# GlassWorm Operators

> As of 2026-05-30, GlassWorm Operators is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning supply chain, malware. Also known as GlassWorm, GlassWorm v2, OpenVSX Sleeper Crew. ATT&CK coverage spans 56 techniques across 11 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1195 (Supply Chain Compromise).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** SUPPLY_CHAIN, MALWARE
- **Also known as:** GlassWorm, GlassWorm v2, OpenVSX Sleeper Crew
- **As of:** 2026-05-30

## ATT&CK techniques observed

56 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (9), Command and Control (8), Credential Access (8), Discovery (6), Execution (6), Persistence (5).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 3 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 3 tracked threats
- [T1027.013](https://intel.threadlinqs.com/technique/T1027.013) Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 2 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1102.001](https://intel.threadlinqs.com/technique/T1102.001) Dead Drop Resolver — Command and Control — observed in 2 of 3 tracked threats
- [T1102.002](https://intel.threadlinqs.com/technique/T1102.002) Bidirectional Communication — Command and Control — observed in 2 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 3 tracked threats
- [T1176](https://intel.threadlinqs.com/technique/T1176) Software Extensions — Persistence — observed in 2 of 3 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 2 of 3 tracked threats
- [T1199](https://intel.threadlinqs.com/technique/T1199) Trusted Relationship — Initial Access — observed in 2 of 3 tracked threats

## Tracked threats

- [GlassWorm Developer Supply Chain Campaign Takedown — CrowdStrike + Google + Shadowserver Disrupt 4-Channel C2 (Solana / BitTorrent DHT / Google Calendar / VPS)](https://intel.threadlinqs.com/threat/TL-2026-0603) — HIGH
- [GlassWorm v2 — 73 Open VSX Sleeper Extensions Activate Supply Chain Malware Against VS Code, Cursor, Windsurf and VSCodium Developers](https://intel.threadlinqs.com/threat/TL-2026-0421) — CRITICAL
- [GlassWorm VS Code Extension Supply Chain Attack - Open VSX Hijack](https://intel.threadlinqs.com/threat/TL-2026-0024) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/GlassWorm%20Operators
