The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Military Industry
Breach intelligence, attack campaigns, and threat reports targeting the Military Industry sector.
Explore Other Sectors
Military Industry Threat Reports
Russian APTs Exploit Messaging App Trust to Compromise EU Government Officials
In 2026, Russian state-sponsored threat actors conducted a sophisticated spear-phishing campaign targeting high-ranking EU government officials through encrypted messaging applications like WhatsApp and Signal. The attackers impersonated platform support teams and used QR code social engineering tactics to compromise accounts, successfully breaching officials including German Bundestag President Julia Klöeckner. Eight significant incidents were documented across EU governments, exposing the vulnerability of consumer messaging platforms used for official communications and prompting several nations to develop sovereign messaging solutions. This incident highlights the critical shift in nation-state attack vectors as threat actors exploit the inherent trust users place in encrypted messaging platforms, moving beyond traditional email-based phishing to leverage communication channels with less security oversight and monitoring capabilities.
4 weeks ago
Kill Chain
Jewelbug's Exploitation of XG-Web: A Dual Threat to Governments and Cryptocurrency Users
In August 2026, the China-linked threat actor known as Jewelbug was identified conducting cyber espionage operations targeting governments and militaries, alongside engaging in cryptocurrency fraud. Utilizing a sophisticated tool named XG-Web, Jewelbug transformed victims' browsers into remote-control channels, enabling deep infiltration into host systems and internal networks. This dual-purpose framework facilitated both espionage against governmental entities across the Middle East, Southeast Asia, and South Asia, and financially motivated cryptocurrency fraud aimed at Chinese-speaking users. The group's operations were marked by the development of multiple generations of command-and-control code and a suite of implants affecting browsers, Windows endpoints, Linux servers, and network devices, all feeding into a centralized victim database. The significance of this incident lies in the convergence of state-sponsored cyber espionage and cybercrime within a single operational framework. Jewelbug's activities underscore the evolving landscape where nation-state actors increasingly blur the lines between political objectives and financial gain. This trend highlights the urgent need for organizations to adopt comprehensive cybersecurity measures that address both traditional espionage tactics and emerging cybercriminal methodologies.
1 month ago
Kill Chain
Jewelbug's 2026 Government Webmail Breach and Crypto Fraud
In August 2026, the Chinese state-sponsored hacking group known as Jewelbug (also referred to as Earth Alux and REF7707) executed a sophisticated cyber-espionage campaign targeting government webmail systems in a Middle Eastern country. By compromising a shared web-hosting platform operated by the national telecommunications provider, Jewelbug gained write access to the webmail installation used by multiple government ministries and agencies. They injected a malicious script into the common template, which, upon execution, established a WebSocket connection to the attackers' command-and-control server, exfiltrated webmail cookies, and retrieved users' email addresses to identify and further exploit high-value government domains. This breach affected 15 government tenants, allowing the attackers to monitor and manipulate sensitive communications. Concurrently, Jewelbug engaged in large-scale cryptocurrency fraud operations, utilizing AI-generated content and click-fraud bots to drive traffic to fraudulent crypto exchange sites, resulting in significant financial losses. ([securityonline.info](https://securityonline.info/chinas-jewelbug-apt-breaches-russian-it-provider-for-5-months-using-yandex-cloud-and-graph-api-c2/?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors who are increasingly blending traditional espionage with financially motivated cybercrime. The dual nature of Jewelbug's operations highlights the necessity for organizations to adopt comprehensive cybersecurity measures that address both information security and financial fraud. The use of AI and automation in these attacks also signals a shift towards more sophisticated and scalable cyber threats, necessitating continuous vigilance and adaptation of defense strategies.
1 month ago
Kill Chain
Russian Intelligence Exploits Fake Support Texts to Breach Messaging Accounts
In June 2026, the Security Service of Ukraine (SSU), in collaboration with the U.S. Federal Bureau of Investigation (FBI), uncovered a prolonged cyber espionage campaign orchestrated by Russian intelligence services. This operation targeted government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The attackers employed social engineering tactics, sending SMS messages that impersonated messaging platform support services to deceive recipients into divulging their account credentials. The primary objective was to access sensitive military, political, and economic information, as well as personal data. ([thehackernews.com](https://thehackernews.com/2026/06/ukraine-says-russian-intelligence-used.html?utm_source=openai)) This incident underscores the escalating sophistication of state-sponsored cyber threats, particularly those leveraging social engineering to exploit human vulnerabilities. Organizations and individuals must remain vigilant, adopting robust security measures such as two-factor authentication and regular monitoring of account activities to mitigate the risks posed by such targeted attacks.
2 months ago
Kill Chain
Gamaredon's 2025 Spearphishing Escalation: A Wake-Up Call for Cybersecurity
In 2025, the Russian state-sponsored APT group Gamaredon intensified its cyber espionage activities against Ukrainian governmental institutions. The group launched numerous spearphishing campaigns, introducing six new malware tools leveraging PowerShell and VBScript to enhance stealth, persistence, and lateral movement. Notably, Gamaredon concealed its command-and-control infrastructure behind Cloudflare tunnels and utilized third-party services like Telegram and Dropbox to obfuscate its operations. ([eset.com](https://www.eset.com/uk/about/newsroom/press-releases/eset-research-russias-gamaredon-apt-group-unleashed-spearphishing-campaigns-against-ukraine-with-an-evolved-toolset-uk/?utm_source=openai)) This escalation underscores the evolving threat landscape, highlighting the need for organizations to adopt advanced detection and response strategies to counter sophisticated state-sponsored cyber threats.
3 months ago
Kill Chain
Gamaredon's 2025 Cyberespionage Tactics: A Deep Dive
In 2025, the Russian-aligned APT group Gamaredon intensified its cyberespionage operations against Ukrainian governmental and military institutions. The group executed 35 distinct spearphishing campaigns, primarily in the latter half of the year, utilizing new PowerShell tools and resurrecting older VBScript weaponizers. Gamaredon also enhanced its data exfiltration methods by upgrading file stealers to support cloud storage services like Wasabi, Tebi, and Intercolo. To conceal its command and control infrastructure, the group increasingly relied on legitimate third-party services, including tunnels, workers, dynamic DNS, and platform-as-a-service offerings. Additionally, Gamaredon exploited various messaging, social media, blogging, and paste services as dead drops for distributing payloads and resolving C&C servers. This evolution in tactics underscores the group's adaptability and the persistent cyber threat it poses to Ukrainian institutions.
3 months ago
Kill Chain
UNC6508: Unveiling the Stealthy Chinese Espionage Group Targeting North American Research
In late 2025, Google's Threat Intelligence Group identified UNC6508, a Chinese state-sponsored espionage group, which had infiltrated U.S. and Canadian organizations since September 2023. The group exploited vulnerabilities in externally facing REDCap servers to deploy a custom backdoor named INFINITERED, enabling them to steal administrative credentials and sensitive data from medical research universities, clinical providers, and military health institutions. UNC6508 remained undetected for over two years, highlighting the sophistication and stealth of their operations. ([cyberscoop.com](https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber espionage groups targeting critical infrastructure and sensitive research sectors. The ability of such groups to operate undetected for extended periods emphasizes the need for enhanced cybersecurity measures and vigilance within organizations handling sensitive data. ([cyberscoop.com](https://cyberscoop.com/google-unc6508-china-espionage-threat/?utm_source=openai))
3 months ago
Kill Chain
Russian Hackers Exploit WinRAR Vulnerability CVE-2025-8088
In mid-2025, Russian state-sponsored threat groups, including RomCom (also known as Storm-0978), exploited a critical vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian military and government organizations. The flaw, a path traversal vulnerability, allowed attackers to execute arbitrary code by delivering specially crafted RAR archives via spear-phishing emails. These campaigns led to unauthorized access, data theft, and potential disruption of critical operations within the targeted entities. Despite the release of WinRAR version 7.13 in July 2025, which addressed this vulnerability, many systems remained unpatched due to the software's lack of an automatic update mechanism. This oversight has enabled continued exploitation by various threat actors, underscoring the importance of timely software updates and robust cybersecurity practices to mitigate such risks.
3 months ago
Kill Chain
FrostyNeighbor's 2026 Cyberattack on Ukrainian Government: A Detailed Analysis
In March 2026, the Belarus-aligned cyberespionage group FrostyNeighbor launched a sophisticated spear-phishing campaign targeting Ukrainian governmental organizations. The attackers distributed malicious PDF documents impersonating the Ukrainian telecommunications company Ukrtelecom. These PDFs contained links that, upon clicking, led to a multi-stage infection chain. If the victim's IP address was identified as Ukrainian, the server delivered a malicious RAR archive containing a JavaScript-based downloader known as PicassoLoader. This downloader collected system information and, upon validation, deployed a Cobalt Strike beacon, granting the attackers remote control over the compromised systems. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in Eastern Europe, highlighting the increasing sophistication of phishing campaigns and the use of geofencing to target specific regions. Organizations must remain vigilant against such targeted attacks, especially those employing multi-stage infection chains and advanced payloads like Cobalt Strike.
4 months ago
Kill Chain
FrostyNeighbor APT's Targeted Cyberespionage Campaign in Poland and Ukraine
In March 2026, the Belarus-aligned advanced persistent threat (APT) group known as FrostyNeighbor launched a targeted cyberespionage campaign against government organizations in Poland and Ukraine. The attackers employed spear-phishing emails containing blurred PDF attachments that impersonated legitimate entities, such as Ukrainian telecom provider Ukrtelecom. These PDFs included malicious links leading to a multi-stage infection chain, culminating in the deployment of Cobalt Strike for post-compromise operations. Notably, the group implemented server-side victim validation, delivering payloads only to users from specific geographic locations, thereby enhancing the precision and effectiveness of their attacks. This incident underscores the evolving sophistication of nation-state cyber threats, particularly in Eastern Europe. The use of geofencing and advanced spear-phishing techniques highlights the need for organizations to bolster their cybersecurity defenses, especially against highly targeted and adaptive adversaries.
4 months ago
Kill Chain
Critical cPanel Vulnerability (CVE-2026-41940) Exploited in Government and MSP Networks
In late April 2026, a critical authentication bypass vulnerability (CVE-2026-41940) was discovered in cPanel and WebHost Manager (WHM), widely used web hosting control panels. This flaw allows unauthenticated remote attackers to gain administrative access to servers, potentially compromising all hosted websites and data. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026?utm_source=openai)) By early May, threat actors exploited this vulnerability to target government and military entities in Southeast Asia, as well as managed service providers (MSPs) and hosting providers in multiple countries, including the U.S. ([thehackernews.com](https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html?utm_source=openai)) The attacks have led to server takeovers, website defacements, and data encryption using ransomware. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/?utm_source=openai)) The rapid exploitation of CVE-2026-41940 underscores the critical need for organizations to promptly apply security patches and review their systems for potential breaches. The widespread use of cPanel and WHM amplifies the risk, making it imperative for all users to ensure their installations are updated to the latest secure versions. ([techcrunch.com](https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/?utm_source=openai))
4 months ago
Kill Chain
Chinese Hackers Infiltrate Southeast Asian Militaries Using Advanced Malware
In March 2026, a China-based cyber espionage operation, identified as CL-STA-1087 by Palo Alto Networks Unit 42, targeted Southeast Asian military organizations. The attackers employed sophisticated malware tools, including AppleChris and MemFun backdoors, and a credential harvester named Getpass, to infiltrate systems and exfiltrate sensitive information related to military capabilities and collaborations with Western armed forces. The campaign demonstrated strategic patience, utilizing advanced techniques such as DLL hijacking and sandbox evasion to maintain prolonged unauthorized access. This incident underscores the persistent threat posed by state-sponsored cyber actors to national security infrastructures. The use of advanced malware and evasion tactics highlights the evolving sophistication of cyber espionage campaigns, necessitating enhanced vigilance and robust cybersecurity measures within military and governmental networks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports