Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
CISA Warns of Chinese 'BrickStorm' Malware on VMware Servers: What Enterprises Must Know
In mid-2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Chinese state-sponsored hackers deployed the 'BrickStorm' malware to backdoor vulnerable VMware vSphere servers across multiple U.S. critical infrastructure sectors. Attackers exploited unpatched or insecurely configured vSphere environments to gain initial access, install persistent web shells, and enable lateral movement within networks. The campaign featured advanced evasion tactics, strong operational security, and targeted high-value assets, risking confidential data exposure, business disruption, and regulatory non-compliance for affected organizations. This attack exemplifies a rising trend of sophisticated supply-chain and infrastructure attacks leveraging known vulnerabilities in virtualized server environments. With ongoing exploitation by nation-state actors and renewed regulatory focus on asset protection, organizations must reevaluate their segmentation, patching, and east-west visibility controls to mitigate similar threats.
8 months ago
Kill Chain
Major Insider Attack Wipes 96 US Government Databases: Lessons for 2024
In June 2024, two Virginia-based former federal contractors were accused of orchestrating a significant insider attack after being terminated from their government roles. Prosecutors allege the brothers conspired to steal sensitive information and deliberately wiped 96 critical government databases, severely disrupting several agencies' operations. The attack exploited their privileged access, allowing them to bypass existing controls and inflict lasting operational and data loss consequences. This incident highlights how trusted insiders with sufficient technical skills and unresolved grievances can weaponize their access against public-sector organizations, exposing gaps in monitoring and segmentation. Insider-powered destructive attacks are on the rise globally, targeting both public and private sectors with increasing sophistication. In a climate of heightened regulatory expectations and increasing adoption of zero trust models, this incident demonstrates the urgency to strengthen monitoring, privileged access controls, and anomaly detection to detect and prevent similar threats.
8 months ago
Kill Chain
2025’s Multi-Vector Supply Chain Attacks: How AI and Automation Redefined Web Security
In 2025, a coordinated wave of sophisticated attacks exploited web supply chain vulnerabilities, impacting over 180,000 websites globally. Threat actors leveraged multi-vector tactics, combining AI-driven injection methods, automated credential stuffing, and lateral movement across cloud and hybrid environments. The adversaries compromised legitimate third-party libraries and embedded malicious code into trusted web assets, bypassing traditional security controls and causing data breaches, unauthorized financial transfers, and reputation damage for thousands of organizations. Rapid east-west propagation enabled attackers to escalate privileges and exfiltrate sensitive customer data before detection. This incident signals a shift in the threat landscape, with attackers increasingly using AI and automation to exploit supply chain trust, targeting hybrid and multi-cloud infrastructures. Organizations face unprecedented pressure to modernize web security, prioritizing zero trust, real-time threat monitoring, and proactive segmentation to defend against rapidly evolving, multi-pronged attack campaigns.
8 months ago
Kill Chain
GoldFactory Trojan Infects 11,000+ Mobile Users in Southeast Asia through Fake Banking Apps
Between October and December 2024, a financially motivated threat group known as GoldFactory orchestrated an extensive campaign targeting mobile users across Indonesia, Thailand, and Vietnam. By impersonating trusted government services, the attackers distributed modified Android banking apps laced with malware, resulting in over 11,000 infections. Once installed, these malicious applications harvested sensitive financial data and enabled unauthorized transactions, posing significant financial risks to individual users and undermining trust in mobile banking channels. The campaign used phishing techniques and social engineering, making detection challenging for average users. This incident illustrates the growing trend of cybercriminals leveraging mobile channels and government impersonation to amplify reach and lower the barrier for monetization in emerging markets. It also highlights the urgent need for stronger mobile security controls, user education, and regulatory vigilance to mitigate evolving threats targeting digital financial services.
8 months ago
Kill Chain
Silver Fox Mimics Russian Tactics: Fake Teams Installer Pushes ValleyRAT in 2025 China Cyber Attack
In December 2025, the threat actor known as Silver Fox executed a targeted cyber campaign in China, distributing the ValleyRAT remote access trojan through a fake Microsoft Teams installer. By leveraging SEO-poisoned websites, attackers lured victims searching for legitimate collaboration apps into downloading malicious files disguised as authentic installers. Once executed, the malware provided the attackers with covert access and enabled data theft, surveillance, and potential lateral movement within targeted organizations. The campaign mimicked Russian threat actor behaviors as a false flag, complicating attribution and response. This incident highlights the increasing sophistication and frequency of social engineering attacks using trusted business tools as lures. The rise of targeted SEO poisoning, deceptive software installers, and identity obfuscation poses heightened risks for organizations handling sensitive data or operating in sensitive regions.
8 months ago
Kill Chain
Intellexa 2024: Spyware Supply Chains Now Targeting Executives Worldwide
In 2024, investigators identified a sprawling global network linked to Intellexa, a major commercial spyware developer behind the Predator malware platform. Entities across multiple countries—including the Czech Republic, Kazakhstan, and the Philippines—were found facilitating the shipment and deployment of Intellexa’s surveillance products to government and private sector customers. Notably, targeting expanded beyond civil society to include executives and high-value private sector individuals, with infection vectors leveraging ad-based mechanisms such as the 'Aladdin' platform. This growing balkanized ecosystem enables strategic intelligence gathering, while obfuscating operator and client identities. This incident reflects intensifying arms-race dynamics in the mercenary spyware market, characterized by increased secrecy, proliferation to jurisdictions with weak oversight, and exposure of private sector leaders. The expanding reach and impact have raised urgent concerns over regulatory gaps, legal liability, and escalating risks to both individual privacy and organizational resilience.
8 months ago
Kill Chain
CISA 2025 Advisories Expose Widespread ICS Vulnerabilities in Critical Infrastructure
On December 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued nine Industrial Control Systems (ICS) advisories after identifying multiple vulnerabilities across key ICS products from major vendors such as Mitsubishi Electric, Johnson Controls, Sunbird, SolisCloud, Advantech, and others. While no active exploitation was confirmed at the time of disclosure, these vulnerabilities—ranging from insufficient access controls and weak encryption to improper input validation—expose critical industrial environments to potential risks including remote code execution, credential compromise, and unauthorized access. The advisories underscore the wide attack surface present in operational technology (OT) and outline mitigation steps for affected organizations. The coordinated disclosure highlights the urgent need for ICS operators to address cybersecurity weaknesses as attackers increasingly target industrial networks. With OT/IT convergence, a sharp rise in ransomware, and persistent geopolitical tensions, these advisories reinforce the imperative for proactive patch management, microsegmentation, encrypted traffic, and continuous OT monitoring to prevent disruptive and costly breaches.
8 months ago
Kill Chain
Millions Exposed: ShadyPanda’s 2024 Browser Supply Chain Attack
In early 2024, the ShadyPanda cyber-threat group, linked to China, orchestrated a large-scale malware campaign by exploiting browser extensions on the Google Chrome and Microsoft Edge marketplaces. The attackers embedded malicious code into seemingly innocuous browser add-ons, silently weaponizing millions of user browsers worldwide. Once installed, these extensions enabled covert surveillance, data exfiltration, and potentially even lateral movement within corporate environments, posing severe risks to both individual privacy and enterprise security. The incident highlights the vulnerabilities in browser supply chains, with organizations scrambling to assess exposure and patch endpoints. This breach underscores a rising trend of sophisticated supply chain and browser-based attacks, where adversaries blend into daily workflows to evade detection. Security leaders must quickly reassess extension controls, threat detection strategies, and regulatory compliance amid growing regulatory scrutiny and persistent attacker innovation.
8 months ago
Kill Chain
How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024
In early 2024, Iranian state-sponsored APT MuddyWater launched a series of cyberattacks against Israeli organizations using a novel evasion method involving a modified version of the classic Snake mobile game. Attackers embedded malicious code within the game to establish a covert communication channel and facilitate lateral movement within compromised networks. Initial access was likely achieved through phishing emails, followed by deployment of specially crafted files to disguise data exfiltration activities. The campaign resulted in unauthorized access to sensitive data and disruption of critical business operations for targeted Israeli entities. This incident highlights a growing trend of threat actors leveraging benign-looking applications and creative techniques to bypass traditional security controls. The use of retro games as a decoy demonstrates that sophisticated attackers are continually adapting, raising the bar for detection and forensic analysis across industries.
8 months ago
Kill Chain
Student Breach: Compromised Gov't and University Access Sold to Chinese Actors (2024)
In early 2024, cyber investigators uncovered a scheme in which a student was selling fully compromised access to high-value government and university websites, predominantly to Chinese threat actors. The access, peddled through underground forums for several hundred dollars apiece, enabled buyers to exploit web server vulnerabilities, deploy malware, and potentially exfiltrate sensitive institutional and personal data. These breaches highlighted significant weaknesses in internal access controls and malware detection at academic and government institutions, risking the integrity of core systems, sensitive research, and regulated personal information. The incident underscores ongoing operational and reputational risks for public sector organizations, particularly where student employees or contractors bypass internal protections. This breach is emblematic of an emerging trend—threat actors leveraging insiders or poorly vetted contractors to facilitate lateral movement targeting valuable educational and governmental data. As ransomware groups and state-sponsored adversaries shift toward supply chain and identity-driven compromise, robust zero trust controls and network segmentation are becoming essential to preempt similar attacks.
8 months ago
Kill Chain
How a 2025 SSH Trojan Attack Leveraged a Government IP and Masquerading Tactics
In November 2025, a sophisticated cyberattack was observed when an adversary used SSH brute-force tactics to infiltrate a honeypot system, exploiting default 'root' credentials. Once inside, the attacker uploaded a malicious ELF binary, masquerading as the legitimate OpenSSH daemon ('sshd'), designed for persistence and stealth. The operation originated from a government-owned IP address, but evidence suggests the IP was likely compromised and misused, underscoring the complexity of attributing attacks. No commands were executed post-login, highlighting advanced attacker tradecraft focused on evasion and long-term foothold. This incident exemplifies modern threats leveraging credential reuse, sophisticated masquerading, and the abuse of trusted system binaries. Such attacks signal the growing use of covert techniques, presenting heightened risks to organizations and reinforcing the need for proactive defense, improved authentication practices, and advanced monitoring.
8 months ago
Kill Chain
PRC State Actors Compromise Public Sector with BRICKSTORM Malware
In late 2025, PRC state-sponsored cyber actors launched a sophisticated espionage campaign using the BRICKSTORM malware, targeting government and information technology sectors. The threat actors gained initial access via a compromised web server in victim DMZs, progressed laterally to internal VMware vCenter servers, and deployed BRICKSTORM to maintain deep persistence in both VMware vSphere and Windows environments. Leveraging advanced encrypted communication channels, stolen credentials, and techniques such as DNS-over-HTTPS and rogue virtual machines, the actors exfiltrated sensitive data while evading detection for extended periods. This incident underscores the evolving tactics of nation-state adversaries, who now frequently employ modular, stealthy malware to attack critical infrastructure. The widespread use of cloud and virtualization platforms in public sector IT environments makes these organizations particularly vulnerable to such persistent threats.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports