick Contreras, Splunk
status: production
description: This analytic story features detections that enable security analysts to identify and investigate unusual activities potentially related to the destructive malware and tools employed by the "Sandworm" group. This analytic story focuses on monitoring suspicious process executions, command-line activities, Master Boot Record (MBR) wiping, data destruction, and other related indicators.
narrative: The Sandworm group's tools are part of destructive malware operations designed to disrupt or attack Ukraine's National Information Agencies. This operation campaign consists of several malware components, including scripts, native Windows executables (LOLBINs), data wiper malware that overwrites or destroys the Master Boot Record (MBR), and file wiping using sdelete.exe on targeted hosts.
references:
- https://cert.gov.ua/article/3718487
- https://attack.mitre.org/groups/G0034/
category:
- Data Destruction
- Malware
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection