Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
LeakNet Ransomware's 2026 Campaign: Exploiting ClickFix and Deno Runtime for Stealthy Attacks
In March 2026, the LeakNet ransomware group initiated a sophisticated campaign leveraging the ClickFix social engineering technique to gain initial access to target systems. By compromising legitimate websites, they presented users with deceptive prompts instructing them to execute malicious PowerShell commands under the guise of resolving non-existent errors. This method effectively bypassed traditional security measures, leading to the deployment of an in-memory loader utilizing the Deno JavaScript runtime. This loader facilitated the execution of the CastleRAT malware directly in memory, thereby evading detection by conventional endpoint security solutions. The campaign resulted in significant data breaches and operational disruptions across multiple sectors. This incident underscores a concerning evolution in ransomware tactics, highlighting the increasing sophistication of social engineering methods and the exploitation of novel technologies like the Deno runtime for stealthy malware deployment. The use of in-memory execution techniques poses a substantial challenge to traditional security defenses, emphasizing the need for advanced detection mechanisms and comprehensive user education to mitigate such threats.
6 months ago
Kill Chain
Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities
In mid-2025, the Warlock ransomware group exploited unpatched Microsoft SharePoint servers to gain initial access to various organizations across North America, Europe, Asia, and Africa. Utilizing known vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), they deployed web shells via HTTP POST requests, enabling reconnaissance, credential theft, and lateral movement. The attack culminated in the deployment of ransomware, encrypting files with the .x2anylock extension and exfiltrating data using RClone. ([clearphish.ai](https://www.clearphish.ai/news/warlock-ransomware-sharepoint-attacks-2025?utm_source=openai)) This incident underscores the critical importance of timely patch management, especially for widely used enterprise applications like SharePoint. The Warlock group's rapid escalation from forum discussions to impactful campaigns highlights the evolving threat landscape and the need for organizations to bolster their cybersecurity defenses against sophisticated ransomware operations.
6 months ago
Kill Chain
Unveiling the Stealth: China's Prolonged Cyber Espionage in Southeast Asia
In March 2026, Palo Alto Networks' Unit 42 uncovered a prolonged cyber espionage campaign attributed to Chinese state-sponsored actors, targeting military organizations in Southeast Asia since at least 2020. The attackers employed novel backdoors, including 'AppleChris' and 'MemFun,' and utilized dead-drop resolvers on platforms like Pastebin and Dropbox to maintain covert command-and-control channels. Their operations focused on exfiltrating sensitive military data, such as information on capabilities, organizational structures, and collaborations with Western forces. The campaign demonstrated strategic patience, with attackers maintaining undetected access for extended periods and employing advanced evasion techniques like delayed execution and timestomping to avoid detection. This incident underscores the evolving sophistication of state-sponsored cyber threats, highlighting the need for organizations to enhance their cybersecurity measures. The use of legitimate web services for malicious activities and the deployment of custom malware with advanced evasion tactics reflect a broader trend in cyber espionage, emphasizing the importance of proactive threat intelligence and robust security protocols.
6 months ago
Kill Chain
Wing FTP Server 2025 Information Disclosure Vulnerability: What You Need to Know
In July 2025, a medium-severity information disclosure vulnerability, identified as CVE-2025-47813, was discovered in Wing FTP Server versions 7.4.3 and earlier. This flaw allowed unauthenticated attackers to obtain sensitive information about the server's local file system by exploiting the 'loginok.html' page with a specially crafted UID cookie. The vulnerability was addressed in version 7.4.4, released on May 14, 2025. Despite the availability of a patch, many systems remained unpatched, leaving them susceptible to potential exploitation. The incident underscores the critical importance of timely software updates and robust vulnerability management practices. Organizations are urged to prioritize the remediation of known vulnerabilities to mitigate the risk of unauthorized access and data breaches.
6 months ago
Kill Chain
Iranian Cyber Threat Evolution: Exploiting MDM Platforms in 2026
In March 2026, Iranian state-sponsored cyber actors executed a large-scale attack by compromising privileged identities within cloud-based Mobile Device Management (MDM) platforms. This allowed them to issue legitimate remote-wipe commands, resulting in the simultaneous erasure of data from over 200,000 devices globally. The attack exploited administrative tools to bypass traditional endpoint detection systems, leading to significant operational disruptions across multiple organizations. This incident underscores a strategic shift in Iranian cyber operations from deploying custom malware to leveraging existing administrative infrastructures for destructive purposes. The use of legitimate management tools for widescale data destruction highlights the evolving threat landscape and the need for organizations to enhance identity and access management protocols to mitigate such risks.
6 months ago
Kill Chain
South Korea's NTS Security Lapse Results in $4.8M Crypto Theft
In February 2026, South Korea's National Tax Service (NTS) conducted raids on 124 high-value tax evaders, seizing digital assets worth approximately $5.6 million. During a press release showcasing the operation, the NTS inadvertently published images displaying a Ledger hardware wallet alongside a handwritten note containing the wallet's mnemonic recovery phrase. This exposure allowed an unauthorized individual to access and transfer 4 million Pre-Retogeum (PRTG) tokens, valued at about $4.8 million, from the confiscated wallet. The NTS has since apologized for the oversight and initiated measures to prevent similar incidents in the future. ([koreajoongangdaily.joins.com](https://koreajoongangdaily.joins.com/news/2026-03-01/national/socialAffairs/Police-probing-unauthorized-crypto-transfer-after-NTS-inadvertently-shared-wallet-recovery-phrase/2534349?utm_source=openai)) This incident underscores the critical importance of secure handling and storage of digital assets, especially by governmental agencies. As cryptocurrency adoption grows, ensuring robust security protocols and staff training is essential to prevent such costly errors and maintain public trust.
6 months ago
Kill Chain
UK's Companies House Security Flaw Exposes Business Data - 2026
In March 2026, the UK's Companies House disclosed a significant security vulnerability in its WebFiling service, which had been present since October 2025. This flaw allowed authenticated users to access and potentially modify sensitive information of any registered company by exploiting a back-navigation loophole. The exposed data included directors' residential addresses, email addresses, and dates of birth. The agency has since rectified the issue, notified affected parties, and reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). This incident underscores the critical importance of rigorous security testing and prompt response to vulnerabilities in public sector digital services. The exposure of personal data over an extended period raises concerns about potential misuse and the necessity for enhanced monitoring and compliance measures to protect sensitive information.
6 months ago
Kill Chain
GoPIX Banking Trojan: A New Threat to Brazil's PIX Payment System
In December 2022, the GoPIX banking Trojan emerged, targeting users of Brazil's PIX instant payment system. Disguised as a WhatsApp Web installer, it spread through malicious ads, leading victims to download malware that intercepts and manipulates PIX transactions. GoPIX employs sophisticated techniques, including IP Quality Score's anti-fraud tools, to evade detection and ensure successful infections. ([usa.kaspersky.com](https://usa.kaspersky.com/about/press-releases/kaspersky-crimeware-report-reveals-new-rhysida-ransomware-lumar-stealer-and-gopix-banking-malware?utm_source=openai)) The rise of GoPIX underscores a growing trend of cybercriminals exploiting popular payment systems in Latin America. Its advanced evasion methods and focus on real-time transaction manipulation highlight the need for enhanced security measures and user awareness to combat such evolving threats. ([usa.kaspersky.com](https://usa.kaspersky.com/about/press-releases/kaspersky-crimeware-report-reveals-new-rhysida-ransomware-lumar-stealer-and-gopix-banking-malware?utm_source=openai))
6 months ago
Kill Chain
PLUGGYAPE Malware: A New Cyber Threat Targeting Defense Sectors
Between October and December 2025, Ukrainian defense forces were targeted by a cyber-espionage campaign attributed to the Russian-affiliated group Void Blizzard (also known as Laundry Bear or UAC-0190). The attackers utilized messaging platforms such as Signal and WhatsApp to impersonate charitable organizations, distributing password-protected archives containing the PLUGGYAPE backdoor malware. Once executed, PLUGGYAPE enabled remote code execution, system reconnaissance, and data exfiltration, maintaining persistence through Windows Registry modifications. This campaign underscores the evolving tactics of state-sponsored actors in leveraging social engineering and trusted communication channels to infiltrate sensitive targets. The incident highlights the increasing sophistication of cyber threats facing defense sectors, emphasizing the need for enhanced vigilance and robust security measures to counteract such espionage activities.
6 months ago
Kill Chain
2025 Identity Threat Landscape: The Rise of Infostealer Malware and Credential Theft
In 2025, the cybersecurity landscape witnessed an unprecedented surge in credential theft, with Recorded Future detecting 1.95 billion malware combo list credential exposures, 36 million database combo list credential exposures, 24 million database dump credential exposures, and 892 million malware log credential exposures. This escalation was primarily driven by the proliferation of infostealer malware, which harvested credentials from both personal and corporate devices, leading to significant breaches across various sectors. Notably, the Lumma Stealer emerged as the most prevalent infostealer, compromising over 394,000 Windows computers between March and May 2025. The widespread availability of stolen credentials on dark web marketplaces facilitated unauthorized access to corporate networks, resulting in data breaches, financial losses, and reputational damage for affected organizations. The current relevance of this incident is underscored by the continuous evolution of infostealer malware and the increasing sophistication of cybercriminal tactics. The commodification of credential theft has lowered the barrier to entry for attackers, enabling even less experienced individuals to execute complex attacks. This trend highlights the urgent need for organizations to adopt comprehensive identity protection strategies, including continuous monitoring, multi-factor authentication, and employee education, to mitigate the risks associated with credential-based attacks.
6 months ago
Kill Chain
Quantum Computing's 2026 Breakthrough: A Call to Action for Cryptographic Security
In March 2026, a new theoretical advancement in quantum factorization was reported, suggesting a potential acceleration in the ability of quantum computers to factor large numbers. This development raises concerns about the security of RSA encryption, which relies on the difficulty of factoring large integers. If quantum computers can perform this task efficiently, they could decrypt data protected by RSA, compromising sensitive information across various sectors. The urgency of this issue is underscored by the increasing feasibility of quantum computing technologies. Organizations must proactively assess their cryptographic infrastructures and consider transitioning to quantum-resistant algorithms to safeguard against future threats.
6 months ago
Kill Chain
Understanding the Shift: Ransomware's Move to Data Extortion in 2026
In 2025, the cyber threat landscape witnessed a significant shift as ransomware groups increasingly favored data theft over traditional encryption methods. This evolution led to a 146% surge in ransomware attempts, with attackers exfiltrating 238 TB of data, marking a 92% increase from the previous year. The United States bore the brunt of these attacks, accounting for 50% of global incidents, with sectors like manufacturing, technology, and healthcare being prime targets. Notably, the oil and gas industry experienced a staggering 900% rise in attacks, underscoring the expanding reach of cybercriminals. ([globenewswire.com](https://www.globenewswire.com/news-release/2025/07/29/3122994/0/en/ransomware-surges-as-attempts-spike-146-amid-aggressive-extortion-tactics.html?utm_source=openai)) This trend underscores the urgency for organizations to bolster their cybersecurity defenses. The pivot towards data extortion highlights the need for comprehensive security strategies that encompass data protection, rapid vulnerability patching, and robust identity management to mitigate the escalating risks posed by these evolving cyber threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports