logo

APT Spotlight: Sandworm

ID: 2c5dc87f-844b-5bd9-aa04-a8090894a30e

STIX ID: report--2c5dc87f-844b-5bd9-aa04-a8090894a30e

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2022-12-12

Date Updated: 2026-04-29

...
...

ReliaQuest’s blog examines the Russia-linked APT group Sandworm (aka Voodoo Bear/Telebots/Iron Viking), summarizing its ties to the GRU, history of destructive operations (NotPetya, BlackEnergy, Industroyer), and recent activity targeting Ukrainian critical infrastructure including Industroyer2, multiple disk wipers (CaddyWiper, ORCSHRED, SOLOSHRED, AWFULSHRED), and ransomware campaigns (RansomBoggs, Prestige). The report emphasizes Sandworm’s high sophistication and political motivation, the potential for significant physical and economic impact from ICS attacks during the Russia–Ukraine war, and recommends that organizations—especially those supporting or operating critical infrastructure—harden ICS defenses and prepare for continued disruptive activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.