✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Law Enforcement
Breach intelligence, attack campaigns, and threat reports targeting the Law Enforcement sector.
Explore Other Sectors
Law Enforcement Threat Reports
Kenyan Activist's Phone Compromised by Cellebrite Extraction
In July 2025, Kenyan pro-democracy activist Boniface Mwangi was arrested, and his personal devices were confiscated by authorities. Upon their return in September 2025, Mwangi discovered that his Samsung phone's password protection had been removed. Forensic analysis by Citizen Lab revealed with high confidence that Kenyan authorities utilized Cellebrite's forensic extraction tools on his device during its custody, enabling full access to sensitive information including messages, personal files, financial data, and passwords. This incident underscores the potential misuse of advanced surveillance technologies by government entities to target civil society members. The case highlights the growing concerns over digital privacy and the ethical implications of deploying such tools without proper oversight, emphasizing the need for stringent regulations to prevent abuse and protect individual rights.
5 months ago
Kill Chain
Serbian Authorities' Misuse of Cellebrite Tools in 2024: A Wake-Up Call for Digital Privacy
In December 2024, Amnesty International reported that Serbian police and intelligence agencies misused Cellebrite's digital forensic tools to unlawfully extract data from mobile devices belonging to journalists and activists. The authorities employed these tools to unlock devices without consent, facilitating the installation of spyware like NoviSpy during detentions and interrogations. This surveillance campaign targeted individuals critical of government policies, leading to significant privacy violations and suppression of civil society. ([amnesty.org](https://www.amnesty.org/en/latest/news/2024/12/serbia-authorities-using-spyware-and-cellebrite-forensic-extraction-tools-to-hack-journalists-and-activists/?utm_source=openai)) The incident underscores the potential for abuse of digital forensic technologies when deployed without stringent oversight. It highlights the urgent need for robust legal frameworks and ethical guidelines to prevent the misuse of such tools against civil society and to protect fundamental human rights.
5 months ago
Kill Chain
ZeroDayRAT: The New Mobile Spyware Threatening Device Security
In early February 2026, cybersecurity researchers identified ZeroDayRAT, a sophisticated mobile spyware platform being sold openly on Telegram. This malware grants attackers full remote control over Android (versions 5 through 16) and iOS devices (up to iOS 26, including the iPhone 17 Pro). Once installed via smishing, phishing emails, or malicious app stores, ZeroDayRAT enables comprehensive surveillance, including GPS tracking, message interception, live camera and microphone access, keylogging, and financial theft targeting banking and cryptocurrency applications. The spyware's user-friendly control panel allows even non-technical operators to exploit compromised devices effectively. ([securityweek.com](https://www.securityweek.com/new-zerodayrat-spyware-kit-enables-total-compromise-of-ios-android-devices/?utm_source=openai)) The emergence of ZeroDayRAT signifies a concerning trend where advanced surveillance tools, previously accessible only to nation-state actors, are now available to a broader range of cybercriminals. This development underscores the urgent need for enhanced mobile security measures and user vigilance to prevent unauthorized access and data breaches. ([securityweek.com](https://www.securityweek.com/new-zerodayrat-spyware-kit-enables-total-compromise-of-ios-android-devices/?utm_source=openai))
5 months ago
Kill Chain
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
Between January 2024 and February 2026, the cyber espionage group TGR-STA-1030, assessed to be state-aligned and operating out of Asia, compromised at least 70 government and critical infrastructure organizations across 37 countries. The group employed phishing emails and exploited known software vulnerabilities to gain initial access, subsequently deploying tools like the Diaoyu Loader and the ShadowGuard rootkit to maintain persistence and exfiltrate sensitive data. Notable targets included national law enforcement agencies, ministries of finance, and departments focusing on trade and diplomacy. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/?utm_source=openai)) This incident underscores the escalating sophistication and reach of state-sponsored cyber espionage activities, highlighting the urgent need for enhanced cybersecurity measures and international cooperation to protect critical infrastructure and sensitive governmental data.
5 months ago
Kill Chain
Dark Web Drug Kingpin Sentenced: The Fall of Incognito Market
In February 2026, Rui-Siang Lin, a 24-year-old Taiwanese national, was sentenced to 30 years in U.S. federal prison for operating 'Incognito Market,' a dark web platform that facilitated over $105 million in illegal drug transactions from October 2020 to March 2024. Lin, known online as 'Pharoah,' managed the marketplace's operations, overseeing more than 1,800 vendors and 400,000 customer accounts. The platform processed over 640,000 transactions involving substantial quantities of narcotics, including cocaine, methamphetamine, and fentanyl-laced pills, which were linked to at least one fatal overdose. ([yahoo.com](https://www.yahoo.com/news/articles/incognito-market-founder-rui-siang-150954026.html?utm_source=openai)) This case underscores the persistent threat posed by dark web marketplaces in the global drug trade. Despite law enforcement's efforts to dismantle such platforms, their sophisticated use of anonymizing technologies and cryptocurrencies continues to challenge regulatory and enforcement agencies worldwide. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/04/incognito-dark-web-drug-market-operator-prison-sentence/?utm_source=openai))
5 months ago
Kill Chain
Amaranth Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In August 2025, the cyberespionage group Amaranth Dragon, linked to China's APT41, exploited the CVE-2025-8088 vulnerability in WinRAR to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they leveraged the vulnerability to place encrypted payloads in the Windows Startup folder, ensuring persistence upon system reboot. These attacks were characterized by the use of legitimate tools combined with the custom Amaranth Loader, which retrieved payloads from command-and-control servers concealed behind Cloudflare infrastructure, enhancing stealth and targeting precision. The continued exploitation of CVE-2025-8088 by multiple threat actors underscores the critical need for organizations to promptly update software and implement robust security measures. Despite the release of WinRAR version 7.13, which addresses this flaw, many systems remain vulnerable due to delayed patching and user unawareness, highlighting a significant gap in cybersecurity defenses.
5 months ago
Kill Chain
EDR Killer Tool Exploits EnCase Driver: A Wake-Up Call for Cybersecurity
In early February 2026, cybersecurity researchers identified a sophisticated attack where threat actors utilized a legitimate but revoked EnCase kernel driver to disable endpoint detection and response (EDR) tools. The attackers gained initial access through compromised SonicWall SSL VPN credentials, exploiting the absence of multi-factor authentication. Once inside, they deployed a custom EDR killer tool disguised as a firmware update utility, which installed the 'EnPortv.sys' driver—a component of the EnCase forensic software. This driver, despite its certificate being revoked, was accepted by Windows due to the operating system's handling of driver signatures. The malware leveraged the driver's kernel-mode capabilities to terminate 59 security processes, effectively neutralizing the system's defenses. The attack was halted before ransomware deployment, but it underscores the critical need for robust access controls and vigilant monitoring of security infrastructure. This incident highlights a growing trend where attackers exploit vulnerable or outdated drivers to disable security mechanisms, a technique known as 'Bring Your Own Vulnerable Driver' (BYOVD). The persistence of such methods, despite existing security measures, emphasizes the necessity for organizations to implement comprehensive defense strategies, including regular updates to security protocols and the enforcement of multi-factor authentication across all access points.
5 months ago
Kill Chain
Amaranth-Dragon's 2025 Exploitation of WinRAR Vulnerability: A Cybersecurity Wake-Up Call
In 2025, the China-linked cyber espionage group Amaranth-Dragon exploited a critical vulnerability in WinRAR (CVE-2025-8088) to target government and law enforcement agencies across Southeast Asia. By crafting malicious RAR archives, they executed arbitrary code upon extraction, leading to unauthorized access and data exfiltration. The campaigns were highly controlled, leveraging spear-phishing emails with tailored lures related to regional political developments, and utilized cloud platforms like Dropbox to distribute the malicious files. The exploitation of this vulnerability underscores the persistent threat posed by nation-state actors and the importance of timely software updates. Despite the release of WinRAR version 7.13, which addressed the flaw, many users remained vulnerable due to delayed patching. This incident highlights the critical need for organizations to maintain up-to-date software and implement robust security measures to defend against sophisticated cyber threats.
5 months ago
Kill Chain
Empire Market Dark Web Takedown: Owner Pleads Guilty in $430M Cybercrime Plot
In January 2026, U.S. authorities announced that Raheim Hamilton (“Sydney”/“ZeroAngel”), a co-founder of the notorious Empire Market, pleaded guilty to federal drug conspiracy charges. From 2018 to 2020, Empire Market operated as a large-scale dark web marketplace accessible via TOR, facilitating over $430 million in illegal transactions, primarily enabling drug sales but also distributing stolen credentials, hacking tools, and counterfeit currency. Hamilton and partner Thomas Pavey laundered illicit proceeds through cryptocurrency and designed the site to evade law enforcement, directly overseeing vendor disputes and operational security. This prosecution underscores the ongoing threat and operational sophistication of dark web cybercrime marketplaces, even after earlier takedowns. As digital criminal platforms persistently adapt, law enforcement and organizations must address the evolving risks involving anonymized markets, cryptocurrency transactions, and the proliferation of illicit digital goods and services.
6 months ago
Kill Chain
US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed
In late 2025 and early 2026, US law enforcement charged 31 additional suspects in a major campaign of ATM jackpotting attacks attributed to the Venezuelan criminal gang Tren de Aragua. The attackers breached numerous ATMs across the United States, installing Ploutus malware by physically accessing internal components and deploying malware to force the machines to dispense large quantities of cash. The sophisticated attacks leveraged swapped hard drives or infected USB devices and allowed the perpetrators to launder stolen funds internationally, inflicting millions of dollars in losses on banks and credit unions. To date, over 87 individuals have been charged in this transnational criminal scheme. This incident highlights the evolving tactics of financially motivated threat groups combining physical access and technical expertise. The designation of Tren de Aragua as a Foreign Terrorist Organization underscores law enforcement’s recognition of cyber-enabled financial crime as a national security threat and signals intensified global scrutiny on such operations.
6 months ago
Kill Chain
US ATM Jackpotting 2024: Venezuelan Hackers Steal Hundreds of Thousands Using Malware
In early 2024, federal prosecutors in South Carolina uncovered a sophisticated ATM jackpotting scheme perpetrated by two Venezuelan nationals. Employing financial malware, the attackers compromised U.S. bank ATM networks and extracted hundreds of thousands of dollars in cash. The scheme involved the unauthorized installation of malware on ATM machines, which enabled the criminals to override withdrawal limits and rapidly dispense large sums of money. Following their arrest, both individuals were convicted and will be deported after serving their sentences, highlighting significant vulnerabilities in ATM security and network segmentation. This incident reflects a growing trend in financial crime, where cybercriminals target banking infrastructure using advanced malware and physical access techniques. Regulators and banks are increasingly focused on hardening ATM systems and tightening controls to prevent similar attacks as cyber-enabled fraud remains a persistent and evolving threat.
6 months ago
Kill Chain
Jordan Government’s Use of Cellebrite Forensics Tools Targets Activists in 2024
Between late 2023 and mid-2024, Jordanian authorities used Cellebrite’s digital forensic technology to access and extract data from the mobile phones of local activists and human rights defenders. According to an investigation by Citizen Lab and OCCRP, authorities seized activists’ devices—three iPhones and one Android—and subjected them to Cellebrite’s phone-cracking tools, often in connection with political protests. Court records and forensic analysis confirmed the use of Cellebrite products to nonconsensually access information, shaking victims’ trust and prompting self-censorship. This incident underscores the growing risks of commercial digital forensics tools being repurposed for surveillance beyond criminal cases. Amnesty International and other watchdogs report a broader trend of such technologies being leveraged against civil society, signaling a need for stronger governance, vendor accountability, and compliance oversight globally.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports