Threats Tagged 'aerospace'
View all threats tagged with 'aerospace'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'aerospace'
Click on any threat for detailed analysis and mitigation recommendations
Cyber threats targeting the global aviation and aerospace sector are rapidly evolving, with ransomware, identity-based intrusions, and platform-level disruptions becoming dominant attack vectors. The interconnected nature of this ecosystem, combined with time-sensitive operations and complex third-party dependencies, makes it highly attractive to threat actors. Shared airport IT platforms represent critical single points of failure, as demonstrated by the September 2025 ransomware attack on Collins Aerospace MUSE system that disrupted major European airports including Heathrow, Brussels, Berlin, and Dublin. Major ransomware groups like LockBit and Cl0p maintain heavy focus on aviation suppliers, while advanced persistent threat groups including Refined Kitten, Wicked Panda, and Fancy Bear conduct strategic espionage targeting intellectual property, aircraft design data, and military aviation intelligence. Emerging threats include vulnerabilities in regional airports, aviation SaaS platforms, and satellite ... Join the discussion | AlienVault OTX General | 05/06/2026, 10:26:02 UTC Added: 05/07/2026, 08:36:22 UTC |
UNC1549, an Iranian-linked threat group, has been targeting aerospace, aviation, and defense industries since mid-2024. They employ sophisticated initial access techniques, including exploiting third-party relationships and targeted phishing. The group uses custom malware like TWOSTROKE, LIGHTRAIL, and DEEPROOT for persistence, and tools like DCSYNCER.SLICK and CRASHPAD for privilege escalation. UNC1549 demonstrates advanced lateral movement, reconnaissance, and defense evasion tactics. They extensively use SSH reverse tunnels and Azure infrastructure for command and control. The group's primary objective appears to be espionage, focusing on data collection and leveraging compromised organizations to target others in the same sector. Join the discussion | AlienVault OTX General | 11/18/2025, 02:11:13 UTC Added: 11/18/2025, 02:22:52 UTC |
The Lazarus Group, a DPRK-linked threat actor, has launched a targeted espionage campaign against aerospace and defense sectors using a new variant of the Comebacker backdoor. The attack employs spear phishing with highly specific lure documents to deliver macro-based malware. The infection chain is multi-staged, featuring custom decryption algorithms and encrypted command-and-control communications, indicating advanced evasion techniques. The campaign infrastructure remains active, suggesting ongoing operations. This threat poses risks to confidentiality and integrity of sensitive defense-related information. European aerospace and defense organizations should enhance phishing defenses and monitor for indicators such as specific file hashes and suspicious domains. No CVSS score is assigned, but the threat is assessed as high severity due to its targeted nature, potential impact, and sophisticated malware. Countries with significant aerospace and defense industries and geopolitical interest in DPRK activities are most at risk. Immediate mitigation includes user training, macro restrictions, network monitoring, and threat intelligence sharing. Join the discussion | AlienVault OTX General | 11/10/2025, 11:12:21 UTC Added: 11/10/2025, 11:35:31 UTC |
RedNovember, a Chinese state-sponsored threat group, has expanded its cyber-espionage activities globally. The group targets high-profile government, intergovernmental, and private sector organizations, focusing on defense, aerospace, and technology sectors. It uses the Go-based backdoor Pantegana and Cobalt Strike for intrusions, exploiting vulnerabilities in perimeter appliances. RedNovember's tactics include combining weaponized proof-of-concept exploits with open-source tools, allowing for scalable operations and attribution obfuscation. The group has shown particular interest in targets across the US, Taiwan, South Korea, and Panama, often aligning its activities with geopolitical events and Chinese strategic interests. Join the discussion | AlienVault OTX General | 09/24/2025, 17:18:47 UTC Added: 09/24/2025, 19:44:52 UTC |
UNG0901, a threat group targeting Russian aerospace and defense sectors, has been discovered conducting a spear-phishing campaign against the Voronezh Aircraft Production Association. The operation, dubbed 'CargoTalon', utilizes a custom DLL implant called EAGLET, which is disguised as a ZIP file containing transport documents. The infection chain involves a malicious LNK file that executes the EAGLET implant, which then establishes communication with a command-and-control server for remote access and data exfiltration. The campaign employs sophisticated tactics, including decoy documents related to Russian logistics operations, and shows similarities with another threat group known as Head Mare. The attackers' motivation appears to be espionage against Russian governmental and non-governmental entities. Join the discussion | AlienVault OTX General | 07/24/2025, 05:49:44 UTC Added: 07/24/2025, 09:02:48 UTC |
Showing 1 to 5 of 5 results