#BadPilöt
Sandworm booked your substation—BadPilot stole creds, CaddyWiper on pyros. Patch or plan candlelit IR. ⚡🕯️

Read → blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #SCADA
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
September 2, 2025 at 9:06 PM
BadPilot: Inside Seashell Blizzard’s (AKA Sandworm) Global Cyber Espionage Campaign

In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by security researchers Anna Seitz and Megan Stalling to unpack new intelligence on the BadPilot Campaign, a…
BadPilot: Inside Seashell Blizzard’s (AKA Sandworm) Global Cyber Espionage Campaign
In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by security researchers Anna Seitz and Megan Stalling to unpack new intelligence on the BadPilot Campaign, a sophisticated operation by a subgroup of Seashell Blizzard—also known as APT-44, Iridium, or Sandworm.   The team explores how this subgroup, active since 2021, uses opportunistic access, remote management tools, and Tor based ShadowLink infrastructure to maintain covert control of compromised systems.
thecyberwire.com
August 29, 2025 at 7:06 PM
UK sanctions Sandworm; they schedule a blackout on your SCADA. BadPilot nabbed creds, CaddyWiper packs fireworks. Keep lights on? Grab the 2-min playbook—maybe subscribe.

Read more & maybe subscribe: blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #Sandworm
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
August 17, 2025 at 3:28 PM
Sandworm booked your substation for its summer tour—BadPilot stole the creds, CaddyWiper’s on pyrotechnics. Candlelight dinner or patch party?

Read more, maybe subscribe: blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #SCADA
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
July 29, 2025 at 9:06 PM
GRU’s Sandworm penciled your SCADA in for next week’s Blackout Friday—fresh off last night’s Ukraine rerun. BadPilot dropped the zero-days, CaddyWiper’s packing confetti. Still want lights? 👀⚡

Read more & maybe subscribe: blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #SCADA
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
July 23, 2025 at 9:16 PM
GRU’s #Sandworm booked your substation for a surprise fireworks show—BadPilot already handed them your creds. Enjoy candles, or snag our 2-min survival guide before the fuse burns.

Read more, maybe subscribe.
blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #InfoSec
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
July 18, 2025 at 1:06 PM
🪱😈 Hey SOC boss—Sandworm just slid 🧼-free into your OT logs. Ghost the creep or shop for generators? 90-sec survival guide 👉 blog.alphahunt.io/sandworms-ev...

#AlphaHunt #CyberSecurity #ZeroDay
Sandworm’s Evolving Playbook: Destructive Malware, BadPilot Subgroup, and the Escalating Threat to Global Critical Infrastructure
Sandworm, a Russian GRU-affiliated cyber threat group (Unit 74455), continues to escalate its offensive cyber operations, with a primary focus on Ukraine and Western allies. The group is notorious…
blog.alphahunt.io
July 4, 2025 at 1:06 PM
Notícia da BleepingComputer

"Campanha de hacking da rede BadPilot alimenta ataques SandWorm russos" #bolhasec
BadPilot network hacking campaign fuels Russian SandWorm attacks
A subgroup of the Russian state-sponsored hacking group APT44, also known as 'Seashell Blizzard' and 'Sandworm', has been targeting critical organizations and governments in a multi-year campaign dubb...
www.bleepingcomputer.com
April 6, 2025 at 11:30 PM
The russian-backed Seashell Blizzard aka #APT44 or #Sandworm is behind a stealthy “BadPilot” campaign focused on gaining persistent network access. Detect adversary activity targeting critical sectors with #Sigma rules from SOC Prime Platform.
buff.ly/2RQye7O
Seashell Blizzard Attack Detection: A Long-Running Cyber-Espionage “BadPilot” Campaign by russian-linked Hacking Group  - SOC Prime
Detect Seashell Blizzard also known as APT44 BadPilot campaign focused on stealthy initial infiltration with Sigma rules from SOC Prime Platform.
buff.ly
April 4, 2025 at 12:51 PM
Seashell Blizzard Attack Detection: A Long-Running Cyber-Espionage “BadPilot” Campaign by russian-linked Hacking Group 

A nefarious russia’s APT group Seashell Blizzard also known as APT44 has been waging global cyber campaigns since at least 2009. Defenders recently spotted a new long-lasting…
Seashell Blizzard Attack Detection: A Long-Running Cyber-Espionage “BadPilot” Campaign by russian-linked Hacking Group 
A nefarious russia’s APT group Seashell Blizzard also known as APT44 has been waging global cyber campaigns since at least 2009. Defenders recently spotted a new long-lasting access campaign called “BadPilot,” reinforcing the group’s focus on stealthy initial infiltration and leveraging a set of advanced detection evasion techniques. Detect Seashell Blizzard Attacks For more than a decade, the russia-backed Seashell Blizzard APT group – also tracked as UAC-0145, APT44 or Sandworm – has persistently targeted Ukraine, focusing on critical sectors. Since the full-scale invasion, this GRU-linked military cyber-espionage unit has escalated its activity, using Ukraine as a testing ground to refine its malicious TTPs before expanding its offensive campaigns to global targets.
buzzleaktv.com
April 4, 2025 at 12:34 PM
April 3, 2025 at 4:14 AM
April 2, 2025 at 8:54 PM
Russia, along with China, are notorious for cyber warfare, but hey let’s ignore that:
Remember when Trump proposed joint cyber unit with Russia?

www.wired.com/story/russia...
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
March 3, 2025 at 3:10 PM
A subgroup of Russia’s Sandworm hacking group has been targeting critical U.S. and European sectors, including energy, telecom, and defense, to aid Russia’s military. Microsoft warns the campaign, active since 2021, exploits software vulnerabilities to gain access, posing global cybersecurity risks.
Subgroup of Russia’s Sandworm compromising US and European organizations, Microsoft says
The BadPilot hackers have expanded their focus beyond Ukraine and Eastern Europe, gaining initial access to dozens of strategically important organizations across the U.S. and U.K.
therecord.media
March 2, 2025 at 1:21 AM
No The Guardian de hj, gov Trump não vê a Rússia como ameaça cibernética. No Wired do dia 12/02, Microsoft vê ameaça a países como EUA, UK, Canadá e Austrália por hackers ligados a Putin

1 archive.ph/WWTLB
2 archive.ph/m333D
February 28, 2025 at 11:02 PM
www.wired.com/story/russia...
In 2022, it set its sights almost entirely on Ukraine, then broadened its hacking in 2023 to networks worldwide, and then shifted again in 2024 to home in on victims in the US, the UK, Canada and Australia.
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks
A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia.
www.wired.com
February 27, 2025 at 10:42 AM
⚠️ CERT-UA reported attacks by the UAC-0173 criminal group (#BadPilot) against Ukrainian notaries, spreading the #DCRat trojan via #phishing emails (guess: disguised as Ministry of Justice communications!).

⚠️
February 27, 2025 at 7:45 AM
Microsoft Uncovers ‘BadPilot’ Campaign as Seashell Blizzard Targets US and UK
Microsoft Uncovers ‘BadPilot’ Campaign as Seashell Blizzard Targets US and UK
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
buff.ly
February 25, 2025 at 6:42 PM
BadPilot network hacking campaign fuels Russian SandWorm attacks
BadPilot network hacking campaign fuels Russian SandWorm attacks
A subgroup of the Russian state-sponsored hacking group APT44, also known as 'Seashell Blizzard' and 'Sandworm', has been targeting critical organizations and governments in a multi-year campaign…
buff.ly
February 24, 2025 at 6:42 PM
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries https://buff.ly/3EwGjNp
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries
Sandworm’s BadPilot campaign exploits eight security flaws to infiltrate global critical sectors, enabling persistent access for cyber espionage opera
buff.ly
February 22, 2025 at 7:42 AM