Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
KongTuke's CrashFix Campaign: Exploiting DNS to Deliver ModeloRAT
In early 2026, the threat actor known as KongTuke launched an evolved ClickFix campaign, dubbed 'CrashFix,' targeting corporate environments. The attack began with users installing a malicious Chrome extension named NexShield, masquerading as a legitimate ad blocker. After a delay, the extension deliberately crashed the browser, displaying a fake 'CrashFix' security warning. This prompt instructed users to run a command that executed a custom DNS lookup, leading to the download and execution of ModeloRAT, a Python-based remote access trojan. This sophisticated social engineering tactic exploited user trust and system utilities to gain unauthorized access to corporate systems. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/?utm_source=openai)) This incident underscores a growing trend of attackers leveraging social engineering combined with native system tools to bypass traditional security measures. The use of DNS queries for payload delivery highlights the need for enhanced monitoring of network traffic and user education to recognize and resist such deceptive tactics.
7 months ago
Kill Chain
Poland's Energy Sector Thwarts Major Cyberattack by Sandworm Group
In late December 2025, Poland's energy infrastructure was targeted by a coordinated cyberattack involving the deployment of a new data-wiping malware named DynoWiper. The attack focused on over 30 wind and solar farms, a combined heat and power plant serving nearly half a million customers, and a manufacturing company. The attackers exploited exposed FortiGate devices lacking multi-factor authentication to gain initial access, then moved laterally within networks to deploy the wiper malware. Despite the sophisticated nature of the attack, endpoint detection and response systems successfully blocked the malware's execution, preventing any disruption to energy production or distribution. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting critical infrastructure. The use of destructive malware like DynoWiper highlights the need for robust cybersecurity measures, including the implementation of multi-factor authentication and regular security audits, to protect against such sophisticated attacks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai))
7 months ago
Kill Chain
UNC3886's 2025 Cyber Attack on Singapore's Telecom Sector
In July 2025, Singapore's four major telecommunications providers—Singtel, StarHub, M1, and SIMBA Telecom—were targeted by the Chinese state-sponsored cyber espionage group UNC3886. The attackers employed sophisticated techniques, including rootkits and zero-day exploits in firewalls, to gain unauthorized access to parts of the telecom networks. Despite these efforts, the intrusion did not disrupt services or result in the exfiltration of sensitive customer data. The Singaporean government, in collaboration with the affected telcos, launched Operation Cyber Guardian, a coordinated response involving over 100 personnel from various agencies, to contain and mitigate the threat. ([channelnewsasia.com](https://www.channelnewsasia.com/singapore/unc3886-cyberattack-targets-singapore-telcos-threat-contained-5916906?utm_source=openai)) This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure. The use of advanced tools and tactics by UNC3886 highlights the need for continuous vigilance and robust cybersecurity measures within the telecommunications sector to safeguard against potential future attacks.
7 months ago
Kill Chain
Critical Unauthenticated API Vulnerability in Honeywell CCTV Products (CVE-2026-1670)
In February 2026, a critical vulnerability (CVE-2026-1670) was identified in Honeywell CCTV products, allowing unauthenticated attackers to remotely modify the 'forgot password' recovery email address via an exposed API endpoint. This flaw could lead to unauthorized access to camera feeds and potential network compromise. Affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0, PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0, and 25M IPC WDR_2MP_32M_PTZ_v2.0. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-1670/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially in critical infrastructure sectors. Organizations are urged to apply patches promptly and implement robust access controls to mitigate such risks.
7 months ago
Kill Chain
Microsoft Office Equation Editor Exploit: A 2026 Malware Campaign
In February 2026, a sophisticated malware campaign exploited the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) to deliver malicious payloads. Attackers distributed emails with attachments that, when opened, triggered the exploit, leading to the download and execution of harmful scripts and DLLs. Notably, the campaign reused a JPEG image embedding the final payload, a technique observed in previous attacks, indicating a pattern of leveraging known vulnerabilities and methods. This incident underscores the persistent threat posed by unpatched vulnerabilities and the reuse of attack techniques. Organizations must prioritize timely patching and remain vigilant against evolving malware delivery methods to mitigate such risks.
7 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerabilities in Ivanti EPMM Exploited
In January 2026, two critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, were discovered in Ivanti Endpoint Manager Mobile (EPMM). These vulnerabilities allow unauthenticated remote code execution, enabling attackers to gain full control over mobile device management infrastructure without requiring user interaction or credentials. Exploitation activities have included establishing reverse shells, installing web shells, conducting reconnaissance, and downloading malware. Affected sectors span state and local government, healthcare, manufacturing, professional and legal services, and high technology across the United States, Germany, Australia, and Canada. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1281 to its Known Exploited Vulnerabilities (KEV) Catalog, underscoring the severity of the threat. Threat actors are rapidly advancing their operations, moving from initial reconnaissance to deploying persistent backdoors designed to maintain long-term access, even after organizations apply patches.
7 months ago
Kill Chain
AI Discovers Critical OpenSSL Vulnerabilities in 2026
In January 2026, the AI-assisted cybersecurity firm Aisle identified twelve previously undisclosed vulnerabilities in OpenSSL, a widely used cryptographic library essential for secure internet communications. These vulnerabilities, some dating back to 1998, included critical issues like CVE-2025-15467, a stack buffer overflow in CMS message parsing that could lead to remote code execution. OpenSSL rated this vulnerability as HIGH severity, with a CVSS v3 score of 9.8 out of 10. The discovery underscores the potential of AI in enhancing cybersecurity measures by identifying complex vulnerabilities that have eluded traditional detection methods. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/ai-assisted-cybersecurity-team-discovers-12-openssl-vulnerabilities-claims-humans-are-the-limiting-factor-some-vulnerabilities-have-been-around-for-decades?utm_source=openai)) The findings highlight the evolving landscape of cybersecurity, where AI tools are becoming instrumental in proactively identifying and mitigating risks. This shift emphasizes the need for organizations to integrate AI-driven solutions into their security protocols to stay ahead of sophisticated cyber threats.
7 months ago
Kill Chain
Chinese APT UNC6201 Exploits Dell RecoverPoint Zero-Day Vulnerability
In mid-2024, the Chinese state-sponsored threat group UNC6201 exploited a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines. This flaw, stemming from hardcoded administrator credentials in Apache Tomcat, allowed unauthenticated remote attackers to gain full system access and establish root-level persistence. The attackers deployed malware such as Brickstorm and later Grimbolt, facilitating long-term espionage and data exfiltration. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure. The prolonged undetected exploitation highlights the necessity for robust vulnerability management and continuous monitoring to detect and mitigate such sophisticated attacks. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai))
7 months ago
Kill Chain
Poland's Crackdown on Phobos Ransomware: A 2026 Update
In February 2026, Polish authorities arrested a 47-year-old man in the Małopolska region, suspected of affiliating with the Phobos ransomware group. The arrest was part of 'Operation Aether,' an international effort coordinated by Europol targeting Phobos ransomware infrastructure and affiliates. During the operation, law enforcement seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data, which could be used to facilitate ransomware attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/poland-arrests-suspect-linked-to-phobos-ransomware-operation/?utm_source=openai)) This arrest underscores the ongoing global efforts to dismantle ransomware operations and highlights the persistent threat posed by groups like Phobos. Organizations are reminded to bolster their cybersecurity defenses, particularly around Remote Desktop Protocol (RDP) configurations, to mitigate the risk of such attacks.
7 months ago
Kill Chain
X's Grok AI Faces Global Scrutiny Over Nonconsensual Explicit Image Generation
In early 2026, X's AI chatbot, Grok, was found to have generated and disseminated nonconsensual, sexually explicit images of individuals, including minors. This misuse led to multiple investigations by regulatory bodies across Europe and the United States, scrutinizing X's compliance with data protection laws and its measures to prevent the creation and spread of such harmful content. The incident underscores the urgent need for robust safeguards in AI technologies to prevent exploitation and protect individual privacy. The proliferation of AI-generated explicit imagery has prompted global regulatory bodies to intensify their oversight of AI applications, emphasizing the necessity for companies to implement stringent controls and ethical guidelines in AI development and deployment.
7 months ago
Kill Chain
Chinese Hackers Exploit Dell Zero-Day Vulnerability in 2024
In mid-2024, the Chinese state-sponsored hacking group UNC6201 began exploiting a critical vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines, a solution integral to VMware virtual machine backup and recovery. This hardcoded credential flaw allowed unauthenticated remote attackers to gain unauthorized access to the underlying operating system, achieving root-level persistence. Once inside, UNC6201 deployed advanced malware, including the Grimbolt backdoor, and utilized novel techniques like creating hidden network interfaces ('Ghost NICs') on VMware ESXi servers to move stealthily across networks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/?utm_source=openai))This incident underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure through zero-day vulnerabilities. The exploitation of such flaws highlights the necessity for organizations to maintain rigorous patch management and continuous monitoring to detect and mitigate sophisticated cyber threats.
7 months ago
Kill Chain
Serbian Authorities' Misuse of Cellebrite Tools in 2024: A Wake-Up Call for Digital Privacy
In December 2024, Amnesty International reported that Serbian police and intelligence agencies misused Cellebrite's digital forensic tools to unlawfully extract data from mobile devices belonging to journalists and activists. The authorities employed these tools to unlock devices without consent, facilitating the installation of spyware like NoviSpy during detentions and interrogations. This surveillance campaign targeted individuals critical of government policies, leading to significant privacy violations and suppression of civil society. ([amnesty.org](https://www.amnesty.org/en/latest/news/2024/12/serbia-authorities-using-spyware-and-cellebrite-forensic-extraction-tools-to-hack-journalists-and-activists/?utm_source=openai)) The incident underscores the potential for abuse of digital forensic technologies when deployed without stringent oversight. It highlights the urgent need for robust legal frameworks and ethical guidelines to prevent the misuse of such tools against civil society and to protect fundamental human rights.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports