Google Threat Intelligence Group (GTIG) data finds state-sponsored groups are bypassing perimeter security by targeting recruitment and unmanaged devices.
For CIOs, this changes the risk calculation: the threat is not just network intrusion, but the corruption of business processes.
Recruitment fraud at industrial scale
Adversaries now view the hiring process as a high-efficacy entry point for espionage and revenue generation. This trend affects organisations well beyond the immediate defence sector, as these tactics exploit the trust inherent in remote work and online recruitment.
North Korean threat actors have moved to internal infiltration via “IT workers”. These individuals, often supported by identity facilitators, secure remote employment at Western companies to generate revenue for the regime and access sensitive data.
In one instance, IT workers reportedly stole data from a California-based contractor developing AI technology. The operation is extensive; a recent US disruption operation identified laptop farms across 29 locations that facilitated these actors.
The threat includes rogue employees and external actors mimicking them. Iranian state-sponsored actors, such as UNC1549, utilise fake recruitment portals and job offers to distribute malware.
Attackers have even created infrastructure that masquerades as legitimate drone manufacturing entities and thermal imaging companies. These campaigns target personnel by spoofing job descriptions for roles at major aerospace and defence firms.
By engaging targets through professional networking platforms, these actors bypass traditional email filters and deliver malicious payloads disguised as résumé builders or interview requirements.
Blind spots at the network edge
While human-focused attacks exploit trust, technical espionage campaigns target infrastructure that security teams often cannot monitor. China-nexus groups represent the most active threat to the defence industrial base by volume.
A distinct tactical shift involves the targeting of edge devices (such as VPN appliances, routers, and firewalls) to gain initial access. These devices sit at the perimeter of the network and frequently do not support Endpoint Detection and Response (EDR) agents, leaving them invisible to standard monitoring tools.
GTIG assesses with high confidence that since 2020, Chinese groups have exploited over two dozen zero-day vulnerabilities in edge devices across ten different vendors.
Actors such as UNC5221, which targets strategic entities including managed service providers, maintain long-term access. In the BRICKSTORM malware campaign, the average dwell time (the duration an intruder remains undetected) was 393 days. This persistence allows adversaries to conduct extended intelligence collection without triggering the alarms associated with lateral movement on Windows endpoints.
Supply chain disruption and ransomware
The security of the defence sector relies on a complex manufacturing supply chain. While dedicated defence firms represent a small fraction of victims on data leak sites, the broader manufacturing sector is consistently the most represented industry in ransomware and extortion data. This sector includes numerous companies that produce dual-use components essential for defence applications.
Disruptions here have cascading effects. A ransomware incident at a UK automotive manufacturer, which also produces military vehicles, halted production for weeks and impacted over 5,000 related organisations. This vulnerability shows how the ability to surge production in a wartime environment can be compromised even if the primary defence contractors remain secure.
Financially-motivated criminals are not the only actors leveraging these weaknesses. Hacktivist groups, particularly those aligned with Russian interests, have claimed distributed denial-of-service (DDoS) attacks against manufacturers of military equipment.Â
Groups like NoName057(16) and Cyber Toufan engage in “hack-and-leak” operations intended to expose schematics, personnel data, and supply chain relationships. These operations aim to erode public trust and intimidate employees through “doxxing,” or the public release of personal information.
Battlefield technology as a primary target
The war in Ukraine demonstrates that software is a military asset. Russian espionage actors have dedicated consistent effort to targeting the technologies fielded on the front lines, particularly unmanned aircraft systems (UAS) and battlefield management software.
Threat actors such as APT44 (Sandworm) have targeted the Android devices of military personnel to extract data from tactical applications like Kropyva and Delta. These systems provide situational awareness and artillery guidance, making them high-value targets for disruption and intelligence gathering. The compromise of these devices often occurs outside traditional enterprise monitoring, as soldiers rely on commercial off-the-shelf technology and encrypted messaging apps like Signal for communication.
Russian groups have also utilised phishing campaigns that mimic drone training academies to harvest credentials from operators. In one instance, a group tracked as UNC5125 used a Google Form purporting to be from a training centre to collect military unit numbers and contact details. This data facilitates further targeted attacks and physical tracking of units.
Securing the enterprise against hybrid threats
The convergence of these threats requires a defensive strategy that encompasses personnel, supply chains, and unmanaged infrastructure. The traditional focus on securing corporate workstations and servers is insufficient when adversaries exploit third-party manufacturers, recruitment platforms, and edge appliances.
Organisations must strengthen identity verification processes for remote hires to detect fraudulent IT workers. Security teams should also prioritise the auditing and patching of edge devices, treating them as critical entry points rather than trusted appliances. Furthermore, visibility into the manufacturing supply chain is essential to understand where disruptions might impact critical deliverables.
The defence industrial base faces a state of constant, multi-vector siege. For enterprise leaders, the data indicates that security is no longer just about protecting data; it is about ensuring the resilience of the people and processes that drive the business.
See also: Specops Software and device trust at the Cyber Security & Cloud Expo Global
Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.
TechHQ is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Author
- View all posts
Ryan Daws is a senior editor at TechForge Media with over a decade of experience in weaving narratives and dissecting complex topics. His articles and interviews with industry leaders have earned him recognition as a key tech influencer from numerous organisations. Under his leadership, publications have been praised by analyst firms for their excellence and performance. Connect with him on X, Mastodon, Bluesky, Threads, and/or LinkedIn.
