Russian Sandworm hackers pose as hacktivists in water utility breaches
ID: 792b9078-5345-5783-b3ae-873e19db8482
STIX ID: report--792b9078-5345-5783-b3ae-873e19db8482
Feed Name: Bleeping Computer
Mandiant attributes long-running destructive and espionage operations to Sandworm (APT44/GRU Unit 74455), reporting that the actor has used Telegram-based false 'hacktivist' personas to leak data, amplify narratives, and claim disruptive intrusions against Ukrainian and international critical infrastructure (including water utilities and power). The group employs phishing, credential theft, vulnerability exploitation, supply-chain compromise, and wiper malware, and is assessed to be actively collecting intelligence and likely to attempt political influence operations such as election interference.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
