APT Spotlight: Sandworm
ID: 2c5dc87f-844b-5bd9-aa04-a8090894a30e
STIX ID: report--2c5dc87f-844b-5bd9-aa04-a8090894a30e
Feed Name: ReliaQuest Blog
ReliaQuest’s blog examines the Russia-linked APT group Sandworm (aka Voodoo Bear/Telebots/Iron Viking), summarizing its ties to the GRU, history of destructive operations (NotPetya, BlackEnergy, Industroyer), and recent activity targeting Ukrainian critical infrastructure including Industroyer2, multiple disk wipers (CaddyWiper, ORCSHRED, SOLOSHRED, AWFULSHRED), and ransomware campaigns (RansomBoggs, Prestige). The report emphasizes Sandworm’s high sophistication and political motivation, the potential for significant physical and economic impact from ICS attacks during the Russia–Ukraine war, and recommends that organizations—especially those supporting or operating critical infrastructure—harden ICS defenses and prepare for continued disruptive activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
