ESET Report: APT Activities and Cyber Threat Trends Q2-Q3 2025
ESET Research released a comprehensive report detailing Advanced Persistent Threat (APT) activities from April to September 2025. China-aligned groups, including PlushDaemon and FamousSparrow, advanced geopolitical objectives through adversary-in-the-middle techniques and targeted Latin American governments. Mustang Panda focused on Southeast Asia and Europe, while Flax Typhoon exploited healthcare sectors in Taiwan. Iran-aligned MuddyWater increased internal spearphishing success rates, and GalaxyGato utilized DLL-search-order hijacking. North Korean actors like Lazarus and Kimsuky expanded into Uzbekistan and targeted cryptocurrency sectors for revenue and espionage, employing ClickFix techniques. Russia-aligned groups maintained intense focus on Ukraine; Gamaredon collaborated with Turla, while Sandworm deployed data wipers against Ukrainian grain and energy sectors to weaken the economy. RomCom exploited a zero-day WinRAR vulnerability in Europe and Canada. Additionally, InedibleOchotense impersonated ESET to distribute malware. The report highlights evolving tactics, including open-source proxy usage and increased cooperation among Russian threat actors, illustrating the dynamic and dangerous landscape of state-sponsored cyber warfare during this period.
Wire timeline
ESET Report: APT Activities and Cyber Threat Trends Q2-Q3 2025
ESET Research released a comprehensive report detailing Advanced Persistent Threat (APT) activities from April to September 2025. China-aligned groups, including PlushDaemon and FamousSparrow, advanced geopolitical objectives through adversary-in-the-middle techniques and targeted Latin American governments. Mustang Panda focused on Southeast Asia and Europe, while Flax Typhoon exploited healthcare sectors in Taiwan. Iran-aligned MuddyWater increased internal spearphishing success rates, and GalaxyGato utilized DLL-search-order hijacking. North Korean actors like Lazarus and Kimsuky expanded into Uzbekistan and targeted cryptocurrency sectors for revenue and espionage, employing ClickFix techniques. Russia-aligned groups maintained intense focus on Ukraine; Gamaredon collaborated with Turla, while Sandworm deployed data wipers against Ukrainian grain and energy sectors to weaken the economy. RomCom exploited a zero-day WinRAR vulnerability in Europe and Canada. Additionally, InedibleOchotense impersonated ESET to distribute malware. The report highlights evolving tactics, including open-source proxy usage and increased cooperation among Russian threat actors, illustrating the dynamic and dangerous landscape of state-sponsored cyber warfare during this period.
WeLiveSecurity