INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Google Links China, Iran to Coordinated Defense Sector

| 2026-02-13 16:23 CRITICAL HIGH
Executive Summary AI-generated
The threat actor group behind the coordinated defense industrial base (DIB) sector cyber operations is a formidable force, comprising state-sponsored actors from China, Iran, North Korea, and Russia. Their targeting strategy centers around four key themes: disrupting Ukraine's military efforts in the Russia-Ukraine War, infiltrating employees through direct approaches and exploiting hiring processes by non-state actors, utilizing edge devices as initial access pathways for groups affiliated with China-nexus networks, and compromising supply chains due to breaches of manufacturing sectors. Notably, some notable threat actors have been linked to these activities, including APT44 (Sandworm) attempting to exfiltrate information from encrypted messaging applications in Ukraine, while others have used questionnaires hosted on Google Forms to conduct reconnaissance against prospective drone operators and distributed malware like MESSYFORK to unmanned aerial vehicle operators.
Technical Mitigations AI-generated
* Implement a secure patching mechanism: Regularly update and patch software, operating systems, and applications to prevent exploitation of known vulnerabilities. * Use multi-factor authentication (MFA): Require two or more forms of verification, such as passwords, biometric data, and one-time codes, to access sensitive areas or services. * Monitor network traffic for suspicious activity: Use intrusion detection and prevention systems (IDPS) to monitor network traffic for signs of unauthorized access, malware, or other malicious activity. * Use a virtual private network (VPN): Establish a secure, encrypted connection between devices and the internet by using a VPN. This can help protect against eavesdropping and man-in-the-middle attacks. * Keep software and operating systems up-to-date: Ensure that all installed software and operating systems are current with the latest security patches and updates to prevent exploitation of known vulnerabilities.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Dream JobOperation Dream Job Mustang PandaMustang PandaVolt TyphoonVolt TyphoonKimsukyKimsukyAPT41APT41APT42APT42Lazarus GroupLazarus GroupAPT5APT5AndarielAndariel CVE-2025-8088CVE-2025-8088
Target & Sectors
DPRK DPRK DACH DACH MIDDLE_EAST MIDDLE_EAST CIS CIS aerospaceaerospace automotiveautomotive energyenergy defensedefense governmentgovernment telecommunicationstelecommunications manufacturingmanufacturing aviationaviation
Incident Timeline
late 2023
Threat actors used a REDCap exploit to target UNC6508, a China-nexus threat cluster that compromised a U.S.-based research institution in late 2023.
source_region China
December 2025
Google's links to China, Iran, Russia, North Korea in its Coordinated Defense Sector were detected by Huntress.
organisation Huntress
2026-01-13
Praetorian used a replica model to target the Coordinated Defense Sector by sending 1,000 queries to its API and training it for 20 epochs.
general_metric 80.1 %
general_metric 1,000 queries
general_metric 20 epochs
Feb 12, 2026
Threat actors used Google to target Iranian, Russian, North Korean and Chinese government entities in a coordinated defense sector cyber operations.
2026-02-13
North Korea-linked threat actor UNC2970 used Google Gemini's API to conduct reconnaissance on targets.
industry Defense
source_region China
industry Manufacturing
source_region Ukraine
organisation Google
organisation Coordinated Defense
threat_actor Mustang Panda
threat_actor APT41
organisation UNC795
organisation PHP
infrastructure Winrar
threat_actor APT42
organisation Google Maps
organisation SIM
organisation PoC
organisation WinRAR
organisation Recon
threat_actor Lazarus Group
organisation HONESTCUE
organisation API
organisation COINBAIT
organisation ClickFix
organisation Google Gemini's
organisation LLM
organisation the Gemini API
Feb 13, 2026
The threat actors involved in the incident targeted aerospace, defense contractors and their employees with tailored phishing lures.
organisation ORB
organisation VERMONSTER
threat_actor Andariel
organisation SmallTiger
threat_actor Kimsuky
threat_actor Lazarus Group
organisation Nimbus Manticore
organisation MINIBIKE
organisation TWOSTROKE
organisation CRASHPAD
threat_actor APT5
threat_actor Volt Typhoon
organisation WhatsApp
organisation DELTA
organisation LNK
infrastructure Android
organisation CraxsRAT
organisation Sandworm
organisation Telegram
organisation Signal
organisation Google Forms
organisation COOKBOX
organisation UAV
organisation GALLGRAB
infrastructure Windows
organisation WAVESIGN
organisation EDR
organisation UAC-0149
organisation ClickFix
organisation TINYWHALE
organisation MeshAgent
Tactical Metrics
Metrics
infrastructure
​Android
Affected Product
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Winrar
Affected Product