The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
North Korea’s Lazarus Group Breaches Drone Developers in 2023 Cyber-Espionage Campaign
In March 2023, the Lazarus Group—an advanced persistent threat attributed to North Korea—successfully targeted three European companies in the defense sector involved in drone development. Leveraging Operation DreamJob, the attackers used social engineering tactics, including fraudulent job offers and a trojanized PDF reader, to gain initial access via phishing emails. The deployment of the ScoringMathTea remote access trojan enabled complete control over compromised systems, potentially allowing sensitive data exfiltration related to unmanned aerial vehicle (UAV) technology and manufacturing know-how. ESET researchers linked the attack to ongoing North Korean efforts to bolster domestic drone capabilities and noted the victims' support of military deployments in Ukraine. The incident exemplifies the persistent and adaptive nature of sophisticated state-linked cyber-espionage campaigns targeting high-value defense technologies. As strategic competition and armed conflicts persist, such tactics have become more prevalent against organizations with intellectual property critical to national security.
8 months ago
Kill Chain
Lazarus APT Penetrates European Defense Firms with Fake Job Lures in 2024
In early 2024, the North Korean state-sponsored Lazarus Group orchestrated a targeted cyberattack against at least three European defense sector companies. Using a spear-phishing strategy known as 'Operation DreamJob,' attackers impersonated defense recruiters, luring employees with fake job offers and malicious documents. Once compromised, the attackers gained unauthorized access, moved laterally within victims' networks, and exfiltrated sensitive corporate and government data with minimal detection. The sophistication and persistence demonstrated in this operation highlight the evolving threat landscape posed by well-resourced APT actors. This campaign underscores the escalating risks facing critical industries from nation-state cyber espionage. As advanced phishing and lateral movement techniques proliferate, even mature security programs remain vulnerable to targeted, multi-stage attacks from groups like Lazarus.
8 months ago
Kill Chain
North Korean APTs Breach UAV Defense Firms Using Fake Job Offers (2025)
In October 2025, multiple European defense contractors specializing in unmanned aerial vehicles (UAVs) were targeted by a sophisticated cyber-espionage campaign attributed to North Korean threat actors, commonly known as Lazarus Group. The attackers masqueraded as recruiters and leveraged convincing fake job offers to defense engineers using social networks and spear-phishing emails, ultimately delivering malicious payloads that provided remote access to corporate networks. The primary objective was to exfiltrate proprietary drone technology and sensitive internal communications, resulting in significant intellectual property theft and exposure of confidential project details. This incident illustrates a persistent trend where state-sponsored actors target the defense sector’s engineers with social engineering tactics, reflecting a broader escalation in advanced persistent threat (APT) campaigns leveraging human-centric attack vectors. Organizations face mounting regulatory scrutiny and must enhance security controls to combat these evolving social-engineering-enabled threats.
8 months ago
Kill Chain
Inside the 2024 Lazarus Group Attack on European Drone Manufacturers
In early 2024, the North Korean-backed Lazarus Group launched a sophisticated cyber-espionage campaign targeting multiple European drone manufacturers. The operation leveraged spear-phishing emails and custom malware to gain unauthorized access to sensitive research, development, and operational data. After establishing persistence, attackers conducted lateral movement across corporate networks and exfiltrated significant volumes of intellectual property and proprietary technology aligning with North Korea's strategic interests. The breach undermined victims’ competitive advantage, presented potential national security risks, and exposed critical supply chain vulnerabilities. The incident underscores the escalation of state-sponsored attacks against the European defense and aerospace sector. As APT groups like Lazarus intensify targeting of high-innovation industries using stealthy techniques, organizations face mounting pressure to strengthen east-west traffic monitoring, encryption practices, and zero trust segmentation.
8 months ago
Kill Chain
Over 100 Government Agencies Breached by Iranian MuddyWater APT with Phoenix Backdoor
In early 2024, the Iranian state-sponsored threat group MuddyWater executed widespread attacks leveraging the Phoenix backdoor (version 4), successfully targeting over 100 government entities worldwide. The campaign exploited spear-phishing and malicious document attachments to deliver the backdoor, enabling persistent access, lateral movement, and data exfiltration from compromised systems. This sophisticated intrusion allowed the attackers to maintain a long-term foothold within highly sensitive government networks, posing significant operational and intelligence risks across multiple regions. This incident underscores a sharp escalation in advanced persistent threat (APT) tactics targeting public sector organizations. It highlights both the evolving sophistication and relentless nature of nation-state cyber operations, amplifying regulatory and operational pressure on government organizations to strengthen east-west traffic security, anomaly detection, and Zero Trust segmentation strategies.
8 months ago
Kill Chain
PassiveNeuron APT: 2024 Cyber Espionage Targets Asia, Africa & LatAm with Neursite Malware
In late 2024, cybersecurity researchers identified a sophisticated cyber espionage campaign targeting government, financial, and industrial organizations across Asia, Africa, and Latin America. Dubbed "PassiveNeuron," the operation leveraged custom malware strains, Neursite and NeuralExecutor, deployed by an advanced persistent threat (APT) group to infiltrate networks, maintain persistence, and exfiltrate sensitive data over several months. The entry vector appears to involve highly targeted spear-phishing and exploitation of vulnerable internet-facing assets, allowing attackers to bypass perimeter defenses and conduct stealthy lateral movement. The attack resulted in significant exposure of confidential communications and potentially state or financial secrets, raising concerns among affected sectors and governments. This incident exemplifies ongoing evolution in state-sponsored cyber attacks, with advanced malware leveraging encrypted traffic and zero trust evasion techniques. Given the increasingly global scope of APT operations and regulatory pressure on critical sectors, organizations must reexamine east-west security, policy enforcement, and anomaly detection capabilities to mitigate rising espionage risks.
8 months ago
Kill Chain
Flax Typhoon Turns ArcGIS Geo-Mapping Server into APT Backdoor
In early 2024, Chinese state-sponsored threat group Flax Typhoon compromised an organization’s ArcGIS geospatial mapping server, turning the platform into a covert backdoor for persistent access. The attackers exploited vulnerabilities and weak segmentation, modifying core ArcGIS components to avoid detection while establishing reliable remote control and lateral movement capabilities. This stealthy intrusion allowed for unauthorized data access without typical alert triggers, posing significant operational and reputational risks for the victim, and demonstrated advanced tactics utilized by APT groups targeting critical infrastructure software. This incident highlights a growing trend where APTs compromise auxiliary business applications—like geo-mapping and analytics platforms—to evade detection and spread across internal networks. Organizations must reassess east-west security, encrypted traffic visibility, and zero trust segmentation to keep pace with evolving attacker tradecraft.
8 months ago
Kill Chain
China’s AI-Driven APT Attack Chains Breach Taiwan’s Defenses
In early 2024, a sophisticated China-linked threat group launched a series of cyberattacks against major Taiwanese government agencies and critical infrastructure providers. Leveraging AI-optimized attack chains, the attackers automated reconnaissance, lateral movement, and customized payload delivery to bypass traditional defenses. The campaign used a combination of phishing emails, zero-day vulnerabilities, and covert encrypted traffic to infiltrate networks, evade detection, and exfiltrate sensitive government data. Operational disruptions and risk of classified information exposure heightened tensions amid ongoing geopolitical strains. These incidents signal an evolution in state-sponsored cyber operations, marked by the integration of artificial intelligence for more adaptive, stealthy attacks. Organizations should be urgently evaluating east-west segmentation, anomaly detection, and compliance readiness in response to the surge of AI-enhanced persistent threats.
8 months ago
Kill Chain
Laser Attacks on Vehicle Microchips: New Frontiers in Auto Cybersecurity
In 2024, security researchers demonstrated a novel cyberattack targeting automotive microchips using precisely aligned laser beams. The attack exploited fundamental hardware vulnerabilities, allowing adversaries to manipulate or extract data from silicon chips embedded in modern vehicles. By directing lasers at sensitive circuits, attackers could trigger faults, bypass certain security controls, and potentially gain access to encrypted data streams or control automotive systems. The proof-of-concept underscores critical exposure across connected and autonomous vehicles, as physical access to components can enable advanced attacks beyond the reach of traditional software-based defenses. This incident is particularly relevant as vehicles and other IoT systems grow increasingly reliant on sophisticated microelectronics. The emergence of physical-layer hardware attacks highlights the urgent need for new security architectures, including microchip hardening and multi-layered threat detection, to counter evolving risks in transportation and critical infrastructure.
8 months ago
Kill Chain
ColdRiver Malware Surge: 2024 Espionage Attack Analysis
In early 2024, the Russia-linked threat group ColdRiver launched a fresh cyber espionage campaign targeting Western government entities, research institutions, and non-governmental organizations. Exploiting spear-phishing emails laden with custom-designed malware, the attackers accessed sensitive emails and files by leveraging well-crafted lures and technical evasion methods. The operation showcased ColdRiver’s rapid adaptation: when prior campaign tactics were exposed, the group swiftly pivoted to deploy new malware strains and infrastructure, signifying a high level of technical agility. The impact included unauthorized data access, intelligence gathering, and operational disruptions for targeted organizations. This incident stands out due to its demonstration of how quickly sophisticated espionage actors can update their tactics in response to detection. With global instability rising and state-aligned groups escalating campaigns, the rapid agility in threat activity puts extra pressure on organizations to strengthen detection and incident response protocols.
8 months ago
Kill Chain
MuddyWater Hits Middle East Governments: Phishing, Phoenix Backdoor & VPN Abuse
In early 2024, the Iranian state-sponsored group MuddyWater orchestrated a large-scale spear-phishing campaign targeting over 100 government entities across the Middle East and Africa. Attackers leveraged a compromised mailbox and NordVPN to distribute phishing emails enticing recipients to enable malicious macros. This led to the deployment of the Phoenix backdoor, providing attackers with persistent access and the ability to move laterally within targeted organizations’ networks, thereby raising concerns over significant data exposure and long-term espionage. The MuddyWater incident exemplifies the growing sophistication and scale of nation-state phishing campaigns. Recent trends show attackers are rapidly adapting credential theft and post-exploitation tactics to bypass traditional defenses. Government entities face mounting regulatory and operational pressure to address advanced persistent threats exploiting email and remote access.
8 months ago
Kill Chain
How Flax Typhoon Used ArcGIS Server as a Backdoor: 2025 Breach Breakdown
In mid-2025, threat intelligence researchers uncovered a year-long, state-sponsored attack committed by Chinese APT group Flax Typhoon (also known as Ethereal Panda/RedJuliett). The group exploited unpatched ArcGIS servers to establish persistent unauthorized access and covertly operated a backdoor for over twelve months. Using sophisticated techniques to evade detection and maintain long-term access, the attackers leveraged lateral movement and encrypted communication within targeted networks. The breach compromised sensitive data and potentially exposed critical infrastructure, highlighting a significant risk to affected organizations. This incident exemplifies a growing threat from well-resourced nation-state actors targeting enterprise geospatial systems, exploiting overlooked or under-patched software for initial entry. Attacks on infrastructure platforms are increasingly sophisticated, raising urgency for IT and security leaders to enhance detection, zero trust segmentation, and patch management programs in response to evolving APT campaigns.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports