Sandworm Team — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
April 28, 2026
Last Seen
September 2, 2026

Related Threat Clusters

  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector

    FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…

    10 articles · Updated May 13, 2026
  • Data Destruction and Disk Wiping Techniques Targeting Organizations

    Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…

    2 articles · Updated July 22, 2026
  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Active Exploitation of Critical Vulnerabilities in Lantronix and Ubiquiti Devices

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability,…

    6 articles · Updated June 25, 2026
  • Spearphishing Campaigns Exploit Malicious Links for User Execution

    Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information,…

    2 articles · Updated September 2, 2026
  • Surge in Android Banking Trojans: Four Campaigns Identified

    Zimperium's zLabs has reported a significant increase in Android Banking Trojan activity, identifying four distinct campaigns: RecruitRat, SaferRat, Astrinox, and Massiv. These campaigns utilize advanced…

    158 articles · Updated April 16, 2026
  • Ernst & Young Data Breach Exposes Client Tax Information

    Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…

    23 articles · Updated July 17, 2026
  • Oncology Institute Data Breach Exposes Patient Data via Third-Party Vendor

    On May 20, 2026, The Oncology Institute, Inc. was notified of unauthorized access to its systems by Kroll, a third-party vendor. The incident, confirmed in an SEC filing on May 22, 2026, involved patient data…

    6 articles · Updated May 26, 2026
  • Critical DoS Vulnerability in Notepad++ Exposes Users to Attacks

    A stack-based buffer overflow vulnerability (CVE-2026-5525) has been identified in Notepad++ version 8.9.3. This flaw occurs when a user drops a directory path of 259 characters onto the application, causing a stack…

    2 articles · Updated June 8, 2026

Recent Intelligence Reports

  • 001 — attack.mitre.org · September 2, 2026
  • T1539 — attack.mitre.org · July 23, 2026
  • 002 — attack.mitre.org · July 23, 2026
  • T1485 — attack.mitre.org · July 23, 2026
  • 001 — attack.mitre.org · July 23, 2026
  • MITRE ATT&CK T1199 — attack.mitre.org · July 20, 2026
  • T1660 — attack.mitre.org · July 11, 2026
  • G0034 — attack.mitre.org · June 24, 2026

CVSS v3.1 Breakdown