• News/
  • https://www.bleepingcomputer.com/news/security/badpilot-network-hacking-campaign-fuels-russian-sandworm-attacks/

BadPilot network hacking campaign fuels Russian SandWorm attacks

BleepingComputer
·
Bill Toulas
·
Published Feb 12, 2025
·
Updated

A subgroup of the Russian state-sponsored hacking group APT44, also known as 'Seashell Blizzard' and 'Sandworm', has been targeting critical organizations and governments in a multi-year campaign dubbed 'BadPilot.' The threat actor has been active since at least 2021 and is also responsible for breaching networks of organizations in energy, oil and gas, telecommunications, shipping, and arms manufacturing sectors. Microsoft's Threat Intelligence team says that the actor is dedicated to achieving initial access to target systems, establishing persistence, and maintaining presence to allow other APT44 subgroups with post-compromise expertise to take over. "We have also observed the initial access subgroup to pursue access to an organization prior to a Seashell Blizzard-linked destructive attack," reads a Microsoft report shared with BleepingComputer. Microsoft's assessment is "that Seashell Blizzard uses this initial access subgroup to horizontally scale their operations as new exploits are acquired and to sustain persistent access to current and future sectors of interest to Russia." Microsoft's earliest observations of the subgroup's activity show opportunistic operations targeting Ukraine, Europe, Central and South Asia, and the Middle East, focusing on critical sectors. Starting 2022, following Russia's invasion of Ukraine, the subgroup intensified its operations against critical infrastructure supporting Ukraine, including government, military, transportation, and logisti...

Read full article

Affected Software

3 affected components
SimpleHelp Remote Monitoring and Management (RMM) software
Palo Alto Networks PAN-OS
Microsoft Threat Intelligence
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the BadPilot hacking campaign led by a subgroup of the Russian APT44 group, targeting critical organizations and governments.

2

What security implications are discussed?

The article highlights that the BadPilot campaign poses a significant threat to national security and critical infrastructure.

3

What products or software are affected by the BadPilot campaign?

The affected software includes SimpleHelp Remote Monitoring and Management, Palo Alto Networks PAN-OS, and Microsoft Threat Intelligence.

4

Who is behind the BadPilot hacking campaign?

The BadPilot campaign is attributed to a subgroup of the Russian state-sponsored hacking group known as Sandworm.

5

How long has the BadPilot campaign been ongoing?

The BadPilot hacking campaign has been ongoing for multiple years, targeting various organizations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203