/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

Wired Andy Greenberg

Context & Ripple Effects

Mandiant’s attribution connects a purported hacktivist brand to Sandworm, a Russia-linked operation previously tied to breaches of French organizations using Centreon and to attacks on Ukraine’s electric utility network.

The link matters because the group’s claims extend the Sandworm record from established espionage and disruptive operations into publicly signaled pressure against utilities in France, the US, and Poland. A third reported attack on Ukraine’s electric utility had already underscored the group’s focus on critical infrastructure.

First-order effects

  • Utility operators and national cyber defenders in the named countries gain a more consequential attribution context for Cyber Army of Russia’s claims, rather than treating them solely as independent hacktivism.
  • Sandworm’s apparent association with a public-facing proxy complicates incident triage: defenders must assess both the claimed activity and whether it could support a more capable Russia-linked operation.

Second-order effects

  • Critical-infrastructure security teams are likely to place greater weight on intelligence sharing and cross-sector monitoring for indicators associated with both Cyber Army of Russia and Sandworm.
  • The finding raises the operational value of coordinated defense among utilities and government responders, since proxy-style activity can create noise, publicity, and potential cover around more targeted campaigns.

Third-order effects

  • If state-linked groups increasingly operate through nominal hacktivist identities, cyber attribution will hinge less on public claims and more on technical and behavioral evidence, increasing the importance of ecosystem-level defense.
  • The pattern points toward a more blended model of cyber coercion around critical infrastructure: deniable public pressure alongside established state-linked capabilities, though a reported linkage alone does not establish control over every claimed incident.

The trend: State-linked cyber operations are increasingly blending recognizable espionage and disruption capabilities with hacktivist-style branding to pressure critical infrastructure while preserving ambiguity.

Discussion

  • @LukaszOlejnik@mastodon.social Lukasz Olejnik on mastodon
    Russian cyber group infiltrated the systems of a hydroelectric dam in France and water utilities in the United States and Poland.  Claims to tamper with industrial control settings.  Sabotage attempt?  —  The aimed political effect of these cyber operators is evident. …
  • @johnhultquist John Hultquist on x
    Even if these are legit hacktivists acting independently under the CARR umbrella, they have latched on to a hacktivist group that Sandworm/APT44 substantially contributed to, or even created. Further, they are a stone's throw from the Kremlin's most aggressive capability. 3/x
  • @johnhultquist John Hultquist on x
    The Russian cyberattacks on US water, Polish water, and a French dam are complicated. We had established that CARR was being used as a front for Sandworm/APT44 (Russian GRU) prior to the incidents and that they were even involved in creating some of CARR's online presence. 1/x
  • @johnhultquist John Hultquist on x
    Most importantly, we shouldn't stand for attacks on water and dams from foreign attackers. These incidents weren't terribly impactful, but they did demonstrate a vulnerability that we must address. US water is now being attacked on three fronts (China, Iran, and Russia). 4/x
  • @johnhultquist John Hultquist on x
    But without evidence of their involvement we had to allow for the possibility of other CARR affiliates acting outside of the direction of Sandworm/APT44. In that case what does Sandworm/APT44 have to do with it? 2/x
  • @ericgeller Eric Geller on x
    The Russian GRU-linked hacker team Sandworm has become so aggressive and impactful that @Mandiant is formally upgrading it to an Advanced Persistent Threat: APT44. https://cloud.google.com/... It presents “a significant proliferation risk for new cyber attack concepts and methods…
  • @mrdanperez Dan Perez on x
    It's been a while since our last post announcing a graduation - but it's been a long time coming! I've dropped a couple hints throughout the period the team worked on this an couldn't be more proud to introduct... #APT44 https://cloud.google.com/...
  • @sherrod_im Sherrod DeGrippo on x
    Microsoft tracks this group as seashell blizzard, aka IRIDIUM. 🐚
  • @gabby_roncone Gabby Roncone on x
    APT44 is an aggressive threat group sponsored by Russian Military Intelligence (GRU) Unit 74455. APT44 sits under the VIO, the Information Operation Troops. This is key: APT44 is a full-spectrum threat actor w/ operations driven by information confrontation objectives. [image]
  • @gabby_roncone Gabby Roncone on x
    Today, @Mandiant / @Google is opening up a Can o' Sandworms. I'm incredibly proud to have led the year+ long effort with a brilliant group of colleagues to graduate Sandworm into APT44. https://cloud.google.com/...
  • @craignewmark Craig Newmark on x
    Time to get really serious about #CyberCivilDefense #cybersecurity “Hackers Linked to Russia's Military Claim Credit for Sabotaging US Water Utilities”
  • @snlyngaas Sean Lyngaas on x
    New —> A hacking incident in January caused a water tank in a small Texas town to overflow. A GRU-backed Telegram channel took responsibility (per Mandiant). I interviewed officials in multiple towns in north Texas on how they responded: https://www.cnn.com/...
  • @anneapplebaum Anne Applebaum on x
    You may not think you are at war with Russia, but Russia is behaving as if it were at war with you
  • @imposecost Andrew Thompson on x
    This is a long time coming. 🇷🇺APT44: Unearthing Sandworm: https://services.google.com/ ... [image]
  • @danwblack Dan Black on x
    Also known commonly as the GRU's Main Centre for Special Technologies (GTsST) or Unit 74455 - APT44 has been at it for the better part of 15 years. Publicly available images of its anniversary insignia place the unit's formation in 2009. [image]
  • @big_bad_w0lf_ John on x
    Happy APT44 day y'all [video]
  • @eliothiggins Eliot Higgins on x
    Google's new report on APT 44 includes the fake USAID phishing campaign we were targeted in December. Thanks to our security training the staff member who received it was immediately able to refer it to our security team, so never underestimate the value of good security... [imag…
  • @big_bad_w0lf_ John on x
    Super excited to share that as part of a multi-year long effort with contributions from across @Mandiant and @Google as well as our partners in Ukraine and industry, we are graduating Sandworm into APT44 https://cloud.google.com/...
  • @780thc @780thc on x
    Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm | Given the active and diffuse nature of the threat posed by Sandworm globally, @Mandiant has decided to graduate the group into a named Advanced Persistent Threat: APT44. https://cloud.google.com/...
  • @bushidotoken Will on x
    They finally graduated https://cloud.google.com/... [image]
  • @danwblack Dan Black on x
    Over a decade in the making: Sandworm is now APT44. Below is a thread with some major takeaways and insights from our new report: https://cloud.google.com/...
  • @shashj Shashank Joshi on x
    Interesting new Mandiant report. Shows that GRU-linked hackers may have messed with control systems at water utilities in the US & Poland (17-18 Jan), and credibly claimed (2 Mar) to have interfered with a dam in France. This is not normal. https://services.google.com/ ... [image…