🪱 Diuna to świetny film, a jeszcze lepsza książka. No i tak się widocznie Rosjanom spodobała, że postanowili mieć swojego własnego Szej-Huluda, piaskowego Czerwia - Sandworma. To właśnie Sandworm jest kryptonimem jednostki 74455, czyli cyberszpiegów operujących w obrębie rosyjskiego wywiadu wojskowej GRU. Jak to w przypadku grup APT, Advanced Persistent Threat bywa, mają one wiele nazw, ale najczęściej spotykam się z nazwą Sandworm. Zresztą pasuje mi ona najlepiej scenerii odcinka i to absolutnie nie jest przypadek.
Linki:
📖 Sandworm: A tale of disruption told anew
https://www.welivesecurity.com/2022/03/21/sandworm-tale-disruption-told-anew/
⚫️ Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland
https://www.welivesecurity.com/2014/09/22/back-in-blackenergy-2014/
🔍 iSIGHT discovers zero-day vulnerability CVE-2014-4114 used in Russian cyber-espionage campaign
https://web.archive.org/web/20141014083644/http://www.isightpartners.com/2014/10/cve-2014-4114/
⚡️ BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry
https://www.welivesecurity.com/2016/01/03/blackenergy-sshbeardoor-details-2015-attacks-ukrainian-news-media-electric-industry/
🔌 BlackEnergy trojan strikes again: Attacks Ukrainian electric power industry
https://www.welivesecurity.com/2016/01/04/blackenergy-trojan-strikes-again-attacks-ukrainian-electric-power-industry/
🖲️ Industroyer: Biggest threat to industrial control systems since Stuxnet
https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/
❗️TeleBots are back: Supply-chain attacks against Ukraine
https://www.welivesecurity.com/2017/06/30/telebots-back-supply-chain-attacks-against-ukraine/
🌍 New WannaCryptor-like ransomware attack hits globally: All you need to know
https://www.welivesecurity.com/2017/06/27/new-ransomware-attack-hits-ukraine/
🔘 The Untold Story of NotPetya, the Most Devastating Cyberattack in History
https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
❓What was the WannaCry ransomware attack?
https://www.cloudflare.com/learning/security/ransomware/wannacry-ransomware/
📑 The Shadow Brokers Leaked Exploits Explained
https://www.rapid7.com/blog/post/2017/04/18/the-shadow-brokers-leaked-exploits-faq/
📃 UNITED STATES DISTRICT COURT WESTERN DISTRICT OF PENNSYLVANIA Criminal No. 20-316
https://www.justice.gov/archives/opa/press-release/file/1328521/dl?inline=
🇷🇺 Grand Jury Indicts 12 Russian Intelligence Officers for Hacking Offenses Related to the 2016 Election
https://www.justice.gov/archives/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-election
👁️ New Sandworm Malware Cyclops Blink Replaces VPNFilter
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-054a
🇺🇦 HermeticWiper: New data-wiping malware hits Ukraine
https://www.welivesecurity.com/2022/02/24/hermeticwiper-new-data-wiping-malware-hits-ukraine/
📍IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
📂 Industroyer2: Industroyer reloaded
https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
🖥️ Плани UAC-0133 (Sandworm) щодо кібердиверсії на майже 20 об'єктах критичної інфраструктури України
https://cert.gov.ua/article/6278706
📰 Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland
https://www.welivesecurity.com/2014/09/22/back-in-blackenergy-2014/
🔗 Uzupełnienie raportu z incydentu w sektorze energii w grudniu 2025 roku
https://cert.pl/posts/2026/08/uzupelnienie-raportu-incydent-sektor-energii-2025/
🐚 The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation
https://www.microsoft.com/en-us/security/blog/2025/02/12/the-badpilot-campaign-seashell-blizzard-subgroup-conducts-multiyear-global-access-operation/
📁 ESET APT Activity Report Q4 2025–Q1 2026
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/
© Wszystkie znaki handlowe należą do ich prawowitych właścicieli.
❤️ Dziękuję za Waszą uwagę.
Znajdziecie mnie również na:
Instagramie @mateuszemsi https://www.instagram.com/mateuszemsi/
Twixxerze @MateuszChrobok https://twitter.com/MateuszChrobok
Mastodonie https://infosec.exchange/@mateuszchrobok
LinkedInie @mateuszchrobok https://www.linkedin.com/in/mateuszchrobok/
Patronite https://patronite.pl/MateuszChrobok
Rozdziały:
00:00 Intro
01:25 Kalendarium
27:12 Wyjątki
27:37 Co Robić i Jak Żyć?
#Sandworm #Rosja #cyberszpiedzy #GRU #rosyjski