
Nozomi Networks’ analysis of 5.5 million alerts from 10 industrial customers reveals that Sandworm (APT44) systematically exploits already-compromised OT environments. Every infected system gave an average of 43 days of advance warning. After detection, Sandworm escalates — targeting PLCs, HMIs, and engineering workstations directly.

Three CODESYS vulnerabilities (CVE-2025-41658/59/60) let attackers backdoor Soft PLCs from hundreds of manufacturers. Full attack chain analysis and defensive playbook for OT security teams.