Sunglow Blizzard

Aliases: DEV-0665

First seen
2022-02-23 00:00:00
Origin
RU
Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:12:49

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:ua

Context

DEV-0665 is a threat actor associated with the HermeticWiper attacks. Their objective is to disrupt, degrade, and destroy specific resources within a targeted country.

Reports & references

  • twitter.com — 1503436420886712321 (report)
  • thehackernews.com — Second New Isaacwiper Data Wiper (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references