Nozomi Networks reported that Sandworm—also tracked as APT44, Seashell Blizzard, and Voodoo Bear—moved from compromised IT environments into operational technology networks at 10 industrial organizations across seven countries, targeting systems tied to physical processes. Based on telemetry collected between July 2025 and January 2026, researchers identified 29 Sandworm-linked events involving aggressive lateral movement across hundreds of internal systems and direct interest in engineering workstations, HMIs, and field devices including PLCs, RTUs, and IEDs. The activity aligned with Moscow business hours, often peaking around Wednesday afternoons, reinforcing assessments that the group operates as a centrally managed Russian state sabotage actor tied to GRU Unit 74455.
The report found that Sandworm largely did not rely on novel exploits, instead abusing unresolved prior compromises, older malware, and long-known, patchable tools. Every affected environment had generated high-confidence alerts for weeks or months before the intrusions escalated, with an average warning window of 43 days, and researchers said the group typically intensified operations after detection rather than withdrawing. Nozomi warned that basic controls—including rapid investigation of commodity alerts, remediation of legacy compromises, tighter lateral movement controls, and stronger IT/OT segmentation—remain critical because preventable security gaps are enabling Sandworm to reach industrial control assets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-14, follow-on reporting expanded on Cato’s TencShell findings by detailing the malware’s infection chain and publishing indicators of compromise including command-and-control infrastructure, hashes, and persistence registry keys. The coverage stressed the growing use of repurposed public offensive tools in sophisticated intrusions.
On 2026-05-14, follow-on reporting emphasized Nozomi’s finding that Sandworm pivoted from compromised IT systems into operational technology environments controlling physical infrastructure. The coverage also highlighted the group’s apparent alignment with Moscow office hours and the average 43-day warning window before major activity.
On 2026-05-13, Nozomi Networks published research summarizing Sandworm activity seen from July 2025 through January 2026. The report said the group relied on long-known, patchable tools and unresolved prior compromises, often generated high-confidence alerts weeks in advance, and tended to escalate after detection rather than withdraw.
On 2026-05-13, Cato Networks disclosed the attempted April intrusion and documented TencShell as a previously unknown malware framework customized to mimic Tencent-like API traffic. The company assessed the activity as suspected China-linked, while noting the evidence was not sufficient for definitive attribution.
During the April 2026 incident, Cato CTRL blocked the intrusion before the attacker could establish persistent remote control. Analysis showed TencShell supported capabilities such as remote command execution, screen interaction, SOCKS5 proxying, in-memory payload execution, browser artifact access, UAC bypass, and registry-based persistence.
In April 2026, a global manufacturing company’s India site was targeted in an intrusion tied to a third-party user with legitimate access. The attack used a multi-stage chain that delivered the previously undocumented TencShell implant, a customized variant of the open-source Rshell framework.
Between July 2025 and January 2026, Nozomi Networks observed 29 events linked to Sandworm across 10 industrial customers in seven countries. The activity involved lateral movement from IT networks toward OT and ICS assets including engineering workstations, HMIs, PLCs, RTUs, and IEDs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecatonetworks.com
Open sourcenozominetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.