#BadPilöt
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 12, 2025 at 5:11 PM
Microsoft alerte sur BadPilot, une sous-unité du groupe de cyberespionnage russe Sandworm, connue pour ses attaques contre l’Ukraine. Désormais, cette équipe s’attaque aussi aux infrastructures des États-Unis, du Royaume-Uni, du Canada et de l’Australie. www.wired.com/story/russia...
February 12, 2025 at 11:14 PM
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks

www.wired.com/story/russia...
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 15, 2025 at 10:40 AM
Microsoft finds a team within Sandworm has been carrying out widespread initial access operations on behalf of the GRU group and focused on US, UK, Canada and Australia networks over 2024, exploiting Connectwise ScreenConnect and Fortinet FortiClient EMS. www.wired.com/story/russia...
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 12, 2025 at 5:07 PM
Microsoft Warns About BadPilot, a Unit of Russian State-Sponsored Group Sandworm
Microsoft Warns About BadPilot, a Unit of Russian State-Sponsored Group Sandworm - INCYBER NEWS
This entity has infiltrated critical organizations in about 50 countries, including Ukraine, the United States, and the United Kingdom.
incyber.org
February 17, 2025 at 4:04 PM
🚨 Russian GRU-linked hackers are exploiting known software flaws to breach critical networks worldwide, targeting the US and UK, Microsoft warns of "BadPilot" campaign.

Read: hackread.com/microsoft-ba...

#CyberSecurity #Microsoft #Russia #Ukraine #BadPilot
Microsoft Uncovers ‘BadPilot’ Campaign as Seashell Blizzard Targets US and UK
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 13, 2025 at 9:36 PM
Microsoft details BadPilot, an "initial access" team within the Russian hacking group Sandworm that targeted the US, the UK, Canada, and Australia in 2024 (Andy Greenberg/Wired)

Main Link | Techmeme Permalink
February 12, 2025 at 7:06 PM
Microsoft Threat Intelligence's latest research uncovers a multiyear global operation by a subgroup within the Russian state actor tracked as Seashell Blizzard. Learn more about the advanced techniques and global reach of this threat.
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
aka.ms
February 13, 2025 at 6:40 PM
⚠️ CERT-UA reported attacks by the UAC-0173 criminal group (#BadPilot) against Ukrainian notaries, spreading the #DCRat trojan via #phishing emails (guess: disguised as Ministry of Justice communications!).

⚠️
February 27, 2025 at 7:45 AM
We have also seen a range of Russia-aligned threat actors attempting to steal Signal database files from compromised Android or Windows systems. Multiple actors in play here, including APT44’s BadPilot subgroup, Turla, and Belarus-linked UNC1151.

www.microsoft.com/en-us/securi...
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
www.microsoft.com
February 19, 2025 at 11:05 AM
future TAs:

HackGPT
Clawed
DeepShit
Llamatakeyourmoney
BadPilot+ with Bing
February 13, 2025 at 12:12 PM
The russian-backed Seashell Blizzard aka #APT44 or #Sandworm is behind a stealthy “BadPilot” campaign focused on gaining persistent network access. Detect adversary activity targeting critical sectors with #Sigma rules from SOC Prime Platform.
buff.ly/2RQye7O
Seashell Blizzard Attack Detection: A Long-Running Cyber-Espionage “BadPilot” Campaign by russian-linked Hacking Group  - SOC Prime
Detect Seashell Blizzard also known as APT44 BadPilot campaign focused on stealthy initial infiltration with Sigma rules from SOC Prime Platform.
buff.ly
April 4, 2025 at 12:51 PM
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
www.wired.com/story/russia...
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 12, 2025 at 6:47 PM
On the pod, we unpack Microsoft's 'BadPilot' report, the APT naming mess, and the latest on Russia's malicious cyber operations Costin Raiu @jags.bsky.social #ThreeBuddyProblem
www.linkedin.com/feed/update/...
Ryan Naraine on LinkedIn: #threebuddyproblem
On the pod, we unpack Microsoft's 'BadPilot' report, the APT naming mess, and the latest on Russia's malicious cyber operations Costin Raiu #ThreeBuddyProblem
www.linkedin.com
February 18, 2025 at 10:06 PM
Sandworm booked your substation—BadPilot stole creds, CaddyWiper on pyros. Patch or plan candlelit IR. ⚡🕯️

Read → blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #SCADA
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
September 2, 2025 at 9:06 PM
Stellar report by Microsoft on APT44 ops. Worth noting: many of these early stage TTPs are very similar to financially motivated groups’ TTPs pre-handoff for ransomware, etc. This trend has continued since @danwblack.bsky.social & I first pointed it out in 2022. www.microsoft.com/en-us/securi...
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
www.microsoft.com
February 13, 2025 at 6:49 PM
ANALYSIS TIME - The Hacker News' Ravie Lakshmanan Presents:

Microsoft Uncovers Vatnik Military Intelligence (GRU) "Sandworm" Subgroup's Global Cyber Attacks Spanning 15+ Countries (These fuckers have been pissing off the #West since 1996 in "Moonlight Maze" hack)

thehackernews.com/2025/02/micr...
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries
Sandworm’s BadPilot campaign exploits eight security flaws to infiltrate global critical sectors, enabling persistent access for cyber espionage opera
thehackernews.com
February 13, 2025 at 2:42 AM
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 14, 2025 at 9:33 AM
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia. www.wired.com/story/russia...
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 12, 2025 at 11:40 PM
BadPilot Attacking Network Devices To Expand Russian Seashell Blizzard’s Attacks
BadPilot Attacking Network Devices To Expand Russian Seashell Blizzard's Attacks
cybersecuritynews.com
February 13, 2025 at 6:48 AM
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries https://thehackernews.com/2025/02/microsoft-uncovers-sandworm-subgroups.html?m=1 via @thehackersnews@bird.makeup
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries
Sandworm’s BadPilot campaign exploits eight security flaws to infiltrate global critical sectors, enabling persistent access for cyber espionage opera
thehackernews.com
February 13, 2025 at 6:16 AM
February 12, 2025 at 5:29 PM