'Sandworm' Group Is Russia's Primary Cyberattack Unit in Ukraine
ID: 7c74a6e9-a7cf-54c5-9783-772714c680b6
STIX ID: report--7c74a6e9-a7cf-54c5-9783-772714c680b6
Feed Name: Dark Reading
Mandiant attributes a broad, highly capable Russian GRU-linked actor known as Sandworm (APT44) with sustained espionage and destructive operations since 2022 — including attacks on Ukraine's infrastructure, the NotPetya outbreak, ransomware targeting a NATO-country logistics provider, and demonstrations against water/hydroelectric facilities — noting the group's global targeting, exploitation of edge devices and living‑off‑the‑land techniques, and use of front personas (e.g., CyberArmyofRussia_Reborn) to advance Russian military and political objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
