US aerospace companies are facing dangerous new cyberattacks
Cybersecurity researchers from BlackBerry have uncovered a new cyber-espionage campaign targeting US organizations in the aerospace industry.
The goal of the campaign seems to be data theft and cyber-espionage, although the threat actors’ endgame remains a mystery. The researchers claim the group is most likely brand new, so they named it AeroBlade.
This group mounted attacks in two stages, the first being more of a reconnaissance move, and the second one being the actual data theft via malware.
Selling the data online
The attack starts with a spear-phishing email, containing a carefully crafted, malicious DOCX file. This file, if opened, downloads a DOTM file from a remote location. If you’re unfamiliar with the DOTM extension, it’s a document template for Microsoft Word. This file can then execute a macro which creates a reverse shell on the target endpoint. This shell will connect with the C2 server and await further instructions.
“Once the victim opens the file and executes it by manually clicking the “Enable Content” lure message, the [redacted].dotm document discretely drops a new file to the system and opens it,” BlackBerry said in its report. “The newly downloaded document is readable, leading the victim to believe that the file initially received by email is legitimate.”
The first step, which was observed to have taken place in September last year, lists all directories on the compromised endpoint, giving the attackers a map of the kingdom and thus simplifying the search for valuable data. The second stage, which took place in July this year, resulted in data theft.
Aeroblade’s origin, or endgame, remain a mystery. While cyber-espionage campaigns can be highly disruptive, this could also be the work of an entirely independent, profit-oriented threat actor, who will later try to sell the stolen data on the dark web to the highest bidder.
Via BleepingComputer
More from TechRadar Pro
Cybersecurity researchers from BlackBerry have uncovered a new cyber-espionage campaign targeting US organizations in the aerospace industry. The goal of the campaign seems to be data theft and cyber-espionage, although the threat actors’ endgame remains a mystery. The researchers claim the group is most likely brand new, so they named…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- The co-creator of Scavengers Reign is working on a new show for Netflix
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023