Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatinitial-access-methodperimeter-device-exposure

Google GTIG Warns of Intensifying Nation-State Targeting of the Defense Industrial Base

Updated 3mo agoFirst seen Feb 13, 20262 sources

Google’s Threat Intelligence Group (GTIG) reported sustained and expanding cyber operations against the defense industrial base (DIB) by state-linked and aligned actors from China, Iran, North Korea, and Russia, driven by battlefield technology demands and geopolitical conflict. Reported themes include targeting defense organizations supporting the Russia–Ukraine war, social engineering and recruitment/hiring-process abuse aimed at employees (notably attributed to North Korean and Iranian activity), increased reliance on edge devices and appliances for initial access by China-nexus groups, and heightened supply-chain exposure tied to compromises in adjacent manufacturing ecosystems.

The reporting highlights specific tactics and actor activity, including Russia-linked APT44 (Sandworm) efforts to access data from Telegram and Signal, including use of a Windows batch script (WAVESIGN) to decrypt and exfiltrate data from Signal Desktop after likely obtaining physical access to devices in Ukraine. Additional activity described includes Ukraine-focused campaigns using defense-themed lures (e.g., drones and counter-drone systems) and broader nation-state use of zero-day exploitation in edge devices to establish footholds in defense contractors’ networks, reinforcing GTIG’s assessment that “pre-positioning” and continuous access-building are now baseline expectations for DIB organizations.

Share:
Google GTIG Warns of Intensifying Nation-State Targeting of the Defense Industrial Base
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 13, 20264mo ago

China-linked actors target contractors via phishing, portals, and edge exploits

China-nexus groups were reported phishing defense contractor personnel, probing contractor portals, exploiting edge infrastructure, and abusing REDCap to implant persistent malware. Researchers also noted use of ORB networks to hinder detection and attribution.

Iran-linked campaigns use fake job materials to deliver malware

Iran-aligned operators were reported targeting aerospace and defense personnel in the U.S. and Middle East with resume- and personality-test-themed lures carrying custom malware. The campaigns also included tailored phishing and job-portal abuse aimed at defense workers.

North Korean actors abuse defense hiring and IT worker channels

Researchers reported North Korea-linked campaigns targeting defense and aerospace organizations through fraudulent recruitment, direct employee outreach, and IT worker schemes. Some activity also involved credential theft, backdooring attempts, and AI-assisted reconnaissance.

Russia-linked clusters target Ukrainian military communications and Android users

GTIG highlighted Russia-aligned activity focused on battlefield-relevant access, including attacks on Ukrainian military communications and Android devices. The operations included abuse of Signal features and Android malware disguised as Ukrainian military tools.

Attackers shift to edge-device exploitation for covert pre-positioning

Researchers described a growing tactic of exploiting internet-facing edge devices such as VPN appliances and security gateways to gain initial access and maintain long-term footholds in strategically important networks. This approach emphasizes persistent pre-positioning and evasion over noisier endpoint-focused intrusion methods.

State-backed groups intensify targeting of the defense industrial base

Google Threat Intelligence Group and other researchers reported sustained cyber operations against defense industrial base organizations by actors linked to China, Russia, Iran, and North Korea. The activity spans espionage, access-building, credential theft, phishing, and supply-chain targeting across multiple regions.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

57 LINKEDOpen in app
Affected products
5 linked
TelegramWindowsWhatsappSignalEncase
Organizations
14 linked
GoogleMeta PlatformsTelegramSignal MessengerGoogle FormsJuniper NetworksCisco SystemsPalo Alto NetworksEsetRecorded FutureFortinetIvantiCitrix SystemsSonicwall
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.