Sandworm APT has conducted a targeted cyber espionage campaign against military entities in Belarus and Russia, including the Belarusian military and Russian Airborne Forces. The attackers leveraged malicious .lnk files and multi-stage PowerShell scripts to compromise systems, deploying backdoors that expose local services such as OpenSSH over the Tor network using obfs4 bridges. This infrastructure allows the threat actors to maintain persistent, anonymous access to compromised networks and evade traditional detection mechanisms.
The infection chain often begins with decoy documents, such as nomination letters from military commanders, to lure victims into executing the malicious payloads. Once infected, the malware establishes persistence and configures the system to route sensitive services through Tor, enabling remote access via onion addresses. The campaign demonstrates a sophisticated approach to targeting high-value military personnel and infrastructure, with attribution pointing to the Sandworm APT group, known for its advanced capabilities and focus on Eastern European targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting attributed the activity to the Sandworm APT and described the use of an OpenSSH backdoor tunneled through Tor, including obfs4 for stealth and persistence. The added technical details clarified the campaign's infrastructure and tradecraft against Belarusian military targets.
Researchers disclosed a campaign dubbed Operation SkyCloak targeting military and defense-related entities in Russia and Belarus. The operation used malicious LNK files as an initial infection vector and focused on espionage-oriented access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.