Tag

#Sandworm

10 stories taggedSandworm.

A computer server room with glowing neural network visualizations on displays, an open access panel revealing circuitry, and a shadowy figure's hand reaching to
Threat Intelligence

Spies and Criminals Are Stealing AI Systems, Not Just Data

Google's threat research team says nation-state hackers and extortion gangs are now going after the AI models, cloud accounts, and secret access keys that companies use to run artificial intelligence, turning those stolen assets into weapons for their own attacks.

4 min read
A laptop screen showing a professional job offer email with subtle malware indicators hidden in the interface, dimly lit against a shadowy background suggesting
Threat Intelligence

Fake Job Offers From Russian Hackers Target Ukrainian IT Staff

Ukraine's cyber emergency team says a Sandworm subgroup is posing as recruiters to slip remote-control malware onto engineers' laptops.

3 min read
A district heating plant's control room with large industrial gauges showing pressure and temperature readings, technicians monitoring SCADA screens showing the
Threat Intelligence

Russian Hackers Used an Obscure Telecom Back Door to Shut Down a Polish Heating Plant

A second cyberattack on Poland's energy sector, running alongside a previously disclosed assault, exploited a rarely scrutinised type of private mobile network to reach deep inside a plant supplying heat to 50,000 people.

4 min read
Threat analyst working at a desk surrounded by printouts and digital screens displaying color-coded threat group designations with two-word labels replacing num
Threat Intelligence

Google Gives Hackers New Names, Here Is Why That Matters

Google's threat-intelligence team is replacing number codes with memorable two-word labels for every hacking group it tracks, making it easier for researchers and companies to talk about the same criminals.

3 min read
A Notepad++ plugin repository page displaying a fake plugin installer file, with code snippets visible in the background showing the LunchPoke loader obfuscated
Threat Intelligence

Ukraine warns of hackers hiding malware inside a fake Notepad++ plugin

CERT-UA links the campaign to UAC-0099, a group previously tied to Russia's Sandworm, which is using a genuine copy of Notepad++ to smuggle in a loader called LunchPoke.

4 min read
Illustration: a laptop screen in a dim office, showing a generic fake verification prompt with a highlighted keyboard
Threat Intelligence

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs

Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

3 min read
Illustration for the story: Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Vulnerabilities

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems

Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.

3 min read
Illustration: a dimly lit modern open-plan office at night, rows of dark computer screens glowing faintly blue, empty chairs
Threat Intelligence

Your Business Is Already a Wartime Target. Here Is What to Do About It.

Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

3 min read
Illustration: A dim control room at a water treatment facility at night
Threat Intelligence

Spanish police arrest suspected helper of pro-Russian hacking crews

The man in Palencia allegedly helped a Ukrainian hacker flee toward Russia and supported groups linked to attacks on U.S. water and energy sites.

3 min read
Illustration: a large municipal water treatment facility at dusk, circular sedimentation tanks reflecting fading orange sky
Threat Intelligence

Iran, Russia, and China Have Been Quietly Attacking Water Systems — and the Door Was Usually Left Unlocked

A new threat-intelligence report finds three governments targeting water and wastewater infrastructure, not primarily to poison anyone, but to cause fear, probe weaknesses, and pre-position for future conflict. The tools they're using are embarrassingly basic.

3 min read
© 2026 Threat Vectr