Sednit reloaded: Back in the trenches

2026-03-11T08:51:45Zb11625e25e3fc5c8894b7372b347b4f129ff9f7261014dc3c570bdb79098f649
APTAndroid malwareCVE-2025-50165DynoWiperESETLongNosedGoblinMDRPromptSpySandwormSednitWindows Imaging Componentdata wiperespionagegenerative AIthreat-researchvulnerability

What happened

ESET WeLiveSecurity reporting highlights a resurgence of nation-state APT activity (Sednit) and destructive cyberattacks attributed to Sandworm (DynoWiper targeting Poland’s energy sector). Researchers also disclose novel threats and techniques: PromptSpy — the first known Android malware to incorporate generative AI into its execution flow — and LongNosedGoblin’s Group Policy–based espionage across Southeast Asian and Japanese government networks. The feed includes a technical revisit of a critical Windows Imaging Component vulnerability (CVE-2025-50165) and multiple operational-security take

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
b11625e25e3fc5c8894b7372b347b4f129ff9f7261014dc3c570bdb79098f649
Enrichment time
2026-03-11T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.