Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024
In early 2024, Iranian state-sponsored APT MuddyWater launched a series of cyberattacks against Israeli organizations using a novel evasion method involving a modified version of the classic Snake mobile game. Attackers embedded malicious code within the game to establish a covert communication channel and facilitate lateral movement within compromised networks. Initial access was likely achieved through phishing emails, followed by deployment of specially crafted files to disguise data exfiltration activities. The campaign resulted in unauthorized access to sensitive data and disruption of critical business operations for targeted Israeli entities. This incident highlights a growing trend of threat actors leveraging benign-looking applications and creative techniques to bypass traditional security controls. The use of retro games as a decoy demonstrates that sophisticated attackers are continually adapting, raising the bar for detection and forensic analysis across industries.
8 months ago
Kill Chain
Student Breach: Compromised Gov't and University Access Sold to Chinese Actors (2024)
In early 2024, cyber investigators uncovered a scheme in which a student was selling fully compromised access to high-value government and university websites, predominantly to Chinese threat actors. The access, peddled through underground forums for several hundred dollars apiece, enabled buyers to exploit web server vulnerabilities, deploy malware, and potentially exfiltrate sensitive institutional and personal data. These breaches highlighted significant weaknesses in internal access controls and malware detection at academic and government institutions, risking the integrity of core systems, sensitive research, and regulated personal information. The incident underscores ongoing operational and reputational risks for public sector organizations, particularly where student employees or contractors bypass internal protections. This breach is emblematic of an emerging trend—threat actors leveraging insiders or poorly vetted contractors to facilitate lateral movement targeting valuable educational and governmental data. As ransomware groups and state-sponsored adversaries shift toward supply chain and identity-driven compromise, robust zero trust controls and network segmentation are becoming essential to preempt similar attacks.
8 months ago
Kill Chain
How a 2025 SSH Trojan Attack Leveraged a Government IP and Masquerading Tactics
In November 2025, a sophisticated cyberattack was observed when an adversary used SSH brute-force tactics to infiltrate a honeypot system, exploiting default 'root' credentials. Once inside, the attacker uploaded a malicious ELF binary, masquerading as the legitimate OpenSSH daemon ('sshd'), designed for persistence and stealth. The operation originated from a government-owned IP address, but evidence suggests the IP was likely compromised and misused, underscoring the complexity of attributing attacks. No commands were executed post-login, highlighting advanced attacker tradecraft focused on evasion and long-term foothold. This incident exemplifies modern threats leveraging credential reuse, sophisticated masquerading, and the abuse of trusted system binaries. Such attacks signal the growing use of covert techniques, presenting heightened risks to organizations and reinforcing the need for proactive defense, improved authentication practices, and advanced monitoring.
8 months ago
Kill Chain
PRC State Actors Compromise Public Sector with BRICKSTORM Malware
In late 2025, PRC state-sponsored cyber actors launched a sophisticated espionage campaign using the BRICKSTORM malware, targeting government and information technology sectors. The threat actors gained initial access via a compromised web server in victim DMZs, progressed laterally to internal VMware vCenter servers, and deployed BRICKSTORM to maintain deep persistence in both VMware vSphere and Windows environments. Leveraging advanced encrypted communication channels, stolen credentials, and techniques such as DNS-over-HTTPS and rogue virtual machines, the actors exfiltrated sensitive data while evading detection for extended periods. This incident underscores the evolving tactics of nation-state adversaries, who now frequently employ modular, stealthy malware to attack critical infrastructure. The widespread use of cloud and virtualization platforms in public sector IT environments makes these organizations particularly vulnerable to such persistent threats.
8 months ago
Kill Chain
Insider Threat at Opexus: Twin Contractors Breach US Federal Agency Data in 2024
In February 2024, twin brothers Muneeb and Sohaib Akhter exploited their privileged positions as contractors at Opexus, a government IT provider, to compromise, steal, and destroy sensitive data belonging to more than 45 federal agencies, including the Department of Homeland Security, IRS, and EEOC. The attack occurred minutes after the brothers were terminated, leveraging insider access to delete 96 critical databases, extract personally identifiable information, and disrupt ongoing investigations. Their methods reportedly included using AI to cover their tracks by clearing system and audit logs. The incident triggered a major federal investigation and prompted urgent responses from affected agencies, highlighting the impact of trusted insider abuse on national operations. This breach exemplifies a growing trend of insider threats exploiting technical know-how and elevated access during termination events, intensified by the use of generative AI tools to evade detection. The case underscores the critical need for organizations handling sensitive federal data to implement rigorous access controls, continuous monitoring, and rapid offboarding processes to mitigate potential insider-driven damage.
8 months ago
Kill Chain
Clop Ransomware Hits University of Phoenix: Oracle Vulnerability Exposes Data
In August 2025, the University of Phoenix reported a significant data breach stemming from a ransomware data theft campaign attributed to the Clop threat group. Attackers exploited vulnerabilities in Oracle E-Business Suite environments, enabling them to gain unauthorized access to sensitive records. As a result, personal and possibly financial information of students and staff were exposed, with operational disruptions and incident response activities triggering increased scrutiny. The attack is part of a broader campaign that has targeted multiple U.S. universities using similar tactics, highlighting systemic weaknesses in ERP system security posture across higher education. The University of Phoenix incident exemplifies the ongoing evolution of ransomware operations targeting critical business applications and underscores the rise of supply-chain and third-party software attacks. Institutions now face heightened regulatory expectations for safeguarding sensitive data as ransomware groups escalate attacks on educational and enterprise systems.
8 months ago
Kill Chain
Aisuru Botnet Shatters DDoS Record with 29.7 Tbps Assault in 2024
Between February and April 2024, the Aisuru botnet orchestrated an unprecedented series of over 1,300 distributed denial-of-service (DDoS) attacks, culminating in a world-record 29.7 Tbps bombardment against a major cloud service provider. Leveraging a vast network of compromised devices, the attackers demonstrated advanced traffic amplification techniques and targeted both edge and core network infrastructure, disrupting service availability and highlighting weaknesses in current DDoS defense postures. The scale and velocity of the assault challenged existing mitigation limits and underscored the dynamic evolution of botnet-driven attacks. This incident sets a new benchmark for volumetric DDoS attacks, illustrating the growing sophistication of threat actors and the accelerating arms race between attackers and defenders. It signals a pressing need for organizations to reassess cloud and network security strategies, emphasizing adaptive, zero trust, and layered defense frameworks.
8 months ago
Kill Chain
DragonForce & Scattered Spider: Ransomware Collaboration Highlights the 2025 Threat Landscape
In early 2025, the DragonForce ransomware group expanded its global campaign by collaborating with Scattered Spider, an English-speaking threat actor notorious for advanced social engineering and initial access techniques. This partnership allowed DragonForce to leverage Scattered Spider’s skills in phishing, credential harvesting, and network penetration to facilitate rapid, multi-stage compromises of major corporate networks across various sectors. Attackers gained initial access using phishing and social engineering against IT and security staff, followed by lateral movement and deployment of ransomware to encrypt critical data. The attacks resulted in significant operational disruption, data loss, and extortion demands for affected organizations. This incident exemplifies a growing threat trend: ransomware operators teaming up with specialized access brokers to accelerate intrusion success and maximize impact. Organizations now face highly coordinated, multi-vector attacks that challenge traditional defenses, driving urgency around zero trust architectures and improved lateral security controls.
8 months ago
Kill Chain
Microsoft Mitigates Windows LNK Zero-Day Exploited in Active Attacks
In June 2024, Microsoft addressed a high-severity zero-day vulnerability (CVE-2024-38112) affecting Windows LNK files. Multiple state-sponsored and cybercriminal groups exploited this flaw in-the-wild, leveraging maliciously crafted shortcut files to execute arbitrary code with user privileges. Attackers gained initial access by delivering LNK payloads via phishing emails and drive-by downloads, bypassing standard user awareness and endpoint defenses. Successful exploitation enabled threat actors to deploy malware, pivot laterally, exfiltrate sensitive data, and disrupt business operations before Microsoft’s silent mitigation, which came ahead of a formal patch release. The incident highlights increasing trends in the exploitation of novel and low-friction attack vectors, such as Windows shortcuts, which evade traditional detection. With LNK abuse on the rise among advanced persistent threats (APTs) and financially motivated actors, organizations face mounting pressure to close gaps in endpoint security, monitoring, and privilege management.
8 months ago
Kill Chain
Critical King Addons Elementor Plugin Flaw Exploited in WordPress Sites (CVE-2025-8489)
In early 2025, attackers began actively exploiting a critical privilege escalation flaw (CVE-2025-8489) in the King Addons for Elementor plugin on WordPress sites. By abusing an insecure registration process, threat actors were able to escalate privileges and gain administrative control over vulnerable sites without authorization. This access could be used to manipulate website content, add malicious backdoors, or exfiltrate sensitive data, impacting website owners' security and reputation. The attacks have been widespread due to the plugin's popularity and ease of exploitation, highlighting the persistent risks present in third-party WordPress extensions. This incident is particularly relevant as it exemplifies an ongoing wave of attacks targeting web application vulnerabilities in widely used CMS platforms. The proliferation of such zero-day exploits magnifies risk for organizations, especially as adversaries move quickly to weaponize flaws before patches are broadly applied.
8 months ago
Kill Chain
Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems
In April 2025, cybersecurity researchers identified a malicious Rust package named "evm-units" that was uploaded to crates.io, the central Rust package registry. Disguised as an Ethereum Virtual Machine (EVM) helper tool, the crate targeted developers working in Web3 environments across Windows, macOS, and Linux systems. Once installed, the package stealthily executed OS-specific malware to compromise developer endpoints, enabling threat actors to potentially gain access to sensitive credentials and project intellectual property. The incident underscores sophisticated, hard-to-detect supply chain tactics exploiting trusted ecosystems and automated developer workflows. This attack highlights the increasing prevalence of supply chain threats targeting open source development pipelines and blockchain ecosystems. Recent trends show attackers adapting to security controls by embedding malware into widely used software components, pressuring organizations to enhance package vetting, anomaly detection, and Zero Trust strategies.
8 months ago
Kill Chain
Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers
In early 2024, Marquis Software Solutions, a financial marketing service provider, was the victim of a significant data breach that compromised sensitive personal information across more than 74 US banks and credit unions. The attackers gained unauthorized access through a third-party vulnerability and exfiltrated data sets containing names, addresses, Social Security numbers, financial account details, and demographic information of hundreds of thousands of customers. The breach not only impacted Marquis’s direct clients but also exposed downstream institutions and their end-users, triggering regulatory notifications and potential reputational damage to affected financial entities. This incident highlights the enduring risk posed by supply chain vulnerabilities within highly regulated industries, as attackers continue targeting trusted vendors with access to sensitive data. It underscores increasing regulatory scrutiny on vendor risk management and data protection, especially within financial and healthcare sectors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports