Security news aggregator

Latest coverage for Sandworm

Stay informed on Sandworm, the notorious cyber threat group. Get the latest updates and insights on their activities in information security.

72 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Sandworm is a cyber espionage group believed to have ties to the Russian government's military intelligence agency, the GRU. This hacking collective has gained notoriety for its advanced cyber attacks against numerous international targets, primarily focusing on NATO member countries, governments in Ukraine, Georgia, and entities in the European Union and United States.

In the context of information security, Sandworm represents a significant and persistent threat due to its sophisticated tactics, techniques, and procedures (TTPs). The group is known for leveraging zero-day vulnerabilities, conducting distributed denial-of-service (DDoS) attacks, and deploying destructive malware like NotPetya, which caused widespread damage and disruption in 2017. Security professionals monitor Sandworm's activities closely to understand their evolving strategies and to develop robust cyber defenses against their operations.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 72 Filtered view
Bank Info Security 4 months, 1 week ago

Wiper Malware Targeting Poland's Power Grid Tied to Moscow

Signs Point to Long-Active 'Sandworm' Military Intelligence Hackers at WorkRussian cyberattacks in late December 2025 that attempted to disrupt Poland's power grid have been attributed to "Sandworm," the codename for an advanced persistent threat group tied to a Moscow military intelligence unit that repeatedly uses wiper malware, including in these attacks.

'Near-global' initial access campaign active since 2021 An initial-access subgroup of Russia's Sandworm last year wriggled its way into networks within the US, UK, Canada and Australia, stealing credentials and data from "a limited number of organizations," according to Microsoft.…

Bank Info Security 2 years, 1 month ago

The Global Menace of the Russian Sandworm Hacking Team

Russian Cyber Sabotage Unit Sandworm Adopting Advanced Techniques, Mandiant WarnsRussia's preeminent cyber sabotage unit presents "one of the widest and high severity cyber threats globally," warned Mandiant in a Wednesday report. Mandiant newly designated Sandworm as APT44 to differentiate it from another hacking unit it will still track as APT28.

Loading more headlines...