Related Threat Clusters
-
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
8 articles · Updated July 23, 2026 -
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and…
7 articles · Updated August 11, 2026 -
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks
The Russian state-sponsored group Sandworm has intensified its cyber operations against industrial and critical infrastructure, utilizing pre-compromised operational technology (OT) environments instead of zero-day…
5 articles · Updated May 14, 2026 -
AWS Attributes Cyber Espionage to Russian GRU-linked Group Sandworm
Amazon Web Services (AWS) has linked a multi-year cyber espionage campaign targeting Western critical infrastructure, particularly in the energy sector, to the Russian GRU-affiliated group Sandworm (APT44). The campaign…
4 articles · Updated December 16, 2025 -
Spanish Police Arrest Pro-Russia Hacktivist Linked to Critical Infrastructure Attacks
Spanish authorities arrested a man in Palencia suspected of being affiliated with pro-Russia hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. The arrest, made in March 2026, followed an FBI tip-off…
4 articles · Updated July 7, 2026 -
Sandworm Hackers Target Ukraine's Grain Sector with Data-Wiping Malware
The Russian state-backed hacker group Sandworm has launched a campaign using data-wiping malware against Ukrainian organizations, particularly focusing on the grain sector. This attack aims to disrupt critical…
9 articles · Updated November 8, 2025 -
APT36's Ongoing Espionage Campaign Against Indian Government
APT36, also known as Transparent Tribe, has been conducting persistent cyber espionage campaigns against the Indian government and defense organizations for over a decade. This espionage ecosystem, which includes the…
2 articles · Updated February 10, 2026
Recent Intelligence Reports
- Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows — Gbhackers · August 12, 2026
- Sandworm hackers target IT pros with trojanized WireGuard VPN client — Bleepingcomputer · August 11, 2026
- Sandworm-Linked UAC — Thehackernews · August 11, 2026
- Notepad++ used in new stealthy attacks targeting Ukraine — Feeds.Feedburner · July 23, 2026
- Hackers abuse Notepad++ plugins to stealthily install malware — Bleepingcomputer · July 23, 2026
- Russia's GRU Hackers Target Ukraine With Fake CAPTCHAs and an Unkillable Blockchain Server — Techtimes · July 21, 2026
- Spain arrests suspected member of pro-Russian hacktivist groups — Bleepingcomputer · July 7, 2026
- Sandworm and Turla — cloud.google.com · June 8, 2026