Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets
ID: 3f6e41ec-240b-5ea7-b6eb-ddeb74d83091
STIX ID: report--3f6e41ec-240b-5ea7-b6eb-ddeb74d83091
Feed Name: cybersecurityNews.com
Sandworm (attributed to GRU Unit 74455) has been observed pivoting from pre-compromised IT networks into operational technology across multiple industrial environments, leveraging long-known exploits (EternalBlue, DoublePulsar, WannaCry) to target engineering workstations, HMIs, PLCs and other field devices; telemetry from 10 industrial customers revealed 29 events, extensive lateral movement (923 internal targets), predictable operational scheduling, and escalation of activity after detection, highlighting the need for rapid isolation, segmentation, and resolution of legacy compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
