December 1, 2025 Cyber Threat Intelligence Briefing
This week’s briefing covers:
00:00 – Intro
05:26 [THREAT ACTOR ACTIVITY] London Council Cyber Attack
The Royal Borough of Kensington & Chelsea, Westminster, and Hammersmith & Fulham Councils disclosed on 24 November that they had suffered a cyberattack. They promptly notified the Information Commissioner's Office, enlisted specialist cyber-incident experts and engaged the National Cyber Security Centre (NCSC). According to Sky News, a number of systems were taken offline.
06:40 Iranian Nation-state Cyber Intelligence Gathering as Precursor to Missile Strikes
Amazon Threat Intelligence has released a report stating it believes Iranian nation-state cyber intrusions are deliberately used to gather real-time intelligence that directly supports non-cyber military attacks.
07:57 Warnings of Potential Credential Leak through Online Tools
This data leak is caused by individuals pasting JSON data, or other code, into these tools to make the code cleaner, but not sanitizing the data first. If the tool provides a saving functionality, as is the case with JSONFormatter, a sharing link is created, and the saved data can be easily parsed by any user.
10:30 [RANSOMWARE] Korean Leaks: MSP Supply Chain Breach by Qilin and Moonstone Sleet
The Korean Leaks operation marked a significant hybrid geopolitical cyber campaign targeting South Korea’s financial sector. It combined the Qilin ransomware-as-a-service platform with the strategic intent of a state-linked actor, specifically the North Korea-linked affiliate Moonstone Sleet.
Dive deeper:
Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report
Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing
Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto
Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist
Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber
Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports
Kroll Responder MDR: https://www.kroll.com/en/services/cyber/kroll-responder
#krollcyber #threatintelligence #cyberthreats