Google Warns of Escalating State-Backed Cyber-Espionage Targeting Europe’s Defense Industrial Base
Google’s Threat Intelligence Group reported an intensifying, state-backed cyber-espionage campaign against Western defense companies—particularly across Europe—describing a “constant, multi-vector siege” aimed at stealing sensitive R&D, disrupting production, and gaining insight into next-generation battlefield systems. The report highlights drone manufacturers and advanced weapons developers as priority targets, with Russia-linked activity emphasized in the context of the war in Ukraine and a focus on unmanned aircraft technologies and their suppliers. Google attributed one phishing campaign to UNC5976, which used malicious Remote Desktop Protocol (RDP) files and spoofed domains impersonating defense firms across multiple countries.
Google assessed that multiple state actors—Russia, Iran, China, and North Korea—are leveraging a broad set of access paths, including exploitation of hiring processes, personal accounts, and remote work environments, while smaller manufacturers and adjacent suppliers are also seeing extortion attempts, indicating widening supply-chain pressure. Separate reporting also described leaked documents indicating China has used a training platform (Expedition Cloud, developed by CyberPeace) to rehearse critical-infrastructure intrusions against neighboring countries by building network “templates” of targets and running reconnaissance-to-attack drills, underscoring the operational maturity and preparation that can translate into real-world campaigns against high-value sectors such as defense and critical infrastructure.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
Google attributes defense-sector phishing campaign to UNC5976
In the same reporting, Google described a phishing campaign attributed to UNC5976 that used malicious RDP files and spoofed domains impersonating defense companies across several countries. The activity was presented as part of the broader pressure on Europe’s defense industrial base.
Google warns of escalating state-backed attacks on defense companies
Google’s Threat Intelligence Group reported that Western defense firms and their employees are facing an intensifying wave of cyber-espionage and extortion activity. The report said actors linked to Russia, Iran, China, and North Korea are targeting the defense industrial base, including smaller suppliers, through multiple vectors.
China reportedly rehearses critical infrastructure intrusions with Expedition Cloud
Leaked technical documents indicate China conducted cyber training drills simulating intrusions into neighboring countries’ critical infrastructure using CyberPeace’s Expedition Cloud platform. The exercises reportedly split teams into reconnaissance and attack functions and logged network traffic, system activity, and operator decisions in detail.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


