The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
BIETA & CIII Unmasked: China’s MSS Deploys Espionage Through Research Firms in 2025
In October 2025, a detailed investigation revealed that Chinese research firms BIETA (Beijing Institute of Electronics Technology and Application) and CIII were directly implicated in cyber operations orchestrated by China’s Ministry of State Security (MSS). The report, based on personnel link analysis and institutional relationships, highlights how BIETA coordinated with MSS operatives and academic partners to conduct covert cyber-espionage campaigns targeting international entities. These campaigns leveraged advanced tactics, including exploitation of internal network flows and the use of encrypted traffic, to exfiltrate sensitive data undetected. The exposure underscores the persistent and sophisticated nature of state-sponsored cyber threats, as well as risks posed by non-traditional actors collaborating with government intelligence agencies. This incident reflects a broader escalation in state-driven cyber espionage, demonstrating that commercial and academic organizations may serve as active operational arms for nation-state threat actors. As attribution capabilities improve, organizations must reassess third-party relationships and reinforce east-west and encrypted traffic controls to mitigate lateral movement and exfiltration risks.
8 months ago
Kill Chain
How Chinese Front Organizations Exploited Western Research to Advance State Cyber Capabilities
In early 2024, coordinated investigations revealed that Chinese government-linked academic and research institutions were covertly collaborating with Western organizations and researchers. Operating under seemingly neutral fronts, these entities facilitated the transfer of advanced cyber technologies and expertise, ultimately benefitting the intelligence apparatus of the People’s Republic of China (PRC). The campaign included joint projects, academic exchanges, and technology partnerships that enabled the PRC to sidestep export controls and gain access to cutting-edge cyber defense and offensive capabilities. The outcome potentially undermines intellectual property protections and heightens risks to network and national security within targeted Western sectors. This incident underscores a marked escalation in supply chain and technology transfer tactics used by nation-state actors. As the global competition for cyber advantage intensifies, regulators and organizations must heighten vigilance around academic, research, and cross-border tech collaborations to mitigate risks of inadvertent technology leakage.
8 months ago
Kill Chain
Cavalry Werewolf APT Hits Russian Agencies with FoalShell and StallionRAT in 2025
In October 2025, a sophisticated threat actor known as Cavalry Werewolf, believed to share links with the YoroTrooper group, orchestrated targeted cyber attacks against Russian public sector agencies. Utilizing custom malware families FoalShell and StallionRAT, the attackers infiltrated key government systems, establishing covert access for potential espionage and data theft. Security firm BI.ZONE detected the activity, noting operational overlaps with other known clusters such as SturgeonPhisher and Comrade Saiga. The cyber-espionage campaign leveraged a mix of spear-phishing, credential theft, and advanced persistence techniques to evade detection and conduct lateral movement within critical infrastructure environments. This incident highlights a continuing trend of state-aligned espionage campaigns that exploit zero trust gaps, advanced malware, and blended tactics to compromise sensitive government data. The increasing frequency and sophistication of such attacks elevate the urgency for robust segmentation and monitoring strategies within public sector networks.
8 months ago
Kill Chain
Confucius Launches Targeted Campaign Against Pakistan with WooperStealer and Anondoor Malware
In October 2025, the advanced persistent threat group Confucius launched a sophisticated phishing campaign targeting Pakistani government, defense, and critical industry sectors. Leveraging spear-phishing emails and malicious documents, the attackers deployed two custom malware strains—WooperStealer and Anondoor—to infiltrate victim environments. These tools enabled the exfiltration of sensitive information and lateral movement across internal networks, potentially exposing military secrets and compromising operational capabilities. The attack underlines the evolving TTPs used by regional espionage actors and demonstrates substantial gaps in defending east-west traffic and data exfiltration from secure environments. This incident highlights the growing prevalence of specialized information-stealing malware and the targeting of governmental infrastructure by geopolitical adversaries. It reflects broader trends in cyber-espionage and underscores heightened regulatory expectations for securing critical east-west and outbound traffic flows.
8 months ago
Kill Chain
US Government 2025 Shutdown: Cyber Intel Sharing and Defense at Risk
In October 2025, a US federal government shutdown led to the temporary lapse of critically important cyber threat information sharing, coinciding with the expiration of the Cybersecurity Information Sharing Act of 2015. As Congressional inaction prevented reauthorization, legal protections for companies sharing threat data vanished, making organizations hesitant or unable to exchange intelligence. Mass furloughs affected over 65% of Cybersecurity & Infrastructure Security Agency (CISA) personnel, and many critical contractors were released, significantly slowing incident response, vulnerability patching, and cross-sector collaboration. The resulting operational gaps increased the risk of adversaries targeting federal networks and exploiting unpatched vulnerabilities. This incident highlights the risks posed by government policy disruptions and shrinking cyber workforce capacity, underscoring how national cybersecurity posture is deeply interconnected with policy stability. Its relevance is underscored by mounting state-backed cyber threats, increased phishing targeting vulnerable personnel, and heightened urgency for robust identity and incident response controls.
8 months ago
Kill Chain
Confucius APT Evolves: Python Backdoors Target Pakistan in 2025 Cyber-Espionage Escalation
In 2025, the Confucius advanced persistent threat (APT) group intensified its cyber-espionage operations targeting Pakistani government, military, and critical infrastructure organizations. Originally operating with infostealers like WooperStealer, Confucius shifted to deploying highly-obfuscated, Python-based surveillance backdoors such as AnonDoor. Attackers exploited spear phishing using spoofed authority emails and action-driven malicious attachments, which initiated complex infection chains via DLL sideloading, LNK files, and PowerShell loaders. This evolution improved persistence and evasiveness, resulting in increased risks to sensitive data and operational security for targeted institutions in Pakistan. The incident reflects a broader trend in state-sponsored cyberthreats: threat actors are adopting modular backdoors, diversifying attack vectors, and leveraging scripting languages to bypass security controls. Such agile TTPs (tactics, techniques, and procedures) heighten challenges for defenders, underscoring the urgent need for real-time threat detection and robust network segmentation.
8 months ago
Kill Chain
Ukraine 2025: CABINETRAT Backdoor Attack Leveraged Signal & XLL Add-ins
In September 2025, CERT-UA reported a targeted cyberattack campaign against Ukrainian organizations involving the CABINETRAT backdoor. The threat group tracked as UAC-0245 employed malicious Microsoft Excel XLL add-ins, disguised within ZIP archives distributed via Signal messenger, to covertly establish persistent backdoor access on victim systems. These XLL files, once executed, enabled attackers to conduct reconnaissance, data theft, and potential lateral movement inside compromised networks, raising concerns about operational disruption, espionage, and data confidentiality. This incident highlights the evolving threat landscape where adversaries leverage secure messaging platforms and file add-ins to bypass traditional email security and endpoint controls. The appearance of CABINETRAT underscores increasing sophistication in malware delivery and emphasizes the need for modern controls and East-West traffic visibility.
8 months ago
Kill Chain
Chinese APT UNC5174 Exploits VMware Zero-Day for Widespread Privilege Escalation
In October 2024, Chinese state-sponsored group UNC5174 began exploiting a zero-day vulnerability (CVE-2025-41244) affecting VMware Aria Operations and VMware Tools, enabling privilege escalation from unprivileged users to root on targeted virtual machines. The flaw, present in both credential-based and credential-less modes, allowed attackers to plant malicious binaries, gain root access, and ultimately compromise internal systems. This attack appears to be part of a wider campaign, with UNC5174 known for targeting critical infrastructure and selling access to compromised entities globally. Broadcom, which owns VMware, patched the vulnerability in September 2025 following an investigation by NVISO and Mandiant, but the exploit was active for nearly a year prior to disclosure. This incident underscores the increasing frequency of sophisticated supply chain and virtualization platform attacks by well-resourced APTs, especially those linked to state interests. Security teams should be alert to the persistence of zero-day exploitation and trends in privilege escalation across hybrid and cloud infrastructure.
8 months ago
Kill Chain
Phantom Taurus: Stealth China-Linked APT Breaches Global Governments in 2025
Between early 2023 and mid-2025, government and telecommunications agencies spanning Africa, the Middle East, and Asia became the targets of a previously undocumented China-linked nation-state threat group, dubbed Phantom Taurus. The group leveraged stealthy, custom malware and encrypted command-and-control channels to infiltrate ministries of foreign affairs, embassies, and military operations, maintaining persistent access to sensitive networks for extended periods. Attackers employed advanced lateral movement and living-off-the-land techniques, hindering detection and enabling covert intelligence collection. Exfiltrated data included diplomatic communications and potentially classified material, posing severe geopolitical and operational risks to the affected organizations. This incident underscores a rising trend of sophisticated China-aligned APT campaigns exploiting stealth malware, encrypted traffic, and advanced cloud evasion to breach strategic targets. As state-sponsored espionage continues to escalate, organizations must strengthen zero trust controls, real-time traffic inspection, and segmented multicloud defenses to counter evolving nation-state tactics.
8 months ago
Kill Chain
Phantom Taurus: Inside the 2025 Chinese APT NET-STAR Espionage Breach
In early 2025, security researchers uncovered a sophisticated espionage campaign attributed to a newly recognized Chinese nation-state actor, Phantom Taurus. Operating since at least late 2022, the group prioritized stealth and advanced tactics, primarily targeting government and telecommunications entities across Africa, the Middle East, and Asia. Attackers leveraged a novel, highly covert malware suite—NET-STAR—capable of remaining fileless within IIS web servers and facilitating persistent, encrypted exfiltration of sensitive diplomatic, military, and geopolitical data. The operation exploited custom-developed tools to move from email theft to direct database compromise, employing in-memory web backdoors and evasion techniques like timestomping and security mechanism bypasses to avoid detection and maintain long-term access. The exposure of Phantom Taurus and the NET-STAR suite highlights an escalating trend of targeted, stealthy cyber espionage campaigns against critical infrastructure by advanced persistent threat (APT) actors. This incident underscores the urgent need for organizations to strengthen east-west security visibility, enforce zero trust principles, and regularly review controls against constantly evolving attacker tradecraft.
8 months ago
Kill Chain
Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)
In September 2025, Cisco disclosed that a sophisticated nation-state threat actor, linked to the ArcaneDoor campaign, exploited multiple zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. These attackers targeted government networks and critical infrastructure globally, leveraging CVE-2025-20333 and CVE-2025-20362, which enabled remote code execution, persistent malware installation, and data exfiltration. Advanced evasion tactics allowed the attackers to disrupt device logging and remain undetected for extended periods, while the deployment of custom malware such as RayInitiator and LINE VIPER provided long-term backdoor access to compromised environments. This case highlights growing trends in state-sponsored exploitation of perimeter devices and demonstrates how quickly nation-state TTPs can proliferate to broader criminal groups. The campaign triggered urgent mandates from CISA and NCSC for organizations—especially in the public sector—to patch and monitor edge infrastructure, emphasizing the escalating risk from zero-day vulnerabilities and the increasing sophistication of attacker methods.
8 months ago
Kill Chain
Nation-State Zero-Day Attacks Breach Cisco Firewalls in 2024
In mid-2024, an advanced nation-state threat group—tracked as UAT4356 (Talos) and Storm-1849 (Microsoft)—launched a widespread espionage campaign exploiting newly discovered zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) firewalls. These attackers gained persistent, full-device control by chaining zero-days, disabling logging, evading defenses, and implanting custom malware on federal networks, achieving potential data exfiltration and establishing long-term persistence beyond standard remediation steps. The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating immediate federal agency response, including mandatory patching or device disconnection. This attack underscores the evolving sophistication and urgency of supply chain and perimeter device threats. As zero-day exploitation targeting network infrastructure escalates and aligns with global power competition, organizations must prioritize detection, segmented defense, and rapid vulnerability management to safeguard high-value assets and comply with emerging federal cyber mandates.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports