Sandworm and the European Power Grid: Anatomy of a Hybrid Campaign Italy Cannot Ignore
2026 is shaping up as the year in which Russia's hybrid war against Europe crossed a critical threshold. In March, three apparently distinct events outlined a converging picture: the Dutch intelligence service AIVD-MIVD published a report documenting the systematic intensification of Russian hybrid operations across the continent; the Munich Security Report classified cyberattacks as the number-one risk for G7 nations for the first time in history; and the Council of the European Union adopted new sanctions against entities responsible for cyber attacks on member states. At the center of this convergence lies a specific actor: Sandworm, also known as APT44, the cyber-sabotage unit of Russia's GRU.
Sandworm/APT44: From the Ukrainian Blackout to the BadPilot Campaign
Sandworm is not an ordinary APT group. It is Unit 74455 of the GRU, Russia's military intelligence service, responsible for some of the most destructive attacks in the history of cybersecurity: the Ukrainian power grid blackout in 2015 and 2016, the 2017 NotPetya wiper that caused 10 billion dollars in global damages, and the attack on Viasat satellite systems in February 2022 that disrupted communications across the European Union in the hours preceding the invasion of Ukraine.
In January 2026, Microsoft and Amazon documented the "BadPilot" campaign: a systematic Sandworm operation exploiting misconfigured perimeter network devices, VPNs, and collaboration platforms to penetrate critical infrastructure in North America and Europe. The analysis by Barracuda Networks, published on March 16, 2026, confirms that the group is targeting specific sectors: energy (including oil & gas), telecommunications, maritime transport, the arms industry, and government agencies. The BadPilot campaign represents a significant tactical evolution: instead of custom malware, Sandworm leverages legitimate tools already present in target systems — the "living off the land" technique — making detection extremely difficult.
The DynoWiper malware, attributed to Sandworm in 2025-2026, is designed specifically for industrial control systems (ICS). It loads corrupted firmware into Remote Terminal Units (RTU), forcing them into infinite reboot loops, and simultaneously wipes human-machine interfaces (HMI). This dual vector — physical disruption + data erasure — represents the most dangerous evolution of OT sabotage.
The Power Grid as a Battlefield: Data from the Munich Security Report 2026
The Munich Security Report 2026 marked a turning point in European strategic discourse. For the first time, cyberattacks were classified as the number-one security risk for G7 nations, rising three positions compared to 2021. Germany recorded the highest cyber risk score (75 out of 100), with 73% of respondents considering a significant attack imminent and 39% doubting their country's preparedness. These data, coming from a context traditionally focused on conventional threats, signal that the European strategic community has reached a consensus on the severity of the cyber threat to energy infrastructure.
The report documents a dramatic escalation of Russian hybrid operations between 2022 and 2026. Researchers catalogued 219 incidents of suspected Russian hybrid warfare in Europe between 2014 and 2025, with 46% concentrated in 2024 alone, according to data cited by GLOBSEC. The operations include Russian drones in Polish airspace (September 2025), MiG-31 aircraft violating Estonian airspace for 12 minutes, sabotage of undersea infrastructure in the Baltic, and coordinated arson attacks. The cyber component of this hybrid campaign is not separate: it is integrated with kinetic operations in what analysts define as "blended cyber-kinetic operations".
The Dutch Intelligence Alarm and the Fountain Case
In March 2026, the Dutch services AIVD and MIVD published a joint report that stands as one of the most explicit documents ever produced by a European intelligence agency on the Russian threat. The report warns that Russia is preparing for a prolonged confrontation with the West through a systematic campaign combining cyber attacks, physical sabotage, and covert influence operations. The Dutch agencies document DDoS attacks against government websites, espionage operations that exfiltrated sensitive data from the police (the "Laundry Bear" case of September 2024), and attempts to manipulate European politicians.
An apparently trivial detail from the report merits analytical attention: hackers linked to Russia penetrated the control system of a public fountain in a Dutch city. The episode might seem insignificant, but it represents exactly the operational logic of Sandworm: testing access to low-risk civilian industrial control systems before striking high-value targets. It is the same approach documented before the attacks on the Ukrainian power grid — reconnaissance and capability validation on secondary objectives.
Russia has not only demonstrated the ability to absorb substantial losses in Ukraine, but has actually expanded and reformed its armed forces. This indicates Moscow's preparation for a sustained conflict.
— Joint AIVD-MIVD report, March 2026
The EU Sanctions of March 2026: A Diplomatic Response to the Cyber Threat
On March 16, 2026, the Council of the European Union adopted new restrictive measures against three entities and two individuals responsible for cyber attacks on member states. The sanctions targeted Integrity Technology Group (China), responsible for the compromise of over 65,000 devices in six member states between 2022 and 2023; Anxun Information Technology (China), a provider of targeted hacking services against critical infrastructure; and Emennet Pasargad (Iran), a front for Iranian cyberattacks including electoral interference in the United States and the attack on the French magazine Charlie Hebdo. The EU sanctions regime now counts 19 designated individuals and 7 designated entities, with an extension until May 18, 2026.
The sanctions signal an important evolution of the European "cyber diplomacy toolbox." However, the absence of Russian entities in the latest package — despite evidence documented by its own intelligence services — reveals internal political tensions within the EU over the management of the confrontation with Moscow. France, in the Ministry of Foreign Affairs communiqué of March 17, emphasized the need to target the "private offensive ecosystem" that enables state operations, suggesting that the next step could involve Russian cybersecurity companies operating as GRU contractors.
The Pre-Positioning Axis: Volt Typhoon and the Chinese Paradigm
The Russian campaign does not operate in isolation. The IISS (International Institute for Strategic Studies) analysis of January 2026 documents how Volt Typhoon, the Chinese group that infiltrated American critical infrastructure, is extending its operations beyond North America. CISA, FBI, and NSA have confirmed that Volt Typhoon maintains persistent access to critical infrastructure networks for potential destructive effects during future crises. The technique is identical to the modus operandi of Sandworm: silent pre-positioning through "living off the land," without detectable malware, with activation deferred to a moment of geopolitical crisis. The Finnish national security report of 2026 confirmed that both Russia and China are actively targeting government networks, technology companies, and research institutes, exploiting weaknesses in the supply chains of Western information systems.
The Google Threat Intelligence Report of February 2026 documented for the first time coordinated operations by China, Iran, Russia, and North Korea against the Western defense industrial base. This is not a formal coalition, but an operational convergence: four state actors striking the same sectors with complementary TTPs, creating a cumulative pressure that no single sectoral defense can contain.
The European Energy Sector: An Expanding Attack Surface
ENISA, in the Threat Landscape 2025, classified the energy sector as the second most targeted in the EU with 11.3% of significant incidents. The paradigmatic case remains the May 2023 attack on Denmark: 22 energy companies hit simultaneously in a two-wave operation — the first exploiting a zero-day in Zyxel firewalls, the second using techniques consistent with Sandworm — documented by the Danish SektorCERT. In 2022, the attack on Deutsche Windtechnik disconnected the remote monitoring of 2,000 wind turbines. These are not isolated incidents: they are operational tests to validate attack chains against the continental power grid.
The acceleration in the deployment of smart grid technologies, renewable energy assets, and connected industrial sensors is dramatically expanding the European OT attack surface. Every new connected device represents a potential entry point. The United Arab Emirates, in February 2026, was intercepting between 90,000 and 200,000 cyberattacks per day, with over 70% attributed to state actors — a figure that reflects the growing pressure on strategic energy infrastructure worldwide.
Implications for Italy and the Response Framework
Italy is particularly exposed. Its dependence on natural gas, interconnections with Mediterranean energy corridors, the presence of strategic NATO infrastructure, and an industrial fabric of SMEs with still-insufficient cybersecurity investments create a high-risk profile. The NIS2 directive, transposed in Italy through the 2024 legislative decree, imposes cybersecurity obligations on energy operators, transport, digital infrastructure, and critical supply chains — with penalties of up to 10 million euros or 2% of global turnover. But regulatory compliance is a necessary condition, not a sufficient one.
The Danish SektorCERT model — sectoral threat intelligence sharing and incident response coordination — represents a best practice that Italy should emulate through the national CSIRT and sectoral ISACs. The deeper challenge, however, is architectural in nature: OT networks designed decades ago for physical isolation are now exposed to the internet through digitalization. The migration toward zero-trust architectures for OT environments, rigorous IT/OT network segmentation, and the adoption of post-quantum cryptography to protect critical SCADA data from "harvest now, decrypt later" attacks are not strategic options — they are immediate operational necessities.
European intelligence estimates that Russia could launch localized operations within six months of a potential ceasefire in Ukraine, preceded by intensified cyberattacks against energy infrastructure, communication networks, and government systems. For every organization in the Italian energy sector, the time for an OT audit, a NIS2 gap analysis, and the implementation of network segmentation and post-quantum cryptography is now — not after the next incident.
Conclusion: Beyond Reactive Defense
The picture emerging from the convergence of Dutch intelligence, the Munich Security Report, the Finnish report, EU sanctions, and analyses by Google, Microsoft, and Barracuda Networks leaves no room for ambiguity. Russia is conducting a coordinated hybrid campaign against European infrastructure, with Sandworm/APT44 as its primary operational arm. China, through Volt Typhoon and Salt Typhoon, pursues a parallel pre-positioning strategy. Iran and North Korea add additional vectors through proxy hacktivists and ransomware. As the NATO Cyber Champions Summit in Prague on March 16, 2026 observed, the transition from "reactive defense" to "anticipatory resilience" is no longer a long-term objective: it is an immediate necessity for the operational survival of European critical infrastructure.