
criticalCritical Infrastructure
Sandworm APT Escalates OT Attacks Against Western Water Management Systems
Recent intelligence confirms that the Russian-linked Sandworm group (APT44) has successfully breached several water utility control systems, demonstrating a growing capability to manipulate HMIs directly.
13 July 2026Last updated 20 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary Over the past 48 hours, security researchers at Encrygma have observed a marked increase in malicious activity targeting water distribution and treatment facilities in Western Europe and North America. Attributed to the Russian General Staff Main Intelligence Directorate (GRU) unit known as Sandworm (or APT44), these operations have moved beyond simple reconnaissance. Current telemetry indicates that the threat actor has successfully gained access to operational technology (OT) environments, specifically targeting Human-Machine Interfaces (HMIs) and Programmable Logic Controllers (PLCs) that manage water pressure and chemical dosing. This represents a significant escalation in the targeting of life-sustaining critical infrastructure. ## Threat Analysis Sandworm remains one of the most capable and aggressive state-sponsored threats globally. Their latest campaign marks a strategic shift from pure espionage toward disruptive potential. By gaining unauthorized access to the OT layer of water utilities, the group creates the capability to cause physical damage or jeopardize public health. The threat analysis reveals that the group is utilizing a combination of stolen credentials and the exploitation of edge-facing equipment to bypass traditional IT security measures. Unlike typical ransomware groups, Sandworm's presence is often silent, aimed at long-term persistence and strategic signaling rather than immediate financial gain. Their ability to remain undetected within industrial networks for extended periods is a primary concern for national security. ## Technical Details The technical details of these recent intrusions involve the exploitation of legacy vulnerabilities in remote access solutions and unpatched administrative portals. Once inside the IT network, Sandworm operators move laterally using custom scripts that mimic legitimate administrative traffic. In several instances, the actors were observed interacting with HMI software, specifically manipulating the graphical interface to change alert thresholds. They have also been seen deploying a lightweight modular backdoor designed to maintain access even after password resets. This 'OT-aware' persistence is a significant advancement in their TTPs, showing a deep understanding of specific industrial control software used in the water sector. They leverage compromised SOHO routers to proxy their traffic, making their connections appear as legitimate local residential activity. ## Attribution Assessment We assess with high confidence that this activity is the work of Sandworm (APT44). The infrastructure used in these attacks overlaps significantly with previous GRU-linked operations targeting the Ukrainian energy sector. Furthermore, the timing of these probes aligns with broader geopolitical tensions, suggesting a coordinated effort to exert pressure on Western infrastructure. The use of specific proprietary scripts previously associated with Sandworm's 'GreyEnergy' and 'Industroyer' toolsets further solidifies this attribution. ## Implications The implications of these breaches are severe. The ability to manipulate water treatment processes could lead to contaminated supplies or structural damage to municipal piping systems. This represents a clear shift in the risk landscape for critical infrastructure providers, where the boundary between cyber operations and physical security has effectively vanished. The psychological impact on the civilian population regarding the safety of their water supply is also a key objective for the adversary. ## Recommendations Encrygma recommends that water utility operators immediately implement several defensive measures. First, ensure that all HMIs are behind a robust firewall and not accessible via the public internet. Second, implement multi-factor authentication for all remote access points, including those used by third-party contractors. Third, perform a thorough review of PLC configurations for any unauthorized changes and ensure that all firmware is up to date. Finally, enhance monitoring of 'living-off-the-land' binaries such as PowerShell and WMI within the OT network to detect lateral movement before it reaches critical control systems.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room