The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Non-Profit/Volunteering

Breach intelligence, attack campaigns, and threat reports targeting the Non-Profit/Volunteering sector.

33 threat reports
Page 2 of 3

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Non-Profit/Volunteering Threat Reports

Showing 13–24 / 33 reports
LucidRook Malware Targets Taiwanese NGOs and Universities in 2025
Impact· HIGH

LucidRook Malware Targets Taiwanese NGOs and Universities in 2025

In October 2025, the threat actor group UAT-10362 launched spear-phishing campaigns targeting non-governmental organizations (NGOs) and universities in Taiwan. These attacks utilized a newly identified Lua-based malware named 'LucidRook,' which was delivered through malicious LNK and EXE files disguised as legitimate software. Once executed, LucidRook embedded a Lua interpreter within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads, enabling the attackers to update functionality without modifying the core malware. The malware performed system reconnaissance, collecting information such as user and computer names, installed applications, and running processes, which was then encrypted and exfiltrated via FTP to attacker-controlled infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats, particularly those targeting educational and non-governmental sectors. The use of modular malware like LucidRook, capable of dynamic updates and extensive obfuscation, highlights the need for organizations to enhance their cybersecurity measures, including employee training on phishing tactics and the implementation of advanced threat detection systems.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
UAT-10362's LucidRook Malware Targets Taiwanese NGOs in Spear-Phishing Attacks
Impact· HIGH

UAT-10362's LucidRook Malware Targets Taiwanese NGOs in Spear-Phishing Attacks

In October 2025, a previously undocumented threat actor, UAT-10362, launched spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and universities. The attackers distributed a new Lua-based malware named LucidRook, which embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads. The malware exhibits region-specific anti-analysis checks, activating only in Traditional Chinese language environments associated with Taiwan. The campaigns utilized malicious LNK and EXE files disguised as antivirus software, leveraging compromised FTP servers and out-of-band application security testing (OAST) services for command-and-control infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats targeting specific regions and sectors. The use of multi-language modular design, layered anti-analysis features, and reliance on compromised or public infrastructure indicates a high level of operational maturity by UAT-10362. Organizations, especially those in Taiwan, should enhance their cybersecurity measures to detect and mitigate such advanced persistent threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
DigitalMint Insider Ransomware Scheme Unveiled
Impact· HIGH

DigitalMint Insider Ransomware Scheme Unveiled

In 2023, Angelo John Martino III, a ransomware negotiator at DigitalMint, exploited his position to orchestrate at least 10 ransomware attacks, extorting over $75 million. Martino, along with co-conspirators, infiltrated networks, encrypted data, and demanded ransoms, even negotiating with victims he had attacked. This breach highlights the severe risks posed by insider threats in cybersecurity firms. The incident underscores the critical need for robust internal controls and vigilant monitoring to prevent such breaches, especially as ransomware tactics evolve and insider threats become more sophisticated.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion
Impact· HIGH

Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion

Between February 3 and 16, 2026, the threat group Velvet Tempest (also known as DEV-0504) conducted a sophisticated cyber intrusion targeting a U.S. non-profit organization with over 3,000 endpoints and 2,500 users. Utilizing a malvertising campaign, they employed the 'ClickFix' technique, deceiving victims into executing obfuscated commands via the Windows Run dialog. This led to the deployment of DonutLoader and the CastleRAT backdoor, facilitating credential harvesting and extensive reconnaissance. Notably, while Velvet Tempest is known for deploying various ransomware strains, including Ryuk, REvil, and Conti, the Termite ransomware was not executed in this particular incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/termite-ransomware-breaches-linked-to-clickfix-castlerat-attacks/?utm_source=openai)) This incident underscores the evolving tactics of ransomware affiliates, highlighting the use of social engineering techniques like 'ClickFix' to gain initial access. The absence of immediate ransomware deployment suggests a strategic shift towards prolonged network infiltration and data exfiltration, posing significant challenges for detection and mitigation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Lazarus Group's Medusa Ransomware Attacks on Healthcare in 2026
Impact· CRITICAL

Lazarus Group's Medusa Ransomware Attacks on Healthcare in 2026

In early 2026, the North Korean state-sponsored Lazarus Group initiated ransomware attacks using the Medusa ransomware variant, targeting healthcare organizations in the Middle East and the United States. These attacks involved data encryption and exfiltration, with ransom demands averaging $260,000. The group employed tools such as RP_Proxy, Mimikatz, and BLINDINGCAN to facilitate their operations. The healthcare sector's critical role and sensitive data made it a prime target, leading to significant operational disruptions and potential patient data breaches. This incident underscores a concerning trend of state-sponsored actors leveraging ransomware-as-a-service platforms to conduct financially motivated attacks. The collaboration between nation-state groups and established cybercriminal infrastructures highlights the evolving threat landscape, necessitating enhanced cybersecurity measures and international cooperation to mitigate such risks.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CRESCENTHARVEST Malware Campaign Exploits Iran Protests to Target Supporters
Impact· MEDIUM

CRESCENTHARVEST Malware Campaign Exploits Iran Protests to Target Supporters

In early January 2026, a cyberespionage campaign named CRESCENTHARVEST emerged, targeting individuals supporting Iran's anti-government protests. Attackers distributed malicious archive files containing authentic protest media and Farsi-language reports, alongside disguised Windows shortcut (.LNK) files. When executed, these shortcuts deployed a remote access trojan (RAT) capable of executing commands, logging keystrokes, and exfiltrating sensitive data. The campaign's sophistication suggests alignment with Iranian state interests, aiming for long-term surveillance and information theft. This incident underscores the increasing use of geopolitical events as lures in cyberattacks, highlighting the need for heightened vigilance among activists, journalists, and dissidents. The campaign's reliance on social engineering and legitimate-looking media emphasizes the importance of verifying the authenticity of received files, especially those related to sensitive political contexts.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Polish Authorities Arrest Phobos Ransomware Affiliate in 2026
Impact· HIGH

Polish Authorities Arrest Phobos Ransomware Affiliate in 2026

In February 2026, Polish authorities arrested a 47-year-old man in the Małopolska region, suspected of affiliating with the Phobos ransomware group. The arrest was part of Operation Aether, a Europol-coordinated effort targeting Phobos affiliates. During the raid, officials seized computers and mobile phones containing stolen credentials, credit card numbers, and server IP addresses. The suspect allegedly used encrypted messaging to communicate with Phobos members and faces charges under Poland's Criminal Code for creating and distributing software designed to illegally access computer systems. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/17/phobos-ransomware-affiliate-arrested-in-poland/?utm_source=openai)) This arrest underscores the persistent threat posed by ransomware groups like Phobos, which have targeted over 1,000 victims globally, including critical infrastructure sectors such as healthcare and education. The incident highlights the importance of international collaboration in combating cybercrime and the need for organizations to bolster their cybersecurity defenses against evolving ransomware tactics. ([justice.gov](https://www.justice.gov/opa/pr/phobos-ransomware-affiliates-arrested-coordinated-international-disruption?utm_source=openai))

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Serbian Authorities' Misuse of Cellebrite Tools in 2024: A Wake-Up Call for Digital Privacy
Impact· HIGH

Serbian Authorities' Misuse of Cellebrite Tools in 2024: A Wake-Up Call for Digital Privacy

In December 2024, Amnesty International reported that Serbian police and intelligence agencies misused Cellebrite's digital forensic tools to unlawfully extract data from mobile devices belonging to journalists and activists. The authorities employed these tools to unlock devices without consent, facilitating the installation of spyware like NoviSpy during detentions and interrogations. This surveillance campaign targeted individuals critical of government policies, leading to significant privacy violations and suppression of civil society. ([amnesty.org](https://www.amnesty.org/en/latest/news/2024/12/serbia-authorities-using-spyware-and-cellebrite-forensic-extraction-tools-to-hack-journalists-and-activists/?utm_source=openai)) The incident underscores the potential for abuse of digital forensic technologies when deployed without stringent oversight. It highlights the urgent need for robust legal frameworks and ethical guidelines to prevent the misuse of such tools against civil society and to protect fundamental human rights.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
RedKitten 2026: Iranian State-Sponsored Malware Targets Human Rights NGOs
Impact· HIGH

RedKitten 2026: Iranian State-Sponsored Malware Targets Human Rights NGOs

In January 2026, a cyber espionage campaign named RedKitten targeted non-governmental organizations and individuals documenting human rights abuses in Iran. The attackers employed AI-generated malware, delivered through malicious Excel files disguised as casualty records from recent protests. Upon enabling macros, the malware, dubbed SloppyMIO, was deployed, utilizing GitHub and Google Drive for configuration and Telegram for command-and-control. This operation is attributed to Iranian state-sponsored actors aiming to infiltrate and disrupt human rights documentation efforts. ([harfanglab.io](https://harfanglab.io/insidethelab/redkitten-ai-accelerated-campaign-targeting-iranian-protests/?utm_source=openai)) This incident underscores the escalating use of artificial intelligence in cyber attacks, enabling rapid development and deployment of sophisticated malware. The targeting of human rights organizations highlights the increasing risks faced by civil society groups, emphasizing the need for enhanced cybersecurity measures and vigilance against state-sponsored cyber threats.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Jordan Government’s Use of Cellebrite Forensics Tools Targets Activists in 2024
Impact· high

Jordan Government’s Use of Cellebrite Forensics Tools Targets Activists in 2024

Between late 2023 and mid-2024, Jordanian authorities used Cellebrite’s digital forensic technology to access and extract data from the mobile phones of local activists and human rights defenders. According to an investigation by Citizen Lab and OCCRP, authorities seized activists’ devices—three iPhones and one Android—and subjected them to Cellebrite’s phone-cracking tools, often in connection with political protests. Court records and forensic analysis confirmed the use of Cellebrite products to nonconsensually access information, shaking victims’ trust and prompting self-censorship. This incident underscores the growing risks of commercial digital forensics tools being repurposed for surveillance beyond criminal cases. Amnesty International and other watchdogs report a broader trend of such technologies being leveraged against civil society, signaling a need for stronger governance, vendor accountability, and compliance oversight globally.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign
Impact· medium

Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign

Between October and December 2025, Ukraine's Defense Forces were targeted by a sophisticated malware campaign attributed to the Russian-linked threat group 'Void Blizzard' (also known as 'Laundry Bear'). Attackers leveraged instant messaging apps like Signal and WhatsApp, using compelling charity-themed lures to trick recipients into downloading a password-protected archive. Inside, the PluggyApe backdoor—bundled as disguised executables—provided remote access to compromised hosts, stealing sensitive data and awaiting additional commands. The malware's second-generation included enhanced obfuscation, anti-analysis techniques, and a novel approach to fetching command-and-control addresses from public services like Pastebin. This campaign reflects the escalating use of social engineering, mobile device targeting, and supply chain tactics by state-aligned groups in espionage operations. It highlights the urgent need for stronger endpoint protection, policy enforcement, and continuous monitoring across both traditional and mobile attack surfaces.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks
Impact· low

FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks

In early 2024, the FBI issued an alert warning of advanced quishing (QR-code phishing) campaigns conducted by North Korean state-sponsored group Kimsuky. The group targeted US and foreign government agencies, NGOs, and academic institutions by sending emails laden with malicious QR codes, which, when scanned, redirected victims to credential-harvesting sites. The campaign relied on the growing trust in QR codes and the challenges of securing email and mobile workflows. While no major data breach was announced, the intent was information theft and espionage, representing a significant risk to critical institutions’ security and reputation. This incident highlights the evolution of phishing techniques—from simple emails to advanced, device-hopping attacks using QR codes—mirroring a wider global threat trend. Organizations are urged to update security controls and awareness programs, as quishing is now surging across industries.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports