logo

Sandworm APT Shifts Focus From Compromised IT To OT Networks

ID: 40d35d1b-11c0-5536-861e-866c0dc562bc

STIX ID: report--40d35d1b-11c0-5536-861e-866c0dc562bc

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Varshini

...
...

The report warns that Sandworm (APT44) is pivoting from IT espionage to deliberate, destructive attacks against OT/ICS across Europe and the U.S., exploiting legacy vulnerabilities (EternalBlue, DoublePulsar, Log4Shell) and commodity tooling (Cobalt Strike) to establish footholds, rapidly move laterally, and escalate operations when detected; researchers observed 29 events across 10 industrial customers in 7 countries and highlight past disruptive incidents (2014–2016 Ukraine outages) as context for high-impact sabotage risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.