logo

Subgroup of Russia’s Sandworm compromising US and European organizations, Microsoft says

ID: fa67947d-7cb6-57b6-b885-5edd23f76c19

STIX ID: report--fa67947d-7cb6-57b6-b885-5edd23f76c19

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-02-12

Date Updated: 2026-05-01

...
...

Microsoft Threat Intelligence attributes a multiyear global initial-access campaign called "BadPilot" to a Sandworm/Seashell Blizzard subgroup that has been exploiting multiple public vulnerabilities and abusing remote management tools to gain and maintain access to high-value targets in energy, telecoms, shipping, manufacturing, government and other sectors across the U.S., U.K. and Europe; the subgroup’s persistent access has supported espionage and, at times, preceded destructive operations tied to the wider Sandworm cluster.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.