
Anton Cherepanov

2026
The ESET research team has been tracking Sandworm’s activities for more than a decade. In 2025 alone, we investigated more than ten incidents involving destructive malware attributed to Sandworm, most of them occurring in Ukraine. In this talk, we’ll use our first-hand experience and unique visibility into the group’s activities to explain their latest TTPs and take a deep dive into one of our recent Sandworm investigations that revealed a rarely documented collaboration between Sandworm and UAC-0099, and a very rare backdoor we named MythicRatatoskr.
Sandworm is a Russia-aligned threat actor known for conducting destructive cyberattacks against a wide range of targets, including government agencies, logistics and transportation companies, energy providers, media organizations, grain sector businesses, and telecommunications firms. These attacks typically involve the deployment of "wiper" malware designed to delete files, erase data, and render systems unbootable.
Between July and September 2025, we investigated an incident involving the targeting of a grain logistics company in Ukraine, during which the attackers carried out a data-wiping attack. During the investigation, we determined that initial access was obtained by UAC-0099 through a spear-phishing email containing a malicious attachment, which led to the execution chain of the UAC-0099’s MATCHWOK backdoor.
Once this initial foothold was established, attackers leveraged it to deploy a previously unseen backdoor we named MythicRatatoskr. What makes MythicRatatoskr so interesting is that its C&C server is hosted within the Yggdrasil network - a decentralized mesh network that implements an experimental routing scheme, where IPv6 communication between nodes is protected end-to-end. The backdoor is unique, and we have not observed it again since this incident.
In this talk, we will cover this incident in detail, provide an in-depth analysis of the MythicRatatoskr backdoor, and explain the inner workings of the Yggdrasil network.
About Anton Cherepanov
Anton Cherepanov is a Principal Malware Researcher at ESET, responsible for analyzing and hunting the most complex cyber threats. He has conducted extensive research on the Sandworm APT group. Anton has presented his findings at numerous international conferences, including Black Hat USA, Virus Bulletin, and CYBERWARCON. His professional interests include detection engineering, reverse engineering, and hunting for previously unknown threats.
