Russian state-backed hacking group Sandworm has intensified its use of data-wiping malware in Ukraine, specifically targeting the country's grain sector, government, education, energy, and logistics organizations. According to ESET's APT Activity Report, Sandworm deployed destructive malware such as ZEROLOT and Sting in attacks during June and September 2025, aiming to disrupt Ukraine's vital economic infrastructure. These operations are part of a broader pattern of Russian cyber aggression, with Sandworm's campaigns standing out for their focus on sabotaging Ukraine's wartime economy by striking at its main revenue source—grain exports.
The attacks leveraged multiple data-wiping malware families, which are designed to irreversibly destroy digital information by corrupting files, disk partitions, and master boot records. Unlike ransomware, these wipers serve purely as tools of sabotage, not extortion. The targeting of the grain sector marks a notable escalation, as previous wiper campaigns primarily focused on government and critical infrastructure. ESET's findings highlight the ongoing evolution and increasing sophistication of Russian APT activity, with Sandworm's destructive operations representing a significant threat to Ukraine's economic stability during the ongoing conflict.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ESET released an APT Activity Report summarizing state-aligned cyber operations observed from April through September 2025. The report highlighted increased activity by Russia-, China-, Iran-, and North Korea-linked groups, including Sandworm’s wiper attacks on Ukraine’s grain sector.
During the 2025 campaign, UAC-0099 was assessed to have helped provide initial access for Sandworm operations. Reporting also noted the group evolved its phishing and malware delivery methods, including use of MatchBoil and DragStare.
Between June and September 2025, the Russia-linked Sandworm group carried out a series of destructive attacks using the Zerolot and Sting wipers against Ukrainian grain, energy, logistics, and government organizations. The campaign was aimed at disrupting critical infrastructure and weakening Ukraine’s wartime economy.
ESET identified an early 2025 Sandworm attack using the Zerolot wiper against a Ukrainian university, marking the start of a renewed destructive campaign. This activity preceded broader attacks on other sectors of Ukraine’s economy.
In the April-September 2025 reporting period, the Russia-linked RomCom group used a WinRAR zero-day in campaigns targeting organizations in the EU and Canada connected to Ukraine’s defense and logistics efforts. The activity reflected Russia’s broader focus on Ukraine and its supporters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.