Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
Stately Taurus: 2022 Bookworm APT Campaign Unveiled in Southeast Asia
In 2022, cybersecurity researchers traced sophisticated spear-phishing attacks against government and commercial entities in Southeast Asia to Stately Taurus, a Chinese advanced persistent threat (APT) group active since at least 2012. Using the Bookworm malware, a modular remote access trojan (RAT) with advanced C2 and lateral movement capabilities, the threat actor gained initial access via tailored phishing emails, followed by persistence and data exfiltration. Detailed code analysis, shared infrastructure, unique PDB paths, and parallel tooling (e.g., ToneShell) confirmed high-confidence attribution. The campaign exposed OPSEC artifacts and overlapping infrastructure, confirming Stately Taurus’s long-term commitment to targeted espionage. This incident underscores a broader surge in targeted APT campaigns using modular malware and sophisticated infrastructure reuse. The precision of the Unit 42 Attribution Framework exemplifies the growing emphasis on multi-layered, evidence-based attribution, which is now critical as state-linked groups automate and diversify their attack techniques.
8 months ago
Kill Chain
PyPI Phishing Attack Exposes Open-Source Supply Chain in 2025
In September 2025, the Python Package Index (PyPI) suffered a targeted supply-chain phishing campaign, where threat actors impersonated PyPI via convincing emails and domain lookalikes (such as pypi-mirror.org). Attackers sent phishing emails to PyPI maintainers, warning of account suspension and requesting email verification. Unsuspecting victims who followed malicious links and entered credentials risked account compromise, enabling attackers to breach legitimate developer accounts. The likely aim was to either infect existing packages with malware or introduce new malicious packages into trusted software repositories, potentially impacting the broader Python ecosystem. This incident underscores the growing sophistication of software supply-chain threats, especially as open-source repositories face sustained phishing campaigns and credential harvesting tactics. As phishing campaigns increasingly target developers and critical infrastructure, strong phishing-resistant authentication and vigilant domain monitoring are now essential industry-wide defenses.
8 months ago
Kill Chain
How Brickstorm Malware Evaded Detection in US Legal & Tech Sectors: A 2025 APT Case Study
In 2025, Google’s Threat Intelligence Group uncovered that the UNC5221 threat actor, suspected to have ties to China, used the Brickstorm malware to conduct stealthy, long-term espionage campaigns against U.S. legal and technology organizations, SaaS providers, and BPOs. The attackers exploited zero-day vulnerabilities in enterprise edge devices lacking EDR protection, establishing persistent access for an average dwell time of over a year. Brickstorm enabled credential theft, lateral movement, and data exfiltration, often targeting email and sensitive code repositories, all while obfuscating forensic traces and regularly changing infrastructure. This incident highlights a growing trend of persistent, supply-chain-oriented APT attacks targeting critical sectors via unmonitored infrastructure. It underscores the importance of timely patching, segmentation, and improved visibility for hybrid and edge environments facing increasing risks from nation-state adversaries.
8 months ago
Kill Chain
Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks
In late August 2025, a newly discovered ransomware variant named Obscura was identified executing across several hosts within an enterprise network. The attack leveraged the organization's Active Directory infrastructure, using the NETLOGON share to automatically deploy a Go-based ransomware binary across all domain controllers and affected endpoints. The attackers created malicious scheduled tasks for persistent execution and attempted to enable remote desktop for potential lateral movement. The ransomware also attempted to disable endpoint recovery options, and the ransom note indicated both data encryption and exfiltration of sensitive company information. Limited security agent coverage hampered detection and response, amplifying the operational disruption and risk of sensitive data exposure. This incident underscores the evolving sophistication of ransomware actors in targeting critical authentication infrastructure and automated deployment mechanisms. As attackers increasingly combine data theft with operational disruption and target identity systems, organizations face heightened regulatory, financial, and reputational risks, warranting renewed focus on segmentation, visibility, and endpoint security.
8 months ago
Kill Chain
Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks
In September 2025, Supermicro disclosed critical firmware vulnerabilities (CVE-2025-7937 and CVE-2025-6198) affecting its server Baseboard Management Controller (BMC). Security researchers at Binarly demonstrated that attackers could leverage these flaws to bypass firmware signature verification and the BMC root of trust, allowing deployment of persistent, malicious firmware on widely used Supermicro servers. Exploits could grant adversaries complete, long-term control over both the BMC and host OS, enabling stealthy persistence and reliable evasion of security controls, while systems appeared to be running valid, signed code. Supermicro confirmed the vulnerabilities, releasing firmware patches, but proof-of-concept exploits are already public. This incident underscores the evolving challenge of hardware-level attacks, as advanced threat actors increasingly target supply chain and firmware layers to establish persistent, hard-to-detect footholds. Recent regulatory pressure and rising incidents of firmware-based threats highlight the urgency for security teams to elevate visibility and controls across hardware trust boundaries.
8 months ago
Kill Chain
Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS
In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts. This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.
8 months ago
Kill Chain
YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus
In June 2025, researchers discovered YiBackdoor, a novel malware family exhibiting significant source code overlaps with the notorious IcedID and Latrodectus strains. Campaigns leveraging YiBackdoor execute advanced backdoor techniques that establish remote access, command execution, and data exfiltration within compromised environments. YiBackdoor is typically deployed as part of a multi-stage attack campaign, using phishing or malicious attachments as its primary entry vector. Its detection signaled the emergence of new collaborative threats between criminal malware groups, raising concerns over increased code sharing and tool evolution. This incident highlights growing technical sophistication and cross-pollination between established malware actors. The use of YiBackdoor in conjunction with IcedID and Latrodectus demonstrates adversary agility and the accelerated pace of malware innovation, elevating the threat to enterprises reliant on traditional detection models.
8 months ago
Kill Chain
Critical Wondershare RepairIt Vulnerabilities in 2025 Expose User Data and AI Models
In September 2025, security researchers from Trend Micro uncovered two critical vulnerabilities in Wondershare RepairIt, a leading file repair software. Identified as CVE-2025-10643 (authentication bypass, CVSS 9.1) and a second AI model tampering flaw, these vulnerabilities allowed unauthorized attackers to access sensitive user information and potentially manipulate embedded AI models. Exploitation could be achieved over unencrypted traffic routes, making lateral movement and data exfiltration easier for adversaries. The flaws highlighted the growing risks associated with AI-driven software and the increased attack surface presented by supply chain exposures. This incident underscores the urgency of securing both traditional application logic and the growing use of embedded AI models. Adversaries are increasingly targeting AI supply chains and exploiting weak east-west segmentation controls, a pattern observed in several recent breaches. Regulatory scrutiny and customer expectations around data protection continue to mount.
8 months ago
Kill Chain
How a Single Weak Password Caused the Collapse of KNP Logistics
In August 2023, KNP Logistics Group—one of the UK’s oldest haulage companies—fell victim to a catastrophic ransomware attack after cybercriminals exploited a weak, reused password to gain initial access. The attackers leveraged this compromised credential to breach internal systems, move laterally, and deploy ransomware, severely encrypting business-critical data. Operations halted, hundreds of employees were affected, and the incident ultimately forced the 158-year-old business into administration, marking a rare instance where a cyberattack directly led to company collapse. This breach exemplifies a growing wave of highly disruptive ransomware attacks exploiting basic identity and password hygiene gaps. As threat actors increasingly target legacy industries and critical infrastructure with credential-based intrusions, the risk to business continuity is escalating—pressing organizations to reevaluate access controls and cyber resilience.
8 months ago
Kill Chain
UNC5221 Breach: BRICKSTORM Backdoor Hits U.S. Legal & Tech Sectors (2025)
In September 2025, a sophisticated cyber espionage operation targeting U.S.-based legal services, SaaS providers, BPOs, and technology firms was attributed to UNC5221, a suspected China-nexus threat actor. The attackers leveraged the BRICKSTORM backdoor as their primary access mechanism, gaining initial entry through spear-phishing campaigns and exploiting software vulnerabilities. Once inside, they focused on lateral movement, data gathering, and exfiltration, leveraging encrypted channels to avoid detection. The incident resulted in exposure of sensitive legal documents, business data, and intellectual property, highlighting the advanced TTPs of nation-state actors targeting critical professional sectors. This breach exemplifies the growing prevalence of targeted espionage campaigns against high-value service and technology industries. It underscores the urgency for organizations to adopt advanced threat detection, zero trust segmentation, and strong encrypted communication controls in the face of persistent, well-resourced adversaries and heightened regulatory scrutiny.
8 months ago
Kill Chain
RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments
In mid-2025, a Chinese state-sponsored threat group known as RedNovember (previously tracked as TAG-100) orchestrated a widespread cyber espionage campaign targeting government and private sector organizations across Africa, Asia, North America, South America, and Oceania. The attackers leveraged sophisticated tools including the Pantegana backdoor and Cobalt Strike to establish persistence, perform lateral movement, and exfiltrate sensitive data. Entry vectors included spear-phishing emails and exploitation of known network vulnerabilities, allowing RedNovember to stealthily compromise high-value systems and harvest intelligence for extended periods before discovery. The impact included unauthorized access to confidential government documents and disruption of critical data workloads. This incident underscores the persistent evolution of state-sponsored attack tactics, with RedNovember employing advanced, evasive techniques and custom malware. The growing use of encrypted command-and-control traffic and living-off-the-land strategies sets a concerning precedent, especially for government agencies and regulated enterprises facing a surge in sophisticated espionage operations.
8 months ago
Kill Chain
Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)
In June 2024, a malicious npm JavaScript package was discovered masquerading as a utility library while covertly deploying a credential-stealing malware. Attackers cleverly embedded the malicious payload using steganography by hiding harmful code within QR code images bundled in the package. Once installed by developers, the malware extracted sensitive credentials and communicated with attacker-controlled infrastructure, posing a significant risk to any organization that unknowingly integrated the tainted dependency in its software supply chain. This incident underscores the mounting threat posed by highly obfuscated, supply chain attacks leveraging trusted open-source platforms. The attack highlights the emergence of sophisticated malware delivery via unconventional vectors such as steganographic encoding within common file formats. With broad software ecosystem dependencies and rapid code adoption, organizations face increasing urgency to vet third-party packages and enforce robust supply chain security controls.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports