/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

US links Sandworm hacking group to Russian agency GRU's Main Center for Special Technology, blaming it for cyberattacks that hit neighboring Georgia in October

Andy Greenberg / Wired :

Wired Andy Greenberg

Context & Ripple Effects

This February 2020 attribution was the moment the US stopped treating Sandworm as an anonymous cluster and named its patron: the GRU's Main Center for Special Technology, with the October cyberattacks on neighboring Georgia pinned to Russian military intelligence. At the time, Sandworm's most notorious confirmed work was sabotage of Ukraine's power grid.

The naming held up as the anchor for everything that followed in the corpus: France later tied Sandworm to a three-year breach campaign against entities running Centreon monitoring software, sources identified Evgenii Serebriakov as the unit's leader, Mandiant connected a third successful strike on Ukraine's grid to the group, and Mandiant eventually traced the hacktivist-front Cyber Army of Russia back to Sandworm itself.

First-order effects

  • Sandworm loses its deniability: US officials publicly bind the group to a named GRU unit, so every future intrusion by its tooling now lands on Moscow's military intelligence ledger rather than on an unnamed threat actor.

Second-order effects

  • Allied governments adopt the template — France's subsequent Centreon breach attribution and Mandiant's corporate attributions show that once one government names the unit, vendors and allies build their own disclosures on top of it.

Third-order effects

  • Public attribution becomes standing policy rather than a one-off: by 2024 the US and allies were unmasking a second GRU unit outright, revealing that Cadet Blizzard belongs to Unit 29155, extending the practice from hacking groups to coup-and-assassination operations.

The trend: State hacking groups are being progressively de-anonymized through a repeatable cycle of government attribution followed by vendor corroboration, turning threat-actor names into diplomatic instruments.

Discussion

  • @rbreich Robert Reich on x
    Your reminder that Mitch McConnell blocked multiple efforts to ensure this didn't happen again. His spineless political posturing places Trump above country, even as foreign governments openly subvert our democracy. He's just as dangerous as Trump. https://twitter.com/...
  • @russ_warrior Enrico Ivanov on x
    In last few days: _ Ukrainian forces conducted an offensive along the demarcation line with LNR (Donbass), Russia blamed. _ Turkish military escalation against Syria, Russia blamed. _ Cyberattack against Georgia, Russia blamed. #US regime's fingerprints in all of this.
  • @aceurasia @aceurasia on x
    🇬🇪🇷🇺 “Russia may be using Georgia as a test lab for new innovations in cyberwar, from election hacking to power grid attacks to data-destroying malware.” @a_greenberg https://www.wired.com/...
  • @caitlin__kelly Caitlin Kelly on x
    New from ⁦@a_greenberg⁩: State Dept officials blame Russia's GRU for cyberattacks in Georgia https://www.wired.com/...