Threat Actor ๐ท๐บ Russia
Sandworm
Also known as: Quedagh ยท VOODOO BEAR ยท TEMP.Noble ยท IRON VIKING ยท G0034 ยท ELECTRUM ยท TeleBots ยท IRIDIUM ยท Blue Echidna ยท FROZENBARENTS ยท UAC-0113 ยท Seashell Blizzard ยท UAC-0082 ยท APT44
This threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial of service, and data destruction purposes. Some believe that the threat actor is linked to the 2015 compromise of the Ukrainian electrical grid and a distributed denial of service prior to the Russian invasion of Georgia. Believed to be responsible for the 2008 DDoS attacks in Georgia and the 2015 Ukraine power grid outage
Indicators of Compromise 41
Domain apn Domain ciscoheartbeat[.]com Domain soprasteria-bg[.]com Filename Evernote.zip Filename GHETTOVIBE Filename InitTest.dll Filename NppExport.dll Filename PFC200 Filename RemoteLibUpdater.exe Filename SCADA Filename assembler.py Filename cloud.exe Filename dotnet-install.ps1 Filename link.ps1 Filename service.aspx Filename service.exe Filename updater.rar Filename winbox64.exe GitHub Repo https://sourceforge.net/projects/sopravpn/ GitHub Repo sourceforge.net/projects/soprabulgariavpn GitHub Repo sourceforge.net/projects/soprasteriavpn GitHub Repo sourceforge.net/projects/sopravpn SHA-256 08ced2cca0b22dd7a211ebf318b8186fc1c2149943338c77ee2ac677b473727f SHA-256 2866763ebd3124bfe9cf3f65d6341dda6bbb98e2653c98dd2f001f152e082291 SHA-256 44b1f3f06607cd3ee16517d31b30208910ce678cb69ba7a0514546dff183dfce SHA-256 47e83dfd0f9680d2e9623fee92c0acc4db40ea4272edeb53164304620305a24f SHA-256 636e04f0618dd578d107f440b1cf6c910502d160130adae5e415b2dd2b36abcb SHA-256 6865685f75a64780aa24a05b267bea128bcc6efdc682fa2893e13a4f63e6d6e7 SHA-256 69cb709bffbeccea60776c49935acb41ecfb160973f1f11b195007c254c1c28c SHA-256 70a5492db39585ec18de512058a5389c9a4043fba13ca8ad7d057ead66298626 SHA-256 79d1c7158d374ed80ec7f9305f6638ad95aefd600c9e280fc7fe081c7ef2f4b4 SHA-256 8140326d7474722e6bdd51dd305609e82319c0150ed429b74587d689acea2d54 SHA-256 8c07c37ac84d4c6fd76de3d966e26b65e401bc641a845baf6f73ad0d6a10fc6b SHA-256 8eb178d5b1d528380c9ccfe1ea7f43aebd97b018a5b449ec911a05c0bd52d207 SHA-256 8fe4e336fbac4f5227f802ba1853f1b07ffdb414cec961c532c115078a2aa55e SHA-256 ba6301e35fc3feb41ece82e518f97a81263aa3bd750de7a84eef01dbf15f3507 SHA-256 c2cf27810cc11ed7c6ae9f70f156f18cf3f73550ab5d675278e3b725fc88e2b0 SHA-256 cf8e09f013fcb5f34c8c274bf07d9047956ba441dabf2d3de87ea025e14058b7 SHA-256 e03b8c54ac916b363f956e4e4e04a19eb4119455d8006c92e9328e16a8cee52f SHA-256 e9a19d42da93e9257dc9b89afc34341e1c13d6a6f7dacd309f2fc545e6b749a3 IP 185[.]145[.]245[.]209
MITRE ATT&CK TTPs 25
T1012 T1021.001 T1048.003 T1053.005 T1059.001 T1059.003 T1069.002 T1070.001 T1071.001 T1071.004 T1078.004 T1083 T1087.002 T1090 T1090.002 T1105 T1129 T1133 T1136.002 T1204.002 T1210 T1217 T1485 T1490 T1566
Query Registry
Discovery
Remote Desktop Protocol
Lateral Movement
Exfiltration Over Unencrypted Non-C2 Protocol
Exfiltration
Scheduled Task
Execution
PowerShell
Execution
Windows Command Shell
Execution
Domain Groups
Discovery
Clear Windows Event Logs
Defense Evasion
Web Protocols
Command And Control
DNS
Command And Control
Cloud Accounts
Defense Evasion
File and Directory Discovery
Discovery
Domain Account
Discovery
Proxy
Command And Control
External Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Shared Modules
Execution
External Remote Services
Persistence
Domain Account
Persistence
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Browser Information Discovery
Discovery
Data Destruction
Impact
Inhibit System Recovery
Impact
Phishing
Initial Access
Source Articles
Sandworm hackers target IT pros with trojanized WireGuard VPN client
The Russian threat group Sandworm, operating as UAC-0145, has been targeting IT professionals and system administrators since at least May 2026 through a social engineering campaign involving fake job offers. The attackers pose as legitimate IT companies, such as Sopra Steria, and lure victims into downloading a trojanized WireGuard-based client called 'SopraVPN' from SourceForge. The malicious client contains a custom Base64 decoder and executes PowerShell code that establishes persistence via scheduled tasks on Windows or downloads additional payloads on Linux through attacker-controlled infrastructure.
bleeping-computer ยท3w ago
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Russian nation-state threat actor UAC-0145, linked to Sandworm (APT44), is conducting a social engineering campaign targeting Ukrainian IT workers through fake job interviews. The attackers pose as recruiters from legitimate IT companies and lure victims into installing a malicious custom VPN client called SopraVPN, hosted on SourceForge. The backdoored WireGuard-based client allows attackers to execute arbitrary PowerShell commands on compromised systems by decrypting malicious scripts using modified configuration files. The malware also establishes persistence via scheduled tasks on Windows or cURL downloads on Linux to retrieve secondary payloads.
hacker-news ยท3w ago
Hackers breached a small Polish energy plant via private APN last year
In December 2025, a threat actor linked to the Russian Electrum group breached a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) network. The attackers gained initial access through a compromised FortiGate firewall and Teltonika cellular router at a wind farm, then moved laterally through the private APN to reach the CHP plant's operational technology (OT) network. They exploited default credentials on a WAGO PFC200 PLC, used it as a bridge to access Siemens PLCs, and ultimately shut down critical systems including the steam turbine and water treatment system.
bleeping-computer ยท3w ago
Ukrainian Organizations Still Heavily Targeted by Russian Attacks | SECURITY.COM
Russian-linked attackers continue to target Ukrainian organizations with a focus on espionage and persistent access. The intrusions involved the use of webshells, living-off-the-land tactics, and minimal malware deployment to harvest credentials and sensitive data. Techniques included memory dumping, registry exfiltration, and disabling security tools, indicating a highly skilled and stealthy threat actor.
security.com
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has identified a campaign by threat cluster UAC-0099 that abuses Notepad++ plugins to stealthily deploy malware. The attackers distribute a malicious archive containing a legitimate Notepad++ installation alongside a malicious plugin named NppExport.dll, which loads the LunchPoke utility to establish persistence. LunchPoke extracts and executes BurnyBear, a loader for the MatchBoil V2 malware, enabling further malicious activity including scheduled task creation and C2 communication.
bleeping-computer ยท1mo ago
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actor UAC-0145, a sub-cluster of Sandworm affiliated with GRU, has been conducting cyberattacks against Ukrainian targets using the ClickFix social engineering technique. The attackers compromise websites and inject fake CAPTCHA checks that prompt users to execute malicious PowerShell commands, leading to malware infection. These commands download and execute malware such as GHETTOVIBE, SCOUTCURL, and COWARDDUCK, enabling data theft and remote control. The campaign also involves backdooring Android devices via malicious APKs distributed as security tools.
hacker-news ยท1mo ago
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom have jointly imposed sanctions on Russian individuals and entities linked to state-sponsored cyberattacks. The targeted groups include GRU officers, FSB-affiliated hackers such as the Turla group, and cybercriminals involved in operations like the Lumma Stealer malware. These actors are accused of conducting cyberespionage, targeting critical infrastructure across Europe, and supporting disinformation campaigns. The sanctions follow a series of attacks on energy grids and government institutions, including failed attempts to disrupt Poland's power infrastructure.
bleeping-computer ยท1mo ago
Spain arrests suspected member of pro-Russian hacktivist groups
Spanish authorities have arrested a man suspected of being an active member of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. He allegedly provided logistical and operational support to a Ukrainian hacker within CARR and facilitated escape routes to Russia. The groups have been linked to attacks on critical infrastructure in the U.S. and Europe, including SCADA systems, and are loosely associated with the Russian state-backed APT44 (Sandworm). The suspect also participated in operations attributed to the hacktivist group NoName057(16), which promotes pro-Russian and anti-Western narratives.
bleeping-computer ยท1mo ago