Activity timeline
APT44 appears in 9 tracked threats between and ; the busiest month was 2026-02 with 3 reports.
ATT&CK techniques observed
- T1059 Command and Scripting Interpreter — Executionobserved in 5 of 9 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 5 of 9 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 4 of 9 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 4 of 9 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 9 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 9 tracked threats
- T1485 Data Destruction — Impactobserved in 4 of 9 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 9 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 3 of 9 tracked threats
- T1059.001 PowerShell — Executionobserved in 3 of 9 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 9 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 9 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 9 tracked threats
- T1090 Proxy — Command and Controlobserved in 3 of 9 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 9 tracked threats
Tracked threats
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes PoultryHIGH
- Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver Trojanized WireGuard VPN Client (SopraVPN)HIGH
- UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign impersonating Sopra Steria BulgariaHIGH
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilitiesCRITICAL
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
- UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against UkraineHIGH
- Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC ExploitationCRITICAL
- State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)HIGH
- Default ICS Credentials Exploited in Destructive Attack on Polish Energy FacilitiesCRITICAL