Related Threat Clusters
-
DynoWiper Malware Targets Polish Energy Sector in Late 2025 Attacks
In late December 2025, Russian-linked hackers from the Sandworm group launched attacks using a new wiper malware named DynoWiper, specifically targeting a Polish energy company. The malware is designed to cause…
2 articles · Updated February 3, 2026 -
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
New Vulnerabilities Discovered in Serial-to-IP Converters Threaten Critical Infrastructure
Forescout Technologies has identified 22 new vulnerabilities in serial-to-IP converters from Lantronix and Silex, which are widely used in critical sectors like healthcare and utilities. These vulnerabilities,…
9 articles · Updated April 21, 2026 -
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
8 articles · Updated July 23, 2026 -
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and…
7 articles · Updated August 11, 2026 -
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks
The Russian state-sponsored group Sandworm has intensified its cyber operations against industrial and critical infrastructure, utilizing pre-compromised operational technology (OT) environments instead of zero-day…
5 articles · Updated May 14, 2026
Recent Intelligence Reports
- Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm — Cybersecuritynews · August 28, 2026
- Dr Louise Marie Hurel with the UK think tank RUSI states — www.rusi.org · August 18, 2026
- Fake job interviews deliver a trojanized WireGuard VPN client to IT pros — Feeds.4Sysops · August 12, 2026
- Risky Bulletin: Russian hackers adopt the fake job interview tactics — News.Risky.Biz · August 12, 2026
- Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals — Cybersecuritynews · August 12, 2026
- Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows — Gbhackers · August 12, 2026
- Sandworm hackers target IT pros with trojanized WireGuard VPN client — Bleepingcomputer · August 11, 2026
- Sandworm-Linked UAC — Thehackernews · August 11, 2026