Microsoft: Russia's Sandworm APT Exploits Edge Bugs Globally
ID: 77e2d838-86d5-5d31-9352-1e5bbeb3c38b
STIX ID: report--77e2d838-86d5-5d31-9352-1e5bbeb3c38b
Feed Name: Dark Reading
This report profiles the Russian GRU-aligned APT Sandworm (Unit 74455) and its access-focused subgroup BadPilot, describing their shift to opportunistic, widespread intrusions by exploiting high-severity CVEs (including multiple 9.8 and a 10.0 CVSS) in email, collaboration, and remote management software to gain persistence (LocalOlive web shell, RMM tools, Tor/ShadowLink), collect credentials, conduct lateral movement, and enable destructive attacks—particularly against Ukrainian critical infrastructure—and expanding targeting to the US and UK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
