Russian Hackers Target Network Edge Devices in Western Critical Infrastructure
Article Content
Browse articles
Since 2021, a Russian state-hacking group has been attacking network edge devices in Western critical infrastructure, with increased activity noted throughout 2025. This campaign, attributed to the GRU and Sandworm group, marks a strategic shift from exploiting zero-day vulnerabilities to targeting misconfigured systems.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Sandworm in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cyclops Blink Malware Targets Cisco Firewall Devices In August 2026, researchers from the Counter Threat Unit™ (CTU) discovered a malicious 64-bit Linux executable named timezone_check on compromised Cisco Firewall Management Center (FMC) devices. This malware variant, linked to the Russian IRON VIKING threat group, offers persistent remote access and advanced…
UAC-0099 Enhances MATCHBOIL Malware Targeting Ukrainian Industries ESET Research has documented the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned group UAC-0099, which has targeted Ukrainian transportation, manufacturing, and energy sectors. The malware, first noted by CERT-UA in August 2025, has been under development since at least April 2024. MATCHBOIL is…