AeroBlade — APT Profile
AeroBlade is the name BlackBerry gave to an unattributed operator that went after a single United States aerospace organisation, disclosed in the vendor's November 2023 write-up. BlackBerry split the activity into two stages: infrastructure stand-up and weapon testing around September 2022, then a live intrusion attempt in July 2023 that reused the same network backbone with a stealthier and more capable toolkit. Delivery in both stages was a spear-phished Office document that pulled its payload down through remote template injection and executed VBA macro code once macros were enabled. The vendor rated the operation commercial and competitive espionage at medium-to-high confidence, though the precise end goal beyond that assessment was never established. Neither BlackBerry nor the ETDA threat-actor encyclopedia attaches a nationality to the group, and no later campaigns have been publicly tied to the name.
Vendor research
Read the full analysis on IntelFusions