Adversary Intelligence — 2026-05-14

Sandworm Shifts From IT Breaches to Targeting Critical OT Infrastructure

Nozomi Networks reported that Russia GRU-linked Sandworm group has shifted tactics from IT network breaches to directly targeting operational technology including HMIs, PLCs, and engineering workstations across manufacturing and transportation sectors. Analysis of 5.5 million alerts from 10 industrial organizations across seven countries identified 29 confirmed Sandworm events between July 2025 and January 2026.

1 sources
  1. Sandworm uses pre-compromised OT environments instead of zero-days to escalate OT, ICS attacks after detection - Industrial Cyber

View in full brief →

UNCLASSIFIED // OPEN SOURCE