Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm
Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.
The link matters because the group’s claims extend the Sandworm record from established espionage and disruptive operations into publicly signaled pressure against utilities in France, the US, and Poland. A third reported attack on Ukraine’s electric utility had already underscored the group’s focus on critical infrastructure.
First-order effects
Utility operators and national cyber defenders in the named countries gain a more consequential attribution context for Cyber Army of Russia’s claims, rather than treating them solely as independent hacktivism.
Sandworm’s apparent association with a public-facing proxy complicates incident triage: defenders must assess both the claimed activity and whether it could support a more capable Russia-linked operation.
Second-order effects
Critical-infrastructure security teams are likely to place greater weight on intelligence sharing and cross-sector monitoring for indicators associated with both Cyber Army of Russia and Sandworm.
The finding raises the operational value of coordinated defense among utilities and government responders, since proxy-style activity can create noise, publicity, and potential cover around more targeted campaigns.
Third-order effects
If state-linked groups increasingly operate through nominal hacktivist identities, cyber attribution will hinge less on public claims and more on technical and behavioral evidence, increasing the importance of ecosystem-level defense.
The pattern points toward a more blended model of cyber coercion around critical infrastructure: deniable public pressure alongside established state-linked capabilities, though a reported linkage alone does not establish control over every claimed incident.
The trend: State-linked cyber operations are increasingly blending recognizable espionage and disruption capabilities with hacktivist-style branding to pressure critical infrastructure while preserving ambiguity.
Russian cyber group infiltrated the systems of a hydroelectric dam in France and water utilities in the United States and Poland. Claims to tamper with industrial control settings. Sabotage attempt? — The aimed political effect of these cyber operators is evident. …
Even if these are legit hacktivists acting independently under the CARR umbrella, they have latched on to a hacktivist group that Sandworm/APT44 substantially contributed to, or even created. Further, they are a stone's throw from the Kremlin's most aggressive capability. 3/x
The Russian cyberattacks on US water, Polish water, and a French dam are complicated. We had established that CARR was being used as a front for Sandworm/APT44 (Russian GRU) prior to the incidents and that they were even involved in creating some of CARR's online presence. 1/x
Most importantly, we shouldn't stand for attacks on water and dams from foreign attackers. These incidents weren't terribly impactful, but they did demonstrate a vulnerability that we must address. US water is now being attacked on three fronts (China, Iran, and Russia). 4/x
But without evidence of their involvement we had to allow for the possibility of other CARR affiliates acting outside of the direction of Sandworm/APT44. In that case what does Sandworm/APT44 have to do with it? 2/x
The Russian GRU-linked hacker team Sandworm has become so aggressive and impactful that @Mandiant is formally upgrading it to an Advanced Persistent Threat: APT44. https://cloud.google.com/... It presents “a significant proliferation risk for new cyber attack concepts and methods…
It's been a while since our last post announcing a graduation - but it's been a long time coming! I've dropped a couple hints throughout the period the team worked on this an couldn't be more proud to introduct... #APT44 https://cloud.google.com/...
APT44 is an aggressive threat group sponsored by Russian Military Intelligence (GRU) Unit 74455. APT44 sits under the VIO, the Information Operation Troops. This is key: APT44 is a full-spectrum threat actor w/ operations driven by information confrontation objectives. [image]
Today, @Mandiant / @Google is opening up a Can o' Sandworms. I'm incredibly proud to have led the year+ long effort with a brilliant group of colleagues to graduate Sandworm into APT44. https://cloud.google.com/...
Time to get really serious about #CyberCivilDefense #cybersecurity “Hackers Linked to Russia's Military Claim Credit for Sabotaging US Water Utilities”
New —> A hacking incident in January caused a water tank in a small Texas town to overflow. A GRU-backed Telegram channel took responsibility (per Mandiant). I interviewed officials in multiple towns in north Texas on how they responded: https://www.cnn.com/...
Also known commonly as the GRU's Main Centre for Special Technologies (GTsST) or Unit 74455 - APT44 has been at it for the better part of 15 years. Publicly available images of its anniversary insignia place the unit's formation in 2009. [image]
Google's new report on APT 44 includes the fake USAID phishing campaign we were targeted in December. Thanks to our security training the staff member who received it was immediately able to refer it to our security team, so never underestimate the value of good security... [imag…
Super excited to share that as part of a multi-year long effort with contributions from across @Mandiant and @Google as well as our partners in Ukraine and industry, we are graduating Sandworm into APT44 https://cloud.google.com/...
Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm | Given the active and diffuse nature of the threat posed by Sandworm globally, @Mandiant has decided to graduate the group into a named Advanced Persistent Threat: APT44. https://cloud.google.com/...
Over a decade in the making: Sandworm is now APT44. Below is a thread with some major takeaways and insights from our new report: https://cloud.google.com/...
Interesting new Mandiant report. Shows that GRU-linked hackers may have messed with control systems at water utilities in the US & Poland (17-18 Jan), and credibly claimed (2 Mar) to have interfered with a dam in France. This is not normal. https://services.google.com/ ... [image…