logo

A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks

ID: 8211aeac-d1c8-52ec-a201-67483107ff82

STIX ID: report--8211aeac-d1c8-52ec-a201-67483107ff82

Feed Name: WIRED Security

Threat Score
85/100

Date Published: 2025-02-12

Date Updated: 2026-04-26

Author: Andy Greenberg

...
...

Microsoft attributes a persistent threat actor named "BadPilot" that performs broad, high-volume intrusion attempts then refines focus on selected victims. From 2022–2024 its targeting shifted from primarily Ukraine to worldwide and then to Western nations (US, UK, Canada, Australia); targeted sectors include energy, oil & gas, telecommunications, shipping, arms manufacturing and international governments. Microsoft also reports that some of BadPilot’s operations coincided with data-destroying cyberattacks carried out by Sandworm against Ukrainian targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.