Maritime — Cyber Threat Activity
Maritime holds no recorded incidents in our log and an actor graph of 5 groups, including APT40, Cotton Sandstorm, Sidewinder, UNC3890 and Worok, with 18 malware families linked through those actors. The sparseness is a collection limit rather than a measure of risk, since shipping lines, ports and terminal operators are frequently classified under transportation and logistics in our corpus and maritime incidents are reported into flag states and port authorities rather than published. The documented targeting is specific and strategic. Proofpoint's analysis of a Chinese-linked operator found sustained spearphishing against naval research centres, US shipbuilding companies, defence contractors and international law firms working on South China Sea disputes, using resume and research-themed lures and lookalike domains, with the selection tracking maritime geopolitics rather than commercial value. Iranian-linked operators have pursued shipping companies in the same region-driven way. The operational technology exposure is separate and serious: vessels run navigation, cargo management and engine systems that were designed for isolation and now hold satellite connectivity, while ports depend on terminal operating systems where a few hours of disruption backs up berths and landside haulage for days. Container shipping has already demonstrated that a single malware incident at one carrier can idle terminals worldwide. Read the empty count as an artefact of how maritime incidents are classified and disclosed, and the actor associations as published vendor research rather than attributions measured in our own corpus.
- Recorded incidents: 12
- Incidents, trailing 180 days: 4
- Tracked threat actors: 14
- Malware families: 25
Threat actors targeting Maritime
- DragonForce 2 incidents
- Akira 1 incident
- Cl0p 1 incident
- Eclipse 1 incident
- Krybit 1 incident
- MS13089 1 incident
- NightSpire 1 incident
- SafePay 1 incident
- Snatch 1 incident
- APT40 researched targeting
- Cotton Sandstorm researched targeting
- Sidewinder researched targeting
- UNC3890 researched targeting
- Worok researched targeting
Malware used against Maritime
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Mimikatz Tool
- PlugX Malware
- China Chopper Malware
- Empire Tool
- gh0st RAT Malware
- PowerSploit Tool
- sqlmap Tool
- at Tool
- BADFLICK Malware
- BITSAdmin Tool
- BLACKCOFFEE Malware
Where these victims are
- Singapore 4
- Italy 2
- Chile 1
- Germany 1
- Thailand 1
- United Arab Emirates 1
- United Kingdom 1
- United States 1
Recent incidents
- Moscord 2026-08-16
- servmarmg.cl 2026-08-15
- LHYK Marine Pte Ltd (Lee Huat Yap Kee) 2026-08-12
- asimar.com 2026-07-14
- Giaroli S.A.S 2026-03-12
- Augustea 2026-02-07
- Karl Geuther 2026-02-04
- Bannenberg & Rowell 2025-10-24
- Marine Floats 2024-12-17
- Seven Seas Group 2024-03-05
- "K" Line Pte Ltd 2021-04-03
- Horizon Fast Ferry Pte. Ltd. 2017-10-09
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.