logo

Russia's Sandworm caught snarfing credentials, data from American and Brit orgs

ID: e5957973-ee09-517e-a09f-82cd38ea11f7

STIX ID: report--e5957973-ee09-517e-a09f-82cd38ea11f7

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-02-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft observed a Sandworm initial-access subgroup (tracked as Seashell Blizzard / "BadPilot") conducting a multi-year, near-global campaign exploiting at least eight vulnerabilities and using legitimate RMM tools and Tor-based ShadowLink persistence to steal credentials, exfiltrate data, and maintain long-term access to critical sectors across the US, UK, Canada, Australia and beyond; some intrusions preceded destructive attacks, indicating potential for disruptive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.