Sandworm APT Shifts Focus From Compromised IT To OT Networks
ID: 40d35d1b-11c0-5536-861e-866c0dc562bc
STIX ID: report--40d35d1b-11c0-5536-861e-866c0dc562bc
Feed Name: Cyber Press
The report warns that Sandworm (APT44) is pivoting from IT espionage to deliberate, destructive attacks against OT/ICS across Europe and the U.S., exploiting legacy vulnerabilities (EternalBlue, DoublePulsar, Log4Shell) and commodity tooling (Cobalt Strike) to establish footholds, rapidly move laterally, and escalate operations when detected; researchers observed 29 events across 10 industrial customers in 7 countries and highlight past disruptive incidents (2014–2016 Ukraine outages) as context for high-impact sabotage risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
