Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4285 to 4296 of 5957
Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026
In early 2026, the Kimwolf botnet orchestrated one of the largest Android targeting campaigns to date, infecting over 2 million devices. Attackers exploited exposed Android Debug Bridge (ADB) interfaces and abused residential proxy networks to establish persistent control and monetize the compromised devices. Synthient researchers revealed that Kimwolf operators maintained access for lateral movement, facilitated app installations, sold network bandwidth, and weaponized infected endpoints for DDoS attacks. The attack chain emphasized exploiting weak or default security configurations on Android devices, allowing broad propagation and quick monetization at scale. The Kimwolf botnet illustrates the evolving risk landscape for mobile endpoints and the increasing use of cloud or residential proxy infrastructure by cybercriminals. Given the speed and scale of infection, this case underscores the urgent need for stronger defense-in-depth strategies and highlights regulatory scrutiny on IoT and mobile security postures.
8 months ago
Kill Chain
Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack
In early 2025, the Russia-aligned cyber-espionage group UAC-0184 undertook a targeted campaign against Ukrainian military and government organizations. Leveraging the popular Viber messaging platform, the threat actors distributed malicious ZIP archives to infiltrate sensitive networks. Security researchers from the 360 Threat Intelligence Center noted that these operations demonstrated continued intelligence-gathering efforts, employing social engineering tactics and the abuse of trusted communication channels. The attack resulted in the unauthorized access and potential exposure of confidential government and defense information, further escalating the cyber hostilities related to the conflict in Ukraine. This incident highlights a growing trend in the weaponization of encrypted messaging apps for cyber-espionage, as nation-state actors increasingly exploit trusted consumer platforms to bypass traditional enterprise security controls. The breach underscores the urgency for robust east-west traffic monitoring, zero trust segmentation, and advanced detection capabilities across critical sectors.
8 months ago
Kill Chain
RondoDox Botnet Leverages React2Shell to Breach Next.js Servers
In early 2024, the RondoDox botnet launched widespread attacks targeting exposed Next.js servers by exploiting a vulnerability known as React2Shell. The threat actors leveraged this exploit to install cryptomining malware, enroll compromised enterprise and IoT devices into their botnet, and facilitate lateral movement across affected networks. The campaign demonstrates advanced threat sophistication, including rapid deployment of botnet payloads and persistent communication over encrypted channels, resulting in operational disruption and the risk of sensitive data exposure for impacted organizations. This incident underscores an uptick in supply chain and application-layer attacks, particularly on modern frameworks like Next.js. With attackers automating exploitation of recently disclosed vulnerabilities, organizations must prioritize patch management and adopt Zero Trust controls to defend against evolving botnet campaigns.
8 months ago
Kill Chain
How Telegram Became the World's Largest Darknet Market Platform in 2026
In early 2026, major Chinese-speaking darknet markets known as Tudou Guarantee and Xinbi Guarantee emerged on the encrypted messaging platform Telegram, quickly becoming the world’s largest such entities. Following enforcement action and the banning of two prior networks, these new markets enabled an illicit ecosystem reportedly handling nearly $2 billion each month in laundering, sale of scamware, stolen data, deepfake technologies, and a disturbing array of black-market services. Their operations fuel high-volume crypto investment and romance scams, including the so-called 'pig butchering' schemes, which exploit trafficked labor and result in billions in global losses—with US victims alone losing around $10 billion a year. This incident illustrates the adaptability of cybercriminal infrastructure, highlighting Telegram’s evolving role as a trusted communications and trading platform for serious organized cyber threats. The surge in Telegram-based darknet activity coincides with increased regulatory scrutiny, growing law enforcement action, and a shift toward encrypted, resilient, and cross-border cybercrime tactics.
8 months ago
Kill Chain
Resecurity 2025: How a Cybersecurity Firm Turned an Alleged Breach Into a Threat Intelligence Win
In December 2025, threat actors identifying as the 'Scattered Lapsus$ Hunters' claimed they had breached systems belonging to cybersecurity firm Resecurity, stealing employee data, internal communications, threat intelligence reports, and client information. The attackers published screenshots to support their claims, including evidence of access to collaboration platforms. However, Resecurity quickly countered the claims, explaining that the compromised environment was actually a carefully monitored honeypot populated with synthetic datasets and fake credentials, intentionally designed to attract cybercriminals for research purposes. The company monitored and logged the attackers’ behaviors, collected valuable intelligence—including reconnaissance, OPSEC failures, and the use of residential proxy infrastructure—and shared key data with law enforcement. No real customer data or production systems were at risk during the incident, according to Resecurity. This case highlights the growing trend of cyber attackers targeting security firms as retaliation for investigations, as well as the strategic use of deceptive honeypots to gather adversary intelligence. The incident underlines the importance of controlled cyber deception, advanced detection, and proactive threat intelligence amid an escalating environment of data theft claims and public leak extortion tactics.
8 months ago
Kill Chain
RondoDox Botnet: React2Shell Flaw Drives Massive Next.js Server Breaches
In December 2025, the RondoDox botnet exploited the critical React2Shell vulnerability (CVE-2025-55182) to breach hundreds of Next.js servers worldwide. Researchers observed the botnet initiating mass scans and automated remote code execution attacks against exposed servers, deploying malware, persistent botnet loaders, and cryptominers. RondoDox leveraged the unpatched flaw in the widely used React Server Components protocol, enrolling compromised systems and IoT devices into its botnet and wiping out competing malware. The attack impacted both consumer and enterprise networks, risking data exfiltration, service outages, and broader supply chain compromise. This campaign underscores the increased urgency around patching application-layer vulnerabilities at scale, as attackers rapidly weaponize zero-day and n-day exploits across popular frameworks. The prevalence of automated exploitation and lateral expansion tactics reflects a shifting threat landscape that challenges traditional perimeter security and requires robust detection, segmentation, and rapid response capabilities.
8 months ago
Kill Chain
Crypto Phishing 2026: How Chatbots and Telegra.ph Power Modern Scams
Between October 2025 and early 2026, a persistent cryptocurrency phishing campaign leveraged fake chatbot websites and phishing emails to target users, primarily using minimalist publishing platforms such as telegra.ph and Google Forms. The attackers distributed scam emails promising recipients substantial payouts in Bitcoin, directing them to malicious pages purporting to automate cryptocurrency mining profits. Victims were eventually asked to pay a fraudulent conversion fee to claim their non-existent funds, with payments funneled into wallets controlled by the attackers. The campaign’s simplicity and abuse of free digital services allowed it to evade basic filtering and reach a wide audience repeatedly. This incident highlights an ongoing rise in abuse of cloud-based publishing and forms services for elaborate phishing scams. Attackers are increasingly automating social engineering techniques, combining chatbots and “cash out” lures that have proven cost-effective and resilient even as major platforms improve traditional anti-phishing measures.
- Banking/Mortgage
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
8 months ago
Kill Chain
GlassWorm Malware Hits macOS: Supply Chain Attack via Malicious VSCode Extensions (2026)
In late 2025 and into January 2026, a new wave of the "GlassWorm" malware campaign targeted macOS developers by infiltrating Visual Studio Code and OpenVSX extension marketplaces. Malicious extensions, embedding AES-256-CBC–encrypted JavaScript payloads, were uploaded using covert techniques. Once installed, the malware stole sensitive credentials, including GitHub, NPM, and crypto wallet data, and established persistence via AppleScript and LaunchAgents. The campaign also attempted to replace popular hardware cryptocurrency wallet apps like Ledger Live and Trezor Suite, although this payload failed due to incomplete attacker infrastructure. Over 33,000 installs were recorded, potentially impacting individual developers and organizations reliant on secure software supply chains. GlassWorm’s evolution targets not only Windows but also macOS ecosystems, signaling a rising trend in sophisticated supply chain attacks against developer tooling. This incident is a cautionary reminder for organizations and developers to tightly scrutinize third-party plugins, raising urgency to implement stronger extension vetting, threat detection, and least-privilege controls.
8 months ago
Kill Chain
AI Supply Chain: Ultralytics, Nx, and ChatGPT Breaches Expose Massive Secrets Leakage
Between late 2024 and mid-2025, a series of major AI supply chain security breaches exposed severe vulnerabilities in widely used machine learning and development platforms. In December 2024, the Ultralytics AI library was compromised and distributed malicious code that hijacked victims’ systems for illicit cryptocurrency mining. By August 2025, attackers published malicious Nx packages that leaked over 2,300 GitHub, cloud, and AI credentials, enabling unauthorized access to sensitive resources. Throughout 2024, vulnerabilities in ChatGPT enabled cross-user data extractions via memory leakage, resulting in the exposure of personal and proprietary information. In total, an alarming 23.77 million secrets were leaked through AI-centric software and supply chain vectors within this period. This string of incidents impacted a wide spectrum of organizations, undermining trust in AI-based workflows and amplifying compliance and regulatory risk. These attacks underscore the rapidly escalating risk of supply chain compromise in AI-centric infrastructure. As organizations increasingly rely on open-source ML libraries and cloud-native platforms, threats targeting code dependencies, API memory, and package repositories are proliferating, outpacing traditional security controls. The incident highlights the urgent need for AI-aware, zero-trust frameworks, advanced east-west traffic monitoring, and routine credential hygiene to prevent similar future exposures.
8 months ago
Kill Chain
27 Malicious npm Packages Turn Dev Ecosystem Into Phishing Playground in 2025
In late 2025, security researchers uncovered a sophisticated supply chain attack leveraging the npm package ecosystem to execute a targeted spear-phishing campaign. Over a five-month period, attackers published 27 malicious npm packages via six aliases, using content delivery networks to host and serve browser-based phishing lures. These lures mimicked document-sharing and Microsoft sign-in portals to trick targeted sales and commercial staff at 25 organizations across manufacturing, industrial automation, healthcare, and allied sectors in the US and Europe. The campaign incorporated advanced anti-analysis checks, obfuscated JavaScript, and honeypot detection to evade security tooling, with hardcoded targets likely sourced from trade show and open-sourced company data. This incident exemplifies the growing abuse of public developer ecosystems and infrastructure in credential theft operations, highlighting an urgent need for organizations to monitor software supply chains and enforce modern, phishing-resistant controls. Attackers' use of legitimate distribution services as resilient hosting and focus on regional, non-IT staff illustrate shifting tactics in supply chain and social engineering threats.
8 months ago
Kill Chain
Trust Wallet Breach 2023: How a Shai-Hulud NPM Supply Chain Attack Stole $8.5M
In November 2023, Trust Wallet suffered a significant security breach in which an attacker exploited a malicious NPM supply chain package—most notably associated with the "Shai-Hulud" attack campaign. By leveraging this industry-wide incident, threat actors managed to compromise the Trust Wallet web browser extension, executing a targeted attack to steal approximately $8.5 million from over 2,500 crypto wallets. The threat actors utilized sophisticated techniques to inject malicious code via the open-source software supply chain, highlighting vulnerabilities in component dependencies and the risk of lateral movement within affected environments. This incident is especially relevant as supply chain attacks using compromised open-source packages are on the rise, impacting a broad range of organizations that rely on third-party code. The Trust Wallet breach underscores the urgency for robust supply chain security strategies, better monitoring of dependencies, and solid east-west traffic controls to detect anomalous behaviors and restrict lateral movement.
- Computer Software/Engineering
- Computer/Network Security
- Investment Management/Hedge Fund/Private Equity
8 months ago
Kill Chain
Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia
In mid-2025, the Chinese cyber espionage group Mustang Panda deployed a previously undocumented, signed kernel-mode rootkit to secretly load a TONESHELL backdoor variant during targeted attacks against government organizations in Southeast and East Asia—mainly Myanmar and Thailand. Leveraging a stolen legacy digital certificate, the attackers installed a Windows minifilter driver to inject TONESHELL into system processes, evade security controls, and shield their malware and associated files from detection. The backdoor enabled ongoing remote control, data exfiltration, and further malware deployments via encrypted channels, establishing persistent clandestine access. This incident is notable for its innovative use of signed kernel drivers to enhance stealth, resilience, and anti-forensic measures. It reflects a broader trend among sophisticated threat actors who increasingly leverage advanced rootkit technology and certificate abuse to bypass endpoint protections and remain undetected for extended periods.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

