Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2385 threat reports
Page 181 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 21612172 / 2385 reports
From Infostealer to Full RAT: Inside the 2025 PureRAT Attack Chain
Impact· medium

From Infostealer to Full RAT: Inside the 2025 PureRAT Attack Chain

In October 2025, Huntress Labs analyzed a sophisticated attack campaign leveraging the PureRAT remote access trojan. The intrusion began with a targeted phishing email containing a ZIP archive that employed DLL sideloading to launch a cascade of in-memory loaders written in Python. Progressing through multi-layered obfuscation, hybrid encryption, and system persistence via Windows registry modifications, the attackers ultimately deployed PureRAT, granting full remote control over victim endpoints. Notably, the operation combined custom-developed loaders with commercial malware, demonstrating advanced evasion and command and control techniques, including encrypted communications and dynamic payload delivery. This incident highlights the growing complexity and modularity of post-phishing attack chains. Organizations must remain vigilant as threat actors increasingly blend bespoke scripts with off-the-shelf RATs, drastically lowering the barrier for stealthy, persistent intrusions targeting credential theft and long-term access.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SonicWall Cloud Backup Breach Exposes Firewall Configurations in 2024
Impact· medium

SonicWall Cloud Backup Breach Exposes Firewall Configurations in 2024

In June 2024, SonicWall disclosed a significant data breach impacting all users of its cloud backup service. Attackers successfully gained unauthorized access and exfiltrated firewall configuration files belonging to these customers. The breach, which reportedly occurred in late May 2024, does not appear to have affected the core SonicWall services but poses considerable risk because leaked configurations may contain sensitive network information, VPN details, hashed passwords, and other operational data. SonicWall took immediate action by disabling the impacted service and advising affected clients to reset credentials and review their setups. This breach highlights increasing attacker focus on cloud-managed infrastructure, particularly targeting device configurations that can offer deep intelligence on enterprise environments. With threat actors exploiting misconfigurations and weak controls in supply chain and managed services, regulators and CISOs are under pressure to strengthen both preventative and responsive security postures.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
China-Based Storm-2603 Weaponizes Velociraptor DFIR in 2025 Ransomware Attacks
Impact· high

China-Based Storm-2603 Weaponizes Velociraptor DFIR in 2025 Ransomware Attacks

In October 2025, security researchers uncovered that the China-based threat group Storm-2603 had abused the open-source Velociraptor DFIR tool in a wide-ranging ransomware campaign. The attacker exploited an outdated, vulnerable version of Velociraptor (CVE-2025-6264) to escalate privileges, create persistent admin accounts, and establish secure remote access on victim systems. This access enabled them to deploy ransomware variants including LockBit and Babuk across Windows and VMware ESXi environments, performing data encryption and exfiltration using PowerShell scripts. Endpoint protections were systematically disabled, and lateral movement leveraged tools like Impacket. This incident highlights an emergent trend: threat actors co-opting legitimate security tools for malicious purposes, increasing the difficulty of detection and response. The blending of nation-state TTPs with ransomware-as-a-service models signals evolving threats, regulatory scrutiny, and substantial operational risks for enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ClayRat Android Spyware: Fake App Campaign Hits Mobile Users in 2025
Impact· medium

ClayRat Android Spyware: Fake App Campaign Hits Mobile Users in 2025

In October 2025, cybersecurity researchers at Zimperium disclosed a widespread Android spyware campaign dubbed ClayRat, which targeted Russian users through phishing portals, Telegram channels, and malicious websites mimicking popular apps such as WhatsApp, TikTok, YouTube, and Google Photos. Using fraudulent Play Store-like websites and social engineering tactics, attackers tricked users into sideloading APKs that installed malicious payloads via a session-based installation method, bypassing Android security. Once installed, ClayRat acts as the device's default SMS handler, enabling interception of messages, call logs, notifications, and exfiltration of sensitive data to an AES-GCM-encrypted command and control (C2) server. It also uses infected devices to propagate itself by sending mass SMS messages to victims' contacts. This incident underscores an accelerating trend in mobile spyware leveraging legitimate app impersonation and sophisticated delivery mechanisms. The high volume of ClayRat samples and droppers, the abuse of sideloading, and the global reach of Telegram-based distribution channels highlight persistent gaps in mobile endpoint and social engineering defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Polymorphic Python RAT: Next-Gen Malware Slips Past Defenses in 2024
Impact· high

Polymorphic Python RAT: Next-Gen Malware Slips Past Defenses in 2024

In October 2024, security researchers identified a new strain of Python-based remote access trojan (RAT) exhibiting advanced polymorphic capabilities. The malware, distributed as 'nirorat.py' and virtually undetectable by most antivirus engines on VirusTotal at the time of discovery, leverages self-modifying code, dynamic junk code injection, and obfuscation to evade detection. Its feature set includes network scanning, credential testing, data exfiltration, cryptomining, screen and audio recording, and file encryption. The Trojan is designed to mutate its code with each execution, making signature-based security tools largely ineffective and challenging forensic analysis post-compromise. This incident is emblematic of an ongoing trend: cybercriminals are increasingly using polymorphic programming techniques and open-source scripting languages to bypass detection and propagate malware. Organizations must adapt their defense strategies as attackers innovate to manipulate familiar toolchains, raising the stakes for endpoint and network security teams.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
RedTail Cryptojacking: 2024 SSH Honeypot Attack Exposes Evasive Trends
Impact· high

RedTail Cryptojacking: 2024 SSH Honeypot Attack Exposes Evasive Trends

In 2024, repeated attempts to deploy RedTail cryptojacking malware were observed targeting honeypots through brute-forced SSH credentials and exploitation of vulnerabilities. Attackers gained access by cracking weak SSH passwords, uploaded and executed scripts such as setup.sh and clean.sh, and implemented persistent access by implanting their own SSH keys. They evaded detection by deleting evidence, queried system info to optimize deployment, and communicated outbound over HTTPS to control mining pools, siphoning off computing resources for Monero mining. The attack demonstrated both technical sophistication and evasiveness, resulting in loss of system performance and increased operational costs for victims. The RedTail campaign stands out for its focus on stealth, persistence, and lateral evasion, signaling a shift from noisy ransomware to more subtle and long-term threats like cryptojacking. With attackers honing in on resource hijacking and leveraging diverse TTPs, organizations face new challenges in detection and response. This incident shows the increasing necessity for robust SSH hardening, proactive monitoring, and defense-in-depth measures against evolving cryptojacking methods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ClickFix Factory: How Automated Phishing Kits Are Changing Social Engineering in 2024
Impact· low

ClickFix Factory: How Automated Phishing Kits Are Changing Social Engineering in 2024

In 2024, Unit 42 researchers exposed the ClickFix Factory, a novel phishing kit generator that dramatically lowers the technical bar for aspiring cybercriminals. ClickFix enables users to design sophisticated phishing campaigns targeting identity verification and anti-abuse modules (IUAM) without deep coding knowledge. By offering user-friendly templates and built-in automation, ClickFix streamlines social engineering attacks and amplifies their reach, resulting in a spike of high-volume, lower-skill phishing campaigns observed targeting enterprises and individuals globally. The release of ClickFix reflects an ongoing trend toward the commoditization of cybercrime tooling, making advanced techniques readily accessible to broader groups of threat actors. Security teams face new urgency to adapt detection, awareness, and prevention strategies as phishing kit marketplaces accelerate both the scale and success rate of social engineering attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
2025 Cloud Provider Breach Uncovers Critical Zero Trust Weaknesses
Impact· medium

2025 Cloud Provider Breach Uncovers Critical Zero Trust Weaknesses

In early 2025, a major global cloud provider suffered a sophisticated multi-stage breach in which adversaries gained initial access using compromised identity credentials, exploited weak east-west segmentation, and moved laterally across multicloud environments. The attackers leveraged unencrypted traffic channels and insufficient policy controls to evade detection, escalate privileges, and access sensitive customer data. As a result, organizations relying on this provider experienced outages, data exfiltration, and business continuity disruptions while the cloud provider scrambled to restore services and conduct forensic investigations. This incident highlights a rapidly growing trend: attackers are increasingly targeting cloud infrastructure, exploiting vulnerabilities in workload isolation, cloud-native policy enforcement, and hybrid connectivity. With regulators enhancing requirements and business dependence on cloud rising, defending against lateral movement and enforcing zero-trust has become a critical priority.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Powered PRISONBREAK Influence Operation Targets Iran Amid Heightened Tensions
Impact· high

AI-Powered PRISONBREAK Influence Operation Targets Iran Amid Heightened Tensions

In early 2025, a coordinated AI-enabled information operation named 'PRISONBREAK' targeted Iranian audiences via over 50 inauthentic X (formerly Twitter) profiles. Likely conducted by an Israeli government agency or contracted group, the operation deliberately synchronized its messaging with Israeli military action against Iran in June 2025. These automated profiles aimed to incite unrest and dissent within Iran, leveraging artificial intelligence to amplify and seed anti-government narratives to large public communities, at times with paid promotion. While organic engagement was limited, several posts garnered tens of thousands of views, representing a sophisticated example of nation-state influence using AI and social media. The operation highlights the new scale and efficiency with which AI can power information warfare, especially when paired with state-level coordination. As similar AI-driven campaigns grow globally, organizations and governments must re-examine detection strategies, policy enforcement, and regulatory frameworks for safeguarding against synthetic and manipulative online content.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
OpenAI 2024: Threat Actors Weaponize AI to Supercharge Cyber Operations
Impact· medium

OpenAI 2024: Threat Actors Weaponize AI to Supercharge Cyber Operations

In 2024, OpenAI’s threat intelligence team uncovered the widespread use of its AI platforms by a variety of state-affiliated and criminal threat actors to automate and strengthen existing cyberattack workflows. Rather than inventing novel threats, adversaries—including Chinese and North Korean clusters—integrated AI tools like ChatGPT into traditional hacking playbooks: malware development, reconnaissance, spearphishing, and influence campaigns. Notable incidents involved coordinated social media manipulation and the leveraging of LLMs for deep reconnaissance or scam orchestration, sometimes in multi-account structures mirroring factory-style operations. This incident highlights an acute shift where AI serves as a force multiplier—making known attacks faster and more scalable, not necessarily more innovative. The continued exploitation of AI by both state and non-state actors underscores urgent needs for security defenses aligned to emerging AI-driven TTPs and for regulatory guidance on responsible AI use.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
RedNovember: Chinese State-Sponsored Espionage Campaign Hits Global Defense and Tech Sectors
Impact· medium

RedNovember: Chinese State-Sponsored Espionage Campaign Hits Global Defense and Tech Sectors

Between June 2024 and July 2025, the Chinese state-sponsored threat group RedNovember (overlapping with Storm-2077 and formerly tagged as TAG-100) orchestrated a far-reaching cyber-espionage campaign targeting government, defense, and technology organizations globally. Leveraging weaponized perimeter device exploits and open-source tools like Pantegana and Cobalt Strike, the group gained initial access via widely used firewalls and VPNs, including SonicWall, Fortinet, Palo Alto, and Ivanti Connect Secure. Victims included ministries, intergovernmental bodies, US defense contractors, European manufacturers, and space organizations. The campaign’s impact highlights persistent perimeter vulnerabilities and demonstrated operational scale and stealth through commodity tooling and strategic timing near geopolitical events. This incident underscores the shift toward exploiting edge devices and open-source frameworks for stealth, scalable compromise by advanced actors. The trend signals urgent challenges for organizations relying on perimeter appliances and highlights the need to strengthen monitoring, zero trust segmentation, and compliance-driven security controls across hybrid and multicloud environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
King KongTuke Breach Unmasks East-West Security Gaps in Multi-Cloud Era
Impact· medium

King KongTuke Breach Unmasks East-West Security Gaps in Multi-Cloud Era

In September 2025, a sophisticated breach attributed to the threat group 'King KongTuke' targeted several enterprises operating in multi-cloud environments. Attackers exploited weaknesses in east-west traffic controls and bypassed improper network segmentation by leveraging encrypted, paste-and-run lures to establish covert lateral movement between cloud workloads. Once inside, the group utilized remote access tools and encrypted tunnels to exfiltrate sensitive data at scale, evading traditional threat detection and impairing business operations across industries including fintech and healthcare. The incident revealed extensive compliance risks and forced urgent remediation of cloud and hybrid network configurations. This breach highlights a growing trend of threat actors exploiting hybrid and multicloud blind spots. The event has triggered renewed urgency on east-west visibility, zero trust controls, and AI-enabled anomaly detection. Regulatory attention is increasing on enforcing segmentation, encryption in transit, and cloud-native policy enforcement at scale.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports