logo

Sandworm probably wasn’t behind Danish critical infrastructure cyberattack, report says

ID: c8ce50c6-34ec-5548-86c8-adc0c52a309d

STIX ID: report--c8ce50c6-34ec-5548-86c8-adc0c52a309d

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2024-01-11

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

Forescout’s analysis of November 2023 attacks against Danish energy companies concludes that two waves — one exploiting a Zyxel firewall vulnerability and another using Mirai-related infrastructure — were likely unrelated and not the work of Sandworm; instead they appear to involve opportunistic IoT botnet activity (Cyclops Blink / Katana Mirai) and unpatched devices, affecting about 22 organizations and complicating attribution and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.