Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Emerging Yurei Ransomware Claims First Victims in 2024
In early June 2024, a new ransomware operation identified as Yurei, reportedly originating from Morocco and named after Japanese spirits, claimed its first set of confirmed victims. The Yurei group leveraged a customized variant of the Prince-Ransomware binary, successfully breaching targets by deploying file-encrypting malware through typical ransomware vectors. Notably, researchers discovered that the malware implementation contained a technical flaw permitting partial data recovery, though this did not nullify the criminal extortion threats made against affected businesses. The attack has led to data loss, service interruption, and urgent incident response at affected organizations. This incident spotlights the evolving ransomware landscape, where new actors rapidly weaponize existing malware tools, often introducing subtle encryption modifications. Yurei’s activity shows how flaws in ransomware code do not necessarily mitigate risk, as extortion and operational disruption remain impactful. Organizations must adapt controls to defend against agile threat actors, even when exploits are imperfectly engineered.
8 months ago
Kill Chain
The FileFix Phishing Campaign: Obfuscation, Steganography, and Multilingual Threats Hit Globally
In early 2024, security researchers identified a sophisticated, widescale phishing campaign leveraging a malicious tool called FileFix. The campaign utilized advanced code obfuscation, steganography, and localization in at least 16 languages to distribute phishing payloads globally. Attackers delivered FileFix through deceptive emails and malicious attachments, successfully bypassing traditional security filters. Once executed, the malware embedded within attachments enabled remote access, data theft, and credential harvesting, affecting organizations in multiple sectors and exposing sensitive business data to potential fraud and operational disruption. FileFix highlights a new wave of phishing threats combining obfuscation, multilingual lures, and novel payload delivery. Its rapid evolution and global reach underscore the increasing sophistication of social engineering attacks, making robust detection and segmentation capabilities essential for all enterprises.
8 months ago
Kill Chain
Salty2FA: The Next Wave of Enterprise Phishing-as-a-Service in 2024
In early 2024, cybersecurity researchers uncovered the Salty2FA Phishing-as-a-Service (PhaaS) kit, designed to bypass multi-factor authentication (MFA) protections for enterprise environments. The kit enables attackers to launch highly convincing phishing campaigns by emulating trusted authentication flows and harvesting credentials—including two-factor tokens—using adversary-in-the-middle proxy techniques. Salty2FA's modular architecture, scalability, and integration with encrypted communication channels make it particularly appealing to cybercriminals targeting corporate user bases. Compromised accounts can facilitate credential stuffing, lateral movement, and data exfiltration in victim organizations. This incident highlights the growing professionalization of cybercriminal groups and a trend toward sophisticated PhaaS offerings that significantly lower barriers for conducting enterprise-level breaches. Organizations should note the surge in attacks able to circumvent standard MFA and adapt their defenses accordingly.
8 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Privilege Escalation Flaws Demand Immediate Action
In September 2025, Microsoft disclosed 81 security vulnerabilities across its portfolio, with a significant focus on escalation of privilege (EoP) flaws. Of the CVEs released, 38 enabled attackers to gain elevated access after initial compromise, affecting modules like SMB and NTLM. Notably, CVE-2025-55234 (SMB) and CVE-2025-54918 (NTLM)—both rated CVSS 8.8—were publicly known and considered high impact, allowing attackers to leverage relay and crafted packet attacks for system takeover. Additional critical vulnerabilities were identified in Windows UI XAML and HPC components. While no active exploitation was confirmed at release, the breadth of affected products and criticality prompted urgent patching recommendations. This wave of privilege escalation vulnerabilities underscores the ongoing risk posed by identity-based attacks and lateral movement, compelling organizations to accelerate patch deployment and strengthen segmentation controls. With the end-of-life of Windows 10 and expanded MFA mandates on the horizon, the incident reinforces the necessity for layered defenses and up-to-date asset management.
8 months ago
Kill Chain
K2 Think AI Model Jailbroken Within Hours of 2024 Release
On September 9, 2024, the UAE-backed 'K2 Think' large language model (LLM) was released with the goal of industry-leading transparent reasoning. Within hours, however, cybersecurity researchers discovered a critical vulnerability known as Partial Prompt Leakage. This flaw allowed adversaries to observe the model's internal logic in plain text, making it easier to methodically bypass safeguards and jailbreak the AI system. The exploit was demonstrated by researcher Alex Polyakov, who publicly documented how attackers could uncover and iterate against the model’s defenses, enabling harmful behaviors such as malware generation. The breach did not result in immediate large-scale misuse, but it revealed a key tradeoff between transparency and security in modern LLM development. This incident is emblematic of new AI security risks emerging as open, auditable models grow in popularity. It underscores the urgency for vendors to balance transparency with robust protection, as attackers quickly adapt to and exploit unique model features. With increased regulatory scrutiny and rising enthusiasm for open-source AI, safeguarding model reasoning is now a critical surface organizations cannot ignore.
8 months ago
Kill Chain
North Korean Kimsuky Leverages Deepfake Military IDs in Sophisticated Social Engineering Attack
In April 2024, threat group Kimsuky, attributed to North Korea, launched a cyberattack campaign targeting South Korean organizations using advanced social engineering tactics. The attackers exploited ChatGPT to generate sophisticated deepfake military ID documents, which were then used as bait to compromise targets via phishing emails and messaging apps. By mimicking authentic credentials, Kimsuky aimed to breach sensitive military and governmental networks, potentially facilitating credential harvesting and further lateral movement within critical infrastructures. This incident highlights the increasing convergence of generative AI and cyberattack techniques, making impersonation and credential-based attacks far more convincing and widespread. It underscores rising urgency for organizations to strengthen verification processes and stay vigilant against emerging deepfake-enabled attack vectors.
8 months ago
Kill Chain
Phoenix Attack Bypasses DDR5 Rowhammer Defenses in 2025
In September 2025, researchers from ETH Zurich and Google disclosed the 'Phoenix' attack—a novel Rowhammer-based hardware vulnerability that successfully bypasses the Target Row Refresh (TRR) defenses in popular DDR5 memory chips, specifically targeting modules from market leader SK Hynix. By exploiting specific shortcomings in TRR’s sampling intervals and synchronizing access over precise refresh cycles, the Phoenix attack can reliably induce bit flips in physical memory. In controlled tests, the attack enabled researchers to gain root-level privileges on commodity systems in under two minutes, expose sensitive cryptographic keys across virtual machines, and manipulate binaries such as sudo for rapid local privilege escalation. The vulnerability, now tracked as CVE-2025-6202, impacts DDR5 modules manufactured between January 2021 and December 2024, posing industry-wide risk since current mitigations are ineffective for existing hardware. This incident stands out as it revives concerns over hardware-level attacks that are resistant to conventional software security solutions. As threats like Phoenix emerge, it highlights the rapid evolution of side-channel and privilege-escalation techniques even in the face of new hardware protections, underlining the pressing need for industry collaboration and innovation on memory security standards.
8 months ago
Kill Chain
How Stark Industries Evaded EU Sanctions: The Persistence of Bulletproof Hosts in 2025
In May 2025, Stark Industries Solutions Ltd.—a notorious bulletproof hosting provider closely linked to Russian cyberattacks and disinformation—was placed under EU financial sanctions, alongside its Moldova-based conduits and owners. Despite these efforts, Stark rapidly rebranded as the[.]hosting, shifted its assets to new legal entities (including Dutch-based WorkTitans BV and Moldova's PQ Hosting Plus S.R.L.), and maintained operational infrastructure with covert support from providers like MIRhosting. Investigations revealed continued operations and asset management by the original threat actors, rendering the sanctions ineffective and allowing persistent delivery of DDoS campaigns, Russian-language proxy services, and malware with minimal disruption. This incident highlights the sophisticated resilience and adaptability of bulletproof hosting operations, as well as the challenges for regulators attempting to curtail nation-state-aligned cyber infrastructure. Similar evasion techniques—including cross-border asset transfers and complex corporate rebranding—are on the rise, escalating pressure on global cybersecurity, law enforcement, and compliance efforts.
8 months ago
Kill Chain
Gentlemen Ransomware Exploits Vulnerable Driver to Disable Enterprise Security (2024)
In early 2024, the Gentlemen ransomware group executed a sophisticated attack leveraging a vulnerable version of the ThrottleStop.sys driver to disable antivirus and endpoint detection and response (EDR) systems. By exploiting this signed but flawed driver, the attackers were able to gain kernel-level privileges, terminate security defenses, and deploy ransomware effectively across targeted organizations. The impact resulted in rapid file encryption, significant operational disruption, and increased ransom demands as incident response capabilities were bypassed. This incident highlights the growing trend of ransomware operators abusing trusted, vulnerable drivers to evade security controls. The ease with which attackers weaponize driver vulnerabilities underscores the urgent need for organizations to enhance driver and device control, patch management, and implement Zero Trust security strategies.
8 months ago
Kill Chain
SonicWall Firewalls Under Siege: Akira Ransomware Exploits CVE-2024-40766
Between July and August 2024, Akira ransomware affiliates targeted SonicWall firewall devices by exploiting CVE-2024-40766, a vulnerability in the SSL VPN protocol, combined with widespread configuration errors. Despite the availability of patches, attackers successfully accessed devices where remediation steps such as local password resets after firmware upgrades and proper multi-factor authentication (MFA) implementation were neglected. These campaigns leveraged misconfigured LDAP group permissions and compromised credentials to gain initial access, enabling Akira to steal sensitive data and encrypt systems across numerous organizations. The resulting attacks led to data theft, system downtime, and expensive ransom demands, with impacts observed globally, including within Australia. Akira’s ongoing surge illustrates the growing sophistication and persistence of ransomware groups in targeting both unpatched and improperly configured perimeter devices. This attack wave highlights the critical need for organizations to not only apply security patches promptly but to rigorously follow up with secure configuration and identity management measures to prevent operational and financial losses.
8 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Vulnerabilities in Cloud, URL Security Zones, and More
On September 9, 2025, Microsoft released its September Patch Tuesday updates, addressing 177 vulnerabilities across its ecosystem, including 86 that impacted Microsoft products directly. Among these, 13 were rated as critical, and two had already been publicly disclosed. Notable vulnerabilities included improper URL security zone classification (CVE-2025-54107, CVE-2025-54917), which could allow attackers to bypass security features, and several remote code execution flaws affecting critical workloads. While none of these vulnerabilities were exploited before disclosure, their wide range—including issues in Azure, Office, and the Windows kernel—signals continued risk across cloud and on-premises environments. These vulnerabilities highlight evolving attacker techniques, such as zone misclassification and privilege escalation in cloud services, while underscoring the complexity of patch management in hybrid infrastructures. The scale of affected Microsoft and open-source components (like Azure Linux/Mariner) points to the growing regulatory and operational urgency for comprehensive and timely vulnerability management.
8 months ago
Kill Chain
Apple 2025 Spyware Surge: Targeted Zero-Day Attacks Threaten High-Profile Users
In 2025, Apple issued multiple urgent notifications to users after detecting a series of targeted spyware attacks leveraging zero-day vulnerabilities on iOS devices. According to French CERT-FR, at least four documented incidents since the beginning of the year involved highly sophisticated, zero-click exploits that required no user interaction. Victims included journalists, politicians, lawyers, activists, and executives in sensitive sectors. Attackers used a combination of a patched Apple zero-day (CVE-2025-43300) and a WhatsApp vulnerability (CVE-2025-55177) to compromise devices, potentially granting remote access to communications and sensitive data. Apple recommended enabling Lockdown Mode and soliciting help from digital security hotlines, but did not attribute the attacks to a specific group or region. This incident underscores increasing use of mercenary spyware and zero-day exploits for high-profile targeting, reflecting the growing challenges of defending against advanced persistent threats. The case highlights the urgency for rapid patching, proactive security postures, and global awareness of targeted surveillance campaigns in both the public and private sectors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports