News Room
16
Share
Sandworm APT Escalates Disruptive Operations Against Western Water Utilities and Power Distribution Networks
criticalCritical Infrastructure

Sandworm APT Escalates Disruptive Operations Against Western Water Utilities and Power Distribution Networks

Intelligence indicates APT44 (Sandworm) is actively compromising Human-Machine Interfaces in European and North American water facilities to manipulate chemical levels and distribution flow.

29 July 2026Last updated 20 August 20265 min readMandiant (Google Cloud)
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
North America and Europe
Confidence:
High Confidence
Source:
Mandiant (Google Cloud)
Read Time:
5 min

Executive Summary

Over the past 48 hours, Encrygma intelligence has tracked a significant escalation in operational technology (OT) targeting by APT44, better known as Sandworm. Following a pattern of disruptive activity originally identified in early 2024, the group has recently successfully compromised three regional water treatment facilities and a secondary power substation across the NATO alliance. This activity represents a transition from reconnaissance to active kinetic-effect signaling. While previous campaigns focused on visibility, the current wave of attacks demonstrates a refined ability to interact directly with Industrial Control Systems (ICS) and Human-Machine Interfaces (HMIs) without triggering immediate fail-safes. The focus remains on smaller-scale utilities with less sophisticated defense postures.

Threat Analysis

The threat actor is primarily utilizing a hybrid methodology that combines traditional IT compromise with specialized OT disruption. Analysis of the latest telemetry suggests that APT44 is capitalizing on insecure remote access configurations, specifically targeting Virtual Network Computing (VNC) and Remote Desktop Protocol (RDP) instances that bridge IT and OT environments. Unlike ransomware actors who seek financial gain, Sandworm’s objectives appear to be geostrategic, aimed at eroding public confidence in critical infrastructure and creating psychological pressure on civilian populations. The group’s focus on water utilities suggests a deliberate attempt to identify the 'soft underbelly' of national infrastructure, where cybersecurity resources are often thinner than in the bulk power system, allowing for higher success rates with lower technical overhead.

Technical Details

The attack chain begins with credential harvesting or exploitation of known vulnerabilities in edge-facing networking equipment. Once inside the IT environment, the actors move laterally until they identify engineering workstations or HMI servers. In the most recent incidents, Sandworm manipulated the setpoints for chemical dosing in water treatment plants, specifically targeting the chlorine injection systems. They achieved this by interacting with the HMI as a legitimate operator would—a technique known as 'living off the land' within OT environments. Evidence of the 'Industroyer2' framework was identified in one instance involving a power substation, where the malware was configured to interact with the IEC-104 protocol to trip circuit breakers. Additionally, the actors deployed the 'CaddyWiper' malware to erase forensic traces and disable recovery efforts on the targeted workstations after the manipulation was completed.

Attribution Assessment

Encrygma aligns with Mandiant and other major intelligence firms in attributing this activity to Unit 74455 of the Russian Main Intelligence Directorate (GRU). The tactical overlaps with historical 'BlackEnergy' and 'NotPetya' campaigns are significant, including the use of similar wiper modules and command-and-control infrastructure. Furthermore, the use of the 'Cyber Army of Russia Reborn' (CARR) Telegram persona as a front for claiming these attacks follows a documented GRU playbook intended to provide a layer of deniability while amplifying the perceived reach of Russian hacktivist groups. Confidence in this attribution is high based on code analysis and infrastructure overlap with previous Sandworm operations.

Implications

The move from speculative probing to active manipulation of water chemistry and power flow signifies a dangerous shift in the global threat landscape. It marks the normalization of civilian infrastructure as a valid target in gray-zone conflicts. Furthermore, the success of these attacks on smaller utilities indicates that current regulatory frameworks and information-sharing programs may not be reaching the local level where vulnerabilities are most acute. If left unaddressed, these tactics could be refined for use against larger, high-consequence infrastructure, leading to a cascading failure of public health systems and essential services during times of geopolitical tension.

Recommendations

To mitigate these threats, Encrygma recommends that critical infrastructure operators: 1. Implement strict multi-factor authentication (MFA) on all remote access points into the OT environment. 2. Disable or strictly firewall VNC and RDP services on all industrial control equipment, ensuring they are not reachable from the public internet. 3. Deploy OT-specific network monitoring tools capable of detecting anomalous HMI interactions and unauthorized setpoint changes in real-time. 4. Conduct immediate reviews of network segmentation to ensure that IT-side compromises cannot transition into the ICS layer via dual-homed systems. 5. Establish and regularly test 'manual-only' operational procedures for water treatment and power distribution to maintain service during cyber-disruptive events.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo