logo

New Sandworm Tradecraft Enables Long-Term Hidden Access

ID: f53082db-f57e-5778-b9ef-52b10ef36696

STIX ID: report--f53082db-f57e-5778-b9ef-52b10ef36696

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Varshini

...
...

**Executive Summary:** The report describes Sandworm (APT-C-13) deploying spear-phishing LNK payloads that install persistent malware which creates double-encrypted SSH-over-Tor tunnels (using obfs4) and exposes internal services such as SMB and RDP via an onion address, enabling covert remote access, data theft, and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.