Skip to content

Cybersecurity

Sandworm in Industrial Environments: What the Data Really Tells Us

An analysis of over 5 million alerts shows how Sandworm targets OT environments: weeks of ignored signals before the real impact lands.

2 min read

Among the threat groups operating against industrial infrastructure, Sandworm (also known as APT44) occupies a category of its own. This is not a ransomware crew seeking a ransom and retreating when discovered: it is a state-sponsored actor with an explicit mandate to strike industrial control systems and a willingness to cause physical disruption of production processes. A recent analysis based on real telemetry data helps explain how it actually operates, and why many defenses arrive too late.

What the Numbers Say

The analyzed dataset comprises over 5.5 million alerts collected from ten industrial companies across seven countries, between July 2025 and January 2026. From this mass of signals, 29 events were isolated as attributable to Sandworm activity. Some figures stand out more than others:

  • Roughly 1.14 million alerts (20.6% of the total) came directly from ICS assets.
  • 17 infected systems generated traffic toward 923 distinct internal targets.
  • In one extreme case, a single host attempted to move laterally toward 405 systems.
  • The OT targets included hundreds of engineering workstations and dozens of HMIs.

Perhaps the most instructive figure is not about the attack itself, but about timing: every compromised system had produced between 20 and 155 days of alerts before impact, with an average window of 43 days. Weeks, sometimes months, of available signals that went unused.

A Methodical, Not Sophisticated, Adversary

Contrary to the zero-day imagery, Sandworm reuses widely documented tools in already-compromised environments. Three victims showed the classic EternalBlue to DoublePulsar to WannaCry chain; four had active command-and-control channels based on Cobalt Strike and Metasploit; a second wave of infections exploited Log4Shell as the entry vector.

The operational rhythm is revealing too: activity concentrates during Moscow office hours, peaking on Wednesday afternoons, and slows down in line with other geopolitical operations. A bureaucratic adversary, predictable in its timing, but relentless in its objectives.

When detected, this actor does not disengage: it accelerates.

This is the substantial difference from ordinary crime. After being discovered, Sandworm tends to intensify severity, tooling and focus on OT/ICS assets, rather than abandoning the target.

The Real Defensive Gap

The picture that emerges is clear: the weakness lies not in the attacker's lack of exotic technologies, but in failing to act on already-recognized signals. Known exploit chains and active C2 are treated as background noise, when in fact they are strategic warnings.

From this, a few concrete priorities follow:

  • Treat recurring alerts as warning bells, particularly known exploit chains and traffic toward C2 infrastructure.
  • Harden the environment before the attack: vulnerability management, credential hygiene, decommissioning of legacy protocols.
  • Watch for lateral movement, spotting anomalous scans and suspicious authentications across networks.
  • Protect systems adjacent to the ICS, starting with engineering workstations, which are critical operational points.
  • Plan for post-detection escalation, without expecting the attacker to retreat.

The MON5 Angle

This is exactly the terrain where visibility matters more than reaction. Without a complete OT asset inventory it is impossible to understand which engineering workstations or HMIs are exposed, and therefore which alerts truly carry weight. Correlating vulnerabilities with the plant context turns thousands of indistinct signals into a handful of actionable priorities: not all vulnerable systems are equally critical to the process.

The MON5 platform is designed to monitor network anomalies and lateral movement without interfering with production, in passive mode. It is precisely within that average 43-day warning window that the game is decided: those who see anomalies in time and put them in context have weeks to contain, instead of minutes to react.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

Related articles

Screen showing malware code and AI symbols highlighting automated payload generation

Cybersecurity

AI in offensive cybersecurity: from payloads to APT operations

Artificial intelligence does not create autonomous threats, but it makes attacks faster and more variable. What changes for those defending OT environments.

2 min read
OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna