GlassWorm
Also known as Glassworm
Reports
6
First seen
May 26, 2026
Last seen
Aug 10, 2026
Motivation
Financial, Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Top ATT&CK techniques
T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools ×3T1219 Remote Access Software ×3T1071.001 Application Layer Protocol: Web Protocols ×3T1566 Phishing ×3T1041 Exfiltration Over C2 Channel ×2T1190 Exploit Public-Facing Application ×2T1195 Supply Chain Compromise ×2T1486 Data Encrypted for Impact ×2T1105 Ingress Tool Transfer ×2T1195.002 Supply Chain Compromise: Compromised Software Dependencies ×2T1071 Application Layer Protocol ×1T1552.007 Unsecured Credentials: Hardcoded Credentials ×1
Indicators
cve ×38filename ×2ip_v4 ×2domain ×1url ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-59199CVE-2026-0257 (exploited)CVE-2026-1402CVE-2026-2332CVE-2026-27771CVE-2026-32996CVE-2026-32997CVE-2026-33825 (exploited)CVE-2026-3593CVE-2026-40933CVE-2026-41089 (exploited)CVE-2026-4115CVE-2026-4480CVE-2026-44930CVE-2026-44962CVE-2026-45659CVE-2026-46775CVE-2026-46839CVE-2026-46840CVE-2026-47783
Recent reports
High