State-aligned actors step up operations against the defence industry

Google Threat Intelligence Group (GTIG) warns that state-aligned actors are increasing cyber operations against the global defence industrial base, targeting contractors, suppliers and research partners as well as military systems. From January 2025 the suspected Russian espionage cluster UNC5976 ran a phishing campaign distributing malicious RDP files that connected to attacker-controlled domains spoofing a Ukrainian telecommunications provider. The group also used hundreds of spoofed domains impersonating defence contractors, including companies in Norway and other NATO countries.

What this means for your organisation

Norwegian suppliers to the defence sector are a stated target, and that includes small subcontractors delivering components, services or research. Attackers routinely go through the weakest link to reach the real target, and a spoofed domain in your name damages your standing with your own customers. For organisations in scope of NIS2, this is also a question the board must be able to answer.

Berigo recommends

  • Block or alert on RDP files arriving by email, and restrict which machines are permitted to open them.
  • Monitor registrations of domains resembling your own and keep a routine for getting them taken down.
  • Map who in your supply chain works towards the defence sector and place equivalent requirements on them.
  • Bring the threat picture for your own sector into board reporting, with concrete measures and status.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch