logo

Microsoft: Russia's Sandworm APT Exploits Edge Bugs Globally

ID: 77e2d838-86d5-5d31-9352-1e5bbeb3c38b

STIX ID: report--77e2d838-86d5-5d31-9352-1e5bbeb3c38b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-02-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

This report profiles the Russian GRU-aligned APT Sandworm (Unit 74455) and its access-focused subgroup BadPilot, describing their shift to opportunistic, widespread intrusions by exploiting high-severity CVEs (including multiple 9.8 and a 10.0 CVSS) in email, collaboration, and remote management software to gain persistence (LocalOlive web shell, RMM tools, Tor/ShadowLink), collect credentials, conduct lateral movement, and enable destructive attacks—particularly against Ukrainian critical infrastructure—and expanding targeting to the US and UK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.