The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

International Affairs

Breach intelligence, attack campaigns, and threat reports targeting the International Affairs sector.

43 threat reports
Page 1 of 4

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

International Affairs Threat Reports

Showing 1–12 / 43 reports
Serbian Government Spyware Campaign Threatens EU Accession Amid Surveillance Scandal
Impact· HIGH

Serbian Government Spyware Campaign Threatens EU Accession Amid Surveillance Scandal

In 2024, Serbian government authorities conducted systematic surveillance operations against student activists and political opposition using Pegasus and NoviSpy spyware. The SHARE Foundation, in collaboration with Amnesty International and The Citizen Lab, discovered infections on activists' phones, with evidence linking NoviSpy deployments directly to Serbian state authorities. The campaign targeted individuals ahead of elections, representing a coordinated effort to suppress political dissent through digital surveillance. This surveillance operation has prompted 29 European Parliament members to demand delays in Serbia's EU accession process until a full investigation is completed and rule-of-law accountability is established. This incident exemplifies the growing trend of nation-state actors weaponizing commercial spyware against civil society, particularly in countries seeking international legitimacy while simultaneously suppressing domestic opposition through sophisticated surveillance technologies.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
APT28 Deploys New HOOKEDGE Backdoor Against European Diplomatic Targets
Impact· HIGH

APT28 Deploys New HOOKEDGE Backdoor Against European Diplomatic Targets

Between September 2025 and April 2026, Russian state-sponsored threat actor APT28 (Fancy Bear) conducted cyber espionage campaigns against government and diplomatic organizations in Romania, Spain, and Turkey using a previously undocumented backdoor called HOOKEDGE. The lightweight Windows batch script was delivered through macro-enabled Microsoft Word documents with diplomatic-themed lures, representing an evolution of APT28's HEADLACE backdoor with improved evasion capabilities and webhook-based command-and-control infrastructure. This incident highlights the persistent targeting of European diplomatic entities by Russian APT groups amid ongoing geopolitical tensions, demonstrating how threat actors continuously refine lightweight tooling to maintain access while adapting to defensive countermeasures and infrastructure limitations.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
BlueDelta's HOOKEDGE Campaign: How Russian APT28 Evolved Diplomatic Espionage Tactics
Impact· HIGH

BlueDelta's HOOKEDGE Campaign: How Russian APT28 Evolved Diplomatic Espionage Tactics

Between September 2025 and April 2026, Russian state-sponsored threat group BlueDelta (APT28, Fancy Bear) conducted sophisticated espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Turkey. The group deployed HOOKEDGE, a lightweight batch-script backdoor delivered through macro-enabled Microsoft Word documents using diplomatic-themed lures, including materials impersonating Spain's Ministry of the Presidency. HOOKEDGE represents an evolution of BlueDelta's earlier HEADLACE malware, utilizing legitimate webhook services for command-and-control operations to blend malicious traffic with normal network activity while targeting European diplomatic entities for intelligence collection. This campaign demonstrates the continuing evolution of state-sponsored espionage tactics, particularly the refinement of lightweight malware tools that can evade detection while maintaining operational effectiveness. As geopolitical tensions escalate and diplomatic intelligence becomes increasingly valuable, threat actors are adapting their methods to exploit legitimate cloud services and social engineering techniques.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian APTs Exploit Messaging App Trust to Compromise EU Government Officials
Impact· HIGH

Russian APTs Exploit Messaging App Trust to Compromise EU Government Officials

In 2026, Russian state-sponsored threat actors conducted a sophisticated spear-phishing campaign targeting high-ranking EU government officials through encrypted messaging applications like WhatsApp and Signal. The attackers impersonated platform support teams and used QR code social engineering tactics to compromise accounts, successfully breaching officials including German Bundestag President Julia Klöeckner. Eight significant incidents were documented across EU governments, exposing the vulnerability of consumer messaging platforms used for official communications and prompting several nations to develop sovereign messaging solutions. This incident highlights the critical shift in nation-state attack vectors as threat actors exploit the inherent trust users place in encrypted messaging platforms, moving beyond traditional email-based phishing to leverage communication channels with less security oversight and monitoring capabilities.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
South Korea's Diplomatic Academy Data Breach: A 10-Month Undetected Cyberattack
Impact· HIGH

South Korea's Diplomatic Academy Data Breach: A 10-Month Undetected Cyberattack

In April 2025, an unidentified threat actor exploited a zero-day vulnerability in the Korea National Diplomatic Academy's online education system, maintaining unauthorized access until February 2026. This breach exposed personal information—including names, user IDs, email addresses, and encrypted passwords—of approximately 10,000 individuals associated with South Korea's Ministry of Foreign Affairs, including current and former diplomats. The compromised system, established in 2022 for remote training during the COVID-19 pandemic, was taken offline in February 2026 upon detection of the intrusion. This incident underscores the escalating sophistication of cyberattacks targeting governmental institutions and the critical need for robust cybersecurity measures. The prolonged undetected access highlights vulnerabilities in monitoring and threat detection systems, emphasizing the importance of regular security audits and timely patch management to mitigate potential breaches.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GoSerpent Malware: A Persistent Threat to Southeast Asian Governments
Impact· HIGH

GoSerpent Malware: A Persistent Threat to Southeast Asian Governments

In late 2025, cybersecurity researchers identified a new malware strain named GoSerpent, actively targeting government and diplomatic entities in Southeast Asia. Discovered by Kaspersky in February 2026, GoSerpent is designed to establish long-term access for intelligence gathering by connecting to external servers and deploying secondary payloads for data collection and credential dumping. The malware's capabilities include setting up SOCKS5 proxy servers, enabling attackers to route traffic through compromised hosts and mask their true IP addresses. Additional tools such as ThumbcacheService for file collection and Mimikatz for credential extraction have been employed to facilitate data exfiltration through network shared drives. ([thehackernews.com](https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html?utm_source=openai)) The resurgence of GoSerpent in May 2026, with evolved tools like the Stowaway RAT and enhanced data exfiltration methods, underscores the persistent and adaptive nature of cyber threats targeting sensitive government information. This incident highlights the critical need for robust cybersecurity measures and continuous monitoring to detect and mitigate sophisticated espionage campaigns. ([thehackernews.com](https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GoSerpent Backdoor: A Persistent Threat to Southeast Asian Governments
Impact· HIGH

GoSerpent Backdoor: A Persistent Threat to Southeast Asian Governments

The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
StrikeShark Campaign Unleashes SharkLoader to Deploy Cobalt Strike Beacons
Impact· HIGH

StrikeShark Campaign Unleashes SharkLoader to Deploy Cobalt Strike Beacons

In June 2026, a cyber attack campaign named StrikeShark was identified, deploying a new malware loader called SharkLoader to deliver Cobalt Strike Beacons on compromised systems. The campaign targeted a diverse range of entities, including diplomatic organizations in Indonesia, government bodies in Taiwan, and software development companies across multiple countries. Attackers exploited known vulnerabilities in Microsoft Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401) to gain initial access, subsequently establishing persistence through web shells and DLL side-loading techniques. The use of open-source post-compromise tools like FScan and Pillager suggests potential involvement of Chinese-speaking threat actors. This incident underscores the persistent threat posed by sophisticated malware loaders and the exploitation of known vulnerabilities. Organizations must prioritize timely patching and employ robust detection mechanisms to mitigate such risks. The broad geographic reach and diverse target set of this campaign highlight the evolving tactics of threat actors in the current cyber threat landscape.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Turla's STOCKSTAY Backdoor: A New Cyber Espionage Threat
Impact· HIGH

Turla's STOCKSTAY Backdoor: A New Cyber Espionage Threat

In June 2026, Google's Threat Intelligence Group identified a new .NET backdoor named STOCKSTAY, attributed to the Russian state-sponsored group Turla. This malware has been deployed against government and military organizations in Ukraine and entities interested in Italian foreign policy. STOCKSTAY, developed since at least December 2022, shares significant code and functional overlaps with Turla's previous implant, Kazuar. The backdoor comprises multiple components that communicate via inter-process communication channels and utilize secure WebSocket connections for command-and-control communication. It supports various commands, including file manipulation, system information gathering, and screen capture. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/?utm_source=openai)) The discovery of STOCKSTAY underscores the evolving sophistication of state-sponsored cyber espionage tools. Its deployment highlights the persistent threat posed by advanced persistent threats (APTs) like Turla, emphasizing the need for robust cybersecurity measures and continuous monitoring to protect sensitive governmental and military information.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Council of Europe Probes ShinyHunters Data Breach Allegations
Impact· CRITICAL

Council of Europe Probes ShinyHunters Data Breach Allegations

In June 2026, the Council of Europe, representing 46 member states and over 700 million people, began investigating claims by the cyber extortion group ShinyHunters of a significant data breach. ShinyHunters alleged they had stolen over 429,000 documents containing sensitive HR and payroll data from multiple departments, including payslips, personnel files, and CVs, encompassing personal and financial information such as names, dates of birth, addresses, salaries, and bank account details. The group threatened to leak the data if their demands were not met by June 16, 2026. This incident underscores the escalating threat posed by cyber extortion groups like ShinyHunters, who have been linked to numerous high-profile data breaches targeting organizations worldwide. Their tactics often involve exfiltrating large volumes of sensitive data and leveraging it for ransom, highlighting the critical need for robust cybersecurity measures and proactive threat detection to safeguard organizational data.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
UN World Food Programme Data Breach: A Wake-Up Call for Humanitarian Cybersecurity
Impact· HIGH

UN World Food Programme Data Breach: A Wake-Up Call for Humanitarian Cybersecurity

In May 2026, the United Nations' World Food Programme (WFP) experienced a significant data breach when unauthorized actors accessed its self-registration application for Palestine. This breach exposed sensitive personal information—including names, ID numbers, mobile numbers, and location data—of approximately 600,000 Palestinian households in Gaza. The WFP promptly suspended the affected platform to implement security enhancements and initiated a comprehensive investigation into the incident. This incident underscores the critical importance of robust cybersecurity measures for humanitarian organizations handling sensitive beneficiary data. The exposure of such information not only compromises individual privacy but also heightens the risk of identity theft and targeted attacks, emphasizing the need for continuous vigilance and proactive security protocols in the humanitarian sector.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chinese APT Mustang Panda's Cyber-Espionage Campaign Against Indian Banks and Korean Policy Circles
Impact· MEDIUM

Chinese APT Mustang Panda's Cyber-Espionage Campaign Against Indian Banks and Korean Policy Circles

In April 2026, the Chinese state-sponsored advanced persistent threat (APT) group known as Mustang Panda initiated a cyber-espionage campaign targeting India's banking sector and U.S.-Korea policy circles. The attackers employed spear-phishing emails, often disguised as IT help desk communications, to deliver malicious files. Upon opening, these files executed DLL sideloading attacks, establishing persistence via the Windows Registry. The campaign deployed a variant of the LotusLite backdoor, enabling remote access for espionage activities. Notably, the malware was camouflaged to resemble legitimate banking software, such as that of HDFC Bank, India's largest private bank. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-indian-banks-korean-policy/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors utilizing well-known tactics to infiltrate critical sectors. Organizations must remain vigilant, as even unsophisticated methods can be effective if basic security controls are inconsistently applied. The targeting of financial institutions for intelligence gathering highlights the strategic value placed on economic data in geopolitical contexts.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports