Sunglow Blizzard
Aliases: DEV-0665
- First seen
- 2022-02-23 00:00:00
- Origin
- RU
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:12:49
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:ua
Context
DEV-0665 is a threat actor associated with the HermeticWiper attacks. Their objective is to disrupt, degrade, and destroy specific resources within a targeted country.
Reports & references
- twitter.com — 1503436420886712321 (report)
- thehackernews.com — Second New Isaacwiper Data Wiper (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)