US links Sandworm hacking group to Russian agency GRU's Main Center for Special Technology, blaming it for cyberattacks that hit neighboring Georgia in October
Andy Greenberg / Wired :
Context & Ripple Effects
This February 2020 attribution was the moment the US stopped treating Sandworm as an anonymous cluster and named its patron: the GRU's Main Center for Special Technology, with the October cyberattacks on neighboring Georgia pinned to Russian military intelligence. At the time, Sandworm's most notorious confirmed work was sabotage of Ukraine's power grid.
The naming held up as the anchor for everything that followed in the corpus: France later tied Sandworm to a three-year breach campaign against entities running Centreon monitoring software, sources identified Evgenii Serebriakov as the unit's leader, Mandiant connected a third successful strike on Ukraine's grid to the group, and Mandiant eventually traced the hacktivist-front Cyber Army of Russia back to Sandworm itself.
First-order effects
- Sandworm loses its deniability: US officials publicly bind the group to a named GRU unit, so every future intrusion by its tooling now lands on Moscow's military intelligence ledger rather than on an unnamed threat actor.
Second-order effects
- Allied governments adopt the template — France's subsequent Centreon breach attribution and Mandiant's corporate attributions show that once one government names the unit, vendors and allies build their own disclosures on top of it.
Third-order effects
- Public attribution becomes standing policy rather than a one-off: by 2024 the US and allies were unmasking a second GRU unit outright, revealing that Cadet Blizzard belongs to Unit 29155, extending the practice from hacking groups to coup-and-assassination operations.
The trend: State hacking groups are being progressively de-anonymized through a repeatable cycle of government attribution followed by vendor corroboration, turning threat-actor names into diplomatic instruments.