Skip to main content
← Threat Intel

Threat Actor

Sandworm

8 tracked articles · Wikipedia profile

  • HIGH 5
  • MEDIUM 2
  • INFO 1
INFO
Threat Intel

Leaked Russian Cyber-Ops Training Exposes Institutional Pathways

Leaked materials reveal Russia's institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.

Runtime Rebel Intel
3 min read · Sep 1, 2026
Sandworm UAC-0145 Uses Fake Job Interviews for Arbitrary Command Execution
MEDIUM
Threat Intel

Sandworm UAC-0145 Uses Fake Job Interviews for Arbitrary Command Execution

CERT-UA warns of Sandworm-linked UAC-0145 targeting IT workers with fake job interviews, deploying a modified WireGuard client that executes arbitrary commands.

Runtime Rebel Intel
5 min read · Aug 16, 2026
MEDIUM
Threat Intel

Sandworm Targets IT Pros With Trojanized WireGuard VPN Client

Russian threat group Sandworm targets IT professionals using fake job interviews and trojanized WireGuard VPN clients to deliver malware.

Runtime Rebel Intel
3 min read · Aug 12, 2026
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
HIGH
Threat Intel

UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware

Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.

Runtime Rebel Intel
4 min read · Jul 19, 2026
HIGH
Threat Intel

Russian APTs Target Critical Infrastructure via Edge Device Exploits

US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.

Runtime Rebel Intel
3 min read · Jul 13, 2026
HIGH
Threat Intel

Russia's Evolving Influence Ecosystem: Global Pivot & AI Integration

Russia's influence ecosystem pivots from Ukraine-centric operations to global targets, leveraging generative AI and hybrid cyber-IO tactics.

Runtime Rebel Intel
5 min read · Jun 29, 2026
CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
HIGH
Threat Intel

CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw

Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.

Runtime Rebel Intel
3 min read · Jun 9, 2026
Geopolitical Exploitation of Compromised IP Cameras
HIGH
Threat Intel

Geopolitical Exploitation of Compromised IP Cameras

Nation-states including Russia and Iran are weaponizing compromised IP cameras for battlefield intelligence and critical infrastructure surveillance.

Runtime Rebel Intel
3 min read · Mar 27, 2026