Cybersecurity
Sandworm in Industrial Environments: What the Data Really Tells Us
An analysis of over 5 million alerts shows how Sandworm targets OT environments: weeks of ignored signals before the real impact lands.
Among the threat groups operating against industrial infrastructure, Sandworm (also known as APT44) occupies a category of its own. This is not a ransomware crew seeking a ransom and retreating when discovered: it is a state-sponsored actor with an explicit mandate to strike industrial control systems and a willingness to cause physical disruption of production processes. A recent analysis based on real telemetry data helps explain how it actually operates, and why many defenses arrive too late.
What the Numbers Say
The analyzed dataset comprises over 5.5 million alerts collected from ten industrial companies across seven countries, between July 2025 and January 2026. From this mass of signals, 29 events were isolated as attributable to Sandworm activity. Some figures stand out more than others:
- Roughly 1.14 million alerts (20.6% of the total) came directly from ICS assets.
- 17 infected systems generated traffic toward 923 distinct internal targets.
- In one extreme case, a single host attempted to move laterally toward 405 systems.
- The OT targets included hundreds of engineering workstations and dozens of HMIs.
Perhaps the most instructive figure is not about the attack itself, but about timing: every compromised system had produced between 20 and 155 days of alerts before impact, with an average window of 43 days. Weeks, sometimes months, of available signals that went unused.
A Methodical, Not Sophisticated, Adversary
Contrary to the zero-day imagery, Sandworm reuses widely documented tools in already-compromised environments. Three victims showed the classic EternalBlue to DoublePulsar to WannaCry chain; four had active command-and-control channels based on Cobalt Strike and Metasploit; a second wave of infections exploited Log4Shell as the entry vector.
The operational rhythm is revealing too: activity concentrates during Moscow office hours, peaking on Wednesday afternoons, and slows down in line with other geopolitical operations. A bureaucratic adversary, predictable in its timing, but relentless in its objectives.
When detected, this actor does not disengage: it accelerates.
This is the substantial difference from ordinary crime. After being discovered, Sandworm tends to intensify severity, tooling and focus on OT/ICS assets, rather than abandoning the target.
The Real Defensive Gap
The picture that emerges is clear: the weakness lies not in the attacker's lack of exotic technologies, but in failing to act on already-recognized signals. Known exploit chains and active C2 are treated as background noise, when in fact they are strategic warnings.
From this, a few concrete priorities follow:
- Treat recurring alerts as warning bells, particularly known exploit chains and traffic toward C2 infrastructure.
- Harden the environment before the attack: vulnerability management, credential hygiene, decommissioning of legacy protocols.
- Watch for lateral movement, spotting anomalous scans and suspicious authentications across networks.
- Protect systems adjacent to the ICS, starting with engineering workstations, which are critical operational points.
- Plan for post-detection escalation, without expecting the attacker to retreat.
The MON5 Angle
This is exactly the terrain where visibility matters more than reaction. Without a complete OT asset inventory it is impossible to understand which engineering workstations or HMIs are exposed, and therefore which alerts truly carry weight. Correlating vulnerabilities with the plant context turns thousands of indistinct signals into a handful of actionable priorities: not all vulnerable systems are equally critical to the process.
The MON5 platform is designed to monitor network anomalies and lateral movement without interfering with production, in passive mode. It is precisely within that average 43-day warning window that the game is decided: those who see anomalies in time and put them in context have weeks to contain, instead of minutes to react.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles
Cybersecurity
Covert networks and hidden C2 channels in OT environments: how APTs operate
APT actors targeting industrial environments do not break in and act immediately: they settle quietly, build hidden command channels, and wait. How they work and how to detect them.

Cybersecurity
AI in offensive cybersecurity: from payloads to APT operations
Artificial intelligence does not create autonomous threats, but it makes attacks faster and more variable. What changes for those defending OT environments.

Cybersecurity
Anomaly detection in OT: building the baseline and managing false positives
OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.