Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-13 and was added to the RWP archive on 2026-09-07.
Nozomi's Sandworm telemetry — 43 days of ignored alerts, then the GRU walked in
Ten industrial customers, seven countries, July 2025–January 2026. 29 Sandworm events. Every infected host had 20–155 days of prior warnings. ICS engineering workstations were in the blast radius.
Bottom line up front
CONFIRMED Nozomi, 13 May 2026 — anonymized telemetry from 10 industrial customers in seven countries (US, Mexico, UK, Germany, Belgium, Colombia, Thailand), 5.54 million alerts, July 2025–January 2026. 29 events attributed as Sandworm (APT44 / Seashell Blizzard) by signature/YARA. Window of detections 13 August 2025–14 January 2026. 17 infected machines. Lateral movement is the pattern, not a quiet implant. Every Sandworm-infected system had 20–155 days of prior serious warnings (average 43) — EternalBlue/DoublePulsar/WannaCry chains, Cobalt Strike, Metasploit, RATs. ICS assets were targeted: 286 engineering workstations at one victim, 102 at another, 13 at a third. Moscow-hours, midweek-after-lunch execution. Victim-acquisition rate slowed ~2.2× after early November 2025, which Nozomi ties to a Polish grid operation pulling resources — that causal link is ASSESSED, not independently proven here. Process manipulation / Stage 2: not demonstrated in this telemetry slice. OT targeting of engineering workstations: CONFIRMED in Nozomi's dataset.
Historical backfill of 13 May 2026 reporting; added 7 September 2026.
What happened
A vendor telemetry paper, not a new wiper sample. Sandworm used environments that were already owned.
Why it mattered
The missed detections are the finding. 43 average days is not "APT stealth." It is uninvestigated noise on industrial networks.
Who / what was affected
Ten unnamed industrial customers. Do not name countries as victim confirmations beyond Nozomi's set.
Technical context
Hunt old Microsoft exploit chains on OT-adjacent Windows. Treat EWS counts in the hundreds as a Sandworm-shaped anomaly. Do not wait for Industroyer3.
Exploitation / threat status at the time
CONFIRMED Nozomi detections in that corpus.
REPORTED Polish-grid resource shift as Nozomi's interpretation.
What defenders should have done
- Work the 43-day queue.
- Segment engineering workstations.
- Patch EternalBlue-class debt on anything that can see a PLC.
RWP assessment
Confidence: High on the warning-window statistic. Medium on the Poland reallocation story.
Defensive actions
- Ticket SLA for exploit-chain alerts on OT Windows.
- EWS inventory and jump-host logging.
- Pair with Dragos YIR ELECTRUM notes; do not merge the two datasets.
Sources
- Nozomi Networks — Sandworm activity in industrial environments
- Dragos — 2026 OT Year in Review (ELECTRUM / Polish DER context)
- Nozomi Networks Labs — Industroyer2 IEC-104 analysis (historical Sandworm OT tooling)