Enterprise Threat Intel

Sandworm Resurfaces with OAuth Abuse and Destructive Wipers

Sandworm Resurfaces with OAuth Abuse and Destructive Wipers

Sandworm (GRU) conducting campaigns against Ukraine and Western critical infrastructure using OAuth abuse, edge exploitation, and destructive wipers. Kill-chain speed 4-6 hours to domain admin. New OT incident: Sandworm pivoted from Fortinet VPN through private APN to disrupt PLCs using DynoWiper – edge devices and private APNs need same rigor as IT. New detection hooks for SOC: OAuth app registrations, LSASS reads, and private APN traffic anomalies. Active and evolving.

Sources (2)
Updated Aug 12, 2026