Sandworm Team
Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.
Read profile →
Threat intelligence and malware analysis for industrial control systems and critical infrastructure.
Profiles of groups known to target industrial control systems and critical infrastructure.
Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.
Read profile →Analysis of malware built to disrupt, manipulate, or destroy industrial control systems.
The first malware framework built to speak grid-control protocols directly — used against a Kyiv transmission substation in 2016.
Read profile →Curated tools, references, and reading material for security professionals.
A curated collection of resources, tools, and references for malware analysis and reverse engineering.
View on GitHub →A comprehensive reference on Advanced Persistent Threat groups, their TTPs, and associated campaigns.
View on GitHub →A comprehensive reference on malware families built to target industrial control systems and operational technology environments.
View on GitHub →In-depth walkthroughs, tutorials, and research breakdowns.
Long-form writeups, research findings, and technical breakdowns.
An analysis of the AceLauncher malware attributed to the TamperedChef/EvilAI campaign — from landing page to .NET binary teardown.
Read post →A practical guide to the PE file format — headers, sections, imports, exports, and detecting packed or obfuscated binaries.
Read post →An introduction to malware analysis — covering types of malware, static vs dynamic analysis techniques, and the tools used to dissect samples.
Read post →Astra covers threat intelligence and malware analysis focused on industrial control systems and critical infrastructure, with an emphasis on reverse engineering real samples, tracking the groups behind them, and breaking down how these attacks actually work.
Get in Touch