Skip to content
Bulwark BlackBulwark Black LLC
Threat Intel
  • Latest reporting
  • Russian CTI
  • Chinese CTI
  • North Korean CTI
  • Iranian CTI
  • Global / Anomalous
  • Malware
Intel Workbench
  • Workbench home
  • IOC Passport
  • Campaign Constellation · Beta
  • Indicator Database
  • Verified Threat Feeds
  • IOC Extractor
  • Threat Alerts
Software
  • Contractor Codex↗
  • SAMscout AI↗
  • VA Disability Calc & Track
  • What we build
  • All software
Services
  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • Small-Business IT & Cybersecurity
Company
  • About
  • Community
  • Contact
The BriefBlog
Threat Intel →Work with us →
All Threat Intel →Latest reportingRussian CTIChinese CTINorth Korean CTIIranian CTIGlobal / AnomalousMalware
All Intel Workbench →Workbench homeIOC PassportCampaign Constellation · BetaIndicator DatabaseVerified Threat FeedsIOC ExtractorThreat Alerts
All Software →Contractor Codex↗SAMscout AI↗VA Disability Calc & TrackWhat we buildAll software
All Services →Websites & Web AppsCustom iOS AppsAI & AutomationSmall-Business IT & Cybersecurity
All Company →AboutCommunityContact
The BriefBlogWork with us →
RSS
Latest
Q3 Attack Trends Show Trusted Paths Are Becoming the Real TargetFortiBleed Shows Why VPN Credential Compromise Needs Full Incident ResponseGitHub Enterprise SSRF Shows Why Secret Scanning Needs Network GuardrailsBlinder Tunnel Shows How Developer Trust Becomes Critical Infrastructure RiskBrowser Detection and Response Shows Why the Browser Is Now a Security Blind SpotApache Struts REST Plugin Flaws Show Why Legacy Java Apps Need Exposure ReviewClingSTUN Shows Why IoT Edge Devices Need Real Egress MonitoringApache Thrift 61-CVE Patch Shows Why RPC Frameworks Need InventoryNIST OT Zero Trust Guidance Shows Segmentation Must Reach Below Level 3Milk Dragon Shows Social Commerce Phishing Needs Identity and Payment ControlsCisco SD-WAN Auth Bypass Shows Edge Control Planes Need Emergency ReviewRansomware Data Theft Surge Shows Why Exfiltration Defense Comes FirstLive Exposed Credentials Show Why Secret Scanning Must End in RevocationAntino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware DetectionQ3 Attack Trends Show Trusted Paths Are Becoming the Real TargetFortiBleed Shows Why VPN Credential Compromise Needs Full Incident ResponseGitHub Enterprise SSRF Shows Why Secret Scanning Needs Network GuardrailsBlinder Tunnel Shows How Developer Trust Becomes Critical Infrastructure RiskBrowser Detection and Response Shows Why the Browser Is Now a Security Blind SpotApache Struts REST Plugin Flaws Show Why Legacy Java Apps Need Exposure ReviewClingSTUN Shows Why IoT Edge Devices Need Real Egress MonitoringApache Thrift 61-CVE Patch Shows Why RPC Frameworks Need InventoryNIST OT Zero Trust Guidance Shows Segmentation Must Reach Below Level 3Milk Dragon Shows Social Commerce Phishing Needs Identity and Payment ControlsCisco SD-WAN Auth Bypass Shows Edge Control Planes Need Emergency ReviewRansomware Data Theft Surge Shows Why Exfiltration Defense Comes FirstLive Exposed Credentials Show Why Secret Scanning Must End in RevocationAntino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware Detection

Threat Intel·Russian Cyber Threat Intelligence·Jan 5, 2024·ByBulwark Violet

Russia-linked APT Sandworm was inside Ukraine telecoms giant Kyivstar for months

Russia-linked APT Sandworm was inside Ukraine telecoms giant Kyivstar for months
Russia-linked APT Sandworm was inside Ukraine telecoms giant Kyivstar for months
IOCs-Russia-linked-APT-SandwormDownload

#Black Energy#Iron Viking#Sandworm

Newer report →

Hide and Seek in Windows’ Closet: Unmasking the WinSxS Hijacking Hideout

Next step

Want this turned into detection for your environment?

We build the defenses we write about: detection rules, hardening, and incident response for small businesses and government contractors. Or take the indicators above and run them yourself, every report ships with machine-readable downloads.

Work With Us →Get the IOC Feeds →

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

readers get The Brief

Double opt-in. One-click unsubscribe on every issue. We never share your address.

Bulwark Black

Veteran-Owned · SDVOSB

Bulwark Black LLC
Cyber threat intelligence, custom software, and remote tech help.
Remote across the United States.

Registered agent address (mailing only):
522 W Riverside Ave, Ste N
Spokane, WA 99201

Intel & Tools

  • Intel Workbench
  • Cyber Threat Intelligence
  • Indicator Database
  • Verified Threat Feeds
  • Campaign Constellation Beta
  • IOC Extractor
  • Threat Alerts
  • The Brief

Services

  • Websites & Web Apps
  • Custom iOS Apps
  • AI & Automation
  • IT + Cybersecurity

Company

  • About
  • Software
  • VA Disability Calc & Track
  • Community
  • Blog
  • How I Work
  • Contact
  • Privacy
  • Terms
  • VA Calc Privacy Policy

For agencies & primes

  • Capability statement
  • CAGE: 17UL6
  • UEI: DVNTWBJ2HMP8
  • SDVOSB · SAM Registered

support@bulwarkblack.com

Connect

  • LinkedIn
  • GitHub

© 2026 Bulwark Black LLC. All rights reserved.

Privacy·Terms·Cookie choices

We use Google Analytics to measure site traffic, which sets cookies. No ads and no cross-site tracking. See our privacy policy.