Russian GRU-linked Sandworm has targeted Ukrainian organizations through multiple intrusion paths, including exploitation of vulnerable Exim Mail Transfer Agent servers and malware-laced Microsoft KMS activation tools. NSA reporting tied GRU operators to active exploitation of Exim for initial access, while newer reporting said Sandworm used trojanized software installers in cyber-espionage campaigns aimed at Ukrainian users, expanding the group’s access beyond perimeter-facing mail infrastructure.
Researchers and media reports said the activity affected about 20 critical organizations in Ukraine, underscoring Sandworm’s continued focus on high-value government and infrastructure targets. The combined reporting shows a sustained campaign that blends server-side exploitation with social engineering and malicious software distribution to establish footholds, steal information, and support disruptive operations associated with the Russian military intelligence apparatus.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Reporting published on April 22, 2024 said Russian Sandworm hackers had targeted 20 critical organizations in Ukraine. The disclosure marked an escalation in publicly known scope by identifying the number of affected critical-sector organizations.
EclecticIQ reported that Sandworm targeted Ukrainian users in cyber-espionage campaigns using trojanized Microsoft KMS activation tools. The activity was attributed to the Russian state-backed group and described as part of ongoing operations against Ukraine.
The U.S. National Security Agency disclosed that Russian GRU cyber actors were actively exploiting a critical Exim Mail Transfer Agent vulnerability. The notice publicly tied the exploitation activity to Russian military intelligence operators and warned organizations to patch affected systems.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceblog.eclecticiq.com
Open sourceweb.archive.org
Open sourcensa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.