• News/
  • https://www.darkreading.com/threat-intelligence/microsoft-russian-sandworm-apt-exploits-edge-bugs-globally

Microsoft: Russia's Sandworm APT Exploits Edge Bugs Globally

Dark Reading
·
Nate Nelson
·
Published Feb 12, 2025
·
Updated

Arguably, no advanced persistent threat (APT) enjoys as much notoriety as Sandworm, otherwise known as Military Unit 74455 within Russia's military intelligence (GRU). Its highlight reel includes NotPetya, an attack against the 2018 Winter Olympics, and two effective assaults on Ukraine's power grid. More recent activities include a campaign against Denmark's energy sector and an unsuccessful attempt to down Ukraine's grid for a third time, followed by a successful attempt. In a sign of the times, Sandworm has subtly been shifting toward quieter, more widespread intrusions. Microsoft, which tracks the group as "Seashell Blizzard," has identified a subgroup within 74455 focused solely on gaining initial access to high-value organizations across major industries and geographic regions. It calls this subgroup "BadPilot." Since at least late 2021, BadPilot has been performing opportunistic attacks against Internet-facing infrastructure, taking advantage of known vulnerabilities in popular email and collaboration platforms. Notable examples include Zimbra's CVE-2022-41352, the Microsoft Exchange bug CVE-2021-34473, and CVE-2023-23397 in Microsoft Outlook. All three of these vulnerabilities received "critical" 9.8 out of 10 scores in the Common Vulnerability Scoring System (CVSS). BadPilot uses these critical vulnerabilities to gain useful initial access to traditionally high-value organizations: telecommunications companies, oil and gas companies, shipping companies, arms manufact...

Read full article

Affected Software

6 affected components
Zimbra Collaboration Suite
Microsoft Exchange
Microsoft Outlook
Fortinet FortiClient Enterprise Management Server
ConnectWise ScreenConnect
Microsoft Windows
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how Russia's Sandworm APT exploits vulnerabilities in Microsoft Edge and other software globally.

2

What significant threat does Sandworm APT pose?

Sandworm APT is notorious for its sophisticated cyber attacks, including the infamous NotPetya ransomware attack.

3

Which software products are affected by the Sandworm APT vulnerabilities?

The affected products include Microsoft Edge, Microsoft Exchange, Microsoft Outlook, and Fortinet's FortiClient.

4

What security measures can organizations implement to mitigate these risks?

Organizations are advised to regularly update their software and apply security patches to safeguard against exploitation.

5

How does Sandworm APT typically conduct its cyber operations?

Sandworm APT employs advanced techniques to exploit software vulnerabilities and conduct extensive cyber espionage activities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203