blog Featured Bellingcat Malware Investigation 💡This article was originally published on 24 March 2024 before I migrated my blog to Ghost. Update 17 April 2024: Mandiant Intelligence analysts published an awesome report on the threat actor group tracked as SANDWORM, which was graduated to APT44. In that report, Mandiant analysts connect this campaign to APT44.