AeroBlade is a threat actor targeting the US aerospace sector for commercial cyber espionage.
Analyst brief
AeroBlade is a previously unknown threat actor targeting an aerospace organization in the United States for what appears to be commercial and competitive cyber espionage. The actor leverages spear-phishing as a delivery mechanism, using weaponized documents that employ malicious VBA macros and remote template injection techniques. Activity has been observed since September 2022, with multiple attack chain phases identified. Defenders should focus on securing email gateways, enforcing strict macro execution policies, and monitoring for anomalous remote template loads in documents.
AeroBlade
unknown
AeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States. Their objective appears to be conducting commercial and competitive cyber espionage. They employ spear-phishing as a delivery mechanism, using weaponized documents with embedded remote template injection techniques and malicious VBA macro code. The attacks have been ongoing since September 2022, with multiple phases identified in the attack chain. The origin and precise objective of AeroBlade remain unknown.