Russian Sandworm Subgroup Expands Global Cyberattack Campaign
- A subgroup of Russia's Sandworm has accessed networks in the US, UK, Canada, and Australia, stealing credentials and data from a limited number of organizations, according to Microsoft.
- The Sandworm subgroup, tracked by Microsoft as Seashell Blizzard, has been running a near-global campaign called BadPilot since at least 2021.
- By 2023, the BadPilot campaign gained persistent access to numerous high-value sectors in the US, Europe, Central Asia, and the Middle East.
- In early 2024, the subgroup started using remote management tools for persistence and communication with command-and-control servers, according to Microsoft.
14 Articles
14 Articles
Russian state threat group shifts focus to US, UK targets
A subgroup of Seashell Blizzard has shifted its focus to targets in the U.S., Canada, Australia and the U.K. within the past year, expanding the scope of its malicious activity, Microsoft’s threat intelligence team said in a report released Wednesday. The initial-access operation, which Microsoft tracks as the “BadPilot campaign,” has allowed the Russian state threat group — commonly known as Sandworm, which operates on behalf of the Russian Mil…
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
Sandworm APT's initial access subgroup hits organizations accross the globe - Help Net Security
A subgroup of Russia’s Sandworm APT has been working to achieve initial and persistent access to the IT networks of organizations working in economic sectors Russia is interested in. “In 2022, its primary focus was Ukraine, specifically targeting the energy, retail, education, consulting, and agriculture sectors. In 2023, it globalized the scope of its compromises, leading to persistent access within numerous sectors in the United States, Europe…
Coverage Details
Bias Distribution
- 75% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage