GRU Unit 74455 responsible for destructive attacks including NotPetya, attacks on Ukrainian power grid, and Olympic Destroyer. Considered one of the most aggressive threat actors.
Also known as: sandworm, voodoo bear, iridium, seashell blizzard, quedagh, electrum, iron viking, blackenergy group
AI Intelligence Brief
cached
Edit Profile
Entity Relationships
Co-occurrence relationships based on article mentions. Node size = frequency.
A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active internal-netwo...
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP'...
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Se...
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at lea...
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state thr...
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notor...
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromis...