The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
Mustang Panda’s 2025 Cyber Espionage: Updated COOLCLIENT Backdoor Hits Government
In late 2025, cyber espionage group Mustang Panda (also known as Earth Preta and Twill Typhoon) launched a series of targeted attacks against government entities, deploying an updated version of the COOLCLIENT backdoor. These intrusions leveraged spear-phishing and custom malware to establish persistent access, exfiltrate sensitive government data, and conduct surveillance. The campaign relied on advanced command-and-control infrastructure and encrypted traffic to evade detection, demonstrating the group’s evolving tactics and technical sophistication. The breach resulted in notable data theft and highlighted vulnerabilities in governmental East-West network security and policy enforcement. This incident underscores a rising trend of state-sponsored attackers continuously updating malware toolsets and intensifying operations against government organizations. The sophistication and stealth of these campaigns demand enhanced data protection, visibility, and zero trust network controls to meet regulatory and operational requirements.
7 months ago
Kill Chain
Pakistan-Linked APT Launches Gopher Strike & Sheet Attack Against Indian Government in 2025
In September 2025, cybersecurity researchers uncovered coordinated cyber campaigns—dubbed Gopher Strike and Sheet Attack—targeting Indian government entities. Attributed to a Pakistan-linked Advanced Persistent Threat (APT) group, the operations leveraged novel, undocumented tactics involving phishing and multi-stage malware to compromise government networks. Attackers exploited existing security gaps, conducted lateral movement, and exfiltrated sensitive data, threatening the confidentiality and integrity of official communications. The campaigns remained undetected for an extended period, highlighting the advanced tradecraft and persistent nature of the threat actor. These incidents underscore the growing risk posed by state-aligned actors employing increasingly sophisticated tactics to target critical government infrastructure. The discovery of new tools and techniques in these attacks signals an escalation in South Asian regional cyber conflict and emphasizes the need for updated security controls and rapid detection capabilities.
8 months ago
Kill Chain
Sandworm’s 2025 DynoWiper Attack on Poland’s Power Grid: Lessons in Critical Infrastructure Resilience
In late 2025, a highly targeted cyberattack attributed to the Sandworm group struck Poland's national power grid. Using custom data-wiping malware identified as DynoWiper, the attackers infiltrated critical infrastructure networks, demonstrating sophisticated knowledge of operational technology environments. The initial compromise involved lateral movement through segmented OT/IT networks, facilitated by exploitation of unprotected east-west traffic and weak segmentation controls. The subsequent deployment of DynoWiper caused destructive impacts, including service outages and loss of operational data across several regional substations, with cascading effects on grid stability and dependent sectors. Immediate containment was complicated by attacker persistence and the rapid spread of the wiper. This incident underscores the rising trend of advanced, nation-state wiper malware targeting critical infrastructure, reflecting a shift from espionage to destructive tactics. Organizations face elevated urgency to harden network segmentation, implement robust egress security, and adopt zero trust operational models in light of these evolving threats.
8 months ago
Kill Chain
GitLab Faces Critical 2FA Bypass and DoS Vulnerabilities in 2026
In January 2026, GitLab urgently patched several high-severity vulnerabilities affecting its widely used Community and Enterprise Editions. The most critical issue, tracked as CVE-2026-0723, allowed attackers with knowledge of a user's account ID to bypass two-factor authentication controls by submitting forged device responses, resulting from unchecked return values in authentication services. In addition, GitLab addressed multiple denial-of-service (DoS) vulnerabilities, including CVE-2025-13927 and CVE-2025-13928, which potentially let unauthenticated threat actors trigger service outages through malformed authentication data and improper API endpoint authorization checks. Immediate patches were released to mitigate the risks of account takeover, service disruption, and operational downtime across a user base spanning major enterprises and nearly 6,000 exposed internet-facing instances. This breach stands out in the context of rising attacks exploiting authentication weaknesses and API logic flaws across the software supply chain. As critical open-source DevSecOps platforms like GitLab underpin enterprise workflows, attackers increasingly target authentication and availability gaps, aligning with regulatory scrutiny and the growing demand for robust zero trust controls.
8 months ago
Kill Chain
North Korea Supply Chain Attack Exploits VS Code Projects – 2026 Analysis
In January 2026, cybersecurity researchers uncovered a sophisticated supply chain attack targeting software developers via malicious Visual Studio Code (VS Code) projects. Threat actors linked to North Korea's Contagious Interview campaign distributed weaponized VS Code samples to compromise developer endpoints and install covert backdoors. Once inside victims' systems, the attackers could move laterally, exfiltrate sensitive source code, and access development infrastructure, risking intellectual property, customer data, and supply chain integrity. The campaign represents an evolution of social engineering tactics and demonstrates the attackers’ focus on high-leverage targets within the tech sector. This incident is highly relevant as it underscores the growing trend of software supply chain attacks leveraging development environments and trusted open-source platforms. Organizations must now reassess third-party code risks and developer security, as attackers increasingly exploit toolchains and social-engineering techniques instead of perimeter defenses.
8 months ago
Kill Chain
Google Pixel 9 (2026): Zero-Click BigWave Driver Breach Exposes Kernel Vulnerabilities
In January 2026, Google Pixel 9 devices were found vulnerable to a sophisticated zero-click exploit chain targeting the Android BigWave hardware driver. Attackers combined a remote code execution exploit affecting a Dolby decoder with a privilege escalation flaw in the /dev/bigwave device, accessible from the mediacodec SELinux sandbox. The chain allowed attackers to escape the sandbox, bypass SELinux protections, and achieve kernel-level arbitrary read/write, essentially gaining full device control. This exploit enabled unauthorized access to sensitive data and even allowed remote data exfiltration by attackers, severely compromising device security. This incident highlights the increasing sophistication of exploit chains leveraging hardware-specific drivers and sandbox escape techniques in mobile ecosystems. With the rise in supply chain threats, use of AI to automate exploit engineering, and growing pressure from privacy regulators, organizations face escalating risks from zero-day attacks targeting embedded devices.
8 months ago
Kill Chain
Black Basta Ransomware Boss Named, Placed on Interpol Red Notice in Major 2026 Crackdown
In January 2026, international law enforcement, led by Ukraine and Germany, identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware-as-a-service (RaaS) gang. Authorities added Nefedov to Interpol's 'Red Notice' and Europol's 'Most Wanted' lists, following coordinated raids that apprehended affiliates specializing in breaching corporate systems, cracking passwords, and escalating privileges to facilitate attacks. Black Basta has been attributed to over 600 global cyber incidents targeting enterprises in sectors from defense to healthcare, employing ransomware and data extortion to extract payments and exfiltrate sensitive information. This incident is significant as it marks one of the first times a major ransomware operation's leadership was officially unmasked and targeted with international warrants. The Black Basta takedown reflects increasing sophistication and coordination in responses to organized cybercrime, underscoring the persistent threat posed by ransomware groups and their rapid evolution post-Conti.
8 months ago
Kill Chain
Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign
Between October and December 2025, Ukraine's Defense Forces were targeted by a sophisticated malware campaign attributed to the Russian-linked threat group 'Void Blizzard' (also known as 'Laundry Bear'). Attackers leveraged instant messaging apps like Signal and WhatsApp, using compelling charity-themed lures to trick recipients into downloading a password-protected archive. Inside, the PluggyApe backdoor—bundled as disguised executables—provided remote access to compromised hosts, stealing sensitive data and awaiting additional commands. The malware's second-generation included enhanced obfuscation, anti-analysis techniques, and a novel approach to fetching command-and-control addresses from public services like Pastebin. This campaign reflects the escalating use of social engineering, mobile device targeting, and supply chain tactics by state-aligned groups in espionage operations. It highlights the urgent need for stronger endpoint protection, policy enforcement, and continuous monitoring across both traditional and mobile attack surfaces.
8 months ago
Kill Chain
PLUGGYAPE Malware Campaign Exposes Messenger Security Gaps in Ukraine’s Defense Sector
Between October and December 2025, Ukrainian defense forces were targeted by cyber espionage campaigns conducted by the Russian-linked group known as Void Blizzard (aka Laundry Bear or UAC-0190). Using popular messaging platforms Signal and WhatsApp, attackers posed as charity organizations and tricked victims into downloading password-protected archives containing a Python-based backdoor, PLUGGYAPE. The malware, distributed through well-crafted social engineering and employing techniques such as obfuscated payloads and anti-analysis, enabled remote command execution and data theft. Attackers further enhanced operational security using external paste services for command-and-control server updates, rendering infrastructure takedowns less effective while maintaining persistent access on compromised hosts. This breach underscores the growing sophistication of social engineering and the exploitation of widely trusted communication platforms for initial access. The incident highlights not only ongoing threat activity against critical state functions but also the evolving nature of cyber threats adapting to countermeasures, necessitating enhanced vigilance and reformulated defense postures across the public and private sectors.
8 months ago
Kill Chain
China-Nexus Hackers Breach Telecoms via Edge Device Exploitation
In January 2026, a sophisticated cyber-espionage campaign attributed to China-linked group UAT-7290 targeted telecommunications providers across South Asia and Southeastern Europe. The threat actors exploited known vulnerabilities in edge network devices using one-day exploits and targeted SSH brute-forcing for initial access, quickly escalating privileges and deploying Linux-based malware such as RushDrop, DriveSwitch, SilentRaid, and Bulbature. Their activities included extensive reconnaissance, persistent backdoor deployment, and converting compromised servers into operational relay boxes for further attacks, causing significant risk to sensitive communications infrastructure. This incident highlights escalating threats to critical telecom sectors, as state-affiliated actors increasingly leverage public exploits and shared toolkits for multi-layered attacks. Such breaches underscore urgent needs for proactive edge device security and improved lateral movement detection strategies amid rising geopolitical cyber operations.
8 months ago
Kill Chain
APT28 Targets Energy and Policy Sectors With Sophisticated Credential Phishing (2025)
Between February and September 2025, Russian state-sponsored APT28 (aka BlueDelta, linked to the GRU) launched highly targeted credential-harvesting attacks against individuals in Turkish energy and nuclear agencies, a European think tank, and organizations in North Macedonia and Uzbekistan. The campaign relied on phishing emails with region-specific lures and fake login pages imitating Microsoft OWA, Google, and Sophos VPN portals. Stolen credentials were exfiltrated via disposable internet services, and victims were seamlessly redirected to legitimate sites to avoid suspicion, evading typical detection methods. Notably, attackers leveraged legitimate PDF documents themed around high-profile geopolitical events as decoy content. These incidents underscore the increasing sophistication and operational focus of nation-state phishing campaigns, with attackers rapidly exploiting current geopolitical tensions to credibly target sensitive sectors. Repeated use of trusted public infrastructure for data exfiltration further complicates defense and detection efforts.
8 months ago
Kill Chain
Fancy Bear’s 2024 Credential Attacks: The Global Secrets Heist Reinvented
In early 2024, the Russian state-sponsored threat group APT28 (also known as Fancy Bear) intensified credential-harvesting campaigns targeting global governmental and enterprise networks. Leveraging basic techniques such as phishing and exploitation of unencrypted or weakly protected authentication channels, the attackers maintained persistent access and exfiltrated sensitive secrets across multiple sectors. The operations demonstrated a preference for cost-effective methods, including the abuse of stolen credentials, rather than relying on advanced custom malware—resulting in widespread data exposure and persistent breaches with significant geopolitical ramifications. This incident highlights the increasing sophistication of threat actors’ social engineering and credential-focused tactics, signaling a shift in espionage campaigns worldwide. As traditional perimeter defenses become less effective against targeted, credential-driven attacks, organizations face renewed urgency to adopt zero trust models, strong encryption, and robust monitoring to combat these persistent threats.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports