✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
China-Linked Ink Dragon Breaches Governments With ShadowPad and FINALDRAFT Malware
Between July and October 2025, a sophisticated cyber-espionage campaign orchestrated by the China-linked group 'Ink Dragon' (a.k.a. Jewelbug, CL-STA-0049, Earth Alux, REF7707) targeted multiple European, Southeast Asian, and South American governments. The attackers leveraged advanced tools such as ShadowPad and FINALDRAFT malware to infiltrate official networks, move laterally through compromised systems, and exfiltrate sensitive government data via encrypted channels. Their operations exhibited a high degree of stealth, blending custom malware with legitimate administrative tools and exploiting trust in east-west network flows, putting confidential geopolitical and citizen information at direct risk. This incident underscores the increasing frequency and sophistication of state-sponsored espionage operations against government entities worldwide. It marks a significant trend where threat actors are adopting modular malware and advanced lateral movement techniques, emphasizing the urgent need for stronger east-west security controls and real-time anomaly detection in critical infrastructure.
6 months ago
Kill Chain
France's Ministry of the Interior Breached in Nation-State Attack: 2024 Suspect Arrested
In June 2024, French authorities arrested a 22-year-old suspect in connection with a cyberattack targeting the Ministry of the Interior. The attack took place earlier in the month and was orchestrated using sophisticated nation-state level tactics, resulting in unauthorized access to sensitive government infrastructure. Although the Ministry quickly identified the incursion and initiated prompt containment measures, the breach underscored significant vulnerabilities in the security perimeter of key government agencies. Investigators believe the attacker leveraged advanced persistence techniques and attempted to exfiltrate confidential information before being apprehended. This incident underscores the growing sophistication of cyber operations targeting European governmental institutions. As nation-state and advanced persistent threats (APTs) escalate in frequency and impact, public sector organizations must reinforce zero trust segmentation, threat detection, and traffic encryption controls to stay ahead of evolving risks.
6 months ago
Kill Chain
APT28 Targeted Ukrainian UKR.net Users in Sophisticated Credential Phishing Campaign (2024–2025)
Between June 2024 and April 2025, the Russian state-sponsored group APT28 orchestrated a prolonged credential harvesting operation targeting users of UKR.net, one of Ukraine’s most popular webmail and news platforms. Threat intelligence from Recorded Future’s Insikt Group indicates that the attackers leveraged spear-phishing emails, cleverly masquerading as legitimate UKR.net communications, to deceive victims into disclosing their login details on malicious lookalike sites. This campaign continued APT28’s longstanding focus on geopolitical and military targets associated with Ukraine, and raises serious concerns about national security and the exposure of sensitive communications during a period of heightened regional conflict. The incident spotlights a surge in state-sponsored credential theft using advanced social engineering, capitalization on trusted local brands, and persistent, evolving methodologies. As phishing techniques become more adept at bypassing basic controls, organizations are under pressure to bolster identity protection, phishing awareness, and multifactor authentication while aligning closely with regulatory guidance for detection and response.
6 months ago
Kill Chain
ForumTroll APT Strikes Again: Russian Political Scientists Hit by Sophisticated Phishing Scheme
In October 2025, the ForumTroll advanced persistent threat (APT) group launched a spear-phishing campaign targeting Russian political science scholars and researchers. Victims received personalized emails disguised as plagiarism report notifications from a fake scientific library domain, prompting them to download a malicious archive. Opening the archive triggered a PowerShell-based attack chain, culminating in the deployment of the Tuoni red-teaming framework via a custom obfuscated loader, with persistence achieved through COM Hijacking. Attacker infrastructure included typosquatted domains and Fastly-based C2 servers. This incident underscores the increasing shift by APT actors to highly targeted, socially engineered phishing attacks, even when technical sophistication is dialed back. Organizations must contend with the reality of persistent, multi-phase campaigns adapting both commercial and bespoke toolkits, heightening the urgency for advanced detection and resilient user training.
6 months ago
Kill Chain
ForumTroll Launches Sophisticated Phishing Attack on Russian Scholars Using Fake eLibrary Emails
In October 2025, Operation ForumTroll, a previously identified threat actor, launched a targeted phishing campaign against Russian academic and scholarly communities. Using convincingly crafted phishing emails that impersonated official eLibrary notifications, attackers distributed malicious attachments designed to harvest credentials and enable broader espionage operations. The campaign, identified by Kaspersky, marks a decisive tactical shift from prior attacks on organizations to focused targeting of individuals, raising concerns about the security posture of research and educational institutions in the region. This incident highlights the increasing trend of sophisticated phishing campaigns that employ social engineering and trusted brands to bypass traditional defenses. The focused targeting of scholars and intellectuals points towards a rise in espionage-motivated threats seeking sensitive research data, emphasizing the need for robust user education, multifactor authentication, and advanced anomaly detection.
6 months ago
Kill Chain
SonicWall SMA 100 Breach 2025: CVE-2025-40602 Actively Exploited
In December 2025, SonicWall disclosed a security breach affecting its Secure Mobile Access (SMA) 100 series appliances, driven by exploitation of CVE-2025-40602—a local privilege escalation vulnerability. The issue arose due to insufficient authorization in the Appliance Management Console (AMC), enabling threat actors to elevate local privileges and gain greater control within affected systems. SonicWall confirmed active exploitation in the wild, prompting an urgent release of security patches while urging all customers to apply updates immediately. The incident underscores the risks facing network appliances and the rapid speed with which attackers can leverage new vulnerabilities to compromise enterprise infrastructure. This event occurs amidst a wider uptick in attacks targeting edge appliances from network security vendors, as adversaries increasingly exploit publicly disclosed software flaws soon after their publication. Organizations are under intensified regulatory and operational pressure to patch critical vulnerabilities rapidly and reinforce privilege management strategies.
6 months ago
Kill Chain
How BlueDelta (APT28) Targeted UKR.NET with Persistent Credential Harvesting (2024-2025)
Between June 2024 and April 2025, Russian state-sponsored threat group BlueDelta (APT28) orchestrated a persistent credential-harvesting campaign targeting users of UKR.NET, a leading Ukrainian webmail and news service. The threat actor employed convincing UKR.NET-lookalike login portals hosted on free services like Mocky, DNS EXIT, ngrok, and Serveo to steal usernames, passwords, and two-factor authentication codes. Phishing lures, primarily PDF attachments embedded with malicious links, were distributed to evade email scanning and sandboxing. Attackers continuously evolved their infrastructure—moving from compromised routers to anonymized tunneling platforms and adding new operational layers—reflecting increasing sophistication and resilience in support of GRU intelligence goals. This campaign exemplifies ongoing adaptations by nation-state actors to Western infrastructure takedowns and detection mechanisms, highlighting escalating risks to critical digital identities. Its advanced evasion techniques, modular infrastructure, and creative abuse of free online services signal a new phase in credential theft, underscoring the urgent need for organizations to reassess their defenses, particularly in the face of targeted phishing and lateral movement threats.
6 months ago
Kill Chain
CISA Flags 3 New Actively Exploited Vulnerabilities: Cisco, SonicWall, ASUS
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added three newly discovered vulnerabilities (CVE-2025-20393, CVE-2025-40602, and CVE-2025-59374) to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. These flaws impact multiple Cisco products, SonicWall SMA1000, and ASUS Live Update, allowing attackers to gain unauthorized access, insert malicious code, or bypass input validations. Such exposures provide fertile ground for cybercriminals to enter networks, move laterally, and compromise data, posing significant operational and business continuity risks to affected organizations across sectors. Their rapid inclusion into the KEV Catalog reflects a surge in the exploitation of software supply chains and critical infrastructure technologies. With attackers leveraging faster exploit-to-impact timelines, government agencies and enterprises face mounting pressure to patch immediately and update their vulnerability and segmentation strategies to prevent cascading breaches.
6 months ago
Kill Chain
Russian Nation-State Hackers Breach Critical Infrastructure via Edge Device Flaws
In early 2024, Russian-linked APT actors launched a prolonged cyberattack campaign targeting critical infrastructure organizations globally, with a particular focus on the energy sector. Leveraging misconfigured edge networking devices, attackers gained initial access to internal networks, allowing them to perform lateral movement and conduct espionage on sensitive operational systems. The campaign, detailed by Amazon's security division, utilized unencrypted management traffic, enabling threat actors to intercept data-in-transit and issue command-and-control instructions undetected. Widespread exploitation resulted in data exfiltration, system compromise, and operational disruptions for affected organizations. This incident highlights a surge in advanced persistent threats exploiting basic configuration weaknesses in edge devices. The continued targeting of critical sectors by nation-state actors underscores the urgent need for stronger segmentation, encrypted network traffic, and improved detection capabilities, as attackers are increasingly adept at bypassing conventional perimeter defenses.
6 months ago
Kill Chain
2025 Ransomware Attack Disrupts Venezuela’s State Oil Giant PDVSA
In December 2025, Petróleos de Venezuela (PDVSA), Venezuela’s national oil and gas company, experienced a significant ransomware attack that targeted its administrative systems. While official company communications downplayed the incident and attributed blame to international adversaries, media reports indicated substantial disruption: the attack resulted in major outages, took down vital IT systems, impacted cargo deliveries, and forced network disconnections. Efforts to remediate using antivirus software exacerbated downtime, and export activities, including loading instructions, were suspended. The incident highlighted operational fragility due to reliance on legacy infrastructure and a lack of segmentation between administrative and critical operational technologies. This breach spotlights the ongoing wave of ransomware attacks targeting energy and critical infrastructure sectors worldwide. It underscores how geopolitically charged environments, and legacy technologies without zero trust segmentation, remain especially vulnerable. The incident serves as a stark warning for the urgent adoption of robust east-west traffic controls and resilient response playbooks to mitigate emerging ransomware TTPs.
6 months ago
Kill Chain
AI Deepfake Geospatial Maps Incident Exposes New Security Frontier (2025)
In December 2025, a high-profile security research initiative revealed significant risks in the unchecked proliferation of AI-generated deepfake satellite maps. Sparked by the personal experience of a deepfake attack, a 17-year-old cybersecurity researcher demonstrated how adversaries could blend or fabricate satellite imagery using advanced GANs and diffusion models. These manipulations, undetectable to the naked eye, could mislead governments and emergency responders, mask critical infrastructure weaknesses, or facilitate large-scale misinformation campaigns with potentially catastrophic consequences on national security and public trust. The incident highlights a rising threat: geospatial deepfakes are evolving rapidly, outpacing current detection solutions and exposing new vulnerabilities in organizations' data and decision pipelines. Growing reliance on AI-generated imagery and the lack of robust verification frameworks make this an urgent issue for security leaders and risk managers in both public and private sectors.
6 months ago
Kill Chain
AWS IAM Credential Theft Drives Massive Cloud Cryptomining in 2024
In early 2024, threat actors exploited stolen Amazon Web Services (AWS) Identity and Access Management (IAM) credentials to launch an extensive cryptomining campaign. Attackers gained unauthorized access to multiple customer environments, leveraging compromised IAM keys to provision and operate Amazon EC2 instances at scale. This unauthorized infrastructure was then used to mine cryptocurrency, resulting in significant financial losses, increased resource utilization, and additional operational overhead for affected organizations. The incident exposed critical gaps in cloud credential management and highlighted the attackers’ agility in abusing cloud-native services for illicit profit. This attack underscores a growing trend where cybercriminals are rapidly pivoting to cloud environments, exploiting mismanaged or stolen credentials. As more businesses migrate workloads to multi-cloud platforms, identity-driven threats and cryptojacking incidents are rising, urging organizations to reexamine their cloud security postures and access controls.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports