logo

Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets

ID: 3f6e41ec-240b-5ea7-b6eb-ddeb74d83091

STIX ID: report--3f6e41ec-240b-5ea7-b6eb-ddeb74d83091

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-15

Author: Tushar Subhra Dutta

...
...

Sandworm (attributed to GRU Unit 74455) has been observed pivoting from pre-compromised IT networks into operational technology across multiple industrial environments, leveraging long-known exploits (EternalBlue, DoublePulsar, WannaCry) to target engineering workstations, HMIs, PLCs and other field devices; telemetry from 10 industrial customers revealed 29 events, extensive lateral movement (923 internal targets), predictable operational scheduling, and escalation of activity after detection, highlighting the need for rapid isolation, segmentation, and resolution of legacy compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.