Sandworm APT Shifts Focus From Compromised IT To OT Networks

The notorious Russian state-sponsored threat group Sandworm is heavily escalating its destructive campaigns against critical infrastructure across Europe and the United States.

Also tracked as APT44, this military intelligence unit is pivoting aggressively from standard IT espionage to actively disrupting Operational Technology (OT) and Industrial Control Systems (ICS).

Unlike financially motivated ransomware gangs that often flee upon discovery, Sandworm deliberately doubles down to inflict maximum physical damage.

A recent deep-dive analysis of industrial environments between July 2025 and January 2026 reveals a chilling operational pattern.

Tracking anonymized telemetry from 10 industrial customers across 7 countries, researchers identified 29 Sandworm events.

Sandworm Targets OT Networks

Rather than relying on highly sophisticated, novel zero-day exploits, Sandworm thrives on organizational complacency.

The threat group consistently infiltrates environments that are already severely compromised by older, well-documented vulnerabilities.

Analysts found that targeted systems often harbored active exploit chains like EternalBlue, DoublePulsar, and Log4Shell.

Many systems were already heavily communicating with command-and-control frameworks like Cobalt Strike.

Instead of breaking new ground, Sandworm walks through digital doors that commodity malware has already kicked open.

Temporal analysis of Sandworm alerts (Source: nozominetworks)
Temporal analysis of Sandworm alerts (Source: nozominetworks)

Strikingly, every infected system in the analyzed dataset generated critical warnings long before Sandworm initiated its sabotage.

On average, victims received 43 days of serious security alerts related to these initial commodity infections.

Ignoring these seemingly routine or noisy alerts allowed Sandworm to establish footholds and quietly prepare for devastating internal expansion.

Sandworm detection cascade (Source: nozominetworks)
Sandworm detection cascade (Source: nozominetworks)

Once inside, rapid lateral movement becomes a primary operational objective. A handful of infected machines quickly generated thousands of internal alerts as they scanned and probed the network.

In one extreme case, a single compromised machine attempted to connect with 405 unique internal targets.

Warning window between first alert and Sandworm detection (Source: nozominetworks)
Warning window between first alert and Sandworm detection (Source: nozominetworks)

The group rapidly maps the network architecture, seeking pathways from corporate IT environments down into the heavily protected OT layers.

By the time defenders realize they are facing a premier military cyber-sabotage unit, the attackers have already woven themselves deep into the industrial infrastructure.

Date / IncidentAttack / Campaign NameDescriptionKey IOCs / Attack Vectors Noted
2014Sandworm Zero-DaySpearphishing targeting Ukraine and NATO-linked entities.Windows CVE-2014-4114
Dec 2015Ukraine Power GridFirst confirmed cyber-induced blackout affecting ~230,000 customers.BlackEnergy
Dec 2016Ukraine Power GridSecond blackout using purpose-built OT malware.Industroyer (CRASHOVERRIDE)

NozomiNetworks said, the most alarming discovery is Sandworm’s behavioral shift when defenders finally attempt to intervene.

Standard incident response protocols often assume that detecting a threat actor will force them to retreat, regroup, or retool.

Sandworm, however, treats detection as a definitive signal to accelerate its attacks.

When discovered, the group drastically increases its alert volume, deploys new malware variants, and wildly expands its target list to encompass Level 1 and 2 Purdue model assets.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories