Six Russian agents have been indicted by the US Department of Justice for attacks related to the Pyeongchang Winter Olympics, the 2017 French elections, and the infamous NotPetya.

This is a group known as “Sandworm” and according to the indictment, all six individuals are part of the Russian intelligence service GRU.
The USA accused Yuriy Sergeyevich Andrienko, 32, Sergey Vladimirovich Detistov, 35, Pavel Valeryevich Frolov, 28, Anatoliy Sergeyevich Kovalev, 29, Artem Valeryevich Ochichenko , 27 and Petr Nikolayevich Pliskin, 32.
The charges against them include conspiracy to commit computer fraud and abuse, conspiracy to commit email fraud , destruction of protected computers , and identity theft.
More specifically, the malicious activities for which they are accused are:
Ukrainian Government: From December 2015 to December 2016, devastating attacks were carried out against Ukraine's electricity grid and the Ministry of Finance, using malware known as BlackEnergy, Industroyer, and KillDisk.
French Elections: In April and May 2017, they conducted phishing campaigns and related hacking and leak attempts, targeting French President Macron's "La République En Marche!" political party, French politicians, and local French governments ahead of the 2017 French elections.
Global Businesses and Critical Infrastructure (NotPetya): On June 27, 2017, they carried out devastating attacks, infecting computers worldwide, using malware known as NotPetya, including hospitals and other medical facilities at Heritage Valley Health System (Heritage Valley) in the Western District of Pennsylvania, a subsidiary of FedEx Corporation, TNT Express BV, and a major pharmaceutical manufacturer in the U.S., which suffered nearly $1 billion in losses from the attacks.
PyeongChang Winter Olympics: From December 2017 to February 2018, they conducted spearphishing and created malicious mobile applications targeting South Korean citizens and officials, athletes, partners and visitors, as well as International Olympic Committee (IOC) officials.
Novichok Poisoning Investigations: In April 2018, they conducted phishing campaigns targeting investigations by the Organization for the Prohibition of Chemical Weapons (OPCW) and the UK's Defense Science and Technology Laboratory (DSTL).
Georgian companies and government entities: They carried out a spearphishing campaign in 2018, targeting a major media company, while in 2019 they attempted to hack the Parliament's network and a broad website hijacking campaign.
Source: BleepingComputer
