Aerospace & Aviation — Cyber Threat Activity
Aerospace and aviation holds one recorded incident in our log, which measures our collection rather than the sector's exposure: airlines, airports, manufacturers and maintenance providers rarely appear on extortion sites, and aviation security incidents are reported into regulators rather than published. The actor graph carries 34 groups associated with the sector, including APT28, APT40, APT1, Dragonfly and AeroBlade, with 149 malware families linked through those actors. Two threats sit here. The first is espionage against the manufacturing and research end, where airframe, propulsion, avionics and satellite programmes represent decades of development that a state can shortcut by stealing it, and where the supply chain of subcontractors and machine shops is far softer than the primes they serve. Iranian-linked operators have used aviation-themed job lures against aerospace and energy firms for exactly this. The second is more mundane and more persistent. Cisco Talos documented a campaign against aviation that ran for years using only off-the-shelf malware and aviation-themed lures such as flight itineraries and manufacturer documents, succeeding not through technical sophistication but through relevance to the recipient, and assessed that credentials taken by small operators of this kind are frequently sold onward to larger extortion crews. Airline operations also depend on scheduling, crew rostering, baggage and ground-handling systems where a few hours of downtime cascades across a network for days. Read the single recorded incident as a disclosure artefact, and the actor associations as published research on each group rather than measured attributions in our corpus.
- Recorded incidents: 17
- Incidents, trailing 180 days: 2
- Tracked threat actors: 41
- Malware families: 163
Threat actors targeting Aerospace & Aviation
- Qilin 2 incidents
- Akira 1 incident
- INC Ransom 1 incident
- LAPSUS$ 1 incident
- Play Ransomware 1 incident
- RansomHouse 1 incident
- Rhysida 1 incident
- SafePay 1 incident
- APT1 researched targeting
- APT28 researched targeting
- APT40 researched targeting
- Dragonfly researched targeting
- Everest researched targeting
- AeroBlade researched targeting
- Ajax Security Team researched targeting
- APT18 researched targeting
- APT20 researched targeting
- APT27 researched targeting
- APT3 researched targeting
- APT33 researched targeting
- APT5 researched targeting
- Chimera researched targeting
- Head Mare researched targeting
- HEXANE researched targeting
Malware used against Aerospace & Aviation
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- Sliver Tool
- AsyncRAT Tool
- Babuk Malware
- Backdoor.Oldrea Malware
- BloodHound Tool
- CaddyWiper Malware
Where these victims are
- United States 4
- Singapore 2
- Argentina 1
- Côte d'Ivoire 1
- France 1
- Germany 1
Recent incidents
- Manchester Airports Group 2026-08-27
- Eana 2026-07-19
- Vision Aero 2026-03-04
- OSAC Aero 2026-03-01
- Air Côte d'Ivoire 2026-02-08
- Astrofein 2025-12-01
- NC Dynamics LLC 2025-08-20
- Vietnam Airlines 2025-06-20
- Olympus Aero Group 2025-05-15
- Newton & Associates, Inc 2025-03-01
- Jet Aviation (Asia Pacific) Pte Ltd 2024-07-26
- Continental Aerospace Technologies 2024-03-09
- TAP Air Portugal 2022-08-25
- Viva Air 2022-03-14
- R.I.S.E Aerospace Pte. Ltd. 2020-08-25
- Utair 2019-03-21
- MalindoAir 2019-03-01
Coverage. 94.8% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.