Thecyberexpress
AWS Attributes Cyber Espionage to Russian GRU-linked Group Sandworm
First seen 16 Dec 2025, 12:56 UTC
•


•60.0
Export
Article Content
Browse articles
Amazon Web Services (AWS) has linked a multi-year cyber espionage campaign targeting Western critical infrastructure, particularly in the energy sector, to the Russian GRU-affiliated group Sandworm (APT44). The campaign has evolved to exploit misconfigured customer network edge devices as the primary access vector, replacing traditional vulnerability exploitation methods.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks