Full Report
Beyond Gravity, a federally owned aerospace supplier, has fallen victim to a targeted cyberattack. According to the company, a highly professional actor is believed to be behind the attack. Beyond Gravity announced on Friday that it had received the first indications of malicious activity in its IT environment on August 12. The investigation is being conducted in collaboration with the Federal Office for Cybersecurity and the IT security firm Mandiant. As of Friday, it was not known who was behind the attack. The company had filed a criminal complaint and strengthened its security measures, the statement added.
Analysis Summary
# Incident Report: Targeted Cyberattack on Beyond Gravity
## Executive Summary
Beyond Gravity, a federally owned Swiss aerospace supplier, was targeted by a highly professional threat actor in a sophisticated cyberattack detected in August. The incident prompted an extensive forensic investigation in partnership with Mandiant and federal authorities to determine the scope of the compromise. While security measures have been strengthened and criminal complaints filed, the identity of the attackers and the full extent of data impact remain under investigation.
## Incident Details
- **Discovery Date:** August 12
- **Incident Date:** Ongoing/Prior to August 12
- **Affected Organization:** Beyond Gravity (formerly RUAG Space)
- **Sector:** Aerospace and Defense
- **Geography:** Switzerland
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed (Prior to August 12)
- **Vector:** Unknown/Undisclosed
- **Details:** The company noted the first indications of malicious activity in their IT environment on August 12.
### Lateral Movement
- **Details:** Specific techniques are currently undisclosed; however, the involvement of "highly professional actors" suggests sophisticated movement within the IT infrastructure.
### Data Exfiltration/Impact
- **Details:** Forensic analysis is ongoing to determine if sensitive aerospace or federal data was exfiltrated. The organization has focused on analyzing affected devices.
### Detection & Response
- **Discovery:** Internal monitoring identified malicious activity on August 12.
- **Response Actions:** Immediate engagement with the Federal Office for Cybersecurity (BACS) and IT security firm Mandiant. Security measures were hardened, and a criminal complaint was filed.
## Attack Methodology
*Note: Due to the ongoing nature of the investigation and the company's prioritize-thoroughness approach, specific technical indicators (TTPs) have not yet been publicly released.*
- **Initial Access:** Highly professional actor (specific method unknown)
- **Persistence:** Under investigation
- **Privilege Escalation:** Under investigation
- **Defense Evasion:** Used sophisticated techniques to remain undetected until August 12
- **Lateral Movement:** Under investigation
- **Collection:** Under investigation
- **Exfiltration:** Under investigation
- **Impact:** Potential compromise of aerospace intellectual property and federal communications
## Impact Assessment
- **Financial:** Undisclosed; costs involve high-tier forensic consulting (Mandiant).
- **Data Breach:** Under forensic review to determine volume and sensitivity.
- **Operational:** The company suggests priority was placed on thoroughness over speed, implying some level of investigative disruption to standard IT operations.
- **Reputational:** High, given the company's role as a federally owned supplier to the aerospace sector.
## Indicators of Compromise
- **Network indicators:** None disclosed to date.
- **File indicators:** None disclosed to date.
- **Behavioral indicators:** Malicious activity detected within the internal IT environment on August 12.
## Response Actions
- **Containment:** Strengthening of internal IT security measures immediately following discovery.
- **Eradication:** Forensic analysis of all affected devices to remove malicious presence.
- **Recovery:** Collaborative investigation with Mandiant and the Federal Office for Cybersecurity.
- **Legal:** Filing of a criminal complaint with relevant authorities.
## Lessons Learned
- **Communication Delays:** The two-month delay in public reporting highlights the conflict between forensic integrity and public transparency. The company maintains that "thoroughness takes precedence over speed" to avoid jeopardizing the investigation.
- **Target Profile:** As a federal spin-off, Beyond Gravity is a high-value target for state-sponsored or highly professional corporate espionage.
## Recommendations
- **Enhanced Monitoring:** Implement advanced behavioral analytics to detect "highly professional" actors earlier in the kill chain.
- **Supply Chain Security:** Ensure rigorous segmentation between federal projects and general corporate IT environments.
- **Continuous Auditing:** Given the aerospace sector's sensitivity, conduct regular third-party compromise assessments to identify dormant persistence mechanisms.