✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
International Affairs
Breach intelligence, attack campaigns, and threat reports targeting the International Affairs sector.
Explore Other Sectors
International Affairs Threat Reports
Chinese Police Exploit ChatGPT in Smear Campaign Against Japan's PM Takaichi
In October 2025, OpenAI identified and banned a ChatGPT account linked to Chinese law enforcement that was used to orchestrate a smear campaign against Japan's Prime Minister, Sanae Takaichi. The individual behind the account attempted to leverage ChatGPT to generate and amplify negative content about Takaichi, including drafting complaints impersonating Japanese citizens and creating social media posts to incite public dissent. These activities were part of a broader, covert influence operation aimed at discrediting foreign officials critical of China's policies. ([theregister.com](https://www.theregister.com/2026/02/25/chinese_law_enforcement_chatgpt_abuse/?utm_source=openai)) This incident underscores the evolving use of artificial intelligence in state-sponsored disinformation campaigns. The exposure of such tactics highlights the need for vigilance against AI-driven influence operations, especially as they become more sophisticated and harder to detect. ([axios.com](https://www.axios.com/2026/02/25/openai-chatgpt-china-japan-prime-minister?utm_source=openai))
4 months ago
Kill Chain
Germany 2026: Signal Account Hijacking Targets Senior Figures
In February 2026, Germany's Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) issued a warning about state-sponsored threat actors targeting high-ranking individuals through phishing attacks on messaging apps like Signal. The attackers employed social engineering tactics, impersonating support teams to deceive politicians, military officers, diplomats, and investigative journalists into granting access to their accounts. This campaign did not exploit technical vulnerabilities or deploy malware but leveraged legitimate app features to gain unauthorized access to sensitive communications. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/germany-warns-of-signal-account-hijacking-targeting-senior-figures/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks that exploit trust in legitimate platforms. Organizations must enhance user awareness and implement robust security measures to mitigate such threats, especially as attackers increasingly target high-profile individuals through commonly used communication tools.
5 months ago
Kill Chain
Iranian Cyber Espionage Intensifies: Middle East Expatriates Targeted in 2026
In early 2026, Iranian state-sponsored cyber actors intensified their espionage activities targeting Middle Eastern expatriates, Syrians, and Israelis. Utilizing sophisticated social engineering techniques, these actors created credible fake personas on multiple platforms, engaging targets over extended periods to build trust. Once rapport was established, they employed spear-phishing campaigns, often delivering malicious links or documents under the guise of legitimate communications. These operations aimed to steal sensitive information, monitor communications, and track the movements of individuals of interest. The impact of these campaigns has been significant, compromising personal and professional data, and posing threats to the safety and privacy of the targeted individuals. The use of advanced social engineering tactics underscores the evolving nature of cyber threats emanating from state-sponsored actors. This incident highlights the urgent need for heightened vigilance and robust cybersecurity measures, especially for individuals and organizations operating in or related to the Middle East. The increasing sophistication of these attacks, coupled with their targeted nature, reflects a broader trend of state actors leveraging cyber capabilities for intelligence gathering and influence operations.
5 months ago
Kill Chain
Amaranth-Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In 2025, the China-linked cyber espionage group Amaranth-Dragon exploited a critical vulnerability in WinRAR (CVE-2025-8088) to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they executed arbitrary code upon extraction, leading to unauthorized access and data exfiltration. The campaigns were highly controlled, leveraging spear-phishing emails with tailored lures related to regional political developments, and utilized cloud platforms like Dropbox to distribute the malicious files. The exploitation of this vulnerability underscores the persistent threat posed by nation-state actors and the importance of timely software updates. Despite the release of WinRAR version 7.13, which addressed the flaw, many users remained vulnerable due to delayed patching. This incident highlights the critical need for organizations to maintain up-to-date software and implement robust security measures to defend against sophisticated cyber threats.
5 months ago
Kill Chain
Hamas Espionage Malware Hits Middle East Diplomats: 2024 Breach Analysis
In early 2024, state-sponsored threat actors linked to Hamas intensified cyber-espionage campaigns targeting Middle Eastern diplomatic entities. Attackers leveraged tailored malware and advanced phishing schemes to infiltrate networks, harvest intelligence, and gain persistent access to government communications. The campaign utilized unpatched vulnerabilities, abused encrypted and lateral east-west traffic, and bypassed conventional perimeter defenses. These intrusions aimed to gather political intelligence and undermine regional security, impacting the operational confidentiality of affected governments and creating heightened diplomatic tensions. This incident reflects a broader escalation in politically motivated cyber-espionage across the region, as Hamas and allied groups continue to innovate with more sophisticated tooling and tactics. The evolving threat landscape underscores the urgency for robust east-west segmentation, encrypted traffic controls, and real-time threat detection among critical infrastructure and state agencies.
6 months ago
Kill Chain
WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag
In late 2025, the advanced persistent threat group WIRTE, linked to Gaza Cyber Gang, launched a far-reaching espionage campaign against government and diplomatic entities across the Middle East using a new malware suite known as AshTag. Attackers used phishing emails with geopolitical lures to entice targets into downloading malicious archives, resulting in the sideloading of AshenLoader and the deployment of AshTag. This modular .NET backdoor enabled remote command execution, persistence, and document exfiltration, specifically targeting sensitive diplomatic materials. Notably, attacks persisted throughout the Israel-Hamas conflict and continued after the Gaza ceasefire, highlighting the threat actors' sustained operational tempo. This campaign is a potent reminder of the increasing sophistication of state-linked espionage operations, including the adoption of advanced malware delivery and in-memory execution tactics designed to evade detection. With attackers broadening their target geography and refining their methods, regional governments and strategic organizations must urgently review and upgrade their defenses.
6 months ago
Kill Chain
Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets
In late 2025, a Hamas-affiliated APT group known as Ashen Lepus (also referred to as WIRTE) executed a sophisticated cyber-espionage campaign targeting governmental and diplomatic organizations across multiple Middle Eastern countries. The attackers leveraged a novel modular malware suite called AshTag, delivered through decoy documents, DLL sideloading, and a carefully staged infection chain. The campaign made extensive use of in-memory payload delivery, advanced encryption, legitimate-themed subdomains for C2 communications, and the abuse of widely used file transfer tools like Rclone to exfiltrate sensitive, often diplomacy-related data. This incident marks a notable evolution in the operational security and technical sophistication of Middle Eastern espionage campaigns. It highlights the rising use of modular malware, infrastructure blending, and legitimate protocol abuse by regionally motivated threat actors, underscoring a trend where state-linked groups continue cyber operations despite geopolitical turmoil or ceasefires.
6 months ago
Kill Chain
Intellexa Predator Spyware Strikes Pakistani Civil Society via WhatsApp (2025)
In June 2025, a human rights lawyer based in Balochistan, Pakistan, was targeted by Intellexa's highly advanced Predator spyware via a malicious WhatsApp link, according to Amnesty International. This marks the first documented case of a civil society member in Pakistan being targeted by this tool. The attacker, likely operating with government-grade resources, used zero-day exploits and an advertising-based infection vector to bypass conventional defenses, aiming to infiltrate the lawyer's mobile device and access sensitive communications. This incident underscores the growing sophistication of spyware campaigns and the expansion of mercenary surveillance tools targeting individuals beyond political figures or journalists. It highlights the urgent need for robust communication security and regulatory scrutiny of commercial spyware vendors.
6 months ago
Kill Chain
Tomiris Unleashes 'Havoc': 2024 CIS Government Cyber-Espionage Explained
In early 2024, the Russian-speaking APT group Tomiris launched a sophisticated cyber-espionage campaign targeting government and diplomatic organizations in several CIS nations and Central Asia. Attackers leveraged new malware tools and refined tactics, initially gaining access via spear-phishing and malicious email attachments designed to exploit trust within diplomatic correspondence chains. Once inside, the group deployed covert tools for lateral movement, maintained persistence, and exfiltrated sensitive diplomatic communications and internal documents. The breach had significant operational security implications, exposing strategic discussions and potentially undermining ongoing government initiatives. This incident exemplifies the ongoing risk posed by advanced persistent threats in geopolitical hotspots, with Tomiris demonstrating evolving tradecraft and adaptability. Organizations are urged to review east-west security, segmentation, and monitoring practices as similar espionage campaigns are increasingly targeting public sector networks.
6 months ago
Kill Chain
Tomiris Leverages Public-Service Implants for Stealthy Government Attacks
In late 2025, the state-sponsored threat actor Tomiris escalated its attacks against government entities and intergovernmental organizations, primarily in Russia and neighboring regions. The group notably shifted its tactics by deploying custom remote access implants that leveraged public cloud services, such as Telegram and Discord, as command-and-control (C2) channels. This allowed Tomiris to disguise their network traffic among legitimate service use, evading conventional perimeter defenses and security controls. The compromise enabled attackers to maintain persistent access, deploy additional payloads, and potentially exfiltrate sensitive diplomatic and policy data. This incident is significant due to its demonstration of the evolving sophistication in APT tactics: the use of ubiquitous public platforms for C2, making detection and attribution harder. It also highlights the urgency for zero trust architectures, enhanced traffic monitoring, and cloud-centric security controls as industries face an increase in nation-state and intelligence-motivated threats.
6 months ago
Kill Chain
Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks
In early 2025, the Tomiris APT group launched a sophisticated cyberespionage campaign targeting foreign ministries, intergovernmental organizations, and government entities across Russia and Central Asia. Using spear-phishing emails with password-protected malicious archives, Tomiris delivered a diverse toolkit of implants written in C/C++, Rust, Go, C#, and Python. Their malware leveraged public services like Telegram and Discord for command-and-control (C2), employed open-source frameworks such as Havoc and AdaptixC2, and enabled attackers to perform reconnaissance, maintain persistence, and exfiltrate sensitive data, while evading traditional network defenses by blending illicit traffic with legitimate channels. This incident highlights a clear evolution in APT tradecraft: rapid adoption of multi-language toolchains, creative lateral movement, and the abuse of popular cloud-based services for covert operations. With the continued rise of lawful-shadow C2 channels and open-source post-exploitation kits, organizations face heightened risks from identity-driven, stealthy attacks that challenge conventional segmentation and anomaly detection strategies.
6 months ago
Kill Chain
SmudgedSerpent 2025: Espionage Hits Policy Experts Amid Iran-Israel Tensions
Between June and August 2025, an advanced threat group dubbed UNK_SmudgedSerpent orchestrated a series of targeted cyber espionage campaigns against U.S.-based academics and foreign policy experts. Leveraging spear-phishing and sophisticated social engineering, the attackers exploited topical Iranian political themes to deliver customized malware, enabling data exfiltration and continuous monitoring of sensitive research communications. The campaign coincided with heightened Iran–Israel tensions, harnessing unauthorized east-west network movement and encrypted C2 channels to bypass traditional security controls, resulting in significant exposure of policy research, analysis drafts, and privileged communications. This intrusion highlights the evolving tactics of nation-state-aligned actors who exploit contextual geopolitical unrest to target civilian research and policy infrastructure. The incident underscores the escalating risk to sectors handling sensitive knowledge, while accelerating demands for retroactive compliance audits and robust zero trust segmentation as espionage techniques continue to proliferate.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports