An initial-access subgroup of Russia's Sandworm last year wriggled its way into networks within the US, UK, Canada and Australia, stealing credentials and data from "a limited number of organizations," according to Microsoft. Sandworm, the offensive cyber operations group that works for the Russian Military Intelligence Unit 74455 (GRU), has previously been linked to attacks on water facilities in the US and EU, the 2018 Winter Olympics, NotPetya, and various other destructive attacks on Ukraine's critical infrastructure. In a report published today, Redmond says a subgroup of Sandworm (Microsoft's threat intel team tracks Sandworm as "Seashell Blizzard") has been carrying out a "near-global" initial access campaign dubbed "BadPilot" since at least 2021. The crew uses several methods to compromise victims' internet-facing infrastructure and gain access to critical sectors including energy, oil and gas, telecommunications, shipping, arms manufacturing, and international governments. And while its initial focus was Ukraine, by 2023 the BadPilot campaign had achieved persistent access to "numerous" high-value sectors in the US, Europe, Central Asia and the Middle East. A year later, it "honed its focus" on US, UK, Canada and Australian victims, we're told. "Microsoft Threat Intelligence assesses that Seashell Blizzard uses this initial access subgroup to horizontally scale their operations as new exploits are acquired and to sustain persistent access to current and future sect...
Russia's Sandworm caught snarfing credentials, data from American and Brit orgs
The Register
·Jessica Lyons
·Published Feb 12, 2025
·Updated
Affected Software
2 affected components
ConnectWise ScreenConnect
Fortinet FortiClient EMS
Frequently Asked Questions
1
What is the primary focus of this article?
The article reports on Russia's Sandworm group infiltrating networks in multiple countries to steal credentials and data.
2
What are the security implications associated with this incident?
The breach highlights vulnerabilities in organizations' network defenses and the importance of securing credentials against advanced persistent threats.
3
Which countries were affected by Sandworm's activities?
The infiltration reportedly affected organizations in the US, UK, Canada, and Australia.
4
What specific software products were identified as being vulnerable in this attack?
The attack involved exploiting vulnerabilities in ConnectWise ScreenConnect and Fortinet FortiClient EMS.
5
Who provided the details regarding the Sandworm infiltration?
The article cites findings from a report by Microsoft regarding the initial-access subgroup's operations.