Hunter Strategy
  • Trending Topics
  • Threat Intelligence
  • Contact Us
  • Hunter Website
Sign in Subscribe

Sandworm

Sandworm (APT44) is a Russian GRU-linked cyber sabotage unit (Unit 74455) responsible for NotPetya, the Ukrainian power grid attacks, and Olympic Destroyer. Also tracked as Voodoo Bear, Seashell Blizzard, Iron Viking, and FROZENBARENTS.

Defense Industrial Base Targeting and External Threat Exposure
Threat Intelligence

Defense Industrial Base Targeting and External Threat Exposure

Adversaries linked to Russia, China, Iran, and North Korea are targeting the defense industrial base through recruitment scams, secure-messaging takeovers, and end-of-support edge devices to gain long-dwell access to controlled technical data.
Read more
William Elchert and Antonio Rivera
GRU Tradecraft and Network Edge Access
Threat Intelligence

GRU Tradecraft and Network Edge Access

A GRU-aligned team is abusing misconfigured, cloud-hosted network edge devices as passive listening posts, harvesting and replaying credentials into Western energy, logistics, and telecom networks without deploying any malware.
Read more
William Elchert and Antonio Rivera
Trending Topics
Sandworm

Trending Topics

Sandworm (APT44) exploits misconfigured network edge devices to target Western critical infrastructure. AI accelerates ransomware operations without changing core tactics. SantaStealer emerges as a new stealer-as-a-service threat.
Read more
William Elchert and Antonio Rivera
Monthly Wrap - February 2025
State Sponsored

Monthly Wrap - February 2025

February 2025 wrap: Vo1d botnet compromises 1.5M Android TVs. Lazarus Group and Mustang Panda continue espionage campaigns. Sandworm (APT44) targets Ukraine via fake Windows activators. LockBit and Cl0p exploit zero-days.
Read more
William Elchert and Antonio Rivera
Hunter Strategy © 2026
Powered by Ghost