The notorious Russian state-sponsored threat group Sandworm is heavily escalating its destructive campaigns against critical infrastructure across Europe and the United States.
Also tracked as APT44, this military intelligence unit is pivoting aggressively from standard IT espionage to actively disrupting Operational Technology (OT) and Industrial Control Systems (ICS).
Unlike financially motivated ransomware gangs that often flee upon discovery, Sandworm deliberately doubles down to inflict maximum physical damage.
A recent deep-dive analysis of industrial environments between July 2025 and January 2026 reveals a chilling operational pattern.
Tracking anonymized telemetry from 10 industrial customers across 7 countries, researchers identified 29 Sandworm events.
Sandworm Targets OT Networks
Rather than relying on highly sophisticated, novel zero-day exploits, Sandworm thrives on organizational complacency.
The threat group consistently infiltrates environments that are already severely compromised by older, well-documented vulnerabilities.
Analysts found that targeted systems often harbored active exploit chains like EternalBlue, DoublePulsar, and Log4Shell.
Many systems were already heavily communicating with command-and-control frameworks like Cobalt Strike.
Instead of breaking new ground, Sandworm walks through digital doors that commodity malware has already kicked open.

Strikingly, every infected system in the analyzed dataset generated critical warnings long before Sandworm initiated its sabotage.
On average, victims received 43 days of serious security alerts related to these initial commodity infections.
Ignoring these seemingly routine or noisy alerts allowed Sandworm to establish footholds and quietly prepare for devastating internal expansion.

Once inside, rapid lateral movement becomes a primary operational objective. A handful of infected machines quickly generated thousands of internal alerts as they scanned and probed the network.
In one extreme case, a single compromised machine attempted to connect with 405 unique internal targets.

The group rapidly maps the network architecture, seeking pathways from corporate IT environments down into the heavily protected OT layers.
By the time defenders realize they are facing a premier military cyber-sabotage unit, the attackers have already woven themselves deep into the industrial infrastructure.
| Date / Incident | Attack / Campaign Name | Description | Key IOCs / Attack Vectors Noted |
|---|---|---|---|
| 2014 | Sandworm Zero-Day | Spearphishing targeting Ukraine and NATO-linked entities. | Windows CVE-2014-4114 |
| Dec 2015 | Ukraine Power Grid | First confirmed cyber-induced blackout affecting ~230,000 customers. | BlackEnergy |
| Dec 2016 | Ukraine Power Grid | Second blackout using purpose-built OT malware. | Industroyer (CRASHOVERRIDE) |
NozomiNetworks said, the most alarming discovery is Sandworm’s behavioral shift when defenders finally attempt to intervene.
Standard incident response protocols often assume that detecting a threat actor will force them to retreat, regroup, or retool.
Sandworm, however, treats detection as a definitive signal to accelerate its attacks.
When discovered, the group drastically increases its alert volume, deploys new malware variants, and wildly expands its target list to encompass Level 1 and 2 Purdue model assets.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.