Sandworm Resurfaces with OAuth Abuse and Destructive Wipers
Sandworm (GRU) conducting campaigns against Ukraine and Western critical infrastructure using OAuth abuse, edge exploitation, and destructive wipers. Kill-chain speed 4-6 hours to domain admin. New OT incident: Sandworm pivoted from Fortinet VPN through private APN to disrupt PLCs using DynoWiper – edge devices and private APNs need same rigor as IT. New detection hooks for SOC: OAuth app registrations, LSASS reads, and private APN traffic anomalies. Active and evolving.
Sources (2)
Updated Aug 12, 2026