Russia's Sandworm caught snarfing credentials, data from American and Brit orgs
ID: e5957973-ee09-517e-a09f-82cd38ea11f7
STIX ID: report--e5957973-ee09-517e-a09f-82cd38ea11f7
Feed Name: The Register (Security)
Microsoft observed a Sandworm initial-access subgroup (tracked as Seashell Blizzard / "BadPilot") conducting a multi-year, near-global campaign exploiting at least eight vulnerabilities and using legitimate RMM tools and Tor-based ShadowLink persistence to steal credentials, exfiltrate data, and maintain long-term access to critical sectors across the US, UK, Canada, Australia and beyond; some intrusions preceded destructive attacks, indicating potential for disruptive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
