The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
International Affairs
Breach intelligence, attack campaigns, and threat reports targeting the International Affairs sector.
Explore Other Sectors
International Affairs Threat Reports
Serbian Government Spyware Campaign Threatens EU Accession Amid Surveillance Scandal
In 2024, Serbian government authorities conducted systematic surveillance operations against student activists and political opposition using Pegasus and NoviSpy spyware. The SHARE Foundation, in collaboration with Amnesty International and The Citizen Lab, discovered infections on activists' phones, with evidence linking NoviSpy deployments directly to Serbian state authorities. The campaign targeted individuals ahead of elections, representing a coordinated effort to suppress political dissent through digital surveillance. This surveillance operation has prompted 29 European Parliament members to demand delays in Serbia's EU accession process until a full investigation is completed and rule-of-law accountability is established. This incident exemplifies the growing trend of nation-state actors weaponizing commercial spyware against civil society, particularly in countries seeking international legitimacy while simultaneously suppressing domestic opposition through sophisticated surveillance technologies.
2 weeks ago
Kill Chain
APT28 Deploys New HOOKEDGE Backdoor Against European Diplomatic Targets
Between September 2025 and April 2026, Russian state-sponsored threat actor APT28 (Fancy Bear) conducted cyber espionage campaigns against government and diplomatic organizations in Romania, Spain, and Turkey using a previously undocumented backdoor called HOOKEDGE. The lightweight Windows batch script was delivered through macro-enabled Microsoft Word documents with diplomatic-themed lures, representing an evolution of APT28's HEADLACE backdoor with improved evasion capabilities and webhook-based command-and-control infrastructure. This incident highlights the persistent targeting of European diplomatic entities by Russian APT groups amid ongoing geopolitical tensions, demonstrating how threat actors continuously refine lightweight tooling to maintain access while adapting to defensive countermeasures and infrastructure limitations.
3 weeks ago
Kill Chain
BlueDelta's HOOKEDGE Campaign: How Russian APT28 Evolved Diplomatic Espionage Tactics
Between September 2025 and April 2026, Russian state-sponsored threat group BlueDelta (APT28, Fancy Bear) conducted sophisticated espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Turkey. The group deployed HOOKEDGE, a lightweight batch-script backdoor delivered through macro-enabled Microsoft Word documents using diplomatic-themed lures, including materials impersonating Spain's Ministry of the Presidency. HOOKEDGE represents an evolution of BlueDelta's earlier HEADLACE malware, utilizing legitimate webhook services for command-and-control operations to blend malicious traffic with normal network activity while targeting European diplomatic entities for intelligence collection. This campaign demonstrates the continuing evolution of state-sponsored espionage tactics, particularly the refinement of lightweight malware tools that can evade detection while maintaining operational effectiveness. As geopolitical tensions escalate and diplomatic intelligence becomes increasingly valuable, threat actors are adapting their methods to exploit legitimate cloud services and social engineering techniques.
4 weeks ago
Kill Chain
Russian APTs Exploit Messaging App Trust to Compromise EU Government Officials
In 2026, Russian state-sponsored threat actors conducted a sophisticated spear-phishing campaign targeting high-ranking EU government officials through encrypted messaging applications like WhatsApp and Signal. The attackers impersonated platform support teams and used QR code social engineering tactics to compromise accounts, successfully breaching officials including German Bundestag President Julia Klöeckner. Eight significant incidents were documented across EU governments, exposing the vulnerability of consumer messaging platforms used for official communications and prompting several nations to develop sovereign messaging solutions. This incident highlights the critical shift in nation-state attack vectors as threat actors exploit the inherent trust users place in encrypted messaging platforms, moving beyond traditional email-based phishing to leverage communication channels with less security oversight and monitoring capabilities.
4 weeks ago
Kill Chain
South Korea's Diplomatic Academy Data Breach: A 10-Month Undetected Cyberattack
In April 2025, an unidentified threat actor exploited a zero-day vulnerability in the Korea National Diplomatic Academy's online education system, maintaining unauthorized access until February 2026. This breach exposed personal information—including names, user IDs, email addresses, and encrypted passwords—of approximately 10,000 individuals associated with South Korea's Ministry of Foreign Affairs, including current and former diplomats. The compromised system, established in 2022 for remote training during the COVID-19 pandemic, was taken offline in February 2026 upon detection of the intrusion. This incident underscores the escalating sophistication of cyberattacks targeting governmental institutions and the critical need for robust cybersecurity measures. The prolonged undetected access highlights vulnerabilities in monitoring and threat detection systems, emphasizing the importance of regular security audits and timely patch management to mitigate potential breaches.
2 months ago
Kill Chain
GoSerpent Malware: A Persistent Threat to Southeast Asian Governments
In late 2025, cybersecurity researchers identified a new malware strain named GoSerpent, actively targeting government and diplomatic entities in Southeast Asia. Discovered by Kaspersky in February 2026, GoSerpent is designed to establish long-term access for intelligence gathering by connecting to external servers and deploying secondary payloads for data collection and credential dumping. The malware's capabilities include setting up SOCKS5 proxy servers, enabling attackers to route traffic through compromised hosts and mask their true IP addresses. Additional tools such as ThumbcacheService for file collection and Mimikatz for credential extraction have been employed to facilitate data exfiltration through network shared drives. ([thehackernews.com](https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html?utm_source=openai)) The resurgence of GoSerpent in May 2026, with evolved tools like the Stowaway RAT and enhanced data exfiltration methods, underscores the persistent and adaptive nature of cyber threats targeting sensitive government information. This incident highlights the critical need for robust cybersecurity measures and continuous monitoring to detect and mitigate sophisticated espionage campaigns. ([thehackernews.com](https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html?utm_source=openai))
2 months ago
Kill Chain
GoSerpent Backdoor: A Persistent Threat to Southeast Asian Governments
The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
2 months ago
Kill Chain
StrikeShark Campaign Unleashes SharkLoader to Deploy Cobalt Strike Beacons
In June 2026, a cyber attack campaign named StrikeShark was identified, deploying a new malware loader called SharkLoader to deliver Cobalt Strike Beacons on compromised systems. The campaign targeted a diverse range of entities, including diplomatic organizations in Indonesia, government bodies in Taiwan, and software development companies across multiple countries. Attackers exploited known vulnerabilities in Microsoft Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401) to gain initial access, subsequently establishing persistence through web shells and DLL side-loading techniques. The use of open-source post-compromise tools like FScan and Pillager suggests potential involvement of Chinese-speaking threat actors. This incident underscores the persistent threat posed by sophisticated malware loaders and the exploitation of known vulnerabilities. Organizations must prioritize timely patching and employ robust detection mechanisms to mitigate such risks. The broad geographic reach and diverse target set of this campaign highlight the evolving tactics of threat actors in the current cyber threat landscape.
3 months ago
Kill Chain
Turla's STOCKSTAY Backdoor: A New Cyber Espionage Threat
In June 2026, Google's Threat Intelligence Group identified a new .NET backdoor named STOCKSTAY, attributed to the Russian state-sponsored group Turla. This malware has been deployed against government and military organizations in Ukraine and entities interested in Italian foreign policy. STOCKSTAY, developed since at least December 2022, shares significant code and functional overlaps with Turla's previous implant, Kazuar. The backdoor comprises multiple components that communicate via inter-process communication channels and utilize secure WebSocket connections for command-and-control communication. It supports various commands, including file manipulation, system information gathering, and screen capture. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/?utm_source=openai)) The discovery of STOCKSTAY underscores the evolving sophistication of state-sponsored cyber espionage tools. Its deployment highlights the persistent threat posed by advanced persistent threats (APTs) like Turla, emphasizing the need for robust cybersecurity measures and continuous monitoring to protect sensitive governmental and military information.
3 months ago
Kill Chain
Council of Europe Probes ShinyHunters Data Breach Allegations
In June 2026, the Council of Europe, representing 46 member states and over 700 million people, began investigating claims by the cyber extortion group ShinyHunters of a significant data breach. ShinyHunters alleged they had stolen over 429,000 documents containing sensitive HR and payroll data from multiple departments, including payslips, personnel files, and CVs, encompassing personal and financial information such as names, dates of birth, addresses, salaries, and bank account details. The group threatened to leak the data if their demands were not met by June 16, 2026. This incident underscores the escalating threat posed by cyber extortion groups like ShinyHunters, who have been linked to numerous high-profile data breaches targeting organizations worldwide. Their tactics often involve exfiltrating large volumes of sensitive data and leveraging it for ransom, highlighting the critical need for robust cybersecurity measures and proactive threat detection to safeguard organizational data.
3 months ago
Kill Chain
UN World Food Programme Data Breach: A Wake-Up Call for Humanitarian Cybersecurity
In May 2026, the United Nations' World Food Programme (WFP) experienced a significant data breach when unauthorized actors accessed its self-registration application for Palestine. This breach exposed sensitive personal information—including names, ID numbers, mobile numbers, and location data—of approximately 600,000 Palestinian households in Gaza. The WFP promptly suspended the affected platform to implement security enhancements and initiated a comprehensive investigation into the incident. This incident underscores the critical importance of robust cybersecurity measures for humanitarian organizations handling sensitive beneficiary data. The exposure of such information not only compromises individual privacy but also heightens the risk of identity theft and targeted attacks, emphasizing the need for continuous vigilance and proactive security protocols in the humanitarian sector.
3 months ago
Kill Chain
Chinese APT Mustang Panda's Cyber-Espionage Campaign Against Indian Banks and Korean Policy Circles
In April 2026, the Chinese state-sponsored advanced persistent threat (APT) group known as Mustang Panda initiated a cyber-espionage campaign targeting India's banking sector and U.S.-Korea policy circles. The attackers employed spear-phishing emails, often disguised as IT help desk communications, to deliver malicious files. Upon opening, these files executed DLL sideloading attacks, establishing persistence via the Windows Registry. The campaign deployed a variant of the LotusLite backdoor, enabling remote access for espionage activities. Notably, the malware was camouflaged to resemble legitimate banking software, such as that of HDFC Bank, India's largest private bank. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-indian-banks-korean-policy/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors utilizing well-known tactics to infiltrate critical sectors. Organizations must remain vigilant, as even unsophisticated methods can be effective if basic security controls are inconsistently applied. The targeting of financial institutions for intelligence gathering highlights the strategic value placed on economic data in geopolitical contexts.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports