✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Non-Profit/Volunteering
Breach intelligence, attack campaigns, and threat reports targeting the Non-Profit/Volunteering sector.
Explore Other Sectors
Non-Profit/Volunteering Threat Reports
Serbian Authorities' Misuse of Cellebrite Tools in 2024: A Wake-Up Call for Digital Privacy
In December 2024, Amnesty International reported that Serbian police and intelligence agencies misused Cellebrite's digital forensic tools to unlawfully extract data from mobile devices belonging to journalists and activists. The authorities employed these tools to unlock devices without consent, facilitating the installation of spyware like NoviSpy during detentions and interrogations. This surveillance campaign targeted individuals critical of government policies, leading to significant privacy violations and suppression of civil society. ([amnesty.org](https://www.amnesty.org/en/latest/news/2024/12/serbia-authorities-using-spyware-and-cellebrite-forensic-extraction-tools-to-hack-journalists-and-activists/?utm_source=openai)) The incident underscores the potential for abuse of digital forensic technologies when deployed without stringent oversight. It highlights the urgent need for robust legal frameworks and ethical guidelines to prevent the misuse of such tools against civil society and to protect fundamental human rights.
5 months ago
Kill Chain
RedKitten 2026: Iranian State-Sponsored Malware Targets Human Rights NGOs
In January 2026, a cyber espionage campaign named RedKitten targeted non-governmental organizations and individuals documenting human rights abuses in Iran. The attackers employed AI-generated malware, delivered through malicious Excel files disguised as casualty records from recent protests. Upon enabling macros, the malware, dubbed SloppyMIO, was deployed, utilizing GitHub and Google Drive for configuration and Telegram for command-and-control. This operation is attributed to Iranian state-sponsored actors aiming to infiltrate and disrupt human rights documentation efforts. ([harfanglab.io](https://harfanglab.io/insidethelab/redkitten-ai-accelerated-campaign-targeting-iranian-protests/?utm_source=openai)) This incident underscores the escalating use of artificial intelligence in cyber attacks, enabling rapid development and deployment of sophisticated malware. The targeting of human rights organizations highlights the increasing risks faced by civil society groups, emphasizing the need for enhanced cybersecurity measures and vigilance against state-sponsored cyber threats.
5 months ago
Kill Chain
Jordan Government’s Use of Cellebrite Forensics Tools Targets Activists in 2024
Between late 2023 and mid-2024, Jordanian authorities used Cellebrite’s digital forensic technology to access and extract data from the mobile phones of local activists and human rights defenders. According to an investigation by Citizen Lab and OCCRP, authorities seized activists’ devices—three iPhones and one Android—and subjected them to Cellebrite’s phone-cracking tools, often in connection with political protests. Court records and forensic analysis confirmed the use of Cellebrite products to nonconsensually access information, shaking victims’ trust and prompting self-censorship. This incident underscores the growing risks of commercial digital forensics tools being repurposed for surveillance beyond criminal cases. Amnesty International and other watchdogs report a broader trend of such technologies being leveraged against civil society, signaling a need for stronger governance, vendor accountability, and compliance oversight globally.
6 months ago
Kill Chain
Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign
Between October and December 2025, Ukraine's Defense Forces were targeted by a sophisticated malware campaign attributed to the Russian-linked threat group 'Void Blizzard' (also known as 'Laundry Bear'). Attackers leveraged instant messaging apps like Signal and WhatsApp, using compelling charity-themed lures to trick recipients into downloading a password-protected archive. Inside, the PluggyApe backdoor—bundled as disguised executables—provided remote access to compromised hosts, stealing sensitive data and awaiting additional commands. The malware's second-generation included enhanced obfuscation, anti-analysis techniques, and a novel approach to fetching command-and-control addresses from public services like Pastebin. This campaign reflects the escalating use of social engineering, mobile device targeting, and supply chain tactics by state-aligned groups in espionage operations. It highlights the urgent need for stronger endpoint protection, policy enforcement, and continuous monitoring across both traditional and mobile attack surfaces.
6 months ago
Kill Chain
FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks
In early 2024, the FBI issued an alert warning of advanced quishing (QR-code phishing) campaigns conducted by North Korean state-sponsored group Kimsuky. The group targeted US and foreign government agencies, NGOs, and academic institutions by sending emails laden with malicious QR codes, which, when scanned, redirected victims to credential-harvesting sites. The campaign relied on the growing trust in QR codes and the challenges of securing email and mobile workflows. While no major data breach was announced, the intent was information theft and espionage, representing a significant risk to critical institutions’ security and reputation. This incident highlights the evolution of phishing techniques—from simple emails to advanced, device-hopping attacks using QR codes—mirroring a wider global threat trend. Organizations are urged to update security controls and awareness programs, as quishing is now surging across industries.
6 months ago
Kill Chain
One Click IP Exposure: How Telegram Proxy Links Created a Privacy Vulnerability in 2026
In January 2026, security researchers revealed that Telegram users could have their real IP address exposed by clicking specially crafted proxy links disguised as regular usernames or harmless URLs. When users clicked these links in Telegram's Android or iOS apps, the app would automatically attempt to connect to the attacker-controlled proxy server, revealing the user's actual IP without further confirmation. This behavior, demonstrated across various public channels, posed targeted privacy risks, including location tracking and the potential for follow-on attacks. Telegram acknowledged the issue and stated they would introduce warnings to alert users about proxy links but did not commit to a timeline for deployment. This incident highlights a growing trend of information disclosure vulnerabilities related to messaging apps and link-based attacks, demonstrating the persistent risk of metadata and IP leaks in platforms used for privacy and circumvention. It brings renewed urgency to strengthen client security and increase user awareness, especially amid rising concerns over digital privacy and targeted cyber threats.
6 months ago
Kill Chain
Kimsuky Leverages QR Code Phishing to Target U.S. Strategic Organizations in 2025
In June 2025, the FBI identified a sophisticated spearphishing campaign by North Korean state-backed group Kimsuky (APT43) targeting U.S. organizations involved in North Korea-related policy, research, and strategic consultancy. Attackers used emails containing malicious QR codes—an attack known as 'quishing'—to lure victims from think tanks, government agencies, and academic institutions into scanning codes with mobile devices. Scanned QR codes redirected victims to convincing phishing pages impersonating Microsoft 365, Okta, and other login portals, harvesting credentials and cloud session tokens to circumvent multi-factor authentication measures. The attacks bypassed traditional email security by exploiting unmanaged mobile endpoints and compromised inboxes, posing significant risks to identity security and ongoing policy work. This incident highlights an escalating trend of QR code phishing, enabling attackers to sidestep conventional defenses while targeting sensitive organizations. The campaign underscores the growing threat posed by identity-driven attacks, advanced social engineering, and multi-factor authentication bypass techniques, prompting urgent calls for improved mobile device security postures and enhanced employee awareness programs.
6 months ago
Kill Chain
Voice Phishing Attack Exposes Harvard Alumni and Donor Data in 2024 Breach
In June 2024, Harvard University disclosed a significant data breach after attackers compromised its Alumni Affairs and Development systems via a sophisticated voice phishing (vishing) attack. By deceiving university staff over the phone, the threat actors gained unauthorized access to sensitive databases containing personal information of students, alumni, donors, faculty, and staff. Although there is no evidence of misuse so far, the exposed data may include contact information, date of birth, employment and education history, and donation records, potentially increasing victims’ risk of targeted phishing and fraud. The breach has raised serious concerns about the vulnerabilities introduced by social engineering and legacy authentication systems among educational institutions. This incident is particularly relevant given the surge in identity-based and social engineering attacks across higher education, where attackers exploit human trust as the weakest link. Regulatory scrutiny and the growing value of academic donor databases place further pressure on institutions to adopt modern defenses, like multi-factor authentication and advanced detection capabilities.
6 months ago
Kill Chain
Konni APT Exploits Google’s Find Hub to Launch Data-Wiping Attacks
In late 2025, the North Korea-linked threat actor known as Konni (also referred to as Earth Imp, Opal Sleet, TA406, and Vedalia) launched a sophisticated campaign targeting Android and Windows users by abusing Google’s Find Hub functionality as a remote data-wiping weapon. The attackers impersonated psychological counselors and North Korean human rights activists, distributing malware via fake stress-relief applications that enabled remote access, data theft, and destructive wipes. The operation leveraged advanced evasion tactics, encrypted traffic channels, and targeted high-value individuals, resulting in significant loss and compromise of sensitive personal and organizational information. This incident exemplifies the growing risk from state-affiliated actors using social engineering and legitimate platform abuse to bypass defenses. With threat techniques evolving, organizations must now prioritize threat hunting, advance east-west traffic visibility, and enforce robust segmentation policies to catch and contain similar attacks.
6 months ago
Kill Chain
Chinese Nation-State Hackers Breach U.S. Non-Profit Using Legacy Bugs
In early 2025, a China-linked advanced persistent threat (APT) group carried out a sophisticated cyber espionage campaign targeting a prominent U.S. non-profit focused on policy issues. Leveraging legacy vulnerabilities such as Log4j and Microsoft IIS flaws, the attackers gained initial access, established persistent footholds, and conducted covert data exfiltration operations while remaining undetected for several months. According to detailed analyses by Symantec and Carbon Black, the group focused on harvesting sensitive documents related to U.S. government policy and influencing discussions through clandestine activity within compromised systems, amplifying strategic risk to both the organization and its stakeholders. This incident exemplifies a broader trend of nation-state actors weaponizing unpatched, well-known vulnerabilities for long-term espionage. Organizations with legacy infrastructure are increasingly attractive targets, underscoring the urgent need for proactive vulnerability management, encrypted traffic controls, and robust east-west security to counter evolving, identity-driven threats.
6 months ago
Kill Chain
University of Pennsylvania Breach Exposes 1.2 Million Donor Records in 2024
In June 2024, a hacker claimed responsibility for breaching the University of Pennsylvania, exposing sensitive information on approximately 1.2 million donors as well as internal documentation. The threat actor infiltrated the university's IT environment, potentially exploiting weaknesses in data encryption and network segmentation. The attack resulted in the unauthorized access and potential leak of donor personal details, which could include names, contact information, and possibly financial data. The incident became publicly known after a 'We got hacked' email was sent from university channels, alerting stakeholders to the scale of the compromise. This incident highlights the increasing prevalence of large-scale data breaches targeting higher education and non-profit institutions. As threat actors employ more advanced techniques to exploit internal network gaps, organizations face mounting regulatory pressure to strengthen defenses and prevent sensitive data exposure.
6 months ago
Kill Chain
PhantomCaptcha Spearphishing Attack Targets Ukraine War Relief Orgs
On June 22, 2024, a coordinated spearphishing campaign dubbed 'PhantomCaptcha ClickFix' targeted Ukrainian regional government entities and major international humanitarian organizations, such as the International Committee of the Red Cross and UNICEF. The attackers used convincing phishing emails distributing malicious links intended to compromise users through browser exploits and credential harvesting, aiming to disrupt relief efforts amid ongoing conflict. Although the operation was short-lived, lasting just one day, it exposed staff to significant risk of account takeover and disruption of war relief operations. This incident spotlights the expanding use of highly targeted, short-duration spearphishing campaigns against NGOs and governmental organizations, reflecting the broader trend of cyber-enabled disruption in geopolitical conflict zones. Attacks exploiting human trust and exploiting organizational urgency are on the rise, demanding renewed vigilance.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports