Sandworm Hackers Shift From IT Breaches to Critical OT Targets
ID: f1c38e5b-4b34-519b-a868-d7c182a4ce6a
STIX ID: report--f1c38e5b-4b34-519b-a868-d7c182a4ce6a
Feed Name: GBHackers
Researchers observed a surge of Sandworm (Russia-linked GRU Unit 74455) activity between July 2025 and January 2026 across 10 industrial organizations in seven countries, identifying 29 confirmed incidents in a dataset of 5.5M alerts. The group leveraged living-off-the-land techniques, pre-existing compromises (Cobalt Strike, Metasploit), and legacy exploit chains (EternalBlue, DoublePulsar, WannaCry) to move from IT into OT/ICS assets—targeting HMIs, engineering workstations, PLCs and RTUs—with long warning windows (average 43 days) before escalation, indicating high risk of physical disruption to critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
