Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
DragonForce Ransomware Cartel: A New Era of Cyber Threats in 2025
In March 2025, the DragonForce ransomware group rebranded itself as a cartel, allowing affiliates to create their own brands while utilizing DragonForce's infrastructure and tools. This strategic shift led to increased collaboration among ransomware groups, notably with LockBit and Qilin, aiming to consolidate power and enhance operational effectiveness. The cartel model facilitated larger, more coordinated ransomware campaigns, employing advanced tactics such as double extortion, exploitation of known vulnerabilities, and the use of sophisticated tools like Cobalt Strike and Mimikatz. This evolution resulted in a significant uptick in ransomware incidents, impacting various sectors globally, including government entities, retail operations, manufacturing companies, and construction firms. The formation of such cartels underscores a concerning trend in the cyber threat landscape, where ransomware groups are increasingly collaborating to amplify their reach and impact. This development necessitates heightened vigilance and adaptive defense strategies from organizations to mitigate the evolving threats posed by these alliances.
7 months ago
Kill Chain
Iranian Cyber Espionage Intensifies: Middle East Expatriates Targeted in 2026
In early 2026, Iranian state-sponsored cyber actors intensified their espionage activities targeting Middle Eastern expatriates, Syrians, and Israelis. Utilizing sophisticated social engineering techniques, these actors created credible fake personas on multiple platforms, engaging targets over extended periods to build trust. Once rapport was established, they employed spear-phishing campaigns, often delivering malicious links or documents under the guise of legitimate communications. These operations aimed to steal sensitive information, monitor communications, and track the movements of individuals of interest. The impact of these campaigns has been significant, compromising personal and professional data, and posing threats to the safety and privacy of the targeted individuals. The use of advanced social engineering tactics underscores the evolving nature of cyber threats emanating from state-sponsored actors. This incident highlights the urgent need for heightened vigilance and robust cybersecurity measures, especially for individuals and organizations operating in or related to the Middle East. The increasing sophistication of these attacks, coupled with their targeted nature, reflects a broader trend of state actors leveraging cyber capabilities for intelligence gathering and influence operations.
7 months ago
Kill Chain
Phishing Campaign 2026: Malformed URLs Bypass Security Measures
In early February 2026, a sophisticated phishing campaign emerged, utilizing malformed URLs to bypass traditional email security measures. Attackers embedded URLs with irregular parameter structures in phishing emails, leading recipients to malicious websites. This technique effectively evaded detection systems that rely on standard URL parsing and validation, thereby increasing the likelihood of successful credential theft and malware distribution. The campaign underscores the evolving tactics of cybercriminals in circumventing established security protocols. The resurgence of such techniques highlights the need for organizations to continuously adapt their security strategies. As attackers refine their methods to exploit weaknesses in URL parsing and detection, it becomes imperative for security systems to incorporate advanced analysis capabilities to identify and mitigate these sophisticated threats.
7 months ago
Kill Chain
Salt Typhoon 2025: Unveiling the Global Espionage Campaign
In 2025, the Chinese state-sponsored cyber group known as Salt Typhoon orchestrated a sophisticated global espionage campaign, compromising government and critical infrastructure across 37 countries and conducting reconnaissance in 155 nations. The attackers exploited unpatched vulnerabilities in networking equipment, including those from Ivanti, Palo Alto, and Cisco, to gain initial access. Once inside, they established persistent access by modifying access control lists, creating privileged accounts, and enabling remote management on unusual high ports. This allowed them to monitor communications, harvest administrator credentials, and exfiltrate sensitive data through covert tunnels, all while remaining undetected for extended periods. The campaign's targets included telecommunications networks, government systems, transportation hubs, lodging networks, and military infrastructure, enabling continuous surveillance of individuals, communications, and movements globally. ([forbes.com](https://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/?utm_source=openai)) The Salt Typhoon campaign underscores the escalating threat posed by state-sponsored cyber actors and the vulnerabilities within critical infrastructure. The attackers' ability to exploit known vulnerabilities and maintain long-term access highlights the urgent need for organizations to prioritize timely patching, robust access controls, and comprehensive monitoring to detect and mitigate such sophisticated threats.
7 months ago
Kill Chain
Notepad++ Supply Chain Attack: A Wake-Up Call for Software Security
Between June and December 2025, Notepad++, a widely used text editor, was compromised through a sophisticated supply chain attack attributed to Chinese state-sponsored hackers. The attackers infiltrated the hosting provider's infrastructure, allowing them to intercept and redirect update traffic to malicious servers. This enabled the delivery of backdoored versions of Notepad++ to selected users, primarily targeting sectors such as government, telecommunications, and critical infrastructure. The breach was identified in early February 2026, prompting immediate security enhancements and advisories for users to update to version 8.9.1 or later. This incident underscores the escalating threat of supply chain attacks, where adversaries exploit trusted software distribution channels to infiltrate target systems. Organizations are urged to reassess and fortify their software update mechanisms, implement stringent verification processes, and remain vigilant against such sophisticated attack vectors.
7 months ago
Kill Chain
Amaranth Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In August 2025, the cyberespionage group Amaranth Dragon, linked to China's APT41, exploited the CVE-2025-8088 vulnerability in WinRAR to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they leveraged the vulnerability to place encrypted payloads in the Windows Startup folder, ensuring persistence upon system reboot. These attacks were characterized by the use of legitimate tools combined with the custom Amaranth Loader, which retrieved payloads from command-and-control servers concealed behind Cloudflare infrastructure, enhancing stealth and targeting precision. The continued exploitation of CVE-2025-8088 by multiple threat actors underscores the critical need for organizations to promptly update software and implement robust security measures. Despite the release of WinRAR version 7.13, which addresses this flaw, many systems remain vulnerable due to delayed patching and user unawareness, highlighting a significant gap in cybersecurity defenses.
7 months ago
Kill Chain
EDR Killer Tool Exploits EnCase Driver: A Wake-Up Call for Cybersecurity
In early February 2026, cybersecurity researchers identified a sophisticated attack where threat actors utilized a legitimate but revoked EnCase kernel driver to disable endpoint detection and response (EDR) tools. The attackers gained initial access through compromised SonicWall SSL VPN credentials, exploiting the absence of multi-factor authentication. Once inside, they deployed a custom EDR killer tool disguised as a firmware update utility, which installed the 'EnPortv.sys' driver—a component of the EnCase forensic software. This driver, despite its certificate being revoked, was accepted by Windows due to the operating system's handling of driver signatures. The malware leveraged the driver's kernel-mode capabilities to terminate 59 security processes, effectively neutralizing the system's defenses. The attack was halted before ransomware deployment, but it underscores the critical need for robust access controls and vigilant monitoring of security infrastructure. This incident highlights a growing trend where attackers exploit vulnerable or outdated drivers to disable security mechanisms, a technique known as 'Bring Your Own Vulnerable Driver' (BYOVD). The persistence of such methods, despite existing security measures, emphasizes the necessity for organizations to implement comprehensive defense strategies, including regular updates to security protocols and the enforcement of multi-factor authentication across all access points.
7 months ago
Kill Chain
Ransomware Groups Exploit VMware ESXi Vulnerability in 2026
In March 2025, Broadcom patched a high-severity VMware ESXi vulnerability (CVE-2025-22225) that allowed attackers with VMX process privileges to perform arbitrary kernel writes, leading to sandbox escapes. Despite the patch, by February 2026, ransomware groups began exploiting this flaw to gain unauthorized access to ESXi hypervisors, encrypting virtual machines and disrupting critical services. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed these exploitations and added the vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply mitigations or discontinue use if patches are unavailable. This incident underscores the persistent threat posed by unpatched vulnerabilities in widely used virtualization platforms, highlighting the need for timely updates and robust security practices to prevent exploitation by ransomware operators.
7 months ago
Kill Chain
Critical GitLab Vulnerability CVE-2023-7028 Exploited in the Wild
In January 2024, GitLab disclosed a critical vulnerability (CVE-2023-7028) affecting versions 16.1.0 through 16.7.1 of its Community and Enterprise Editions. This flaw allowed attackers to send password reset emails to unverified email addresses, enabling account takeovers without user interaction. Exploitation of this vulnerability could lead to unauthorized access to sensitive data, code repositories, and potential supply chain attacks. ([arstechnica.com](https://arstechnica.com/security/2024/05/0-click-gitlab-hijacking-flaw-under-active-exploit-with-thousands-still-unpatched/?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2023-7028 to its Known Exploited Vulnerabilities catalog in May 2024, indicating active exploitation in the wild. Organizations using affected GitLab versions were urged to apply patches immediately to mitigate the risk of account hijacking and associated threats. ([computerweekly.com](https://www.computerweekly.com/news/366583457/Patch-GitLab-vuln-without-delay-users-warned?utm_source=openai))
7 months ago
Kill Chain
SolarWinds Web Help Desk 2026 Untrusted Data Deserialization RCE
In January 2026, a critical vulnerability (CVE-2025-40551) was discovered in SolarWinds Web Help Desk (WHD), allowing unauthenticated remote code execution through untrusted data deserialization. Exploitation of this flaw enables attackers to execute arbitrary commands on the host system, potentially leading to full system compromise. SolarWinds released WHD version 2026.1 on January 28, 2026, addressing this and other vulnerabilities. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/cve-2025-40551?utm_source=openai)) The inclusion of CVE-2025-40551 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the patch promptly. This incident highlights the persistent threat posed by deserialization vulnerabilities and the importance of timely software updates to mitigate such risks. ([securityweek.com](https://www.securityweek.com/fresh-solarwinds-vulnerability-exploited-in-attacks/?utm_source=openai))
7 months ago
Kill Chain
NGINX Server Compromise 2026: Understanding the Traffic Redirection Attack
In early February 2026, a sophisticated cyberattack targeted NGINX servers, leading to unauthorized redirection of user traffic through attacker-controlled infrastructure. The threat actors exploited vulnerabilities in NGINX configurations, particularly by injecting malicious 'location' blocks into existing configuration files. This manipulation allowed them to intercept and reroute incoming requests without triggering standard security alerts, as the abuse leveraged legitimate directives like 'proxy_pass'. The campaign primarily affected websites with Asian top-level domains and government and educational institutions, compromising the integrity and confidentiality of user data. This incident underscores the critical need for organizations to regularly audit and secure their web server configurations. The attackers' method of embedding malicious instructions within NGINX configuration files highlights the evolving sophistication of cyber threats and the importance of proactive defense measures to prevent similar breaches.
7 months ago
Kill Chain
Amaranth-Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In 2025, the China-linked cyber espionage group Amaranth-Dragon exploited a critical vulnerability in WinRAR (CVE-2025-8088) to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they executed arbitrary code upon extraction, leading to unauthorized access and data exfiltration. The campaigns were highly controlled, leveraging spear-phishing emails with tailored lures related to regional political developments, and utilized cloud platforms like Dropbox to distribute the malicious files. The exploitation of this vulnerability underscores the persistent threat posed by nation-state actors and the importance of timely software updates. Despite the release of WinRAR version 7.13, which addressed the flaw, many users remained vulnerable due to delayed patching. This incident highlights the critical need for organizations to maintain up-to-date software and implement robust security measures to defend against sophisticated cyber threats.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports