Google’s Threat Intelligence Group (GTIG) reported sustained and expanding cyber operations against the defense industrial base (DIB) by state-linked and aligned actors from China, Iran, North Korea, and Russia, driven by battlefield technology demands and geopolitical conflict. Reported themes include targeting defense organizations supporting the Russia–Ukraine war, social engineering and recruitment/hiring-process abuse aimed at employees (notably attributed to North Korean and Iranian activity), increased reliance on edge devices and appliances for initial access by China-nexus groups, and heightened supply-chain exposure tied to compromises in adjacent manufacturing ecosystems.
The reporting highlights specific tactics and actor activity, including Russia-linked APT44 (Sandworm) efforts to access data from Telegram and Signal, including use of a Windows batch script (WAVESIGN) to decrypt and exfiltrate data from Signal Desktop after likely obtaining physical access to devices in Ukraine. Additional activity described includes Ukraine-focused campaigns using defense-themed lures (e.g., drones and counter-drone systems) and broader nation-state use of zero-day exploitation in edge devices to establish footholds in defense contractors’ networks, reinforcing GTIG’s assessment that “pre-positioning” and continuous access-building are now baseline expectations for DIB organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
China-nexus groups were reported phishing defense contractor personnel, probing contractor portals, exploiting edge infrastructure, and abusing REDCap to implant persistent malware. Researchers also noted use of ORB networks to hinder detection and attribution.
Iran-aligned operators were reported targeting aerospace and defense personnel in the U.S. and Middle East with resume- and personality-test-themed lures carrying custom malware. The campaigns also included tailored phishing and job-portal abuse aimed at defense workers.
Researchers reported North Korea-linked campaigns targeting defense and aerospace organizations through fraudulent recruitment, direct employee outreach, and IT worker schemes. Some activity also involved credential theft, backdooring attempts, and AI-assisted reconnaissance.
GTIG highlighted Russia-aligned activity focused on battlefield-relevant access, including attacks on Ukrainian military communications and Android devices. The operations included abuse of Signal features and Android malware disguised as Ukrainian military tools.
Researchers described a growing tactic of exploiting internet-facing edge devices such as VPN appliances and security gateways to gain initial access and maintain long-term footholds in strategically important networks. This approach emphasizes persistent pre-positioning and evasion over noisier endpoint-focused intrusion methods.
Google Threat Intelligence Group and other researchers reported sustained cyber operations against defense industrial base organizations by actors linked to China, Russia, Iran, and North Korea. The activity spans espionage, access-building, credential theft, phishing, and supply-chain targeting across multiple regions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.