Security News > 2024 > April > Russian Sandworm hackers pose as hacktivists in water utility breaches

Russian Sandworm hackers pose as hacktivists in water utility breaches
2024-04-17 17:08

The Sandworm hacking group associated with Russian military intelligence has been hiding attacks and operations behind multiple online personas posing as hacktivist groups.

Sandworm - a.k.a. BlackEnergy, Seashell Blizzard, Voodoo Bear, has been active since at least 2009, with multiple governments attributing its operations to Unit 74455, the Main Centre for Special Technologies within the Main Directorate of the General Staff of the Armed Forces of the Russian Federation, better known as the Main Intelligence Directorate.

The group targets journalists and organizations like Bellingcat that investigate Russian government activities using phishing messages.

APT44's activities remain concentrated on Ukraine, with ongoing operations to disrupt and collect intelligence, supporting Russian military and political goals in the region.

Russian hackers target German political parties with WineLoader malware.

US offers $10 million reward for tips on Russian Sandworm hackers.


News URL

https://www.bleepingcomputer.com/news/security/russian-sandworm-hackers-pose-as-hacktivists-in-water-utility-breaches/