Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligencecritical-infrastructure-threatinitial-access-method

Google Warns of Escalating State-Backed Cyber-Espionage Targeting Europe’s Defense Industrial Base

Updated 3mo agoFirst seen Feb 13, 20262 sources

Google’s Threat Intelligence Group reported an intensifying, state-backed cyber-espionage campaign against Western defense companies—particularly across Europe—describing a “constant, multi-vector siege” aimed at stealing sensitive R&D, disrupting production, and gaining insight into next-generation battlefield systems. The report highlights drone manufacturers and advanced weapons developers as priority targets, with Russia-linked activity emphasized in the context of the war in Ukraine and a focus on unmanned aircraft technologies and their suppliers. Google attributed one phishing campaign to UNC5976, which used malicious Remote Desktop Protocol (RDP) files and spoofed domains impersonating defense firms across multiple countries.

Google assessed that multiple state actors—Russia, Iran, China, and North Korea—are leveraging a broad set of access paths, including exploitation of hiring processes, personal accounts, and remote work environments, while smaller manufacturers and adjacent suppliers are also seeing extortion attempts, indicating widening supply-chain pressure. Separate reporting also described leaked documents indicating China has used a training platform (Expedition Cloud, developed by CyberPeace) to rehearse critical-infrastructure intrusions against neighboring countries by building network “templates” of targets and running reconnaissance-to-attack drills, underscoring the operational maturity and preparation that can translate into real-world campaigns against high-value sectors such as defense and critical infrastructure.

Share:
Google Warns of Escalating State-Backed Cyber-Espionage Targeting Europe’s Defense Industrial Base
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 12, 20264mo ago

Google attributes defense-sector phishing campaign to UNC5976

In the same reporting, Google described a phishing campaign attributed to UNC5976 that used malicious RDP files and spoofed domains impersonating defense companies across several countries. The activity was presented as part of the broader pressure on Europe’s defense industrial base.

Google warns of escalating state-backed attacks on defense companies

Google’s Threat Intelligence Group reported that Western defense firms and their employees are facing an intensifying wave of cyber-espionage and extortion activity. The report said actors linked to Russia, Iran, China, and North Korea are targeting the defense industrial base, including smaller suppliers, through multiple vectors.

Feb 10, 20264mo ago

China reportedly rehearses critical infrastructure intrusions with Expedition Cloud

Leaked technical documents indicate China conducted cyber training drills simulating intrusions into neighboring countries’ critical infrastructure using CyberPeace’s Expedition Cloud platform. The exercises reportedly split teams into reconnaissance and attack functions and logged network traffic, system activity, and operator decisions in detail.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Organizations
5 linked
Recorded FutureThe RecordSentinelOneNetAskariCyberPeace
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.