✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security
In Q2 2025, industrial automation systems worldwide experienced significant and persistent threats, with 20.5% of ICS (Industrial Control Systems) computers encountering malicious objects, despite a slight quarterly decrease. Attackers leveraged a multi-stage campaign, beginning with phishing emails and malicious documents to gain access, and subsequently deploying next-stage malware such as spyware, ransomware, and cryptominers. Regions like Africa and sectors such as biometrics were among the most targeted, while common initial infection sources included malicious internet resources, infected emails, and removable media devices. Multiple sophisticated malware families (over 10,000 variants) exploited ICS security gaps to enable lateral movement, persistent access, and data exfiltration, impacting operational resilience and increasing risk of service disruption for critical industries. This incident underscores the continued evolution of ICS-targeting malware and the increasing sophistication of attack vectors in the operational technology sector. The upward trend in email-based infiltration and malicious cloud links, coupled with persistent use of multi-stage payloads, highlights the urgent need for robust, layered security, Zero Trust policies, and compliance alignment to protect critical infrastructure environments against both commodity and targeted threats.
6 months ago
Kill Chain
Russian APTs Gamaredon and Turla Join Forces: Kazuar Backdoor Attack on Ukraine (2025)
In February 2025, cybersecurity researchers observed a coordinated attack on Ukrainian organizations involving collaboration between Russian APT groups Gamaredon and Turla. Utilizing tools such as PteroGraphin and PteroOdd, Gamaredon gained initial access and facilitated the deployment of Turla’s advanced Kazuar backdoor onto a compromised Ukrainian endpoint. This multi-stage intrusion enabled persistent remote access and potential data exfiltration, underscoring a notable escalation in Russian state-sponsored cyber tactics, as adversaries actively combined resources and malware capabilities to maximize operational impact. The attack targeted sensitive Ukrainian infrastructure, heightening concerns over the defense of critical systems. This incident exemplifies the increasing integration and sophistication among nation-state threat actors, specifically through sharing or chaining malware tools for greater effect. The cooperative tactics and advanced persistence mechanisms highlight the evolving threat landscape and emphasize the urgency for enhanced east-west traffic security, zero trust segmentation, and anomaly detection across critical sectors.
6 months ago
Kill Chain
UNC1549: Iranian Cyber Espionage Breaches 11 European Telecoms Using LinkedIn Lures
In mid-2025, an Iran-affiliated cyber espionage group tracked as UNC1549 executed a coordinated attack targeting 11 European telecommunications firms. Using LinkedIn job recruitment lures and the custom MINIBIKE malware, the attackers successfully infiltrated 34 devices within these organizations, gaining persistent access to sensitive internal systems. The campaign, discovered by Swiss cybersecurity company PRODAFT, leveraged sophisticated social engineering alongside stealthy lateral movement, indicating considerable operational capability and intent to harvest confidential information potentially valuable for nation-state interests. This incident underscores a rising trend of strategic supply chain and telecom attacks using spear phishing and novel malware, highlighting the importance of strong east-west traffic controls and threat detection. It also reflects growing geopolitical tensions fueling state-sponsored cyber campaigns against critical infrastructure in Europe.
6 months ago
Kill Chain
Charming Kitten’s 2024 Campaign: Telecoms and Satellite Companies Breached by Iranian APT
In early 2024, an Iranian state-linked advanced persistent threat (APT) group known as "Subtle Snail," associated with Charming Kitten, executed a series of highly customized cyberattacks targeting 11 global telecommunications, satellite operators, and aerospace manufacturers. The attackers, leveraging detailed reconnaissance via LinkedIn and other platforms, impersonated recruiters from major aerospace firms to lure high-value IT and engineering personnel into sophisticated spearphishing campaigns. Victims were tricked into downloading a modular backdoor malware dubbed 'MiniBike,' which allowed the group to evade detection through unique variants for each target. The breaches resulted in the theft of sensitive documents, credentials, personally identifiable information, proprietary business data, and call data records, posing significant risks to corporate and national security across regions from the Middle East to North America. This attack highlights sharply increased innovation in APT social engineering tactics and malware obfuscation. It underscores the need for organizations to bolster identity verification, east-west segmentation, and behavioral anomaly detection, especially as state-aligned threat actors refine tools for targeting critical infrastructure and global communications.
6 months ago
Kill Chain
Chinese APT Bypasses Philippine Military Defenses with EggStreme Fileless Malware (2025)
In September 2025, a Chinese advanced persistent threat (APT) group breached a Philippines-based military company using a sophisticated multi-stage attack leveraging the novel fileless malware framework, EggStreme. According to Bitdefender, the attackers achieved persistence and stealth by injecting their malicious code directly into memory and utilizing DLL sideloading to execute payloads without writing files to disk. This allowed them to maintain an undetected presence, conduct espionage, and potentially exfiltrate sensitive military and government data. The breach underscores ongoing risks to national security organizations from highly resourced nation-state actors employing advanced techniques. This incident highlights the emergence of more evasive, memory-resident malware frameworks targeting defense and critical infrastructure. Fileless attack methods such as those used by EggStreme are increasingly common and harder to detect, urging organizations to adopt advanced threat detection, improved segmentation, and robust incident response capabilities.
6 months ago
Kill Chain
Mustang Panda’s SnakeDisk USB Worm Targets Thailand: Advanced APT Breach Breakdown
In September 2025, cybersecurity analysts revealed that the China-aligned APT group Mustang Panda leveraged a novel USB worm dubbed SnakeDisk to target networks with Thailand-based IP addresses. The malware was specifically designed to execute only on devices with these geolocations, enabling highly targeted delivery of the TONESHELL loader and the Yokai backdoor. Attackers gained initial access through infected USB drives, allowing for stealthy lateral movement and installation of persistent remote access tools, posing risks to government, defense, and commercial operations in Thailand. The campaign’s use of an undocumented worm, encrypted command channels, and evasive tactics complicated detection and response efforts for affected organizations. This highly targeted operation demonstrates the continuous evolution of advanced persistent threat techniques, with regional targeting and removable media attacks making a significant comeback. The incident underscores the urgent need for robust east-west traffic controls, endpoint security, and focused detection in the face of increasingly sophisticated nation-state cyber campaigns.
6 months ago
Kill Chain
Chinese Hackers Impersonate US Congressman in Sophisticated 2024 Spear-Phishing Campaign
In early 2024, Chinese state-sponsored hackers allegedly orchestrated spear-phishing attacks by impersonating Michigan Congressman John Moolenaar. The threat actors crafted convincing emails designed to gain the trust of recipients, targeting government and private sector individuals. Using tailored messaging, the adversaries sought to trick victims into engaging with malicious links or attachments, potentially enabling credential theft, malware installation, or further lateral movement within targeted organizations. The incident demonstrates the growing sophistication and persistence of social engineering tactics deployed by advanced persistent threat (APT) groups with strategic intelligence-gathering objectives. This attack reflects a broader rise in politically themed spear-phishing campaigns leveraging impersonation of public officials to increase credibility. Organizations must remain alert as nation-state groups continually evolve their tactics, conducting highly targeted attacks that bypass technical safeguards and prey on human vulnerabilities.
6 months ago
Kill Chain
North Korean Kimsuky Leverages Deepfake Military IDs in Sophisticated Social Engineering Attack
In April 2024, threat group Kimsuky, attributed to North Korea, launched a cyberattack campaign targeting South Korean organizations using advanced social engineering tactics. The attackers exploited ChatGPT to generate sophisticated deepfake military ID documents, which were then used as bait to compromise targets via phishing emails and messaging apps. By mimicking authentic credentials, Kimsuky aimed to breach sensitive military and governmental networks, potentially facilitating credential harvesting and further lateral movement within critical infrastructures. This incident highlights the increasing convergence of generative AI and cyberattack techniques, making impersonation and credential-based attacks far more convincing and widespread. It underscores rising urgency for organizations to strengthen verification processes and stay vigilant against emerging deepfake-enabled attack vectors.
6 months ago
Kill Chain
Exploits for Dassault DELMIA Apriso RCE (CVE-2025-5086) Target Manufacturing Operations
In June 2025, Dassault Systèmes disclosed a critical deserialization vulnerability (CVE-2025-5086) in its DELMIA Apriso Manufacturing Operation Management system, affecting releases from 2020 through 2025. Attackers exploited this remote code execution flaw via crafted SOAP requests containing malicious serialized data, enabling them to upload and execute arbitrary Windows executables on vulnerable servers. The exploit activity, orchestrated through automated scanners—some associated with the Project Discovery framework—originated from multiple geographies and targeted the core manufacturing process integration point, posing risks to operational uptime and potential lateral movement within enterprise environments. This incident underscores the growing threat targeting industrial control applications and critical infrastructure through software supply chain vulnerabilities. Exploiting deserialization bugs in widely deployed operational technology platforms has become a preferred method for threat actors, highlighting the urgent need for timely patching, application-layer anomaly detection, and zero trust segmentation within manufacturing and industrial settings.
6 months ago
Kill Chain
DSLRoot & the Legal Botnet Threat: How Proxy Networks Create Global Security Gaps
In August 2025, longstanding residential proxy provider DSLRoot was exposed for recruiting US residents to host dedicated proxy devices on their home Internet lines, including high-risk individuals such as a U.S. Air National Guard member with top-secret clearance. The company, with origins and affiliations in Russia and Eastern Europe, leverages consent-based proxy networks—sometimes referred to as 'legal botnets'—enabling anonymized traffic redirection and potential abuse by third parties. DSLRoot's proxies are promoted on underground forums and have leveraged adware pay-per-install schemes, bypassing traditional ISP terms and offering services worldwide. The incident raised concerns about unmanaged East-West network traffic, lack of egress controls, and gaps in threat detection on residential endpoints, highlighting the ease with which attackers or unauthorized users can exploit commoditized infrastructure for fraud, anonymity, or more severe criminal purposes. This case underscores the growing risks of proxy network abuse, which threatens both enterprise and government environments by eroding identity controls and facilitating untraceable activity. The increasing prevalence of 'legal botnets' fueled by incentives and lax regulation makes this a high-priority issue for organizations seeking to enforce policy, maintain compliance, and detect anomalous traffic patterns across diverse environments.
6 months ago
Kill Chain
APT28 Exploits Microsoft Outlook: Inside the 2024 NotDoor Backdoor Attack
In 2024, the Russian state-sponsored group APT28 (also known as Fancy Bear) leveraged a new backdoor called "NotDoor" to infiltrate targeted organizations via Microsoft Outlook. Researchers from Lab52 revealed that attackers delivered NotDoor using DLL sideloading through OneDrive.exe, enabling them to bypass Outlook's macro security and gain persistent access. Once deployed, NotDoor monitored incoming Outlook emails for specific trigger words, allowing APT28 to exfiltrate sensitive data, upload malicious files, and execute remote commands without detection. Outlook's native functions were abused to provide covert communications and stealthy data transfers, making detection difficult. This incident illustrates the continued evolution of state-sponsored attack methods, especially the abuse of ubiquitous business software like Microsoft Outlook for stealthy, command-and-control operations. Organizations face mounting pressure to address advanced persistent threats exploiting native application behaviors and to enhance email and endpoint security in response to these sophisticated tactics.
6 months ago
Kill Chain
CISA, FBI, and NSA Warn: China-Backed APTs Compromise Global Critical Infrastructure
In June 2024, leading international cybersecurity agencies—including the CISA, FBI, and NSA—issued a joint advisory detailing the extensive, multi-year espionage campaign attributed to Chinese state-backed actors such as Salt Typhoon. These APTs have targeted critical infrastructure sectors including telecommunications, government, transportation, and defense, largely by exploiting known vulnerabilities in network hardware like routers and firewalls since at least 2021. Attackers leveraged tactics such as modifying access control lists, opening non-standard ports, establishing persistent footholds, and actively capturing sensitive network traffic for credential harvesting, with the aim of gaining long-term, stealthy access and potential disruption capability across global networks. This incident underscores a major strategic escalation from pure data theft to pre-positioning for possible future disruption of vital services. Organizations face heightened pressure to implement robust detection, network segmentation, and security hardening, as state-sponsored campaigns become more brazen and influential across global critical systems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports