The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
International Affairs
Breach intelligence, attack campaigns, and threat reports targeting the International Affairs sector.
Explore Other Sectors
International Affairs Threat Reports
Grinex Exchange Halts Operations After $13.74M Cyberattack
In April 2026, Grinex, a Kyrgyzstan-registered cryptocurrency exchange with strong ties to Russia, suspended operations following a cyberattack that resulted in the theft of over $13.74 million (approximately 1 billion rubles) from user funds. The exchange attributed the attack to foreign intelligence agencies, citing the sophisticated nature of the breach. The stolen funds were primarily in USDT, which were swiftly converted to TRX and ETH to evade potential asset freezing by Tether. This incident underscores the vulnerabilities of cryptocurrency exchanges operating in regulatory grey areas and highlights the ongoing geopolitical tensions affecting financial infrastructures. The attack on Grinex is part of a broader trend of state-sponsored cyber operations targeting financial entities, emphasizing the need for enhanced security measures and regulatory oversight in the cryptocurrency sector.
5 months ago
Kill Chain
TA416's Renewed Cyber Espionage Campaigns Target European Governments
In mid-2025, the China-aligned threat actor TA416 resumed cyber espionage operations targeting European government and diplomatic entities after a two-year hiatus. The group employed sophisticated techniques, including web bug reconnaissance and evolving malware delivery methods, to deploy the PlugX backdoor via DLL sideloading. These campaigns primarily focused on individuals associated with NATO and EU delegations, leveraging compromised accounts and freemail services to distribute malicious payloads. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai)) This resurgence underscores the persistent threat posed by state-sponsored actors to governmental institutions, highlighting the need for enhanced cybersecurity measures and vigilance against evolving attack vectors. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai))
5 months ago
Kill Chain
TA416's Renewed Cyberespionage Campaigns in Europe and Middle East
Between mid-2025 and early 2026, the China-aligned cyberespionage group TA416, also known as Mustang Panda, resumed targeting European government and diplomatic entities after a period of reduced activity in the region. The group employed web bug campaigns and malware delivery methods, including phishing emails with lures about Europe sending troops to Greenland, to deliver their customized PlugX backdoor via DLL sideloading techniques. In March 2026, following the outbreak of conflict in Iran, TA416 expanded its operations to target Middle Eastern government and diplomatic entities, marking a strategic shift in their focus. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/id-come-running-back-eu-again-ta416-resumes-european-government-espionage?utm_source=openai)) This resurgence in TA416's activities underscores the evolving nature of state-sponsored cyber threats, particularly in the context of geopolitical tensions. Organizations within the targeted regions should remain vigilant and enhance their cybersecurity measures to mitigate the risks associated with such sophisticated cyberespionage campaigns.
5 months ago
Kill Chain
Transparent Tribe's AI-Driven Malware Campaign: A 2026 Cybersecurity Wake-Up Call
In early 2026, the Pakistan-aligned threat actor Transparent Tribe (APT36) launched a cyber espionage campaign targeting Indian government entities. Utilizing AI-assisted development, they produced a high volume of malware implants in lesser-known programming languages such as Nim, Zig, and Crystal. These implants exploited trusted services like Slack, Discord, Supabase, and Google Sheets for command-and-control communications, complicating detection efforts. The attack vectors included spear-phishing emails with weaponized Windows shortcut (LNK) files and PDF lures leading to malicious downloads. Once executed, these payloads provided the attackers with remote access, enabling data exfiltration and further network compromise. This campaign underscores the evolving threat landscape where AI tools are leveraged to rapidly develop and deploy diverse malware strains, overwhelming traditional defense mechanisms. Organizations must enhance their cybersecurity posture by adopting advanced threat detection systems capable of identifying and mitigating such sophisticated attacks.
6 months ago
Kill Chain
Chinese Police Exploit ChatGPT in Smear Campaign Against Japan's PM Takaichi
In October 2025, OpenAI identified and banned a ChatGPT account linked to Chinese law enforcement that was used to orchestrate a smear campaign against Japan's Prime Minister, Sanae Takaichi. The individual behind the account attempted to leverage ChatGPT to generate and amplify negative content about Takaichi, including drafting complaints impersonating Japanese citizens and creating social media posts to incite public dissent. These activities were part of a broader, covert influence operation aimed at discrediting foreign officials critical of China's policies. ([theregister.com](https://www.theregister.com/2026/02/25/chinese_law_enforcement_chatgpt_abuse/?utm_source=openai)) This incident underscores the evolving use of artificial intelligence in state-sponsored disinformation campaigns. The exposure of such tactics highlights the need for vigilance against AI-driven influence operations, especially as they become more sophisticated and harder to detect. ([axios.com](https://www.axios.com/2026/02/25/openai-chatgpt-china-japan-prime-minister?utm_source=openai))
7 months ago
Kill Chain
Germany 2026: Signal Account Hijacking Targets Senior Figures
In February 2026, Germany's Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) issued a warning about state-sponsored threat actors targeting high-ranking individuals through phishing attacks on messaging apps like Signal. The attackers employed social engineering tactics, impersonating support teams to deceive politicians, military officers, diplomats, and investigative journalists into granting access to their accounts. This campaign did not exploit technical vulnerabilities or deploy malware but leveraged legitimate app features to gain unauthorized access to sensitive communications. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/germany-warns-of-signal-account-hijacking-targeting-senior-figures/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks that exploit trust in legitimate platforms. Organizations must enhance user awareness and implement robust security measures to mitigate such threats, especially as attackers increasingly target high-profile individuals through commonly used communication tools.
7 months ago
Kill Chain
Iranian Cyber Espionage Intensifies: Middle East Expatriates Targeted in 2026
In early 2026, Iranian state-sponsored cyber actors intensified their espionage activities targeting Middle Eastern expatriates, Syrians, and Israelis. Utilizing sophisticated social engineering techniques, these actors created credible fake personas on multiple platforms, engaging targets over extended periods to build trust. Once rapport was established, they employed spear-phishing campaigns, often delivering malicious links or documents under the guise of legitimate communications. These operations aimed to steal sensitive information, monitor communications, and track the movements of individuals of interest. The impact of these campaigns has been significant, compromising personal and professional data, and posing threats to the safety and privacy of the targeted individuals. The use of advanced social engineering tactics underscores the evolving nature of cyber threats emanating from state-sponsored actors. This incident highlights the urgent need for heightened vigilance and robust cybersecurity measures, especially for individuals and organizations operating in or related to the Middle East. The increasing sophistication of these attacks, coupled with their targeted nature, reflects a broader trend of state actors leveraging cyber capabilities for intelligence gathering and influence operations.
7 months ago
Kill Chain
Amaranth-Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In 2025, the China-linked cyber espionage group Amaranth-Dragon exploited a critical vulnerability in WinRAR (CVE-2025-8088) to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they executed arbitrary code upon extraction, leading to unauthorized access and data exfiltration. The campaigns were highly controlled, leveraging spear-phishing emails with tailored lures related to regional political developments, and utilized cloud platforms like Dropbox to distribute the malicious files. The exploitation of this vulnerability underscores the persistent threat posed by nation-state actors and the importance of timely software updates. Despite the release of WinRAR version 7.13, which addressed the flaw, many users remained vulnerable due to delayed patching. This incident highlights the critical need for organizations to maintain up-to-date software and implement robust security measures to defend against sophisticated cyber threats.
7 months ago
Kill Chain
Hamas Espionage Malware Hits Middle East Diplomats: 2024 Breach Analysis
In early 2024, state-sponsored threat actors linked to Hamas intensified cyber-espionage campaigns targeting Middle Eastern diplomatic entities. Attackers leveraged tailored malware and advanced phishing schemes to infiltrate networks, harvest intelligence, and gain persistent access to government communications. The campaign utilized unpatched vulnerabilities, abused encrypted and lateral east-west traffic, and bypassed conventional perimeter defenses. These intrusions aimed to gather political intelligence and undermine regional security, impacting the operational confidentiality of affected governments and creating heightened diplomatic tensions. This incident reflects a broader escalation in politically motivated cyber-espionage across the region, as Hamas and allied groups continue to innovate with more sophisticated tooling and tactics. The evolving threat landscape underscores the urgency for robust east-west segmentation, encrypted traffic controls, and real-time threat detection among critical infrastructure and state agencies.
8 months ago
Kill Chain
WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag
In late 2025, the advanced persistent threat group WIRTE, linked to Gaza Cyber Gang, launched a far-reaching espionage campaign against government and diplomatic entities across the Middle East using a new malware suite known as AshTag. Attackers used phishing emails with geopolitical lures to entice targets into downloading malicious archives, resulting in the sideloading of AshenLoader and the deployment of AshTag. This modular .NET backdoor enabled remote command execution, persistence, and document exfiltration, specifically targeting sensitive diplomatic materials. Notably, attacks persisted throughout the Israel-Hamas conflict and continued after the Gaza ceasefire, highlighting the threat actors' sustained operational tempo. This campaign is a potent reminder of the increasing sophistication of state-linked espionage operations, including the adoption of advanced malware delivery and in-memory execution tactics designed to evade detection. With attackers broadening their target geography and refining their methods, regional governments and strategic organizations must urgently review and upgrade their defenses.
8 months ago
Kill Chain
Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets
In late 2025, a Hamas-affiliated APT group known as Ashen Lepus (also referred to as WIRTE) executed a sophisticated cyber-espionage campaign targeting governmental and diplomatic organizations across multiple Middle Eastern countries. The attackers leveraged a novel modular malware suite called AshTag, delivered through decoy documents, DLL sideloading, and a carefully staged infection chain. The campaign made extensive use of in-memory payload delivery, advanced encryption, legitimate-themed subdomains for C2 communications, and the abuse of widely used file transfer tools like Rclone to exfiltrate sensitive, often diplomacy-related data. This incident marks a notable evolution in the operational security and technical sophistication of Middle Eastern espionage campaigns. It highlights the rising use of modular malware, infrastructure blending, and legitimate protocol abuse by regionally motivated threat actors, underscoring a trend where state-linked groups continue cyber operations despite geopolitical turmoil or ceasefires.
8 months ago
Kill Chain
Intellexa Predator Spyware Strikes Pakistani Civil Society via WhatsApp (2025)
In June 2025, a human rights lawyer based in Balochistan, Pakistan, was targeted by Intellexa's highly advanced Predator spyware via a malicious WhatsApp link, according to Amnesty International. This marks the first documented case of a civil society member in Pakistan being targeted by this tool. The attacker, likely operating with government-grade resources, used zero-day exploits and an advertising-based infection vector to bypass conventional defenses, aiming to infiltrate the lawyer's mobile device and access sensitive communications. This incident underscores the growing sophistication of spyware campaigns and the expansion of mercenary surveillance tools targeting individuals beyond political figures or journalists. It highlights the urgent need for robust communication security and regulatory scrutiny of commercial spyware vendors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports