Skip to content
Bulwark Black Bulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
  • IOC / YARA downloads
Software
  • Contractor Codex ↗
  • SAMscout AI ↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
IOC Extractor Indicators Feeds The Brief Blog
Threat Intel → Work with us →
All Threat Intel → Latest reporting Russian CTI Chinese CTI North Korean CTI Iranian CTI Global / Anomalous Malware IOC / YARA downloads
All Software → Contractor Codex ↗ SAMscout AI ↗ VA Disability Calc & Track What we build All software
All Services → Websites & Web Apps Custom iOS Apps AI & Automation Small-Business IT & Cybersecurity
All Company → About Community Contact
IOC Extractor Indicators Feeds The Brief Blog Work with us →
RSS
Latest
Malware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack SurfaceUNC6671 Shows Why Helpdesk Vishing Is a Cloud Data-Theft ProblemVeloCloud Orchestrator RCE Shows Why SD-WAN Controllers Need Incident ResponseMSI Router Command-Injection Cluster Shows Why Edge Devices Need Exposure ControlJuly CVE Data Shows Why Patch Priority Needs Threat ContextExfilSquad Shows Why CRM and Portal Data Need Extortion-Ready ControlsMalware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack SurfaceUNC6671 Shows Why Helpdesk Vishing Is a Cloud Data-Theft ProblemVeloCloud Orchestrator RCE Shows Why SD-WAN Controllers Need Incident ResponseMSI Router Command-Injection Cluster Shows Why Edge Devices Need Exposure ControlJuly CVE Data Shows Why Patch Priority Needs Threat ContextExfilSquad Shows Why CRM and Portal Data Need Extortion-Ready Controls

Threat Intel·Russian Cyber Threat Intelligence·Jan 5, 2024·By Albert LaScola

Russia-linked APT Sandworm was inside Ukraine telecoms giant Kyivstar for months

Russia-linked APT Sandworm was inside Ukraine telecoms giant Kyivstar for months
Russia-linked APT Sandworm was inside Ukraine telecoms giant Kyivstar for months
IOCs-Russia-linked-APT-SandwormDownload

#Black Energy#Iron Viking#Sandworm

Newer report →

Hide and Seek in Windows’ Closet: Unmasking the WinSxS Hijacking Hideout

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Two front doors

  • Cyber Threat Intelligence
  • Indicator Database
  • Threat Feeds
  • Shared Infrastructure
  • Threat Alerts
  • The Brief
  • Tech Services & Apps

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy · Terms · Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.