Adversary Intelligence — 2026-05-14

Sandworm Shifts Tactics to Target Pre-Compromised OT Environments After Detection

BLUFSandworm's parasitic targeting of pre-compromised OT networks shifts the burden to defenders, and while a destructive ICS attack outside Ukraine is unlikely within roughly 12 months, confirmed footholds across seven NATO-adjacent countries demand immediate remediation.

Nozomi Networks analyzed 5.5 million alerts from 10 industrial organizations across seven countries between July 2025 and January 2026, confirming 29 Sandworm intrusion events and finding the group exploited already-compromised networks via legacy tooling, including EternalBlue, WannaCry, Cobalt Strike, and Log4Shell, rather than zero-day exploits. Every infected system had produced high-confidence warning alerts for between 20 and 155 days before Sandworm activity began, averaging 43 days. Across the dataset, 17 infected machines targeted 923 unique internal systems, with one host probing 405 machines individually. In each affected environment, Sandworm escalated after detection, expanding tooling and shifting focus toward engineering workstations, HMIs, PLCs, and RTUs rather than withdrawing.

Analysis
Sandworm's operational model is parasitic rather than pioneering, per Nozomi Networks' single-source telemetry. The group exploited already-compromised OT networks using legacy tooling, with every infected host having generated high-confidence alerts an average of 43 days before intrusion activity, shifting culpability squarely to defender inaction. Post-detection behavior inverts standard incident response assumptions: the group escalated across multiple dimensions, pivoting toward engineering workstations, HMIs, PLCs, and RTUs rather than withdrawing. The escalation pattern may instead reflect automated kill-chain progression rather than deliberate operator-directed decisions. A destructive ICS attack outside Ukraine is unlikely within approximately 12 months, but active footholds confirmed across seven countries make the remediation question immediate for NATO OT-ICS defenders.
2 sources
  1. Sandworm uses pre-compromised OT environments instead of zero-days to escalate OT, ICS attacks after detection - Industrial Cyber
  2. Sandworm Activity in Industrial Environments: What the Data Reveals - Nozomi Networks

View in full brief →

UNCLASSIFIED // OPEN SOURCE