Full Report
For over a decade, russia-backed Sandworm APT group (also tracked as UAC-0145, APT44) has consistently targeted Ukrainian organizations, with a primary focus on state bodies and critical infrastructure. Since the full-scale invasion, this GRU-affiliated military cyber-espionage group has intensified its attacks against Ukrainian targets. The latest malicious campaign, analyzed in February 2025, appears to have […] The post Sandworm APT Attacks Detection: russian State-Sponsored Hackers Deploy Malicious Windows KMS Activators to Target Ukraine appeared first on SOC Prime.
Analysis Summary
Since you have provided the structure of the article's JSON schema but **not the actual content** (`{description}`), I cannot generate a specific threat actor summary.
Please provide the content of the article (the actual text that describes the threat actor) so I can perform the analysis and populate the required structure.
Here is the template structure ready for input:
# Threat Actor: [Name/Alias]
## Attribution & Identity
[Actor identification, aliases, known associations]
## Activity Summary
[Recent campaigns and operations described in the article]
## Tactics, Techniques & Procedures
- [List specific TTPs mentioned]
- [Include MITRE ATT&CK IDs if present]
## Targeting
- Sectors: [Targeted industries/sectors]
- Geography: [Targeted regions/countries]
- Victims: [Specific organizations if mentioned]
## Tools & Infrastructure
- [Malware families used]
- [Infrastructure (C2, domains, IPs - defang URLs)]
## Implications
[Strategic implications and threat assessment]
## Mitigations
- [Defense recommendations specific to this actor]