• News/
  • https://www.theregister.com/2025/02/12/russias_sandworm_caught_stealing_credentials/

Russia's Sandworm caught snarfing credentials, data from American and Brit orgs

The Register
·
Jessica Lyons
·
Published Feb 12, 2025
·
Updated

An initial-access subgroup of Russia's Sandworm last year wriggled its way into networks within the US, UK, Canada and Australia, stealing credentials and data from "a limited number of organizations," according to Microsoft. Sandworm, the offensive cyber operations group that works for the Russian Military Intelligence Unit 74455 (GRU), has previously been linked to attacks on water facilities in the US and EU, the 2018 Winter Olympics, NotPetya, and various other destructive attacks on Ukraine's critical infrastructure. In a report published today, Redmond says a subgroup of Sandworm (Microsoft's threat intel team tracks Sandworm as "Seashell Blizzard") has been carrying out a "near-global" initial access campaign dubbed "BadPilot" since at least 2021. The crew uses several methods to compromise victims' internet-facing infrastructure and gain access to critical sectors including energy, oil and gas, telecommunications, shipping, arms manufacturing, and international governments. And while its initial focus was Ukraine, by 2023 the BadPilot campaign had achieved persistent access to "numerous" high-value sectors in the US, Europe, Central Asia and the Middle East. A year later, it "honed its focus" on US, UK, Canada and Australian victims, we're told. "Microsoft Threat Intelligence assesses that Seashell Blizzard uses this initial access subgroup to  horizontally scale their operations as new exploits are acquired and to sustain persistent access to current  and future sect...

Read full article

Affected Software

2 affected components
ConnectWise ScreenConnect
Fortinet FortiClient EMS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary focus of this article?

The article reports on Russia's Sandworm group infiltrating networks in multiple countries to steal credentials and data.

2

What are the security implications associated with this incident?

The breach highlights vulnerabilities in organizations' network defenses and the importance of securing credentials against advanced persistent threats.

3

Which countries were affected by Sandworm's activities?

The infiltration reportedly affected organizations in the US, UK, Canada, and Australia.

4

What specific software products were identified as being vulnerable in this attack?

The attack involved exploiting vulnerabilities in ConnectWise ScreenConnect and Fortinet FortiClient EMS.

5

Who provided the details regarding the Sandworm infiltration?

The article cites findings from a report by Microsoft regarding the initial-access subgroup's operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203