A team Microsoft calls BadPilot is acting as Sandworm’s “initial access operation,” the company says. And over the last year it’s trained its sights on the US, the UK, Canada, and Australia.A team Microsoft calls BadPilot is acting as Sandworm’s “initial access operation,” the company says. And over the last year it’s trained its sights on the US, the UK, Canada, and Australia.
A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks from Wired Andy Greenberg
![](https://www.tombettenhausen.net/wp-content/uploads/2025/02/putin-tussia-hackers-sec-202195701776-lNujpj.jpeg)