logo

Russian Sandworm hackers targeted 20 critical orgs in Ukraine

ID: 37b2d344-414f-5b38-8d75-8c988d2dfd99

STIX ID: report--37b2d344-414f-5b38-8d75-8c988d2dfd99

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CERT‑UA attributes March 2024 operations to Russian APT Sandworm targeting around 20 energy, water, and heating suppliers across Ukraine via supply‑chain compromises and supplier remote‑access, deploying Windows and new Linux variants (QUEUESEED, BIASBOAT, LOADGRIP, GOSSIPFLOW) along with tunnellers and post‑exploitation tools; at least three supply‑chain breaches were confirmed and CERT‑UA conducted remediation from March 7–15.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.