Sednit reloaded: Back in the trenches
2026-03-11T08:51:45Z•b11625e25e3fc5c8894b7372b347b4f129ff9f7261014dc3c570bdb79098f649
APTAndroid malwareCVE-2025-50165DynoWiperESETLongNosedGoblinMDRPromptSpySandwormSednitWindows Imaging Componentdata wiperespionagegenerative AIthreat-researchvulnerability
What happened
ESET WeLiveSecurity reporting highlights a resurgence of nation-state APT activity (Sednit) and destructive cyberattacks attributed to Sandworm (DynoWiper targeting Poland’s energy sector). Researchers also disclose novel threats and techniques: PromptSpy — the first known Android malware to incorporate generative AI into its execution flow — and LongNosedGoblin’s Group Policy–based espionage across Southeast Asian and Japanese government networks. The feed includes a technical revisit of a critical Windows Imaging Component vulnerability (CVE-2025-50165) and multiple operational-security take
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- b11625e25e3fc5c8894b7372b347b4f129ff9f7261014dc3c570bdb79098f649
- Enrichment time
- 2026-03-11T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.