Weekly news threat forecast – Generalitat 01/12



Apart from its function, CATALONIA-CERT constantly monitors cybersecurity threats that affect the Agency's area of responsibility. In this sense, the evolution of these threats is compiled and analysed in accordance with the activity observed by the entire SOC/CERT in our territory. 

During this week, in the context of recent cyber threats:

  • NoName057(16) focuses its DDoS attacks on Spanish entities in the wake of Zelensky's visit.

  • A second wave of npm package engagements is identified in the Shai Hulud 2.0 campaign.



Below we list the 5 main threats identified in the scope of the Generalitat, the forecast of their evolution and the news regarding these and other threats that we have analyzed during the last week. The objective is to share this vision so that the appropriate prevention, detection and protection measures can be taken to mitigate the most relevant threats in a prioritized way.

All the threats they carry are written ingarnet have been detected in the area or have been affected.



RELEVANT THREATS

  • ATTACKS ASSOCIATED WITH HACKTIVIST GROUPS



  • 25/11/2025 – Activity of the hacktivist group NoName057 against Spain and Catalonia following Zelensky's visit:Following the visit of the Ukrainian president to Spain to hold several meetings with the Spanish government, the pro-Russian hacktivist group NoName057, with more than two years of history, has intensified its activity against Spanish entities through DDoS attacks distributed through its DDoSia client. This group usually runs campaigns every 2-3 months, but activates new rounds when events that it considers relevant occur, such as in this case Zelensky's visit.



The main targets of the attacks have been public institutions and companies linked to mobility, both at the state and regional level. As a result, several web portals of these entities have been rendered inaccessible.



  • SUPPLY CHAIN ENGAGEMENT



  • 25/11/2025 – Shai Hulud Campaign 2.0 - npm Package Engagement: The new wave of the Shai Hulud campaign represents a significant escalation in the attack on the supply chain of the JavaScript ecosystem. The actors have committed approximately 500 npm packages, many of them used in real-world engineering, automation, and corporate integration processes, extending the impact far beyond the initial campaign in the summer of 2025. By illegitimately accessing maintainer accounts, the attackers have injected malicious code capable of stealing secrets, manipulating workflows, and propagating to projects that transitively rely on these altered packages. The result is a high, cross-cutting risk that affects development environments, CI/CD pipelines, and GitHub repositories, even organizations that were not direct targets of the attack.





CATALONIA-CERT has compiled and providedindicators of commitment for intake in perimeter tools

We remain at your disposal in case you have any doubts or need support in this regard.

















Content Blocks

Details

Comments

CERCA Ecosystem Information

CERCA Ecosystem Information

CERCA Communities
DEEPTECH Area