{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/actors/sandworm/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Sandworm","BlackEnergy","Voodoo Bear","Seashell Blizzard","IRIDIUM"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VPN and firewall","Cellular router","Programmable logic controller","Serial device server","Network switch","Variable frequency drive"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Fortinet","Teltonika","Wago","Siemens","Moxa","ABB","Schneider Electric"],"content_html":"\u003cp\u003eIn December 2025, threat actors linked to Sandworm conducted a targeted cyberattack against a combined heat and power (CHP) plant in Poland. The attackers successfully sabotaged industrial control systems (ICS), leading to the shutdown of steam turbines and water treatment systems. This incident is notable for the group's novel use of a private Access Point Name (APN) configuration as an attack vector to pivot from a compromise at a wind farm into the operational technology (OT) network of the energy facility. The attackers performed reconnaissance, took control of programmable logic controllers (PLCs), and ultimately bricked hardware to hinder incident response and forensic analysis. This incident occurred alongside a broader campaign targeting approximately 30 energy sites in Poland.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access was gained via an internet-facing Fortinet VPN and firewall device located at a wind farm.\u003c/li\u003e\n\u003cli\u003eThe attackers accessed the admin interface of a Teltonika cellular router connected to the same network as the firewall.\u003c/li\u003e\n\u003cli\u003eAn SSH service on the Teltonika router was leveraged to establish an unauthorized tunnel.\u003c/li\u003e\n\u003cli\u003eThe tunnel enabled the attackers to pivot into a private APN network managed by the distribution system operator (DSO).\u003c/li\u003e\n\u003cli\u003eThe attackers scanned the private APN network, identifying a Wago PLC that acted as a gateway into the CHP plant’s internal OT network.\u003c/li\u003e\n\u003cli\u003eUsing SSH access on the Wago PLC, the attackers moved laterally to Siemens PLCs, setting them to 'stop' mode and applying unauthorized passwords to prevent operator intervention.\u003c/li\u003e\n\u003cli\u003eThe attackers targeted Moxa network infrastructure and ABB/Schneider Electric variable frequency drives to disable operator access and control.\u003c/li\u003e\n\u003cli\u003eFinal objective was achieved through system disruption and permanent destruction (bricking) of hardware to cover tracks and prevent recovery.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe attack resulted in the shutdown of steam turbine and water treatment systems, causing a disruption to the cogeneration process at a facility supplying heat to 50,000 residents. While the supply of electricity and heat was not interrupted long-term, the attackers caused permanent hardware damage to several ICS components, requiring physical replacement and logic restoration from backups.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all internet-facing VPN and firewall appliances for unauthorized remote access or misconfigured interfaces.\u003c/li\u003e\n\u003cli\u003eRestrict access to cellular router administration interfaces using strong authentication and network segmentation.\u003c/li\u003e\n\u003cli\u003eReview private APN configurations to ensure that OT networks are not routable from edge devices or external tunnels without strict policy enforcement.\u003c/li\u003e\n\u003cli\u003eImplement secure, authenticated access controls for all PLC management interfaces; disable unused SSH services on industrial hardware.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized SSH tunneling or unusual scanning activity originating from cellular infrastructure within the OT environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T10:28:24Z","date_published":"2026-08-10T10:28:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-polish-energy-apn/","summary":"In December 2025, the threat actor Sandworm exploited an internet-facing firewall and a misconfigured cellular router to pivot through a private APN into a Polish energy facility's OT network, resulting in industrial sabotage.","title":"Sandworm Targeted Polish Energy Facility via Private APN Pivot","url":"https://feed.craftedsignal.io/briefs/2026-08-polish-energy-apn/"}],"language":"en","title":"CraftedSignal Threat Feed - Sandworm","version":"https://jsonfeed.org/version/1.1"}