AeroBlade

First seen
2022-09-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
unknown
Profile updated
2026-07-07 12:10:48

Targeted industries: defense-and-aerospace

Targeted regions: country_code:us

Context

AeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States. Their objective appears to be conducting commercial and competitive cyber espionage. They employ spear-phishing as a delivery mechanism, using weaponized documents with embedded remote template injection techniques and malicious VBA macro code. The attacks have been ongoing since September 2022, with multiple phases identified in the attack chain. The origin and precise objective of AeroBlade remain unknown.

Reports & references

  • blogs.blackberry.com — Aeroblade On The Hunt Targeting Us Aerospace Industry (report)

External references