Skip to content
supplychainattack.orgSupply chain attack incident catalog

Sandworm supply chain incidents

Russia-linked group publicly attributed to the NotPetya outbreak, delivered through a compromised update server of the M.E.Doc accounting software.

Also tracked as: Voodoo Bear, Seashell Blizzard, GRU Unit 74455

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. activehigh

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Sandworm threat group has been distributing a trojanized WireGuard VPN client to IT professionals and system administrators since at least May 2026, using fake job offers as a social engineering vector.

    SandwormOtherCompromised package