Sandworm probably wasn’t behind Danish critical infrastructure cyberattack, report says
ID: c8ce50c6-34ec-5548-86c8-adc0c52a309d
STIX ID: report--c8ce50c6-34ec-5548-86c8-adc0c52a309d
Feed Name: CyberScoop
Threat Score
Forescout’s analysis of November 2023 attacks against Danish energy companies concludes that two waves — one exploiting a Zyxel firewall vulnerability and another using Mirai-related infrastructure — were likely unrelated and not the work of Sandworm; instead they appear to involve opportunistic IoT botnet activity (Cyclops Blink / Katana Mirai) and unpatched devices, affecting about 22 organizations and complicating attribution and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
