Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Smishing Triad’s 2024 US SMS Phishing Campaign: Government Impersonation Goes Mainstream
In early 2024, a threat group known as the 'Smishing Triad' launched a wave of phishing attacks targeting American mobile phone users through fake government-related SMS messages. The group impersonated federal and state agencies, primarily sending texts about unpaid toll fees and penalties to lure recipients into clicking malicious links. These links redirected victims to counterfeit payment portals to steal personal and financial information. The campaign used low-frequency, highly targeted smishing tactics which significantly increased trust and subsequent victim engagement, resulting in a notable uptick in credential theft and financial fraud. This incident is part of a broader trend where cybercriminal organizations leverage sophisticated social engineering and government impersonation at a time of regulatory scrutiny around SMS-based phishing (smishing). Its evolving tactics show how attackers adapt to increase impact, highlighting the urgent need for layered, identity- and zero-trust-driven defenses.
8 months ago
Kill Chain
Former L3Harris Executive Charged with Selling Cyber Trade Secrets to Russia
In August 2025, U.S. federal prosecutors charged Peter Williams, a former executive at L3Harris Technologies’ cyber division, with stealing and selling sensitive trade secrets to an undisclosed Russian buyer. Williams, the former general manager of specialized hacking group Trenchant, allegedly misappropriated eight proprietary technologies from two companies between April 2022 and August 2025, totaling $1.3 million in illicit gains. The Department of Justice seeks forfeiture of assets derived from the scheme. Neither L3Harris nor Trenchant is accused of direct wrongdoing. This incident underscores the growing threat posed by insiders with privileged access to highly sensitive cyber capabilities. As governments and critical industries bolster defenses, advanced techniques to detect, monitor, and mitigate insider risk are essential to prevent breaches that could have national security consequences.
8 months ago
Kill Chain
Salt Typhoon’s 2024 Attack: Nation-State Espionage Exploits Forgotten Network Devices
In early 2024, a cyber espionage campaign orchestrated by the China-linked Salt Typhoon group targeted forgotten and unpatched network perimeter devices, such as out-of-support routers, VPNs, and firewalls, across both public and private sector organizations in the U.S. and allied nations. Adversaries leveraged advanced "living off the land" tactics, establishing persistent access by exploiting technical debt and overlooked legacy hardware—bypassing hardened endpoint defenses and moving laterally within affected networks. Operational impacts included exposure of sensitive credentials, long-term surveillance risks, and significant challenges in incident detection and response due to the stealthy nature of the attacks. This incident highlights a surge in sophisticated nation-state threats adapting to improved endpoint security by targeting unmanaged infrastructure. The campaign underscores the urgency for organizations to reassess asset inventories, prioritize decommissioning of end-of-life devices, and deploy proactive detection strategies, as similar tactics are increasingly observed across multiple state-sponsored and ransomware actors.
8 months ago
Kill Chain
Lazarus APT Penetrates European Defense Firms with Fake Job Lures in 2024
In early 2024, the North Korean state-sponsored Lazarus Group orchestrated a targeted cyberattack against at least three European defense sector companies. Using a spear-phishing strategy known as 'Operation DreamJob,' attackers impersonated defense recruiters, luring employees with fake job offers and malicious documents. Once compromised, the attackers gained unauthorized access, moved laterally within victims' networks, and exfiltrated sensitive corporate and government data with minimal detection. The sophistication and persistence demonstrated in this operation highlight the evolving threat landscape posed by well-resourced APT actors. This campaign underscores the escalating risks facing critical industries from nation-state cyber espionage. As advanced phishing and lateral movement techniques proliferate, even mature security programs remain vulnerable to targeted, multi-stage attacks from groups like Lazarus.
8 months ago
Kill Chain
CISA Sounds Alarm: Lanscope Endpoint Manager Flaw Actively Exploited
In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) warned organizations of active exploitation of a critical vulnerability in Motex’s Lanscope Endpoint Manager software. Threat actors leveraged the flaw (tracked as CVE-2024-27956) to gain unauthorized access and potentially execute remote code on unpatched systems. The attackers could bypass authentication and gain administrative privileges, enabling lateral movement and further compromise of affected network environments. The incident impacted enterprises using Lanscope Endpoint Manager for device monitoring and management, raising concerns over exposure of sensitive data and operational disruption. This incident is notable for its speed of exploitation following public disclosure, illustrating the ongoing trend of threat actors rapidly weaponizing software vulnerabilities in endpoint management tools. The breach underscores the importance of immediate patching and rigorous monitoring as attackers increasingly target IT infrastructure software to establish initial footholds.
8 months ago
Kill Chain
CISA Confirms Critical Lanscope Endpoint Manager Vulnerability Under Active Attack
In October 2025, a critical vulnerability (CVE-2025-61932, CVSS 9.3) in Motex Lanscope Endpoint Manager was added to CISA’s Known Exploited Vulnerabilities catalog after confirmed active exploitation in the wild. Attackers leveraged the on-premises endpoint management platform’s remote code execution flaw to obtain unauthorized access, enabling lateral movement and potential data exfiltration. Organizations relying on Lanscope Endpoint Manager may face business disruption, data integrity issues, and heightened regulatory scrutiny as a result of this exposure. The recent exploitation of this vulnerability underscores a larger trend of remote code execution exploits targeting widely deployed endpoint management products. With attackers increasingly seeking supply-chain and IT management footholds, regulatory bodies and security leaders are prioritizing rapid patch cycles and robust segmentation to limit risk.
8 months ago
Kill Chain
North Korean APTs Breach UAV Defense Firms Using Fake Job Offers (2025)
In October 2025, multiple European defense contractors specializing in unmanned aerial vehicles (UAVs) were targeted by a sophisticated cyber-espionage campaign attributed to North Korean threat actors, commonly known as Lazarus Group. The attackers masqueraded as recruiters and leveraged convincing fake job offers to defense engineers using social networks and spear-phishing emails, ultimately delivering malicious payloads that provided remote access to corporate networks. The primary objective was to exfiltrate proprietary drone technology and sensitive internal communications, resulting in significant intellectual property theft and exposure of confidential project details. This incident illustrates a persistent trend where state-sponsored actors target the defense sector’s engineers with social engineering tactics, reflecting a broader escalation in advanced persistent threat (APT) campaigns leveraging human-centric attack vectors. Organizations face mounting regulatory scrutiny and must enhance security controls to combat these evolving social-engineering-enabled threats.
8 months ago
Kill Chain
Mideast & African Hackers Launch Multi-Vector Attacks on Governments, Banks, and Retailers in 2024
In early 2024, multiple threat groups originating from the Middle East and Africa executed a series of sophisticated, multi-vector cyber campaigns targeting government agencies, banks, and small to midsize retailers across the region. Attackers leveraged a blend of techniques including encrypted traffic evasion, lateral movement, cloud misconfiguration, and remote access tools. These campaigns exploited gaps in east-west security, egress controls, and cloud segmentation, resulting in data exfiltration, service disruptions, and operational downtime across multiple sectors. The tactics exposed critical weaknesses in hybrid cloud architectures, impacting regulatory compliance and eroding trust in public and financial institutions. This incident highlights the escalating trend of advanced regional threat actors targeting not just political or large economic entities, but also smaller businesses, using methods that combine traditional and cloud-native attack vectors. The frequency and sophistication of such attacks underscore the need for adaptive, zero trust security frameworks and heightened vigilance across both public and private sectors.
8 months ago
Kill Chain
Inside the 2024 Lazarus Group Attack on European Drone Manufacturers
In early 2024, the North Korean-backed Lazarus Group launched a sophisticated cyber-espionage campaign targeting multiple European drone manufacturers. The operation leveraged spear-phishing emails and custom malware to gain unauthorized access to sensitive research, development, and operational data. After establishing persistence, attackers conducted lateral movement across corporate networks and exfiltrated significant volumes of intellectual property and proprietary technology aligning with North Korea's strategic interests. The breach undermined victims’ competitive advantage, presented potential national security risks, and exposed critical supply chain vulnerabilities. The incident underscores the escalation of state-sponsored attacks against the European defense and aerospace sector. As APT groups like Lazarus intensify targeting of high-innovation industries using stealthy techniques, organizations face mounting pressure to strengthen east-west traffic monitoring, encryption practices, and zero trust segmentation.
8 months ago
Kill Chain
The 2024 Global Smishing Deluge: China-Based SMS Phishing at Scale
In early 2024, a China-based threat group orchestrated a massive global smishing campaign, flooding mobile devices across multiple continents with fraudulent SMS messages impersonating banks, government agencies, and delivery services. Leveraging a rapidly-evolving attack ecosystem, the actors utilized wide-scale automation and regional tailoring to bypass spam filters and trick users into revealing sensitive credentials or installing malware. The attack’s magnitude caught many organizations off guard, resulting in significant credential theft, unauthorized transactions, and growing operational strain as firms raced to block fast-moving SMS domains and educate affected users. This campaign signals a sharp escalation in the sophistication and reach of smishing attacks, highlighting persistent gaps in mobile security awareness and detection. As similar TTPs gain traction among organized threat groups, critical infrastructure and commercial service providers face increased risks of large-scale credential exposure and downstream fraud.
8 months ago
Kill Chain
F5 2025 Supply-Chain Breach: Nation-State Attackers Target Update Infrastructure
In October 2025, F5 Networks—an industry-leading provider of enterprise networking and security appliances—disclosed a sophisticated supply-chain breach attributed to a nation-state threat actor. Attackers maintained long-term, covert access to F5’s internal environment, ultimately compromising systems responsible for building and distributing software updates for its widely deployed BIG-IP products. The breach allowed unauthorized access to proprietary source code, documentation of unpatched vulnerabilities, and a trove of sensitive customer configuration data, significantly enlarging the risks of downstream exploitation for thousands of major enterprises and critical infrastructure providers globally. This incident underscores the growing threat of highly persistent, technically advanced supply-chain attacks targeting the software build and delivery processes of core technology vendors. The breach reflects recent escalation in nation-state tactics and highlights the continued exposure of global businesses to supply-chain and software update system threats.
8 months ago
Kill Chain
F5 Vulnerability Exposes Visibility Gaps in DHS’s CDM Program
In June 2024, a critical vulnerability affecting F5 devices exposed a major blind spot within the Department of Homeland Security's Continuous Diagnostics and Mitigation (CDM) program, which is tasked with overseeing federal cybersecurity assets. The Cybersecurity and Infrastructure Security Agency (CISA) was forced to issue an emergency directive after learning that a nation-state actor had exploited F5 edge devices to gain persistent access across multiple civilian federal agencies. The directive revealed that while thousands of F5 systems were in use, there was significant uncertainty about their location due to gaps in federal asset inventory capabilities, particularly for internet-facing edge devices like F5 BIG-IP load balancers. As a result, agencies had to scramble to manually identify and secure affected systems, highlighting the operational impact of incomplete visibility and asset management. The incident underscores the growing risks associated with network edge devices, which have become prime targets for sophisticated attackers exploiting gaps outside traditional IT inventories. As cloud adoption and edge architectures proliferate, ensuring asset visibility and securing non-traditional endpoints have become urgent priorities for government and private sector organizations alike, as attackers increasingly exploit these visibility gaps.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports