The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Mining/Metals
Breach intelligence, attack campaigns, and threat reports targeting the Mining/Metals sector.
Explore Other Sectors
Mining/Metals Threat Reports
BlueMoon Exploit Kit Weaponizes Chrome and Windows Zero-Days in Multi-Group APT Campaign
Multiple Chinese cyber-espionage groups deployed the BlueMoon exploit kit in August-September 2026, chaining three zero-day vulnerabilities in Chrome and Windows to achieve remote code execution and privilege escalation. The kit exploited CVE-2026-85046 and CVE-2026-87491 in Chrome's V8 JavaScript engine for sandbox escape, combined with CVE-2026-85880 in Windows ALPC for local privilege escalation. Threat actors including JungleBamboo (APT31), UTA0560, UNK_LateNight, and UNK_DoubleCheck targeted NGOs, aerospace companies, and manufacturing firms through spearphishing campaigns that delivered various backdoors including ShadowPad and Grimwedge. This incident demonstrates the increasing sophistication of state-sponsored actors in rapidly weaponizing zero-day vulnerabilities and sharing exploit tools across multiple threat groups. The coordinated use of BlueMoon by different Chinese APT groups signals a concerning trend of exploit kit sharing and collaborative cyber operations targeting critical infrastructure and civil society organizations.
2 weeks ago
Kill Chain
Chinese APT Groups Coordinate BlueMoon Zero-Day Campaign Against U.S. Organizations
In late August 2024, at least four Chinese state-sponsored espionage groups exploited a zero-day exploit chain dubbed BlueMoon to conduct surveillance operations against U.S. organizations. The campaign, initiated by APT31 (Violet Typhoon) on August 28, leveraged three zero-day vulnerabilities in Chrome browsers and Windows to achieve remote code execution, sandbox escape, and system privilege escalation. The attackers targeted NGOs, mining companies, aerospace firms, and government organizations through phishing emails that installed malicious browser extensions disguised as Google Gemini, enabling credential theft and system surveillance. This incident highlights the accelerating timeline of zero-day exploitation as threat actors increasingly reverse-engineer public patches to weaponize vulnerabilities before widespread deployment. The coordinated use of the same exploit chain by multiple Chinese APT groups demonstrates enhanced intelligence sharing and operational coordination within China's cyber espionage apparatus, signaling a more systematic approach to targeting critical infrastructure and strategic industries.
2 weeks ago
Kill Chain
BlueMoon Exploit Kit Signals New Era of Commoditized Zero-Day Attacks
In August 2026, multiple China-aligned espionage groups rapidly adopted the BlueMoon exploit kit, which chains together three zero-day vulnerabilities in Google Chrome and Windows. The kit was first deployed by APT31 on August 28, 2026, targeting NGOs, mining companies, and commodity trading firms through spear-phishing campaigns. Within days, three additional threat clusters began using the same exploit chain, deploying various payloads including the GemStone browser backdoor, ShadowPad malware, and custom .NET assemblies for persistent access and credential theft. This incident highlights the emerging trend of AI-assisted exploit development and the rapid commoditization of previously high-value exploit chains. The simultaneous adoption by multiple threat actors suggests a new paradigm where sophisticated exploit capabilities are becoming more accessible, potentially lowering barriers to entry for state-sponsored cyber espionage operations.
2 weeks ago
Kill Chain
Phantom Deal Campaign Exploits M&A Processes in Sophisticated Enterprise Fraud
The 'Phantom Deal' campaign represents a sophisticated evolution of advance fee scams targeting large enterprises through fake merger and acquisition proposals. Threat actors conducted extensive reconnaissance on companies like Gen (Norton/Avast parent company), impersonating executives via WhatsApp and creating fraudulent documentation from legitimate firms like PwC. The attackers attempted to trick employees into authorizing substantial financial transfers, with one attempt involving €626,735.45, by leveraging detailed corporate intelligence and social engineering tactics that exploited M&A processes and confidentiality requirements. This campaign highlights the growing sophistication of business email compromise attacks as threat actors increasingly target high-value corporate transactions. With M&A activity remaining robust and remote work normalizing digital-only communications, similar social engineering campaigns pose escalating risks to enterprise financial controls and decision-making processes.
3 weeks ago
Kill Chain
State-Sponsored Cyber Attacks on AI Supply Chain in 2026
In 2026, the global race to dominate artificial intelligence (AI) has intensified, with nations vying for control over critical minerals, semiconductor production, and AI model development. This competition has led to increased state-sponsored cyber operations targeting every link in the AI supply chain, from mining companies to data centers and AI research institutions. Notably, Chinese state-sponsored hackers have been implicated in sophisticated cyber espionage campaigns aimed at extracting sensitive information and disrupting competitors' advancements in AI technologies. The urgency of securing the AI development chain has never been more critical. As AI becomes deeply integrated into various sectors, the potential for cyber threats to disrupt economies and national security has escalated. Organizations must adopt comprehensive cybersecurity strategies to protect against these evolving threats, ensuring the resilience of their AI infrastructures.
1 month ago
Kill Chain
Critical Vulnerability in Carlson VASCO-B GNSS Receiver (CVE-2026-3893)
In April 2026, a critical vulnerability (CVE-2026-3893) was identified in Carlson Software's VASCO-B GNSS Receiver versions prior to 1.4.0. This flaw, due to missing authentication mechanisms, allows remote attackers to alter system configurations and disrupt device operations without requiring credentials. The vulnerability has a CVSS score of 9.4, indicating its severity, and primarily affects the Critical Manufacturing sector globally. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai)) The incident underscores the importance of securing GNSS receivers, which are integral to infrastructure operations. Organizations are advised to update to version 1.4.0 or later, minimize network exposure of control systems, implement firewalls, and use secure remote access methods like VPNs to mitigate potential risks. ([socdefenders.ai](https://www.socdefenders.ai/item/3f9fa938-de90-494a-99b5-bc0ba05499a8?utm_source=openai))
5 months ago
Kill Chain
Northern Minerals Suffers Data Breach in 2024 BianLian Ransomware Attack
In late March 2024, Australian rare earths mining company Northern Minerals experienced a cyberattack attributed to the BianLian ransomware group. The attackers exfiltrated corporate, operational, financial, and personal data, including information on current and former employees and shareholders. The stolen data was subsequently published on the dark web. Despite the breach, Northern Minerals reported no material impact on its operations or broader systems. The company promptly engaged legal, technical, and cybersecurity specialists, notified relevant authorities, and implemented measures to strengthen its systems. This incident underscores the evolving tactics of ransomware groups like BianLian, which have shifted from encrypting systems to focusing on data theft and extortion. Organizations, especially those in critical infrastructure sectors, must remain vigilant and enhance their cybersecurity defenses to mitigate such threats.
5 months ago
Kill Chain
Critical Vulnerability in RISS SRL MOMA Seismic Station Firmware (CVE-2026-1632)
In February 2026, a critical vulnerability (CVE-2026-1632) was identified in RISS SRL's MOMA Seismic Station firmware versions up to and including v2.4.2520. The flaw exposes the device's web management interface without requiring authentication, allowing unauthenticated attackers to modify configuration settings, access sensitive data, or remotely reset the device. This vulnerability poses significant risks to seismic monitoring operations, potentially leading to data manipulation, unauthorized data access, and operational disruptions. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1632?utm_source=openai)) The absence of authentication mechanisms in critical infrastructure devices underscores the urgent need for robust security measures in industrial control systems. As cyber threats targeting operational technology (OT) environments increase, organizations must prioritize securing their OT assets to prevent potential exploitation and ensure the integrity of essential services.
7 months ago
Kill Chain
Güralp Systems 2025: Unauthenticated DoS Threat Hits Critical OT Devices
In December 2025, Güralp Systems disclosed a vulnerability affecting its Fortimus, Minimus, and Certimus Series devices, widely deployed in critical manufacturing and infrastructure sectors globally. The flaw (CVE-2025-14466) in the devices' web interface allows unauthenticated attackers on the network to send specially crafted HTTP requests, forcing the web service to restart and causing a temporary denial-of-service (DoS) condition. While the process automatically recovers, repeated exploitation could severely impact system availability for organizations relying on these seismic monitoring instruments. This type of DoS vulnerability is increasingly significant as threat actors increasingly target industrial control devices and operational technology (OT) with low-complexity attacks from unauthenticated vectors. Regulatory scrutiny of ICS network hygiene and cross-industry best practices is intensifying, pushing organizations to proactively address resource allocation and network exposure.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports