logo

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations

ID: a333519f-0de8-5263-aefb-5fc062391026

STIX ID: report--a333519f-0de8-5263-aefb-5fc062391026

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Google Threat Intelligence Group (GTIG) reports that numerous state-sponsored and criminal groups from China, Iran, North Korea, and Russia are actively targeting the defense industrial base (DIB). The activity spans tailored phishing and social-engineering (including recruitment-themed ‘Dream Job’ lures), exploitation of software (REDCap), abuse of messaging app features to hijack accounts, Android and Windows malware families (e.g., VERMONSTER, SPECTRUM, MESSYFORK, GALLGRAB, CraxsRAT variants), use of ORB reconnaissance infrastructure, and supply-chain and edge-device attacks — all aimed at stealing credentials, sensitive data, and achieving persistent access to defense-related systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.