The images in this article were generated with artificial intelligence. How we publish
The companies and contractors involved in the defence industry are receiving increasing attention from state actors, hackers and criminal gangs, and this is not an isolated phenomenon: this is documented by the Google threat intelligence team in a recent report. The pressure is simultaneous from several fronts, with objectives ranging from technologies deployed on the battlefield to industrial supply chains apparently non-conflict.
One of the most concerned lines of attack is the targeting of autonomous platforms and unmanned aircraft. As drones and self-employed vehicles become essential in modern conflicts, they become valuable targets for espionage and sabotage. Google GTIG notes that several groups have focused their curiosity on these systems, seeking information on design, control and deployment, and sometimes trying to appropriate the credentials and operational data used by their operators. You can read the full Google analysis on your threat blog: Threats to the defense industrial base.

In addition to the obsession with combat technology, there is another recurring strategy: attacking people who build, maintain or operate these systems. Different groups have exploited false recruitment processes and job offers to gain the confidence of technicians and specialists, send them malicious software or get access to their personal devices. These "dream employment" or malicious recruitment campaigns not only seek credentials but also resort to highly tuned social engineering, with documents and portals that imitate real companies.
The entry paths chosen by the attackers are varied and in many cases creative. Groups linked to China have shown a preference to take advantage of edge devices - such as connecting doors, applications and industrial IoT equipment - to open a first gap without directly touching corporate servers. The use of operational relay networks (ORB) to mask the source of traffic and complicate detection is an example of how these tactics make attribution difficult: a technical analysis of the use of ORB in telecommunications networks explores this pattern and its implications, and is available in the blog of Team Cymru.
The exposure of the manufacturing supply chain is another major concern. When a provider of parts, software or services is compromised, the extent of the damage can be multiplied: infected components, manipulated updates or persistent access inserted into production processes. Google and other observers have documented incidents in which the alteration of updating processes or holdings on research management platforms have served to deploy backdoors capable of stealing credentials and maintaining long-term access.
The catalogue of actors and tools involved is extensive and shows different tactics according to origin and objectives. Some groups have sought to extract data from secure messaging applications after obtaining physical access to devices in combat areas; others have used online forms like decoys to recognize targets and distribute malware designed for UAV control stations. There are campaigns that have abused legitimate features of secure applications to kidnap accounts, or that have replaced control software updates with malicious installers. On another front, actors who use mobile malware families to collect files, contacts and data from field-specific apps have been observed.
In certain cases, malware and very specific techniques have been identified: from binaries that exfilter data from encrypted messaging desktop versions to Android Trojan camouflaged as combat control tools. The use of legitimate remote managers, deployed through discards, has also been identified to facilitate the covert management of compromised environments. For those following threats like these, there are published reports and technical analyses that help identify patterns and signs of commitment: for example, research into campaigns that affected aerospace and defence sectors can be compared with reports of security firms and specialized media.
This threat map is not static: groups evolve to draw defenses. A common feature is the deliberate search to avoid endpoints protection solutions, using intrusions directed towards specific devices or vectors that are not covered by the usual detection. That forces you to think security beyond the classic perimeter. and to look at controls at the less valued points, from field employee laptops to firmware updates from external suppliers.

For sector organizations, the response is to combine technical measures with changes in processes and culture. To review and strengthen the recruitment and validation protocols of personnel, to rigorously segment industrial networks, to monitor the integrity of software supply and update routes, and to deploy detection capabilities including network telemetry and behaviour analysis are necessary actions. In addition, sharing threat intelligence with agencies and peers facilitates an early and coordinated response to targeted campaigns. In the public sphere, resources and guides on security in the supply chain are available on the website of the CISA.
If there is a clear lesson, it is that the defence industry cannot afford complacency: the combination of state motivation, sophisticated technical capabilities and high-value objectives makes this sector a priority and resilient objective. Effective protection requires visibility, cooperation and continuous adaptation and both private organizations and government agencies must keep the guard high to anticipate and mitigate threats that can affect from first-line systems to components that are apparently only part of the industrial periphery.
To deepen the specific findings and technical examples to which this picture refers, Google's GTIG analysis offers a detailed and accessible starting point: Threats to the defense industrial base (Google GTIG). Other specialized analyses, such as the technical links mentioned in the text, make it possible to contrast tactics and procedures and serve as a reference for technicians and security officials who should prioritize mitigation in their organizations.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...