logo

BadPilot network hacking campaign fuels Russian SandWorm attacks

ID: 745b578e-a4b4-5ae9-8e66-ef09ad5c64d0

STIX ID: report--745b578e-a4b4-5ae9-8e66-ef09ad5c64d0

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

- Microsoft intelligence attributes a multi-year campaign named "BadPilot" to an APT44 subgroup (Seashell Blizzard/Sandworm) that has targeted critical infrastructure, governments, and industry since at least 2021 across Ukraine, Europe, Central/South Asia, the Middle East, and more recently the US, UK, Canada, and Australia; the report details exploitation of multiple n-day vulnerabilities, supply-chain intrusions, credential theft, deployment of web shells and backdoors, use of legitimate remote-management tools and Tor for stealth, data exfiltration methods, and linkage to destructive wiper attacks while providing IoCs and detection guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.