Inside Sandworm: Decade of Cyber Sabotage and Espionage Activity
ID: 1b2b2f53-7f87-5ef2-88c4-adac1a6f74c2
STIX ID: report--1b2b2f53-7f87-5ef2-88c4-adac1a6f74c2
Feed Name: Resources-2
Date Published: 2025-11-19
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
Sandworm is a long-running, highly capable GRU-linked APT that has executed strategic espionage and destructive cyber-sabotage operations since 2014 — from spearphishing and Office zero-days to supply-chain NotPetya and firmware-rooted Cyclops Blink — targeting Ukraine and NATO-aligned nations; the report consolidates major incidents, maps Sandworm tooling and behaviors (including wipers, ransomware, infostealers, firmware persistence and C2 techniques) to the MITRE ATT&CK framework, and provides example artifacts and mitigation/testing guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
