Skip to content
Auto-CTI
Back to all actors

Sandworm

Nation-state Sabotage Russia Active

Aliases: Voodoo Bear · Seashell Blizzard · APT44 · Telebots · Iridium

Also seen as: SANDWORM

Mentions
2
First seen
21 Jul 2026
Last seen
14 Sept 2026

Relevant to you · Relevant

Threat focus:
supply chainespionage / apt

Origin

Russia — Russian military intelligence (GRU Unit 74455)

Profile

Sandworm is a Russian threat actor that recently exploited Cisco vulnerabilities to deploy the Cyclops Blink malware. The actor is also associated with the detection of SANDWORM_MODE and emerging AI toolchain supply chain attacks. These activities indicate sophisticated attacks targeting network infrastructure and software supply chains.

Affected vendors

Cisco

Targeted sectors

TechnologyAI DevelopmentNetworkingSoftware Development

Associated malware / tools

SANDWORM_MODECyclops Blink

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC