A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
ID: 8211aeac-d1c8-52ec-a201-67483107ff82
STIX ID: report--8211aeac-d1c8-52ec-a201-67483107ff82
Feed Name: WIRED Security
Microsoft attributes a persistent threat actor named "BadPilot" that performs broad, high-volume intrusion attempts then refines focus on selected victims. From 2022–2024 its targeting shifted from primarily Ukraine to worldwide and then to Western nations (US, UK, Canada, Australia); targeted sectors include energy, oil & gas, telecommunications, shipping, arms manufacturing and international governments. Microsoft also reports that some of BadPilot’s operations coincided with data-destroying cyberattacks carried out by Sandworm against Ukrainian targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
