2026-07-20NOTABLEGRU's Sandworm adopts ClickFix, blockchain-hidden C2 (EtherHiding) and a Signal-lured Android backdoor, transferable tradecraft for EU CI defenders
Sandworm
actor · actor:sandworm single-source-national-cert
Russian GRU-linked destructive/disruptive threat actor. Referenced in pipeline coverage as the contested alternative attribution for the 29 December 2025 Poland energy-grid sabotage: earlier ESET reporting (via BleepingComputer, 2026-01-24) attributed the DynoWiper attack to Sandworm, while CERT Polska and the 2026-07-13 UK/EU government attribution assign the incident to the Static Tundra / FSB Centre 16 cluster.
Aliases: APT44, Seashell Blizzard, UAC-0113, Voodoo Bear, SANDWORM RELIC
Coverage
5
3 about it · 2 mentions · first 2026-05-10 → last 2026-09-20
Latest activity
2026-09-18
Cisco has replaced the hot fixes for its CVSS 10.0 Secure FMC authentication bypass with the September…
Peak priority
high
2 high · 1 notable
Targets
public-sector
sectors: public-sector, defense, technology · regions: europe, russia-cis, switzerland
Sources cited
29
21 hosts
2026-05-105 appearances2026-08-04
Action items (3)
Do-now tasks recorded on the entries about Sandworm, newest first. Check the date before acting on an older one.
- Upgrade every Secure FMC to its September 2026 hardening release (7.0 and earlier to 7.0.10, 7.2 to 7.2.12, 7.4 to 7.4.8, 7.6 to 7.6.6, 7.7 to 7.7.13, 10.0 to 10.0.2, 10.1 to 10.1.0). Cisco replaced the earlier per-train hot fixes with these releases on 2026-09-16; there is no workaround, and no configuration makes an FMC non-vulnerable.2026-08-04CVE-2026-20079 +2
- Run Cisco's revised compromise check on every FMC that has been network-reachable since 2026-03-04: in expert mode,2026-08-04CVE-2026-20079 +2
zgrep "package_info.*license" /var/log/messages*, a hit naming /var/tmp/license.tmp means the chain reached the package-install step, and Cisco directs those cases to TAC rather than to self-remediation. - Disable Cisco Smart Install (2026-07-13CVE-2018-0171
no vstack) and confirm CVE-2018-0171 is remediated on every internet-facing IOS/IOS XE device, and alert on inbound SNMP Set-Requests carrying the config-copy OIDs named in the advisory (1.3.6.1.4.1.9.9.96.1.1 Cisco Config Copy; 1.3.6.1.4.1.9.9.96.1.1.1.1.5 Config Copy Server Address); both are in-use FSB Centre 16 access and config-exfiltration vectors.
Defender insights
What each entry about Sandworm tells a defender to do, newest first.
Triage
Latest update · triage · detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
overlaps with
- UAT-11823Cisco Talos: UAT-11823 overlaps in tooling with the Sandworm APT actor.
related to
- UAC-0145CERT-UA: UAC-0145 is a subcluster of UAC-0002, also known as Sandworm / APT44 / Seashell Blizzard (the typed vocabulary has no actor→actor subcluster edge; related-to records the stated hierarchy without overclaiming)
attributed activity
- Cyclops BlinkCisco Talos, citing the 2022 US/UK government attribution: Cyclops Blink is a malware family previously attributed to Sandworm.
Story timeline
Every entry that names Sandworm, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-08-04CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)
- 2026-07-20CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor
- 2026-07-13FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
- 2026-05-30ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset
- 2026-05-10Bauman University "Department No. 4", leaked GRU cyber-operator training pipeline reveals direct line to Sandworm and APT28 operations against European targets
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (32 across 13 tactics)
32 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Scanning IP Blocks · Active Scanning: Vulnerability Scanning
- Resource DevelopmentAcquire Infrastructure: Virtual Private Server · Compromise Infrastructure: Server · Compromise Infrastructure: Network Devices · Obtain Capabilities: Exploits
- Initial AccessValid Accounts · Valid Accounts: Default Accounts · Drive-by Compromise · Exploit Public-Facing Application · Phishing
- ExecutionCommand and Scripting Interpreter: PowerShell · User Execution: Malicious File · User Execution: Malicious Copy and Paste
- PersistenceValid Accounts · Valid Accounts: Default Accounts · Server Software Component: Web Shell · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationExploitation for Privilege Escalation · Valid Accounts · Valid Accounts: Default Accounts · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Valid Accounts · Valid Accounts: Default Accounts
- Defense ImpairmentModify System Image: Patch System Image · Disable or Modify Tools
- Credential AccessOS Credential Dumping
- CollectionData from Configuration Repository: SNMP (MIB Dump) · Data from Configuration Repository: Network Device Configuration Dump
- Command and ControlApplication Layer Protocol · Application Layer Protocol: DNS · Proxy · Web Service · Dynamic Resolution · Protocol Tunneling
- ExfiltrationExfiltration Over Alternative Protocol
- ImpactData Destruction · Data Encrypted for Impact
Reconnaissance TA0043
T1595.001Active Scanning: Scanning IP Blocks×1
Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Resource Development TA0042
T1583.003Acquire Infrastructure: Virtual Private Server×1
Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1584.004Compromise Infrastructure: Server×1
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1584.008Compromise Infrastructure: Network Devices×1
Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1588.005Obtain Capabilities: Exploits×1
Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1189Drive-by Compromise×2
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1190Exploit Public-Facing Application×2
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×2
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×1
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Defense Impairment TA0112
T1601.001Modify System Image: Patch System Image×1
Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Credential Access TA0006
T1003OS Credential Dumping×1
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Collection TA0009
T1602.001Data from Configuration Repository: SNMP (MIB Dump)×1
Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1602.002Data from Configuration Repository: Network Device Configuration Dump×1
Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1071.004Application Layer Protocol: DNS×1
Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1102Web Service×1
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · ATT&CK page ↗
T1568Dynamic Resolution×1
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.
Evidence: 2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Exfiltration TA0010
T1048Exfiltration Over Alternative Protocol×1
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×1
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix · ATT&CK page ↗
Entries about Sandworm (3)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cisco IOS×1
- Cisco IOS XE×1
- Cisco IOS/IOS XE Smart Install pre-auth RCE, actively exploited by FSB Centre 16 / Static Tundra×1
- Cisco Secure Firewall Management Center×1
- Cisco Secure Firewall Management Center Java deserialization RCE via External Database Access allowlist (CVSS 9.8), not reported exploited×1
- Cisco Secure Firewall Management Center sftunnel arbitrary file write to root (CVSS 9.9), requires existing low-privilege device credentials, not reported exploited×1
- Cisco Security Cloud Control Firewall Management×1
- CVE-2026-20079, Cisco Secure Firewall Management Center web interface: unauthenticated authentication bypass to root via a boot-time csm_processes session (CVSS 10.0, CWE-288); disclosed 2026-03-04 with no fix, per-train hot fixes added to the advisory 2026-07-31; Cisco reports no known malicious use, VulnCheck built a working exploit×1
Where this entity is cited
Source distribution
- sec.cloudapps.cisco.com5 (17%)
- bleepingcomputer.com2 (7%)
- blog.talosintelligence.com2 (7%)
- cisa.gov2 (7%)
- heise.de2 (7%)
- cert.gov.ua1 (3%)
- cert.pl1 (3%)
- cert.ssi.gouv.fr1 (3%)
- other13 (45%)
All cited sources (29)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/fmc-ongoing-exploitation/
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/static-tundra/
- cert.gov.uaCERT-UAhttps://cert.gov.ua/article/6318437
- cert.plCERT Polskahttps://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/
- cert.ssi.gouv.frCERT-FR (ANSSI)https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/
- cisa.govCISA AA24-060Ahttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a
- cisa.govCISA Known Exploited Vulnerabilities Catalog (JSON feed)https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- cyber.gouv.frANSSI (cyber.gouv.fr)https://cyber.gouv.fr/actualites/ciblage-et-compromission-dentites-francaises-par-le-fsb/
- defense.gouv.frMinistère des Armées / COMCYBERhttps://www.defense.gouv.fr/comcyber/actualites/ciblage-compromission-dentites-francaises-au-moyen-du-mode-du-mode-operatoire-dattaque-turla
- gov.ukUK Government (FCDO)https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions
- heise.deheise onlinehttps://www.heise.de/en/news/EU-sanctions-Russia-for-serious-cyberattacks-and-sabotage-11363418.html
- heise.deheise online, 2026-05-07https://www.heise.de/news/Cyberkrieg-Medien-zitieren-Interna-aus-Russlands-Geheimdienstausbildung-11285528.html
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/chinese-hackers-exploit-iran-war/
- lemonde.frLe Monde, 2026-05-07https://www.lemonde.fr/en/m-le-mag/article/2026/05/07/moscow-s-bauman-university-the-clandestine-school-training-russian-hackers_6753208_117.html
- media.defense.govNSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
- meduza.ioMeduza (English), 2026-05-07https://meduza.io/amp/en/feature/2026/05/07/secret-gru-linked-department-at-top-russian-university-trains-hackers-and-saboteurs-investigation-finds
- ncsc.gov.ukNCSC-UKhttps://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting
- sec.cloudapps.cisco.comCisco PSIRT (CVE-2026-20242 advisory)https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk
- sec.cloudapps.cisco.comCisco PSIRT (CVE-2026-20324 advisory)https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2
- sec.cloudapps.cisco.comCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
- sec.cloudapps.cisco.comCisco PSIRT (advance notification)https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP
- sec.cloudapps.cisco.comCisco PSIRThttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
- spiegel.deDer Spiegel, 2026-05-07https://www.spiegel.de/ausland/hybrider-krieg-moskau-bildet-in-einem-geheimen-uni-programm-spione-und-hacker-aus-a-2de79023-aa56-4ed6-b5de-d7c222402e63
- theguardian.comThe Guardian, 2026-05-07https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
- vulncheck.comVulnCheckhttps://www.vulncheck.com/blog/cisco-fmc-auth-bypass-cve-2026-20079
- welivesecurity.comESET WeLiveSecurityhttps://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/