{"id":3126,"date":"2024-04-17T05:00:00","date_gmt":"2024-04-17T10:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/-sandworm-group-is-russia-s-primary-cyber-attack-unit-in-ukraine"},"modified":"2024-04-17T05:00:00","modified_gmt":"2024-04-17T10:00:00","slug":"sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/17\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine\/","title":{"rendered":"&#8216;Sandworm&#8217; Group Is Russia&#8217;s Primary Cyberattack Unit in Ukraine"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt9095ccd3d7e6ca7a\/661f247443fdac46e402e9b1\/gru_Militarist_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The formidable Sandworm hacker group has played a central role supporting Russian military objectives in Ukraine over the past two years even as it has stepped up cyberthreat operations in other regions of strategic political, economic, and military interest to Russia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s the upshot of the analysis of the threat actor&#8217;s activities undertaken by Google Cloud&#8217;s Mandiant security group. They found that Sandworm \u2014 or APT44, as Mandiant has been tracking it \u2014 to be responsible for nearly all disruptive and destructive cyberattacks in Ukraine since Russia&#8217;s invasion in February 2022.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the process, the threat actor established itself as the primary cyberattack unit within Russia&#8217;s Main Intelligence Directorate (GRU) and among all Russian state-backed cybergroups, Mandiant assessed. No other cyber outfit appears as totally integrated with Russia&#8217;s military operators as Sandworm is presently, the security vendor noted in a report this week that offers a detailed look at the group&#8217;s tools, techniques, and practices.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;APT44 operations are global in scope and mirror Russia&#8217;s wide ranging national interests and ambitions,&#8221; Mandiant warned. &#8220;Even with an ongoing war, we have observed the group sustain access and espionage operations across North America, Europe, the Middle East, Central Asia, and Latin America.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One manifestation of Sandworm&#8217;s broadening global mandate was a series of attacks on three water and hydroelectric facilities in the US and France earlier this year by a hacking outfit called CyberArmyofRussia_Reborn, which Mandiant believes is controlled by Sandworm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacks \u2014 which appear to have been more a demonstration of capabilities than anything else \u2014 caused a system malfunction at one of the attacked US water facilities. In October 2022, a group that Mandiant believes was APT44 deployed ransomware against logistics providers in Poland in a rare instance of deploying a disruptive capability against a NATO country.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Global Mandate\">Global Mandate<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sandworm is a threat actor that has been active for more than a decade. It&#8217;s well known for numerous high-profile attacks such as the one in 2022 that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/sandworm-cyberattackers-ukrainian-power-grid-missile-strikes\" rel=\"noopener\">took down sections of Ukraine&#8217;s power grid<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> just prior to a Russian missile strike; the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/decrypting-the-motivations-behind-notpetya-expetr-goldeneye\" rel=\"noopener\">2017 NotPetya ransomware outbreak<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and an attack at the opening ceremony of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/emailed-cyberattack-targets-2018-pyeongchang-olympics\" rel=\"noopener\">Pyeongchang Olympic Games<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in South Korea. The group has traditionally targeted government and critical infrastructure organizations, including those in the defense, transportation, and energy sectors. The US government and others have attributed the operation to a cyber unit within Russia&#8217;s GRU. In 2020, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/russian-military-officers-unmasked-indicted-for-high-profile-cyberattack-campaigns\" rel=\"noopener\">US Justice Department indicted several Russian military officers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for their alleged role in various Sandworm campaigns.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;APT44 has an extremely broad targeting remit,&#8221; says Dan Black, principal analyst at Mandiant. &#8220;Organizations who develop software or other technologies for industrial control systems and other critical infrastructure components should have APT44 front and center in their threat models.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Gabby Roncone, a senior analyst with Mandiant&#8217;s Advanced Practices team, includes media organizations among APT44\/Sandworm&#8217;s targets, especially during elections. &#8220;Many key elections of high interest to Russia are taking place this year, and APT44 may attempt to be a key player&#8221; in them, Roncone says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mandiant itself has been tracking APT44 as a unit within Russia&#8217;s military intelligence. &#8220;We track a complex external ecosystem that enables their operations, including state-owned research entities and private companies,&#8221; Roncone adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Within Ukraine, Sandworm&#8217;s attacks have increasingly focused on espionage activity with a view to gathering information for Russian military forces&#8217; battlefield advantage, Mandiant said. In many cases, the threat actor&#8217;s favorite tactic for gaining initial access to target networks has been through exploitation of routers, VPNs, and other <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/palo-alto-network-issues-hot-fixes-for-zero-day-bug-in-its-firewall-os\" rel=\"noopener\">edge infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. It&#8217;s a tactic that the threat actor has been increasingly using since Russia&#8217;s Ukraine invasion. While the group has accumulated a vast collection of bespoke attack tools, it has often relied on legitimate tools and living-off-the-land techniques to evade detection.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"An Elusive Enemy\">An Elusive Enemy<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;APT44 is adept at flying under the detection radar. Building detections for commonly abused open source tools and living-off-the-land methods is critical,&#8221; Black says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Roncone also advocates that organizations map and maintain their network environments and segment networks where possible because of Sandworm&#8217;s penchant for targeting vulnerable edge infrastructure for initial entry and re-entry into environments. &#8220;Organizations should additionally be wary of APT44 pivoting between espionage and disruptive goals after gaining access to networks,&#8221; Roncone notes. &#8220;For folks working in media and media organizations in particular, digital safety training for individual journalists is key.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Black and Roncone perceive APT44\/Sandworm&#8217;s use of hacking fronts like CyberArmyofRussia_Reborn as an attempt to draw attention to its campaigns and for deniability purposes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We have seen APT44 repeatedly use the CyberArmyofRussia_Reborn Telegram to post evidence from and draw attention to its sabotage activity,&#8221; Black says. &#8220;We cannot conclusively determine if this is an exclusive relationship but judge that APT44 has the ability to direct and influence what the persona posts on Telegram.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Black says APT44 could be using personas such as CyberArmyofRussia_Reborn as a way to avoid direct attribution in case they cross a line or provoke a response. &#8220;But the second [motive] is that they create a fake sense of popular support for Russia&#8217;s war \u2014 a false impression that average Russians are self-assembling to join the cyber fight against Ukraine.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/-sandworm-group-is-russia-s-primary-cyber-attack-unit-in-ukraine\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The formidable Sandworm hacker group has played a central role<\/p>\n","protected":false},"author":12,"featured_media":3127,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3126","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sandworm-group-is-russias-primary-cyberattack-unit-in-ukraine.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3126"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3126\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3127"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}