[{"id":11049,"date":"2025-10-08T19:58:53","date_gmt":"2025-10-08T19:58:53","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/allanite\/"},"modified":"2026-07-31T20:43:57","modified_gmt":"2026-07-31T20:43:57","slug":"allanite","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/allanite","title":{"rendered":"Allanite"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><span style=\"font-size: 11.0pt; line-height: 107%; ,sans-serif;color: black;\">This threat actor targets business and industrial control networks in the power-utility sector, for the purpose of espionage. In 2017, the U.S. Department of Homeland Security <a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/TA17-293A\">warned<\/a> U.S. critical infrastructure operators about this threat actor and its capabilities.<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This threat actor targets business and industrial control networks in the power-utility sector, for the purpose of espionage. In 2017, the U.S. Department of Homeland Security warned U.S. critical infrastructure operators about this threat actor and its capabilities.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"cyber_operation":[49],"state_sponsor":[141],"victim_category":[138],"victim_government_response":[186],"victim":[180,182],"class_list":["post-11049","post","type-post","status-publish","format-standard","hentry","category-threat-actor","cyber_operation-espionage","state_sponsor-russian-federation","victim_category-private-sector","victim_government_response-unknown","victim-united-kingdom","victim-united-states"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=11049"}],"version-history":[{"count":4,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11049\/revisions"}],"predecessor-version":[{"id":11398,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11049\/revisions\/11398"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=11049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=11049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=11049"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=11049"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=11049"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=11049"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=11049"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=11049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":11044,"date":"2025-10-08T19:58:52","date_gmt":"2025-10-08T19:58:52","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/trisis\/"},"modified":"2025-10-08T19:58:52","modified_gmt":"2025-10-08T19:58:52","slug":"trisis","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/trisis","title":{"rendered":"Trisis"},"content":{"rendered":"<p>This threat actor targets the Triconex safety instrumented system (SIS) controllers produced by Schneider Electric, as well as a proprietary network communications protocol. SIS controllers maintain safe conditions in an industrial system should other failures occur. In 2017, the U.S. Department of Homeland Security released <a href=\"https:\/\/ics-cert.us-cert.gov\/sites\/default\/files\/documents\/MAR-17-352-01%20HatMan%20-%20Safety%20System%20Targeted%20Malware%20%28Update%20A%29_S508C.PDF\">a malware analysis report<\/a> on the tools used by this threat actor.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This threat actor targets the Triconex safety instrumented system (SIS) controllers produced by Schneider Electric, as well as a proprietary network communications protocol. SIS controllers maintain safe conditions in an industrial system should other failures occur. In 2017, the U.S. Department of Homeland Security released a malware analysis report on the tools used by this [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"cyber_operation":[144],"state_sponsor":[141],"victim_category":[138],"victim_government_response":[186],"victim":[145],"class_list":["post-11044","post","type-post","status-publish","format-standard","hentry","category-threat-actor","cyber_operation-sabotage","state_sponsor-russian-federation","victim_category-private-sector","victim_government_response-unknown","victim-saudi-arabia"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=11044"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11044\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=11044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=11044"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=11044"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=11044"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=11044"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=11044"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=11044"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=11044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":11018,"date":"2025-10-08T19:58:51","date_gmt":"2025-10-08T19:58:51","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/leafminer\/"},"modified":"2025-10-08T19:58:51","modified_gmt":"2025-10-08T19:58:51","slug":"leafminer","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/leafminer","title":{"rendered":"Leafminer"},"content":{"rendered":"<p><span style=\"font-size:11.0pt;line-height:107%;,sans-serif;color:black\">This threat actor targets government organizations and entities in the financial, petrochemical, and transportation sectors for espionage purposes.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This threat actor targets government organizations and entities in the financial, petrochemical, and transportation sectors for espionage purposes.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"cyber_operation":[],"state_sponsor":[76],"victim_category":[63,138],"victim_government_response":[186],"victim":[4,12,13,45,77,80,139,145,178],"class_list":["post-11018","post","type-post","status-publish","format-standard","hentry","category-threat-actor","state_sponsor-iran-islamic-republic-of","victim_category-government","victim_category-private-sector","victim_government_response-unknown","victim-afghanistan","victim-azerbaijan","victim-bahrain","victim-egypt","victim-iran-islamic-republic-of","victim-israel","victim-qatar","victim-saudi-arabia","victim-united-arab-emirates"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=11018"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11018\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=11018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=11018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=11018"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=11018"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=11018"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=11018"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=11018"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=11018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":11008,"date":"2025-10-08T19:58:50","date_gmt":"2025-10-08T19:58:50","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/compromises-of-government-embassies-telecommunications-companies-and-a-russian-oil-company\/"},"modified":"2025-10-08T19:58:50","modified_gmt":"2025-10-08T19:58:50","slug":"compromises-of-government-embassies-telecommunications-companies-and-a-russian-oil-company","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/compromises-of-government-embassies-telecommunications-companies-and-a-russian-oil-company","title":{"rendered":"Compromises of government embassies, telecommunications companies, and a Russian oil company"},"content":{"rendered":"<p><span style=\"font-size:11.0pt\"><span style=\",sans-serif\"><span style=\"color:black\">A group has attacked 131 victims in thirty organizations since September 2018, including unidentified government embassies, telecommunications firms, and a Russian oil and gas company.<\/span><\/span><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A group has attacked 131 victims in thirty organizations since September 2018, including unidentified government embassies, telecommunications firms, and a Russian oil and gas company.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[2],"tags":[],"cyber_operation":[49],"state_sponsor":[76],"victim_category":[63,138],"victim_government_response":[186],"victim":[127,142,145,171],"class_list":["post-11008","post","type-post","status-publish","format-standard","hentry","category-incident","cyber_operation-espionage","state_sponsor-iran-islamic-republic-of","victim_category-government","victim_category-private-sector","victim_government_response-unknown","victim-pakistan","victim-russian-federation","victim-saudi-arabia","victim-turkey"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=11008"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/11008\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=11008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=11008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=11008"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=11008"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=11008"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=11008"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=11008"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=11008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":10965,"date":"2025-10-08T19:58:37","date_gmt":"2025-10-08T19:58:37","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/kimusky\/"},"modified":"2025-10-08T19:58:37","modified_gmt":"2025-10-08T19:58:37","slug":"kimusky","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/kimusky","title":{"rendered":"Kimusky"},"content":{"rendered":"<p>This threat actor targeted foreign ministries and think tanks in Europe and the United States using malware hidden in Microsoft Word documents and antiquated file formats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This threat actor targeted foreign ministries and think tanks in Europe and the United States using malware hidden in Microsoft Word documents and antiquated file formats.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"cyber_operation":[],"state_sponsor":[91],"victim_category":[63,138],"victim_government_response":[],"victim":[56,149,180,182],"class_list":["post-10965","post","type-post","status-publish","format-standard","hentry","category-threat-actor","state_sponsor-korea-democratic-peoples-republic-of","victim_category-government","victim_category-private-sector","victim-france","victim-slovakia","victim-united-kingdom","victim-united-states"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10965"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10965\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10965"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10965"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10965"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10965"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10965"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":10921,"date":"2025-10-08T19:58:35","date_gmt":"2025-10-08T19:58:35","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/targeting-of-sporting-and-anti-doping-organizations-ahead-of-2020-tokyo-olympics\/"},"modified":"2026-07-31T20:41:59","modified_gmt":"2026-07-31T20:41:59","slug":"targeting-of-sporting-and-anti-doping-organizations-ahead-of-2020-tokyo-olympics","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/targeting-of-sporting-and-anti-doping-organizations-ahead-of-2020-tokyo-olympics","title":{"rendered":"Targeting of sporting and anti-doping organizations ahead of 2020 Tokyo Olympics"},"content":{"rendered":"<p>Just prior to news reports suggesting that the World Anti-Doping Agency might ban Russian athletes from all international sporting events, <a href=\"https:\/\/www.cfr.org\/cyber-operations\/apt-28\">APT 28<\/a> attacked a number of sporting and anti-doping organizations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just prior to news reports suggesting that the World Anti-Doping Agency might ban Russian athletes from all international sporting events, APT 28 attacked a number of sporting and anti-doping organizations.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[2],"tags":[],"cyber_operation":[49],"state_sponsor":[141],"victim_category":[32,63],"victim_government_response":[],"victim":[],"class_list":["post-10921","post","type-post","status-publish","format-standard","hentry","category-incident","cyber_operation-espionage","state_sponsor-russian-federation","victim_category-civil-society","victim_category-government"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10921"}],"version-history":[{"count":3,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10921\/revisions"}],"predecessor-version":[{"id":11397,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10921\/revisions\/11397"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10921"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10921"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10921"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10921"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10921"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":10907,"date":"2025-10-08T19:58:34","date_gmt":"2025-10-08T19:58:34","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/apt-c-23\/"},"modified":"2025-10-08T19:58:34","modified_gmt":"2025-10-08T19:58:34","slug":"apt-c-23","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/apt-c-23","title":{"rendered":"APT-C-23"},"content":{"rendered":"<p>Previously targeted Israeli soldiers&nbsp;by pretending to be women looking for romantic partners.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Previously targeted Israeli soldiers&nbsp;by pretending to be women looking for romantic partners.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"cyber_operation":[],"state_sponsor":[131],"victim_category":[],"victim_government_response":[],"victim":[80],"class_list":["post-10907","post","type-post","status-publish","format-standard","hentry","category-threat-actor","state_sponsor-palestine-state-of","victim-israel"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10907"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10907\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10907"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10907"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10907"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10907"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10907"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":10760,"date":"2025-10-08T19:58:05","date_gmt":"2025-10-08T19:58:05","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/apt-28\/"},"modified":"2025-10-08T19:58:05","modified_gmt":"2025-10-08T19:58:05","slug":"apt-28","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/apt-28","title":{"rendered":"APT 28"},"content":{"rendered":"<p>This threat actor is linked to espionage campaigns, high-profile doxing efforts, and disruptive incidents that compromised targets believed to be of interest to the Russian government.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This threat actor is linked to espionage campaigns, high-profile doxing efforts, and disruptive incidents that compromised targets believed to be of interest to the Russian government.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"cyber_operation":[],"state_sponsor":[141],"victim_category":[63,110,138],"victim_government_response":[194],"victim":[4,8,19,27,31,56,58,59,71,83,85,87,111,127,135,163,171,176,180,182],"class_list":["post-10760","post","type-post","status-publish","format-standard","hentry","category-threat-actor","state_sponsor-russian-federation","victim_category-government","victim_category-military","victim_category-private-sector","victim_government_response-yes","victim-afghanistan","victim-armenia","victim-belgium","victim-canada","victim-china","victim-france","victim-georgia","victim-germany","victim-hungary","victim-japan","victim-jordan","victim-kazakhstan","victim-mongolia","victim-pakistan","victim-poland","victim-tajikistan","victim-turkey","victim-ukraine","victim-united-kingdom","victim-united-states"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10760"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10760\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10760"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10760"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10760"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10760"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10760"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":10698,"date":"2025-10-08T19:58:02","date_gmt":"2025-10-08T19:58:02","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/targeting-of-u-s-diplomats-in-uganda\/"},"modified":"2025-10-08T19:58:02","modified_gmt":"2025-10-08T19:58:02","slug":"targeting-of-u-s-diplomats-in-uganda","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/targeting-of-u-s-diplomats-in-uganda","title":{"rendered":"Targeting of U.S. diplomats in Uganda"},"content":{"rendered":"<p>Uganda was accused of using the spyware Pegasus, which is sold by the Israeli NSO Group, to spy on journalists and U.S. diplomats based in the country. The incident was the first reported instance that NSO Group&#8217;s tools have been used to surveil U.S. government personnel.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Uganda was accused of using the spyware Pegasus, which is sold by the Israeli NSO Group, to spy on journalists and U.S. diplomats based in the country. The incident was the first reported instance that NSO Group&#8217;s tools have been used to surveil U.S. government personnel.&nbsp;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[2],"tags":[],"cyber_operation":[49],"state_sponsor":[174],"victim_category":[32,63],"victim_government_response":[186],"victim":[175],"class_list":["post-10698","post","type-post","status-publish","format-standard","hentry","category-incident","cyber_operation-espionage","state_sponsor-uganda","victim_category-civil-society","victim_category-government","victim_government_response-unknown","victim-uganda"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10698"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10698\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10698"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10698"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10698"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10698"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10698"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":10673,"date":"2025-10-08T19:57:52","date_gmt":"2025-10-08T19:57:52","guid":{"rendered":"http:\/\/localhost\/cyber-operations\/targeting-of-american-defense-industry\/"},"modified":"2025-10-08T19:57:52","modified_gmt":"2025-10-08T19:57:52","slug":"targeting-of-american-defense-industry","status":"publish","type":"post","link":"https:\/\/www.cfr.org\/cyber-operations\/targeting-of-american-defense-industry","title":{"rendered":"Targeting of American defense industry"},"content":{"rendered":"<p>The North Korean threat actor Lazarus Group leveraged a Windows update to conduct spear-phishing attacks, sending fake job offers from Lockheed Martin. Lazarus has used fake job offers in the past to plant malware on defense industry systems.&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The North Korean threat actor Lazarus Group leveraged a Windows update to conduct spear-phishing attacks, sending fake job offers from Lockheed Martin. Lazarus has used fake job offers in the past to plant malware on defense industry systems.&nbsp;&nbsp;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_cloudinary_featured_overwrite":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[2],"tags":[],"cyber_operation":[49],"state_sponsor":[91],"victim_category":[110,138],"victim_government_response":[186],"victim":[182],"class_list":["post-10673","post","type-post","status-publish","format-standard","hentry","category-incident","cyber_operation-espionage","state_sponsor-korea-democratic-peoples-republic-of","victim_category-military","victim_category-private-sector","victim_government_response-unknown","victim-united-states"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10673","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/comments?post=10673"}],"version-history":[{"count":0,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/posts\/10673\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/media?parent=10673"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/categories?post=10673"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/tags?post=10673"},{"taxonomy":"cyber_operation","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/cyber_operation?post=10673"},{"taxonomy":"state_sponsor","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/state_sponsor?post=10673"},{"taxonomy":"victim_category","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_category?post=10673"},{"taxonomy":"victim_government_response","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim_government_response?post=10673"},{"taxonomy":"victim","embeddable":true,"href":"https:\/\/www.cfr.org\/cyber-operations\/wp-json\/wp\/v2\/victim?post=10673"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}]