Amazon warns that Russia’s Sandworm has shifted its tactics
ID: 5daca2b6-af34-5a72-93ed-70e45ae5990e
STIX ID: report--5daca2b6-af34-5a72-93ed-70e45ae5990e
Feed Name: CyberScoop
Amazon Threat Intelligence links a multi-year campaign to Russia’s GRU-linked Sandworm (APT44/Seashell Blizzard) targeting Western critical infrastructure—notably energy-sector organizations—by compromising enterprise routers, VPNs, remote-access gateways and other network edge devices hosted on AWS. The actor historically exploited vulnerabilities (including CVE-2022-26318, CVE-2021-26084, CVE-2023-22518, CVE-2023-27532) but in 2025 shifted to abusing customer misconfigurations to capture network traffic, harvest credentials, and pivot to other services; Amazon has notified affected customers, remediated compromised EC2 instances, and shared intelligence with partners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
