Russian hackers TA488 target US nuclear installations and defense contractors using a rare "half-click" email exploit.

Russian-aligned threat actor TA488 has conducted a cyber-espionage campaign targeting nuclear installations, defense contractors, and government entities in the United States. According to research from Proofpoint, the hackers utilized a "half-click" exploit, which allows them to steal data simply by a user opening an email, without requiring any clicks on links or attachments. The campaign specifically targeted entities with an interest in nuclear fusion technology to provide the Kremlin with strategic insights into Western military logistics and policy. The hackers used a rare software exploit to steal three months of email communications and entire organizational directories. This activity followed a trend of Russian operatives testing their techniques on Ukrainian targets before deploying them against NATO allies. While the group has been active since at least July 2025, it has recently been identified as a private contractor working for Russian intelligence. The administration and its allies issued a federal advisory to help assess the intelligence gathered by these operatives. Thai authorities recently arrested one member of the group, a Russian man in his 30s.

Sources