<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Serial Device Server - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/serial-device-server/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 10 Aug 2026 10:28:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/serial-device-server/feed.xml" rel="self" type="application/rss+xml"/><item><title>Sandworm Targeted Polish Energy Facility via Private APN Pivot</title><link>https://feed.craftedsignal.io/briefs/2026-08-polish-energy-apn/</link><pubDate>Mon, 10 Aug 2026 10:28:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-polish-energy-apn/</guid><description>In December 2025, the threat actor Sandworm exploited an internet-facing firewall and a misconfigured cellular router to pivot through a private APN into a Polish energy facility's OT network, resulting in industrial sabotage.</description><content:encoded><![CDATA[<p>In December 2025, threat actors linked to Sandworm conducted a targeted cyberattack against a combined heat and power (CHP) plant in Poland. The attackers successfully sabotaged industrial control systems (ICS), leading to the shutdown of steam turbines and water treatment systems. This incident is notable for the group's novel use of a private Access Point Name (APN) configuration as an attack vector to pivot from a compromise at a wind farm into the operational technology (OT) network of the energy facility. The attackers performed reconnaissance, took control of programmable logic controllers (PLCs), and ultimately bricked hardware to hinder incident response and forensic analysis. This incident occurred alongside a broader campaign targeting approximately 30 energy sites in Poland.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access was gained via an internet-facing Fortinet VPN and firewall device located at a wind farm.</li>
<li>The attackers accessed the admin interface of a Teltonika cellular router connected to the same network as the firewall.</li>
<li>An SSH service on the Teltonika router was leveraged to establish an unauthorized tunnel.</li>
<li>The tunnel enabled the attackers to pivot into a private APN network managed by the distribution system operator (DSO).</li>
<li>The attackers scanned the private APN network, identifying a Wago PLC that acted as a gateway into the CHP plant’s internal OT network.</li>
<li>Using SSH access on the Wago PLC, the attackers moved laterally to Siemens PLCs, setting them to 'stop' mode and applying unauthorized passwords to prevent operator intervention.</li>
<li>The attackers targeted Moxa network infrastructure and ABB/Schneider Electric variable frequency drives to disable operator access and control.</li>
<li>Final objective was achieved through system disruption and permanent destruction (bricking) of hardware to cover tracks and prevent recovery.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The attack resulted in the shutdown of steam turbine and water treatment systems, causing a disruption to the cogeneration process at a facility supplying heat to 50,000 residents. While the supply of electricity and heat was not interrupted long-term, the attackers caused permanent hardware damage to several ICS components, requiring physical replacement and logic restoration from backups.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit all internet-facing VPN and firewall appliances for unauthorized remote access or misconfigured interfaces.</li>
<li>Restrict access to cellular router administration interfaces using strong authentication and network segmentation.</li>
<li>Review private APN configurations to ensure that OT networks are not routable from edge devices or external tunnels without strict policy enforcement.</li>
<li>Implement secure, authenticated access controls for all PLC management interfaces; disable unused SSH services on industrial hardware.</li>
<li>Monitor for unauthorized SSH tunneling or unusual scanning activity originating from cellular infrastructure within the OT environment.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>