Cyber threats targeting the global aviation and aerospace sector are rapidly evolving, with ransomware, identity-based intrusions, and platform-level disruptions becoming dominant attack vectors. The interconnected nature of this ecosystem, combined with time-sensitive operations and complex third-party dependencies, makes it highly attractive to threat actors. Shared airport IT platforms represent critical single points of failure, as demonstrated by the September 2025 ransomware attack on Collins Aerospace MUSE system that disrupted major European airports including Heathrow, Brussels, Berlin, and Dublin. Major ransomware groups like LockBit and Cl0p maintain heavy focus on aviation suppliers, while advanced persistent threat groups including Refined Kitten, Wicked Panda, and Fancy Bear conduct strategic espionage targeting intellectual property, aircraft design data, and military aviation intelligence. Emerging threats include vulnerabilities in regional airports, aviation SaaS platforms, and satellite ...
Targeted Sectors
Executive Summary
The threat actor group, known by multiple aliases including LockBit, Cl0p, Refined Kitten, Wicked Panda, and Fancy Bear, is a high-sophistication cybercriminal operation targeting the aerospace, transportation, and defense sectors. The group employs advanced persistent threat (APT) tactics to conduct espionage and ransomware attacks, focusing on stealing intellectual property and disrupting critical aviation systems.
Goals & Targeting
The primary strategic objective appears to be financial gain through ransomware attacks, coupled with intelligence-gathering missions targeting intellectual property and military aviation data. The group's targeting of aerospace and defense sectors suggests an intent to compromise critical national infrastructure and gain a competitive advantage in the global market through stolen technology.
Enhanced Description
The group operates with significant technical proficiency, leveraging both ransomware campaigns and APT techniques to target key infrastructure and sensitive data within the aerospace and defense industries. Notable for its focus on high-value targets including aviation suppliers and manufacturers, the group has demonstrated a particular interest in disrupting shared airport IT platforms and satellite communication systems. The actor's operations span multiple continents, with a focus on critical third-party dependencies that underpin global aviation.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The group has been involved in several high-profile campaigns, including the September 2025 ransomware attack on Collins Aerospace MUSE system, which disrupted major European airports. Campaign patterns include targeting third-party aviation suppliers and leveraging shared IT platforms for maximum disruption.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the group's existence and operational focus, with multiple intelligence sources corroborating activities. Some gaps remain in specific technical details of their tools and exact geographic targeting.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics