Skip to main content
Insights

Sandworm’s Devastating Cyber Attacks: BadPilot Expands Globally 2025

Table of Contents Sandworm Subgroup’s Global Cyber Attacks: Uncovering BadPilot’s Expanding Footprint <strong>Who is Sandworm?</strong> <strong>How Does the BadPilot Campaign Work?</strong> <strong>The Impact of Sandworm’s Expanding Cyber Attacks</strong> <strong> Energy and Telecommunications</strong> <strong>Mitigation Strategies: How to Defend Against Sandworm’s Tactics</strong> <strong>Conclusion: A Growing Cybersecurity Threat</strong>Sandworm Subgroup’s Global Cyber Attacks: Uncovering BadPilot’s Expanding Footprint In a […]

Shiva 4 min read Updated Feb 13, 2025
Sandworm Devastating Cyber Attacks BadPilot Expands Globally
Cybersecurity 803 words
Technical article

Sandworm Subgroup’s Global Cyber Attacks: Uncovering BadPilot’s Expanding Footprint

In a rapidly evolving cyber threat landscape, state-sponsored hacking groups continue to develop sophisticated tactics to infiltrate critical infrastructure, governments, and private organizations worldwide. One such group, Sandworm, a notorious Russian-backed hacking collective, has recently been linked to a multi-year cyber espionage campaign known as BadPilot.

This campaign has expanded Sandworm’s operations globally, targeting high-value sectors across North America, Europe, and Asia, as well as energy, telecom, and defense industries. Microsoft Threat Intelligence reports that the hacking subgroup, tracked as Seashell Blizzard (APT44), has been exploiting multiple zero-day vulnerabilities and leveraging criminally sourced tools to maintain persistent access to compromised networks.

In this article, we’ll break down:

  • The objectives and methods used by Sandworm’s subgroup.
  • Key vulnerabilities exploited in the attacks.
  • The impact on organizations across various industries.
  • Mitigation strategies to defend against this ongoing threat.

 

Who is Sandworm?

Sandworm, also referred to as Seashell Blizzard, APT44, FROZENBARENTS, Telebots, and Iron Viking, is a state-sponsored threat group linked to Russia’s military intelligence agency (GRU), Unit 74455.

A Brief History of Sandworm’s Attacks

The group has been active since 2013, specializing in:

  • Cyber espionage and data exfiltration.
  • Disruptive malware attacks against Ukraine.
  • Infrastructure sabotage, including attacks on power grids and telecommunication networks.

BadPilot: A New Wave of Attacks

Microsoft’s recent investigation reveals that a subgroup of Sandworm has been conducting a global cyber infiltration campaign called BadPilot since late 2021. The operation focuses on gaining initial access to high-value targets and supporting long-term espionage efforts.

The geographical reach of these attacks has expanded significantly:

  • 2022: Focused on Ukraine’s energy, retail, education, and agriculture sectors.
  • 2023: Expanded to U.S., Europe, Central Asia, and the Middle East.
  • 2024: Widespread targeting of government entities and enterprises in North America, Canada, Australia, and the UK.

 

How Does the BadPilot Campaign Work?

The BadPilot operation relies on a combination of targeted exploits, criminally sourced malware, and advanced persistence techniques.

  1. Exploiting Security Vulnerabilities

The Sandworm subgroup actively exploits publicly disclosed vulnerabilities in widely used software to gain initial access. Some of the key CVEs they have weaponized include:

Vulnerability Targeted Software CVE ID
ProxyShell Microsoft Exchange Server CVE-2021-34473
Openfire Openfire Chat Server CVE-2023-32315
Fortinet FortiClient EMS CVE-2023-48788
Outlook Microsoft Outlook CVE-2023-23397
Zimbra Zimbra Collaboration Suite CVE-2022-41352
TeamCity JetBrains TeamCity CVE-2023-42793
JBOSS Enterprise Application Platform Unknown CVE

These vulnerabilities enable remote code execution (RCE), credential theft, and persistent access.

2. Persistence and Lateral Movement

Once inside a network, Sandworm deploys three primary persistence mechanisms:

  • Legitimate Remote Access Tools: Abuse of software like Atera Agent and Splashtop to maintain access.
  • Custom Web Shells: Deployment of a backdoor named LocalOlive for continuous command-and-control (C2).
  • Malicious Outlook Web Access (OWA) Modifications: Injection of JavaScript code to steal credentials in real time.

3. Leveraging Criminally Sourced Tools

Unlike traditional state-sponsored groups, Sandworm buys and uses malware from cybercriminal markets. Some examples include:

  • DarkCrystal RAT (DCRat) – A remote access trojan for data theft.
  • Warzone RAT – Enables keylogging and remote execution.
  • RADTHIEF (Rhadamanthys Stealer) – A credential harvesting tool.

This hybrid approach allows them to expand operations quickly while maintaining plausible deniability.

How Does the BadPilot Campaign Work

The Impact of Sandworm’s Expanding Cyber Attacks

The consequences of BadPilot have been far-reaching, affecting critical industries across the world.

  • Government and Defense

  • U.S., UK, and European government agencies have been compromised.
  • Sensitive diplomatic and intelligence data is at risk.
  • Energy and Telecommunications

  • Power grids and oil and gas firms in Europe and the Middle East have been targeted.
  • Telecom providers in Asia and Africa are experiencing data breaches.
  • Private Sector Enterprises

  • Companies in finance, healthcare, and technology have reported unauthorized access.
  • Ransomware and data-wiping attacks pose a major threat.

 

Mitigation Strategies: How to Defend Against Sandworm’s Tactics

With state-sponsored groups like Sandworm constantly refining their attack methods, organizations must adopt proactive cybersecurity measures.

  • Patch Known Vulnerabilities

Regularly update and apply security patches to Microsoft Exchange, Fortinet, Openfire, and Zimbra servers.

  • Implement Multi-Factor Authentication (MFA)
  • Reduce the risk of credential theft by enforcing MFA for all remote and privileged access.
  • Monitor for Suspicious Activities
  • Deploy intrusion detection systems (IDS) to track unusual network behavior.
  • Use SIEM solutions to correlate security logs and identify patterns of attack.
  • Block High-Risk Remote Access Tools
  • Disable unauthorized remote access applications like Atera, Splashtop, and TeamViewer.
  • Improve Endpoint Security
  • Deploy behavior-based antivirus solutions to detect DCRat, Warzone, and Rhadamanthys Stealer.

 

Conclusion: A Growing Cybersecurity Threat

The Sandworm subgroup’s global expansion marks a significant escalation in state-sponsored cyber warfare. Their use of criminally sourced tools, zero-day exploits, and nation-state resources makes them one of the most dangerous APTs in the world.

🔹 Next Steps:

Patch all affected systems
Enable multi-factor authentication
Strengthen endpoint security
Monitor for unauthorized access

What are your thoughts on Sandworm’s tactics? Share your insights below!

Questions answered

Frequently asked questions.

Answers connected directly to this article and its subject.

01 Who is behind the BadPilot cyber attacks?

BadPilot is a global cyber espionage campaign led by a subgroup of Sandworm (Seashell Blizzard/APT44), affiliated with Russia’s GRU.

02 What are the primary targets of Sandworm’s attacks?

Sandworm focuses on government agencies, energy, oil & gas, telecom, and defense industries.

03 How does Sandworm maintain persistence in infected networks?

They use remote access tools, web shells (LocalOlive), and modified authentication pages to steal credentials and maintain long-term access.

04 What vulnerabilities should organizations patch immediately?

Organizations should prioritize patching ProxyShell (CVE-2021-34473), Outlook (CVE-2023-23397), Fortinet (CVE-2023-48788), and TeamCity (CVE-2023-42793).

05 How can companies detect if they’ve been compromised?
  • Check network logs for unauthorized remote connections.
  • Monitor user activity for unusual login locations.
  • Use threat intelligence feeds to detect Sandworm’s C2 infrastructure.
Shiva
Written by

Shiva

Engineering context

Research is useful when it survives contact with the system.

Explore implementation work, production systems and case studies from FireXCore.