Skip to main content

Threats Tagged 'uav'

View all threats tagged with 'uav'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: uav

Threats Tagged 'uav'

Click on any threat for detailed analysis and mitigation recommendations

A newly identified threat group, designated as GhostShell, has been conducting cyber operations against Ukraine's unmanned aerial vehicle supply chain since February 2026. The attackers employ malicious archives containing decoy documents that impersonate Besomar, a Ukrainian manufacturer of high-precision interceptor drones, to compromise defense and procurement networks. The attack chain deploys three distinct payloads: a custom backdoor (122.exe) utilizing mTLS client certificates for screen capture and command execution, an in-memory stager (update.exe) disguised as a Windows Health Service that fetches next-stage payloads via Telegram, and a proxy launcher (22.exe) that tunnels traffic through Xray Core to deploy the Vidar v2 information stealer. The targeting strongly suggests a Russian cyber operation, though analysts employ the SOLBIT framework to avoid attribution based on easily forgeable indicators.

Join the discussion

Operation DreamJob is a cyberespionage campaign by the North Korea-aligned Lazarus group targeting European defense companies specializing in UAV technology. The attackers use social engineering and trojanized open-source software to deliver a sophisticated malware toolset including ScoringMathTea RAT and BinMergeLoader. The campaign aims to steal intellectual property and manufacturing knowledge to support North Korea's drone program. Attack techniques involve multiple stages with droppers, loaders, and downloaders, exploiting user interaction and system reconnaissance. The threat poses a medium severity risk due to targeted espionage with potential long-term strategic impact on defense capabilities. European UAV manufacturers and defense contractors are primary targets, especially in countries with significant aerospace industries. Mitigation requires enhanced supply chain security, strict validation of open-source software, user training against social engineering, and robust endpoint detection. Countries like Germany, France, Italy, and the UK are most likely affected given their UAV sector prominence and defense industry size. The campaign does not require zero-day exploits but leverages social engineering and trojanized software, increasing the risk of successful infiltration. Defenders should prioritize monitoring for known malware components and suspicious network activity related to this campaign.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: uav
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses