Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia
In mid-2025, the Chinese cyber espionage group Mustang Panda deployed a previously undocumented, signed kernel-mode rootkit to secretly load a TONESHELL backdoor variant during targeted attacks against government organizations in Southeast and East Asia—mainly Myanmar and Thailand. Leveraging a stolen legacy digital certificate, the attackers installed a Windows minifilter driver to inject TONESHELL into system processes, evade security controls, and shield their malware and associated files from detection. The backdoor enabled ongoing remote control, data exfiltration, and further malware deployments via encrypted channels, establishing persistent clandestine access. This incident is notable for its innovative use of signed kernel drivers to enhance stealth, resilience, and anti-forensic measures. It reflects a broader trend among sophisticated threat actors who increasingly leverage advanced rootkit technology and certificate abuse to bypass endpoint protections and remain undetected for extended periods.
8 months ago
Kill Chain
US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures
In December 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) removed three individuals previously sanctioned for their involvement with Intellexa and its Predator commercial spyware from the Specially Designated Nationals (SDN) list. The individuals—Merom Harpaz, Andrea Nicola Constantino Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou—were linked to leadership and distribution roles within the Intellexa Consortium. Their removal followed a petition and OFAC’s evaluation that they had separated themselves from the Intellexa ecosystem, but no underlying details or independent confirmation were disclosed. The original sanctions stemmed from their roles in developing, distributing, and enabling Predator software, a tool implicated in high-profile surveillance of civil society figures, including journalists and activists, through stealth zero-day and social engineering attacks. This case underscores the continued risks posed by commercial spyware vendors and associated compliance exposures. Ongoing public reporting highlights Predator’s persistent activity despite regulatory efforts, as well as geopolitical pressures that drive international balkanization and new attack trends targeting sensitive sectors. With regulatory frameworks evolving and threat actors shifting tactics, the risk of spyware misuse for human rights abuses and espionage remains acute.
8 months ago
Kill Chain
Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026
In early January 2026, it was revealed that over 10,000 Fortinet FortiGate firewalls remain exposed to a critical authentication bypass vulnerability (CVE-2020-12812) first patched by Fortinet in July 2020. Attackers exploit this flaw by manipulating username case sensitivity to bypass two-factor authentication (2FA) on SSL VPNs—allowing unauthorized access to devices with unpatched software and certain LDAP configurations. Despite years of vendor and government warnings, more than 1,300 vulnerable systems in the United States alone are still online, placing organizations at ongoing risk of compromise. The persistence of this five-year-old flaw’s exploitation highlights chronic issues in vulnerability management and patch adoption within network infrastructure. Active targeting by both cybercriminal and state-backed actors, combined with evidence of ransomware deployment, underscores the need for continuous configuration hardening, zero trust adoption, and rapid remediation of exposed security controls.
8 months ago
Kill Chain
Phishing Goes Cloud-Native: Google Cloud Application Integration Abused in 2026 Attack
In early 2026, a sophisticated phishing campaign was uncovered in which cybercriminals leveraged Google Cloud’s Application Integration service to send deceptive emails that mimicked legitimate Google communications. By exploiting the inherent trust in Google’s cloud infrastructure, attackers generated emails from authentic Google addresses, increasing the likelihood of victims engaging with malicious links or sharing sensitive information. According to Check Point researchers, this multi-stage approach enabled attackers to bypass traditional email security measures, posing significant risks to organizations that rely heavily on cloud-based productivity suites for daily operations. This campaign highlights an emerging trend in the abuse of trusted SaaS and cloud platforms for targeted phishing attacks. As adversaries shift toward cloud-native TTPs and social engineering techniques, organizations must enhance detection, improve user awareness, and adapt inline controls to mitigate risks tied to trusted service abuse.
8 months ago
Kill Chain
IBM API Connect Critical Authentication Bypass (2025): What You Must Know
In December 2025, IBM disclosed a critical security vulnerability (CVE-2025-13915) in its API Connect platform, rated 9.8 on the CVSS scale. The flaw allowed remote attackers to bypass authentication mechanisms and gain unauthorized access to exposed applications. Exploitation could enable attackers to manipulate sensitive workloads, extract confidential data, or pivot deeper into network environments. The incident highlighted how a simple authentication bypass in widely deployed enterprise middleware presents major risks for organizations relying on API-enabled digital ecosystems. This breach underscores the escalating sophistication of identity-focused attacks and the necessity for robust authentication and segmentation controls. With API-driven architectures proliferating in nearly every sector, such vulnerabilities are increasingly targeted; urgency is amplified by regulatory pressure and the rising adoption of zero trust frameworks.
8 months ago
Kill Chain
How Transparent Tribe’s 2026 RAT Offensive Breached Indian Government & Academia
In early 2026, the advanced persistent threat group Transparent Tribe (APT36) launched a sophisticated cyber espionage campaign targeting Indian governmental and academic institutions. Attackers distributed spear-phishing emails containing ZIP archives with malicious Windows shortcut (LNK) files, disguised as legitimate PDFs. Upon execution, these files deployed remote access trojans (RATs) by loading encrypted payloads in-memory and displaying decoy documents to evade suspicion. The malware adapted its persistence techniques based on detected antivirus solutions and enabled functions such as file management, system reconnaissance, data exfiltration, and command execution via a dynamic command-and-control infrastructure. This incident highlights the persistent evolution of state-linked cyber threats and the rising use of multi-stage spear-phishing, evasive loaders, and context-aware persistence. As state-sponsored attacks become more adaptive and target the public sector, organizations face increased regulatory and operational pressure to fortify internal security controls and monitor lateral movement.
8 months ago
Kill Chain
Flock Cloud Misconfiguration Exposes AI Camera Surveillance Feeds in 2026
In January 2026, Flock, a prominent provider of AI-enabled surveillance technologies, faced a significant cybersecurity incident due to a cloud misconfiguration. Unauthorized online access was discovered, revealing live video streams from Flock’s advanced Condor pan-tilt-zoom cameras deployed in public areas and private properties. These cameras, designed for AI-driven facial and movement tracking, unintentionally exposed high-resolution footage of civilians—including children—across multiple locations, highlighting considerable privacy and operational risks. No evidence suggests the exposure was caused by active exploitation; instead, the open access points were a direct result of insufficient cloud security controls and misapplied access permissions. The incident triggered regulatory and public concern around surveillance, data protection, and compliance obligations, emphasizing the criticality of proper cloud configurations in the era of AI-driven physical security systems. This breach is indicative of a broader rise in cloud infrastructure misconfigurations exposing sensitive, AI-powered surveillance data. Regulatory agencies and industry groups are increasing pressure on technology vendors to enforce robust controls, with cloud and IoT security now considered foundational to protecting physical as well as digital environments.
8 months ago
Kill Chain
2025 Cloud Provider Breach: Multi-Vector Ransomware and the East-West Security Imperative
In early 2025, a sophisticated multi-vector cyberattack struck a leading multinational cloud services provider. Threat actors leveraged a combination of zero-day exploits, lateral movement, and exploited east-west traffic weaknesses to progressively compromise internal workloads across hybrid and multicloud environments. Utilizing encrypted channels, they evaded detection and ultimately deployed pervasive ransomware, resulting in widespread data exfiltration, service disruptions, and significant financial and reputational damage. Despite existing controls, gaps in segmentation and egress policy enforcement were exploited, with the incident exposing vulnerabilities in both cloud-native and on-premise environments. This breach highlights an escalating trend: attackers using complex, multi-stage TTPs that blend cloud-native exploits with traditional ransomware vectors. Security leaders must prioritize zero trust segmentation, real-time east-west inspection, and enforceable multicloud security controls to address rapidly evolving threat landscapes.
8 months ago
Kill Chain
Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign
In April and May 2024, thousands of organizations worldwide were compromised after a Chinese state-sponsored advanced persistent threat (APT) group exploited multiple previously unknown zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) platform. The attackers used these flaws as entry points to gain administrative control, move laterally, and deploy persistent malware, leading to widespread data exfiltration and operational disruption. The campaign targeted government, critical infrastructure, and private sector entities, exploiting unpatched systems at scale before public disclosure, prompting rapid security advisories and emergency patching. This Ivanti EPMM incident underscores the growing sophistication of nation-state campaigns leveraging zero-day vulnerabilities for large-scale compromise. It highlights the urgent industry need for rigorous vulnerability management, zero trust architectures, and rapid detection in light of escalating APT tactics.
8 months ago
Kill Chain
ErrTraffic ClickFix: The 2024 Malware Campaign Exploiting Fake Browser Glitches
In March 2024, security researchers uncovered a large-scale cybercriminal campaign leveraging a service named ErrTraffic to automate 'ClickFix' attacks via fake browser glitches. Threat actors compromised legitimate websites, deploying scripts to simulate error pop-ups and glitches that tricked users into downloading malicious payloads or executing harmful actions. The attackers utilized advanced social engineering, presenting credible browser dialog impersonations, and used the campaign to rapidly distribute information-stealing malware across multiple geographies. The impact included significant compromises of user credentials and personal information, highlighting growing risk to businesses reliant on web applications. This incident is particularly notable as it demonstrates both evolving infostealer TTPs and the increasing sophistication of social engineering through browser-manipulation. The widespread adoption of automated 'glitch' services like ErrTraffic signals a broader shift towards commoditizing web-based attacks targeting both enterprises and individuals.
8 months ago
Kill Chain
ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security
In June 2024, the European Space Agency (ESA) confirmed a cybersecurity incident involving unauthorized access to external servers outside its core corporate IT network. These servers contained 'unclassified' information tied to ESA's collaborative engineering activities. The breach was detected and announced on June 24, with the agency rapidly taking down the compromised servers to contain the incident and beginning an internal investigation. No critical or classified ESA infrastructure was reportedly affected, and mission operations remained unaffected. This breach underscores persistent risks facing organizations collaborating with external partners and utilizing externally accessible infrastructure. Similar methodologies targeting non-core systems and lateral movements are increasing, highlighting the importance of robust segmentation, external system monitoring, and continuous risk assessment for third-party assets.
8 months ago
Kill Chain
Silver Fox Exploits Income Tax Phishing to Deploy ValleyRAT in India (2025)
In December 2025, the Chinese-origin threat group Silver Fox launched a sophisticated phishing campaign targeting Indian users with income tax-themed emails. Victims received emails purportedly from India’s Income Tax Department containing decoy PDF attachments. When recipients opened the PDFs, they were redirected to a malicious website serving a ZIP file with a trojanized installer. The infection leveraged DLL hijacking and a legitimate executable to sideload malware, ultimately installing ValleyRAT—a modular remote access trojan—by process hollowing. Once active, ValleyRAT enabled attackers to harvest credentials, establish persistence, and communicate via encrypted channels for ongoing control. This incident highlights the convergence of advanced phishing lures, supply chain manipulation, and evasive malware tailoring persistent access to high-value targets across public, financial, healthcare, and technology organizations. ValleyRAT’s modularity, anti-analysis features, and delayed communication underline a pivot towards low-noise, highly adaptive attacks exploiting human trust and regulatory touchpoints.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports