<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library: Nation-State &amp; APT Feed</title>
    <link>https://cybercaselibrary.com/actors/</link>
    <description>Advanced persistent threats, nation-state cyber espionage, wipers, and state-sponsored indictments.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:02:15 GMT</lastBuildDate>
    <atom:link href="https://cybercaselibrary.com/feeds/nation-state.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)]]></title>
      <link>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</link>
      <guid>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</guid>
      <description><![CDATA[Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Thu, 15 Oct 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: Volt Typhoon Critical Infrastructure Pre-Positioning]]></title>
      <link>https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/</link>
      <guid>https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/</guid>
      <description><![CDATA[State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: Colonial Pipeline DarkSide Ransomware Attack]]></title>
      <link>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</guid>
      <description><![CDATA[DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Fri, 07 May 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)]]></title>
      <link>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</link>
      <guid>https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/</guid>
      <description><![CDATA[Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Sun, 13 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/</guid>
      <description><![CDATA[Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Tue, 27 Mar 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</guid>
      <description><![CDATA[Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Fri, 08 Jun 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-seleznev-track2/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-seleznev-track2/</guid>
      <description><![CDATA[Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Thu, 03 Mar 2011 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/</guid>
      <description><![CDATA[Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Thu, 01 May 2014 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-nguyen-chipmixer/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-nguyen-chipmixer/</guid>
      <description><![CDATA[Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Wed, 15 Mar 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-netyksho-apt28-dnc/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-netyksho-apt28-dnc/</guid>
      <description><![CDATA[Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Fri, 13 Jul 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Tyler Barriss (Serial Swatting / Wichita Incident)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-barriss-serial-swatting/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-barriss-serial-swatting/</guid>
      <description><![CDATA[Perpetrator of dozens of fraudulent emergency 911 calls and bomb threats across the United States for hire, culminating in a fatal police shooting in Wichita, Kansas, over a Call of Duty video game dispute.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Tue, 20 Mar 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-khusyaynova-project-lakhta/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-khusyaynova-project-lakhta/</guid>
      <description><![CDATA[Russian chief accountant charged with managing the financial administration of Project Lakhta, a massive state-funded covert influence and cyber operation designed to sow political discord in U.S. elections.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Fri, 28 Sep 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. & International Action: Dmitry Badin (German Bundestag Hack)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-badin-german-bundestag-apt28/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-badin-german-bundestag-apt28/</guid>
      <description><![CDATA[Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Tue, 05 May 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/</guid>
      <description><![CDATA[International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Mon, 08 Nov 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-clark-twitter-bitcoin/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-clark-twitter-bitcoin/</guid>
      <description><![CDATA[17-year-old hacker orchestrated a spearphishing and social engineering scheme targeting Twitter employees, gaining access to internal administrative customer service tools and hijacking 130 high-profile verified accounts (including Joe Biden, Barack Obama, Elon Musk, and Apple) to promote a fraudulent Bitcoin giveaway.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Fri, 31 Jul 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)]]></title>
      <link>https://cybercaselibrary.com/cases/operation-olympic-games-stuxnet/</link>
      <guid>https://cybercaselibrary.com/cases/operation-olympic-games-stuxnet/</guid>
      <description><![CDATA[Joint United States and Israeli covert cyber operation that deployed the Stuxnet computer worm, the first known malware capable of causing physical destruction to industrial hardware. The worm exploited four Windows zero-day vulnerabilities and compromised Siemens Step7 PLC software to spin Natanz nuclear centrifuges out of control.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Thu, 17 Jun 2010 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)]]></title>
      <link>https://cybercaselibrary.com/cases/saudi-aramco-shamoon-wiper/</link>
      <guid>https://cybercaselibrary.com/cases/saudi-aramco-shamoon-wiper/</guid>
      <description><![CDATA[Devastating state-sponsored wiper attack attributed to Iranian threat actors ('Cutting Sword of Justice') that detonated the Shamoon (Disttrack) wiper across Saudi Aramco, simultaneously wiping 35,000 workstation hard drives and overwriting Master Boot Records with an image of a burning American flag.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Wed, 15 Aug 2012 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[State-Sponsored Attack: Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)]]></title>
      <link>https://cybercaselibrary.com/cases/microsoft-midnight-blizzard-email-breach/</link>
      <guid>https://cybercaselibrary.com/cases/microsoft-midnight-blizzard-email-breach/</guid>
      <description><![CDATA[Russian Foreign Intelligence Service (SVR / Midnight Blizzard / APT29) compromised Microsoft corporate email systems via a password spray campaign against a legacy non-production test tenant lacking multi-factor authentication. Attackers leveraged the test account's permissions to grant full OAuth app-level access, reading executive emails and exfiltrating source code and customer cryptographic secrets.]]></description>
      <category><![CDATA[Nation-State & Cyber Espionage]]></category>
      <pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate>
    </item>
  
  </channel>
</rss>