Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
US Treasury Highlights $4.5B in Ransomware Payments: 2024 Threat Landscape
In February 2024, the US Treasury’s Financial Crimes Enforcement Network (FinCEN) reported that ransomware attacks have resulted in over $4.5 billion in ransom payments since 2013, underscoring a dramatic surge in both scale and sophistication. Attackers typically infiltrated organizations through phishing campaigns, exploitation of unpatched vulnerabilities, and compromised remote desktop protocols, deploying ransomware variants to encrypt data and demand payment. These incidents disrupted critical business operations across sectors, forced enterprises to halt services, and left many struggling with reputational and financial damage. This report is especially relevant as ransomware strains evolve, facilitating large-scale attacks on enterprises, healthcare, and infrastructure. Heightened regulatory scrutiny, such as OFAC and FinCEN advisories, means organizations face intensified pressure to monitor, report, and prevent ransomware-related activities.
8 months ago
Kill Chain
Critical Flaw in India-Based CCTV Cameras Exposes Credentials via Missing Authentication
In December 2025, a critical vulnerability (CVE-2025-13607) was discovered in multiple India-based CCTV camera systems, particularly impacting D-Link's DCS-F5614-L1 model up to version v1.03.038, with other vendors like Sparsh Securitech and Securus CCTV also implicated. The flaw allowed remote attackers to access sensitive camera configuration information and steal account credentials without any authentication, dramatically raising the risk of unauthorized surveillance, data breaches, or lateral movement across commercial facility networks. Security researchers reported this issue to CISA, who validated the high-severity risk with a CVSS v4 score of 9.3. This incident highlights the persistent risk posed by insecure IoT devices in critical sectors. Vulnerabilities in widely deployed camera models remain a prime target for opportunistic attackers and serve as a cautionary signal amidst the global increase in attacks exploiting exposed IoT endpoints.
8 months ago
Kill Chain
Apache Tika’s Critical Patch Flaw: 2024 Supply-Chain Wake-Up Call
In June 2024, The Apache Software Foundation disclosed that its initial patch for a critical vulnerability (CVE-2024-29945) in Apache Tika was incomplete, leaving systems exposed to remote code execution risks. Tika, widely used for content detection and extraction, is embedded in many enterprise and cloud-native applications, amplifying the scale of exposure through the software supply chain. Attackers who exploit this flaw can execute arbitrary code on affected servers, potentially enabling data breaches or lateral movement across environments. The revised advisory and updated CVE has prompted urgent action to remediate the unresolved security gap. This incident highlights persistent challenges around open-source supply chain risks, insufficient patch validation, and the rapid exploitation of incomplete fixes. Organizations must evaluate their dependency chains, continuously monitor vendor advisories, and implement layered security controls as supply-chain vulnerabilities become increasingly frequent and business-critical.
8 months ago
Kill Chain
UK Cyber Agency Issues Stark Warning: Prompt Injection in LLMs is Here to Stay
In June 2024, the UK’s National Cyber Security Centre (NCSC) publicly warned that large language models (LLMs), including popular AI tools such as ChatGPT and Claude, possess a fundamental and persistent vulnerability known as prompt injection. This flaw arises because LLMs are architecturally incapable of reliably distinguishing between trusted and untrusted input within prompts. Despite repeated industry efforts to implement guardrails, researchers routinely bypass these safeguards, allowing malicious actors to manipulate LLM behavior, potentially leading to harmful outputs or the execution of unauthorized actions in real-world applications that integrate LLMs. This alert is especially significant as LLM-driven automations are rapidly proliferating in software development, browser agents, and enterprise workflows. The NCSC’s assessment signals an urgent need for organizations to shift their risk models, as AI prompt injection represents a persistent, unfixable attack vector with serious implications for data security, business integrity, and regulatory compliance.
8 months ago
Kill Chain
Nation-State Cyber Espionage: Iran’s Shahid Shushtari Unit and the $10M Bounty
In late 2024, security authorities announced a $10 million reward for information regarding the whereabouts of Mohammad Bagher Shirinkar and Fatemeh Sedighian Kashi, key leaders of Shahid Shushtari — a cyber unit operating under Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. Known by threat intelligence analysts as UNC5866, Cotton Sandstorm, and Haywire Kitten, the group targets critical infrastructure sectors, including news, shipping, travel, energy, financial services, and telecom across the U.S., Europe, and the Middle East. Their operations span spear-phishing, malware campaign delivery, and cyberespionage, with significant disruptions and financial damages reported. Notably, the group attempted to influence the 2020 U.S. presidential election and continues its multi-pronged attacks using evolving techniques and new tradecraft. This incident underscores the persistent and evolving threat posed by nation-state actors targeting both public and private institutions globally. Increased vigilance, timely intelligence sharing, and robust controls around east-west network traffic and encrypted communications are now critical countermeasures as similar attacks escalate.
8 months ago
Kill Chain
Poland Arrests Ukrainians in 2024 Espionage Cyber Incident
In June 2024, Polish authorities arrested three Ukrainian nationals accused of using sophisticated hacking equipment to carry out cyberattacks targeting Polish IT systems, with particular emphasis on the theft of 'computer data of particular importance to national defense.' The suspects were apprehended while allegedly attempting to damage government information technology infrastructure, utilizing encrypted communications and advanced attack tools likely designed to evade monitoring and facilitate data exfiltration. The incident underscores heightened tensions in the region and reveals vulnerabilities within national networks, with Polish law enforcement quickly intervening to mitigate further impact. This breach is emblematic of a broader escalation in nation-state cyber operations across Europe, featuring cross-border actors relying on advanced techniques to infiltrate sensitive targets. The event highlights the urgent need for robust east-west traffic security, encrypted communications, and real-time anomaly detection controls to guard national interests and critical IT environments.
8 months ago
Kill Chain
Iranian APT 'MuddyWater' Launches UDPGangster Backdoor in Multi-Nation Espionage Campaign
In late 2025, the Iranian cyber espionage group MuddyWater launched a targeted campaign against organizations in Turkey, Israel, and Azerbaijan using a novel backdoor dubbed UDPGangster. The malware leveraged UDP-based command-and-control channels to enable remote management of infected systems while evading traditional network detection techniques. Attacks typically began via spear-phishing emails containing malicious attachments or links, granting the attackers a foothold in victim environments and facilitating lateral movement and data exfiltration. Fortinet FortiGuard Labs was among the first to document the malware and its unique communication characteristics. The campaign highlighted substantial risks to critical sectors and national security in the affected countries. This incident exemplifies rising threat actor sophistication—specifically, abuse of obscure protocols like UDP for covert C2—and underscores the strategic evolution of Iranian groups. Its tactics reflect broader cyber espionage trends across the Middle East and signal urgent needs for advanced lateral movement detection and zero trust controls.
8 months ago
Kill Chain
Ransomware: FinCEN Reports Over $2.1B Paid to Gangs (2022–2024)
Between 2022 and early 2024, ransomware gangs operating globally extorted over $2.1 billion from victims, according to an official report by the Financial Crimes Enforcement Network (FinCEN). Activity surged markedly in 2023, driven by large-scale campaigns from prolific threat groups such as ALPHV/BlackCat and LockBit. Attackers commonly gained initial access through phishing, vulnerable VPNs, or exposed remote services, rapidly leveraging lateral movement and data exfiltration before deploying file-encrypting malware to maximize leverage. As a result, numerous organizations across multiple sectors experienced severe operational disruption, financial losses, reputational damage, and in some cases, regulatory scrutiny. This incident underscores the growing reach and impact of organized ransomware, even as some law enforcement takedowns in late 2023 and 2024 caused temporary disruption to top gangs. The pattern highlights evolving attacker strategies, heightened regulatory attention, and the need for proactive cyber defense and comprehensive incident response preparedness.
8 months ago
Kill Chain
JS#SMUGGLER Campaign: How Compromised Websites Delivered NetSupport RAT in 2025
In December 2025, cybersecurity researchers discovered a widespread campaign called JS#SMUGGLER leveraging compromised websites to deliver NetSupport RAT, a versatile remote access trojan. The attack chain involved injecting obfuscated JavaScript loaders onto legitimate sites, which delivered device-aware, multi-stage payloads via hidden iframes, HTML application (HTA) loaders, and encrypted PowerShell scripts. This sophisticated approach enabled attackers to remotely control infected hosts, exfiltrate sensitive data, and evade detection through in-memory and fileless techniques. The campaign targeted enterprise users indiscriminately and was attributed to yet-uncategorized threat actors, though infrastructure overlap with SmartApeSG was noted. The incident is a timely reminder of advancing web-based malware deployment tactics, blending script obfuscation, evasive loaders, and context-aware delivery. As enterprises increasingly rely on web interfaces and remote access, defenders face mounting pressure to detect, segment, and monitor east-west and egress network activity in real time to thwart lateral movement and data theft.
8 months ago
Kill Chain
CISA Flags Active D-Link & Array Networks Vulnerabilities in 2025 KEV Catalog
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog to include two actively exploited vulnerabilities: CVE-2022-37055, a buffer overflow in D-Link routers, and CVE-2025-66644, an OS command injection flaw impacting Array Networks ArrayOS AG. These vulnerabilities provide attack vectors for cybercriminals to gain unauthorized access, conduct lateral movement, or exfiltrate sensitive data within federal and private sector networks. The directive mandates that all Federal Civilian Executive Branch (FCEB) agencies address these threats promptly to reduce risk exposure and protect operational integrity. This update underscores the persistent threat posed by unpatched network infrastructure vulnerabilities, which remain prime targets for attackers. Timely remediation of KEV-listed vulnerabilities is increasingly critical for all organizations amid a rising trend of targeted attacks against widely deployed network devices.
8 months ago
Kill Chain
Escalating Credential Attacks on Palo Alto GlobalProtect VPNs: 2024 Threat Review
In early 2024, cybersecurity analysts observed a widespread campaign targeting Palo Alto Networks’ GlobalProtect VPN portals and SonicWall SonicOS API endpoints with aggressive login attempts and scanning activity. Threat actors used automated tools to conduct credential stuffing and exploit potential vulnerabilities in exposed VPN portals, aiming to gain unauthorized network access. While no specific breaches were confirmed, the campaign's scope affected numerous organizations globally relying on these remote access solutions, highlighting the heightened risk to large enterprises and managed service providers leveraging vulnerable or misconfigured VPN infrastructure. This incident illustrates the surge in identity-driven and credential-based attacks exploiting remote access technologies, especially as hybrid and remote workforces remain prevalent. The rapid evolution and broad targeting underscore the urgent need for continuous VPN hardening, robust access governance, and threat monitoring to preempt similar intrusion attempts impacting business continuity.
8 months ago
Kill Chain
Intellexa Predator Spyware Strikes Pakistani Civil Society via WhatsApp (2025)
In June 2025, a human rights lawyer based in Balochistan, Pakistan, was targeted by Intellexa's highly advanced Predator spyware via a malicious WhatsApp link, according to Amnesty International. This marks the first documented case of a civil society member in Pakistan being targeted by this tool. The attacker, likely operating with government-grade resources, used zero-day exploits and an advertising-based infection vector to bypass conventional defenses, aiming to infiltrate the lawyer's mobile device and access sensitive communications. This incident underscores the growing sophistication of spyware campaigns and the expansion of mercenary surveillance tools targeting individuals beyond political figures or journalists. It highlights the urgent need for robust communication security and regulatory scrutiny of commercial spyware vendors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports