The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 31 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 361–372 / 418 reports
North Korea’s Lazarus Group Breaches Drone Developers in 2023 Cyber-Espionage Campaign
Impact· medium

North Korea’s Lazarus Group Breaches Drone Developers in 2023 Cyber-Espionage Campaign

In March 2023, the Lazarus Group—an advanced persistent threat attributed to North Korea—successfully targeted three European companies in the defense sector involved in drone development. Leveraging Operation DreamJob, the attackers used social engineering tactics, including fraudulent job offers and a trojanized PDF reader, to gain initial access via phishing emails. The deployment of the ScoringMathTea remote access trojan enabled complete control over compromised systems, potentially allowing sensitive data exfiltration related to unmanned aerial vehicle (UAV) technology and manufacturing know-how. ESET researchers linked the attack to ongoing North Korean efforts to bolster domestic drone capabilities and noted the victims' support of military deployments in Ukraine. The incident exemplifies the persistent and adaptive nature of sophisticated state-linked cyber-espionage campaigns targeting high-value defense technologies. As strategic competition and armed conflicts persist, such tactics have become more prevalent against organizations with intellectual property critical to national security.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Lazarus APT Penetrates European Defense Firms with Fake Job Lures in 2024
Impact· low

Lazarus APT Penetrates European Defense Firms with Fake Job Lures in 2024

In early 2024, the North Korean state-sponsored Lazarus Group orchestrated a targeted cyberattack against at least three European defense sector companies. Using a spear-phishing strategy known as 'Operation DreamJob,' attackers impersonated defense recruiters, luring employees with fake job offers and malicious documents. Once compromised, the attackers gained unauthorized access, moved laterally within victims' networks, and exfiltrated sensitive corporate and government data with minimal detection. The sophistication and persistence demonstrated in this operation highlight the evolving threat landscape posed by well-resourced APT actors. This campaign underscores the escalating risks facing critical industries from nation-state cyber espionage. As advanced phishing and lateral movement techniques proliferate, even mature security programs remain vulnerable to targeted, multi-stage attacks from groups like Lazarus.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
North Korean APTs Breach UAV Defense Firms Using Fake Job Offers (2025)
Impact· medium

North Korean APTs Breach UAV Defense Firms Using Fake Job Offers (2025)

In October 2025, multiple European defense contractors specializing in unmanned aerial vehicles (UAVs) were targeted by a sophisticated cyber-espionage campaign attributed to North Korean threat actors, commonly known as Lazarus Group. The attackers masqueraded as recruiters and leveraged convincing fake job offers to defense engineers using social networks and spear-phishing emails, ultimately delivering malicious payloads that provided remote access to corporate networks. The primary objective was to exfiltrate proprietary drone technology and sensitive internal communications, resulting in significant intellectual property theft and exposure of confidential project details. This incident illustrates a persistent trend where state-sponsored actors target the defense sector’s engineers with social engineering tactics, reflecting a broader escalation in advanced persistent threat (APT) campaigns leveraging human-centric attack vectors. Organizations face mounting regulatory scrutiny and must enhance security controls to combat these evolving social-engineering-enabled threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Inside the 2024 Lazarus Group Attack on European Drone Manufacturers
Impact· low

Inside the 2024 Lazarus Group Attack on European Drone Manufacturers

In early 2024, the North Korean-backed Lazarus Group launched a sophisticated cyber-espionage campaign targeting multiple European drone manufacturers. The operation leveraged spear-phishing emails and custom malware to gain unauthorized access to sensitive research, development, and operational data. After establishing persistence, attackers conducted lateral movement across corporate networks and exfiltrated significant volumes of intellectual property and proprietary technology aligning with North Korea's strategic interests. The breach undermined victims’ competitive advantage, presented potential national security risks, and exposed critical supply chain vulnerabilities. The incident underscores the escalation of state-sponsored attacks against the European defense and aerospace sector. As APT groups like Lazarus intensify targeting of high-innovation industries using stealthy techniques, organizations face mounting pressure to strengthen east-west traffic monitoring, encryption practices, and zero trust segmentation.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Over 100 Government Agencies Breached by Iranian MuddyWater APT with Phoenix Backdoor
Impact· low

Over 100 Government Agencies Breached by Iranian MuddyWater APT with Phoenix Backdoor

In early 2024, the Iranian state-sponsored threat group MuddyWater executed widespread attacks leveraging the Phoenix backdoor (version 4), successfully targeting over 100 government entities worldwide. The campaign exploited spear-phishing and malicious document attachments to deliver the backdoor, enabling persistent access, lateral movement, and data exfiltration from compromised systems. This sophisticated intrusion allowed the attackers to maintain a long-term foothold within highly sensitive government networks, posing significant operational and intelligence risks across multiple regions. This incident underscores a sharp escalation in advanced persistent threat (APT) tactics targeting public sector organizations. It highlights both the evolving sophistication and relentless nature of nation-state cyber operations, amplifying regulatory and operational pressure on government organizations to strengthen east-west traffic security, anomaly detection, and Zero Trust segmentation strategies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
PassiveNeuron APT: 2024 Cyber Espionage Targets Asia, Africa & LatAm with Neursite Malware
Impact· high

PassiveNeuron APT: 2024 Cyber Espionage Targets Asia, Africa & LatAm with Neursite Malware

In late 2024, cybersecurity researchers identified a sophisticated cyber espionage campaign targeting government, financial, and industrial organizations across Asia, Africa, and Latin America. Dubbed "PassiveNeuron," the operation leveraged custom malware strains, Neursite and NeuralExecutor, deployed by an advanced persistent threat (APT) group to infiltrate networks, maintain persistence, and exfiltrate sensitive data over several months. The entry vector appears to involve highly targeted spear-phishing and exploitation of vulnerable internet-facing assets, allowing attackers to bypass perimeter defenses and conduct stealthy lateral movement. The attack resulted in significant exposure of confidential communications and potentially state or financial secrets, raising concerns among affected sectors and governments. This incident exemplifies ongoing evolution in state-sponsored cyber attacks, with advanced malware leveraging encrypted traffic and zero trust evasion techniques. Given the increasingly global scope of APT operations and regulatory pressure on critical sectors, organizations must reexamine east-west security, policy enforcement, and anomaly detection capabilities to mitigate rising espionage risks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Flax Typhoon Turns ArcGIS Geo-Mapping Server into APT Backdoor
Impact· medium

Flax Typhoon Turns ArcGIS Geo-Mapping Server into APT Backdoor

In early 2024, Chinese state-sponsored threat group Flax Typhoon compromised an organization’s ArcGIS geospatial mapping server, turning the platform into a covert backdoor for persistent access. The attackers exploited vulnerabilities and weak segmentation, modifying core ArcGIS components to avoid detection while establishing reliable remote control and lateral movement capabilities. This stealthy intrusion allowed for unauthorized data access without typical alert triggers, posing significant operational and reputational risks for the victim, and demonstrated advanced tactics utilized by APT groups targeting critical infrastructure software. This incident highlights a growing trend where APTs compromise auxiliary business applications—like geo-mapping and analytics platforms—to evade detection and spread across internal networks. Organizations must reassess east-west security, encrypted traffic visibility, and zero trust segmentation to keep pace with evolving attacker tradecraft.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China’s AI-Driven APT Attack Chains Breach Taiwan’s Defenses
Impact· low

China’s AI-Driven APT Attack Chains Breach Taiwan’s Defenses

In early 2024, a sophisticated China-linked threat group launched a series of cyberattacks against major Taiwanese government agencies and critical infrastructure providers. Leveraging AI-optimized attack chains, the attackers automated reconnaissance, lateral movement, and customized payload delivery to bypass traditional defenses. The campaign used a combination of phishing emails, zero-day vulnerabilities, and covert encrypted traffic to infiltrate networks, evade detection, and exfiltrate sensitive government data. Operational disruptions and risk of classified information exposure heightened tensions amid ongoing geopolitical strains. These incidents signal an evolution in state-sponsored cyber operations, marked by the integration of artificial intelligence for more adaptive, stealthy attacks. Organizations should be urgently evaluating east-west segmentation, anomaly detection, and compliance readiness in response to the surge of AI-enhanced persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Laser Attacks on Vehicle Microchips: New Frontiers in Auto Cybersecurity
Impact· medium

Laser Attacks on Vehicle Microchips: New Frontiers in Auto Cybersecurity

In 2024, security researchers demonstrated a novel cyberattack targeting automotive microchips using precisely aligned laser beams. The attack exploited fundamental hardware vulnerabilities, allowing adversaries to manipulate or extract data from silicon chips embedded in modern vehicles. By directing lasers at sensitive circuits, attackers could trigger faults, bypass certain security controls, and potentially gain access to encrypted data streams or control automotive systems. The proof-of-concept underscores critical exposure across connected and autonomous vehicles, as physical access to components can enable advanced attacks beyond the reach of traditional software-based defenses. This incident is particularly relevant as vehicles and other IoT systems grow increasingly reliant on sophisticated microelectronics. The emergence of physical-layer hardware attacks highlights the urgent need for new security architectures, including microchip hardening and multi-layered threat detection, to counter evolving risks in transportation and critical infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ColdRiver Malware Surge: 2024 Espionage Attack Analysis
Impact· medium

ColdRiver Malware Surge: 2024 Espionage Attack Analysis

In early 2024, the Russia-linked threat group ColdRiver launched a fresh cyber espionage campaign targeting Western government entities, research institutions, and non-governmental organizations. Exploiting spear-phishing emails laden with custom-designed malware, the attackers accessed sensitive emails and files by leveraging well-crafted lures and technical evasion methods. The operation showcased ColdRiver’s rapid adaptation: when prior campaign tactics were exposed, the group swiftly pivoted to deploy new malware strains and infrastructure, signifying a high level of technical agility. The impact included unauthorized data access, intelligence gathering, and operational disruptions for targeted organizations. This incident stands out due to its demonstration of how quickly sophisticated espionage actors can update their tactics in response to detection. With global instability rising and state-aligned groups escalating campaigns, the rapid agility in threat activity puts extra pressure on organizations to strengthen detection and incident response protocols.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
MuddyWater Hits Middle East Governments: Phishing, Phoenix Backdoor & VPN Abuse
Impact· low

MuddyWater Hits Middle East Governments: Phishing, Phoenix Backdoor & VPN Abuse

In early 2024, the Iranian state-sponsored group MuddyWater orchestrated a large-scale spear-phishing campaign targeting over 100 government entities across the Middle East and Africa. Attackers leveraged a compromised mailbox and NordVPN to distribute phishing emails enticing recipients to enable malicious macros. This led to the deployment of the Phoenix backdoor, providing attackers with persistent access and the ability to move laterally within targeted organizations’ networks, thereby raising concerns over significant data exposure and long-term espionage. The MuddyWater incident exemplifies the growing sophistication and scale of nation-state phishing campaigns. Recent trends show attackers are rapidly adapting credential theft and post-exploitation tactics to bypass traditional defenses. Government entities face mounting regulatory and operational pressure to address advanced persistent threats exploiting email and remote access.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Flax Typhoon Used ArcGIS Server as a Backdoor: 2025 Breach Breakdown
Impact· low

How Flax Typhoon Used ArcGIS Server as a Backdoor: 2025 Breach Breakdown

In mid-2025, threat intelligence researchers uncovered a year-long, state-sponsored attack committed by Chinese APT group Flax Typhoon (also known as Ethereal Panda/RedJuliett). The group exploited unpatched ArcGIS servers to establish persistent unauthorized access and covertly operated a backdoor for over twelve months. Using sophisticated techniques to evade detection and maintain long-term access, the attackers leveraged lateral movement and encrypted communication within targeted networks. The breach compromised sensitive data and potentially exposed critical infrastructure, highlighting a significant risk to affected organizations. This incident exemplifies a growing threat from well-resourced nation-state actors targeting enterprise geospatial systems, exploiting overlooked or under-patched software for initial entry. Attacks on infrastructure platforms are increasingly sophisticated, raising urgency for IT and security leaders to enhance detection, zero trust segmentation, and patch management programs in response to evolving APT campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports