Defense & Military — Cyber Threat Activity
Defense and military is the clearest case in this dataset of a sector whose threat picture cannot be measured by incident counts. Our canonical log holds a single recorded incident, because defense compromises are classified, disclosed years late, or never disclosed at all, and the extortion crews that generate most of our volume avoid targets that invite a state response. What we can show instead is the actor graph, and it is the largest we hold for any sector: 196 groups carry a researched association with defense targeting at profile level, and 414 malware families are linked through those actors. The named set is a roll-call of state programmes rather than criminals, including Salt Typhoon, Volt Typhoon, Lazarus Group, Andariel, APT1, APT10, APT28 and RomCom. Their objectives divide cleanly. Espionage operators pursue weapons programme data, procurement schedules, personnel records and the supply chain around a prime contractor, on the reasoning that a subcontractor holds the same drawings with a fraction of the security. Pre-positioning operators pursue something different: persistent quiet access to the logistics, transport and communications infrastructure that would have to function during mobilisation, held in reserve rather than used. Documented campaigns against naval research centres, shipbuilders and defence-adjacent universities show how far outside the perimeter that targeting reaches. Read the single incident on this page as an artefact of disclosure, not as a measure of activity, and read the actor list as the honest evidence: these associations come from published vendor and government research on each group, not from attributed incidents in our own corpus.
- Recorded incidents: 10
- Incidents, trailing 180 days: 4
- Tracked threat actors: 201
- Malware families: 455
Threat actors targeting Defense & Military
- LockBit 5 incidents
- Salt Typhoon 1 incident
- BlackSuit 1 incident
- INC Ransom 1 incident
- MedusaLocker 1 incident
- RansomHouse 1 incident
- RomCom researched targeting
- Lazarus Group researched targeting
- Volt Typhoon researched targeting
- Andariel researched targeting
- APT1 researched targeting
- APT10 researched targeting
- APT28 researched targeting
- APT29 researched targeting
- APT35 researched targeting
- APT38 researched targeting
- APT40 researched targeting
- Famous Chollima researched targeting
- Gamaredon Group researched targeting
- HAFNIUM researched targeting
- Kimsuky researched targeting
- MuddyWater researched targeting
- Sandworm Team researched targeting
- Turla researched targeting
Malware used against Defense & Military
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Cobalt Strike Malware
- Impacket Tool
- Metasploit Tool
- Mimikatz Tool
- NotPetya Malware
- PlugX Malware
- PsExec Tool
- Qilin Malware
- Sliver Tool
- SUNBURST Malware
- WannaCry Malware
Where these victims are
- United States 4
- Brazil 1
- Canada 1
- Czech Republic 1
- Indonesia 1
- Italy 1
Recent incidents
- Itaguaí Construções Navais S.A. known as ICN, 2026-08-22
- pushidrosal.id 2026-08-04
- Forces 2026-07-07
- DEFCON 2026-04-29
- visionproducts.llc 2025-12-07
- visionproducts.llc 2025-04-12
- 9fsfalcons.org 2024-12-23
- VOP CZ 2024-10-28
- RhinoCorps 2024-07-24
- US Army National Guard (unnamed state) 2024-03-01
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.