
Nozomi Networks’ analysis of 5.5 million alerts from 10 industrial customers reveals that Sandworm (APT44) systematically exploits already-compromised OT environments. Every infected system gave an average of 43 days of advance warning. After detection, Sandworm escalates — targeting PLCs, HMIs, and engineering workstations directly.