Jurisdiction: Global
Court filings and enforcement actions documenting cyber intrusions within or targeting entities in Global.
Key Facts
- 3 documented prosecution matters involving Global.
- Cumulative identified losses exceed $3.2 billion.
- Includes federal court filings, international extraditions, and sanctions designations.
Documented Incidents
XZ Utils liblzma Upstream Linux Supply Chain Backdoor (CVE-2024-3094)
Sophisticated multi-year social engineering and software supply chain operation where persona Jia Tan gained co-maintainer status on the foundational open-source xz compression project, embedding a multi-stage obfuscated backdoor into liblzma tarballs that hijacked OpenSSH sshd authentication to enable unauthorized pre-auth remote code execution.
Log4Shell Ubiquitous Remote Code Execution Crisis (CVE-2021-44228)
Universal zero-day vulnerability in Apache Log4j (Log4Shell) where arbitrary JNDI lookup strings (${jndi:ldap://...}) processed by logger components permitted unauthenticated remote code execution, triggering mass scanning and exploitation across billions of enterprise cloud servers by nation-state actors and ransomware syndicates worldwide.
3CX DesktopApp Cascading Supply Chain Attack (Lazarus Group)
North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.