πNew WriteupβοΈ
βββββββββββββββ
πDate: Sun, 05 Mar 2023 19:09:11 GMT
βββββββββββββββ
βοΈTitle: Sandworm Book Summary
βββββββββββββββ
πLink: https://medium.com/p/2b3adf31b719
βββββββββββββββ
Tags: #cybersecurity #cybercrime #notpetya #sandworm
βββββββββββββββ
πDate: Sun, 05 Mar 2023 19:09:11 GMT
βββββββββββββββ
βοΈTitle: Sandworm Book Summary
βββββββββββββββ
πLink: https://medium.com/p/2b3adf31b719
βββββββββββββββ
Tags: #cybersecurity #cybercrime #notpetya #sandworm
Medium
Sandworm Book Summary
Sandworm is a book by Andy Greenberg that explores the history and impact of a group of Russian state-sponsored hackers known as Sandwormβ¦
β€· Title: Cyber Espionage and Influence: Unmasking APT28βs Tactics Sources and related content
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 01 Feb 2025 01:46:01 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT28 #CredoMap #CVE_2022_30190 #CVE_2023_23397 #CVE_2023_38831 #google chrome #MASEPIE #microsoft edge #Mozilla Firefox #OCEANMAP #SANDWORM #STEELHOOK
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 01 Feb 2025 01:46:01 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT28 #CredoMap #CVE_2022_30190 #CVE_2023_23397 #CVE_2023_38831 #google chrome #MASEPIE #microsoft edge #Mozilla Firefox #OCEANMAP #SANDWORM #STEELHOOK
Daily CyberSecurity
Cyber Espionage and Influence: Unmasking APT28's Tactics Sources and related content
Explore the Maverits Special Report on APT28, a notorious Russian cyber espionage group. Learn about their tactics, targets, and impact on government institutions.
β€· Title: Sandworm APT Exploits Trojanized KMS Tools to Target Ukrainian Users in Cyber Espionage Campaign
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 12 Feb 2025 02:09:30 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #APT44 #BACKORDER #BACKORDER loader #DcRAT malware #Sandworm APT
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 12 Feb 2025 02:09:30 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #APT44 #BACKORDER #BACKORDER loader #DcRAT malware #Sandworm APT
Cybersecurity News
Sandworm APT Exploits Trojanized KMS Tools to Target Ukrainian Users in Cyber Espionage Campaign
Learn about the notorious Sandworm APT44 and their state-sponsored cyber espionage targeting Ukrainian Windows users with trojanized KMS activators.
β€· Title: CVE-2024-1709 and CVE-2023-48788: Exploits Fueling Russiaβs BadPilot Campaign
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 17 Feb 2025 01:31:25 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Vulnerability #APT44 #BadPilot #BadPilot campaign #BlackEnergy Lite #CVE_2021_34473 #CVE_2022_41352 #CVE_2023_48788 #CVE_2024_1709 #SANDWORM #Seashell Blizzard #ShadowLink
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 17 Feb 2025 01:31:25 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Vulnerability #APT44 #BadPilot #BadPilot campaign #BlackEnergy Lite #CVE_2021_34473 #CVE_2022_41352 #CVE_2023_48788 #CVE_2024_1709 #SANDWORM #Seashell Blizzard #ShadowLink
Daily CyberSecurity
CVE-2024-1709 and CVE-2023-48788: Exploits Fueling Russia's BadPilot Campaign
Uncover the threats posed by Seashell Blizzard, a cyber espionage group behind the BadPilot campaign targeting critical sectors.
β€· Title: Threat Intel Diaries #2βββProfiling Sandworm Team (APT44)
ββββββββββββββββββββββββ
πͺ Author: Karim Walid
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 17 May 2025 07:47:51 GMT
ββββββββββββββββββββββββ
β Tags: #threat_intelligence #apt #sandworm #hacking #threat_hunting
ββββββββββββββββββββββββ
πͺ Author: Karim Walid
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 17 May 2025 07:47:51 GMT
ββββββββββββββββββββββββ
β Tags: #threat_intelligence #apt #sandworm #hacking #threat_hunting
Medium
Threat Intel Diaries #2βββProfiling Sandworm Team (APT44)
Threat Actor Overview
β€· Title: Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 31 Oct 2025 00:07:31 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 31 Oct 2025 00:07:31 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
Daily CyberSecurity
Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
Symantec exposed a Russian-aligned espionage campaign in Ukraine using LotL tactics. Attackers used a Sandworm-linked webshell (Localolive) and abused scheduled tasks to dump credentials and bypass Windows Defender.
β€· Title: Sandworm APT Attacks Belarus Military With LNK Exploit and OpenSSH Over Tor obfs4 Backdoor
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 01 Nov 2025 11:35:46 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russia APT #SANDWORM #Tor network
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 01 Nov 2025 11:35:46 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russia APT #SANDWORM #Tor network
Daily CyberSecurity
Sandworm APT Attacks Belarus Military With LNK Exploit and OpenSSH Over Tor obfs4 Backdoor
Cyble exposed a Sandworm-linked espionage campaign targeting Belarusian military UAV personnel. It uses a malicious LNK file to deploy OpenSSH over Tor obfs4 for stealthy, persistent remote access.
β€· Title: Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
ββββββββββββββββββββββββ
πͺ Author: Waqas
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 16 Dec 2025 17:55:38 +0000
ββββββββββββββββββββββββ
β Tags: #Security #0day #Amazon #APT44 #AWS #Curly COMrades #Cyber Attack #Cyber Crime #Cybersecurity #GRU #Malware #Russia #Sandworm #Seashell Blizzard #Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Waqas
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 16 Dec 2025 17:55:38 +0000
ββββββββββββββββββββββββ
β Tags: #Security #0day #Amazon #APT44 #AWS #Curly COMrades #Cyber Attack #Cyber Crime #Cybersecurity #GRU #Malware #Russia #Sandworm #Seashell Blizzard #Vulnerability
Hackread
Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
β€· Title: Sandwormβs Tactical Pivot: Russian GRU Abandons Zero-Days to Weaponize Misconfigured Edge Devices
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 17 Dec 2025 01:57:59 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Amazon Threat Intelligence #APT44 #Credential Replay #Critical Infrastructure #Curly COMrades #Edge Device #GRU #misconfiguration #SANDWORM
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 17 Dec 2025 01:57:59 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Amazon Threat Intelligence #APT44 #Credential Replay #Critical Infrastructure #Curly COMrades #Edge Device #GRU #misconfiguration #SANDWORM
Daily CyberSecurity
Sandwormβs Tactical Pivot: Russian GRU Abandons Zero-Days to Weaponize Misconfigured Edge Devices
Sandworm (APT44) has shifted tactics, favoring misconfigured edge devices over complex exploits to breach energy and telecom sectors via credential replay.
β€· Title: The Persistence of WinRAR: Google Warns of Widespread CVE-2025-8088 Attacks
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 29 Jan 2026 04:15:22 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Vulnerability #Ads #CVE_2025_8088 #Google Threat Intelligence #InfoSec 2026 #path traversal #phishing #RomCom #Sandworm #Startup Persistence #Winrar
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 29 Jan 2026 04:15:22 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Vulnerability #Ads #CVE_2025_8088 #Google Threat Intelligence #InfoSec 2026 #path traversal #phishing #RomCom #Sandworm #Startup Persistence #Winrar
Penetration Testing Tools
The Persistence of WinRAR: Google Warns of Widespread CVE-2025-8088 Attacks
The Google Threat Intelligence Group (GTIG) has disclosed the extensive exploitation of a critical vulnerability, designated CVE-2025-8088, residing
β€· Title: Beyond Blackouts: The ELECTRUM Strike on Poland and the New Era of βDigital Arsonβ
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 03 Feb 2026 04:55:47 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #CERT Polska #Distributed Energy Resources (DER) #Dragos #DynoWiper #ELECTRUM #grid stability #Industrial Control Systems #Operational Technology (OT) #Polish power grid #Sandworm #Tech News
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 03 Feb 2026 04:55:47 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #CERT Polska #Distributed Energy Resources (DER) #Dragos #DynoWiper #ELECTRUM #grid stability #Industrial Control Systems #Operational Technology (OT) #Polish power grid #Sandworm #Tech News
Penetration Testing Tools
Beyond Blackouts: The ELECTRUM Strike on Poland and the New Era of "Digital Arson"
A cyberattack that initially garnered scant attention in Poland has since emerged as a pivotal signal for the
β€· Title: Targeting the Grid: ESET Unmasks βDynoWiperβ After Destructive Strike on Polish Energy Sector
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 03:50:20 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Active Directory GPO #Critical Infrastructure #cyber sabotage #data wiper #DynoWiper #ESET research #LSASS memory dump #Poland energy sector #rsocx #Rubeus #Sandworm #Tech News 2026 #ZOV wiper
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 03:50:20 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Active Directory GPO #Critical Infrastructure #cyber sabotage #data wiper #DynoWiper #ESET research #LSASS memory dump #Poland energy sector #rsocx #Rubeus #Sandworm #Tech News 2026 #ZOV wiper
Penetration Testing Tools
Targeting the Grid: ESET Unmasks "DynoWiper" After Destructive Strike on Polish Energy Sector
ESET has disclosed the intricate technical specifications of an incursion involving a nascent data-obliteration utility designated as DynoWiper.
β€· Title: Under Siege: GTIG Report Exposes North Korean Spies & Russian Drone Hacks in Defense Sector
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 11 Feb 2026 00:50:32 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT44 #cyber_espionage #Defense Industrial Base #Drone Security #Edge Device Security #Google Threat Intelligence #GTIG #Insider Threat #North Korean IT workers #SANDWORM
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 11 Feb 2026 00:50:32 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT44 #cyber_espionage #Defense Industrial Base #Drone Security #Edge Device Security #Google Threat Intelligence #GTIG #Insider Threat #North Korean IT workers #SANDWORM
Daily CyberSecurity
Under Siege: GTIG Report Exposes North Korean Spies & Russian Drone Hacks in Defense Sector
GTIG report: Defense Industrial Base faces "constant siege" from Russian drone hackers & North Korean IT insiders. Learn the new threats.
β€· Title: SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains
ββββββββββββββββββββββββ
πͺ Author: Nam Phong
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 26 Jul 2026 10:47:32 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #AI Toolchain #CrowdStrike #NPM Malware #SANDWORM_MODE #supply chain attack
ββββββββββββββββββββββββ
πͺ Author: Nam Phong
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 26 Jul 2026 10:47:32 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #AI Toolchain #CrowdStrike #NPM Malware #SANDWORM_MODE #supply chain attack
Information Security News
SANDWORM_MODE Worm Exploits AI Toolchains and Supply Chains
The Emergence of AI Infrastructure Worms Malicious packages have evolved to inconspicuously masquerade as routine operations executed by artificial intelligence assistants and automated build systβ¦