Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lockbit, cl0p, refined kitten, wicked panda, fancy bear

lockbit, cl0p, refined kitten, wicked panda, fancy bear

TLP:CLEAR
Active

Description

Cyber threats targeting the global aviation and aerospace sector are rapidly evolving, with ransomware, identity-based intrusions, and platform-level disruptions becoming dominant attack vectors. The interconnected nature of this ecosystem, combined with time-sensitive operations and complex third-party dependencies, makes it highly attractive to threat actors. Shared airport IT platforms represent critical single points of failure, as demonstrated by the September 2025 ransomware attack on Collins Aerospace MUSE system that disrupted major European airports including Heathrow, Brussels, Berlin, and Dublin. Major ransomware groups like LockBit and Cl0p maintain heavy focus on aviation suppliers, while advanced persistent threat groups including Refined Kitten, Wicked Panda, and Fancy Bear conduct strategic espionage targeting intellectual property, aircraft design data, and military aviation intelligence. Emerging threats include vulnerabilities in regional airports, aviation SaaS platforms, and satellite ...

Goals & Targeting

Targeted Sectors

Aerospace
Transportation
Defense

AI Analysis

· 1 week ago

Executive Summary

The threat actor group, known by multiple aliases including LockBit, Cl0p, Refined Kitten, Wicked Panda, and Fancy Bear, is a high-sophistication cybercriminal operation targeting the aerospace, transportation, and defense sectors. The group employs advanced persistent threat (APT) tactics to conduct espionage and ransomware attacks, focusing on stealing intellectual property and disrupting critical aviation systems.

Goals & Targeting

The primary strategic objective appears to be financial gain through ransomware attacks, coupled with intelligence-gathering missions targeting intellectual property and military aviation data. The group's targeting of aerospace and defense sectors suggests an intent to compromise critical national infrastructure and gain a competitive advantage in the global market through stolen technology.

Enhanced Description

The group operates with significant technical proficiency, leveraging both ransomware campaigns and APT techniques to target key infrastructure and sensitive data within the aerospace and defense industries. Notable for its focus on high-value targets including aviation suppliers and manufacturers, the group has demonstrated a particular interest in disrupting shared airport IT platforms and satellite communication systems. The actor's operations span multiple continents, with a focus on critical third-party dependencies that underpin global aviation.

Key Capabilities

  • Advanced Persistent Threat (APT) tactics
  • Ransomware deployment
  • Credential dumping
  • Data exfiltration
  • Targeted spear-phishing campaigns

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Initial Access
Credential Access
Defense Evasion

ATT&CK Techniques

T1505.002
T1569.001
T1055
T1093.001
T1078.001

Software / Tooling

Mimikatz
Custom APT tools
LockBit ransomware
Cl0p ransomware

Campaigns & Victims

The group has been involved in several high-profile campaigns, including the September 2025 ransomware attack on Collins Aerospace MUSE system, which disrupted major European airports. Campaign patterns include targeting third-party aviation suppliers and leveraging shared IT platforms for maximum disruption.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • C2 infrastructure using fast-flux domains
  • Scheduled task creation for persistent access
  • Abnormal network traffic volumes during attacks

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems
  • Segment networks to isolate aviation-related IT from corporate networks
  • Monitor for unusual exfiltration activity using network monitoring tools
  • Conduct regular phishing simulations and employee training
  • Apply patches and updates to aviation software and third-party dependencies

Suggested Tags

APT
ransomware
espionage
aerospace
defense

Confidence Assessment

High confidence in the group's existence and operational focus, with multiple intelligence sources corroborating activities. Some gaps remain in specific technical details of their tools and exact geographic targeting.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Supply Chain Attack
Government Targeting
ransomware
espionage
aerospace
defense

Details

Type
Criminal
Confidence
55%
Added
May 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.