Increase in attacks in Ukraine and Europe

ESET Research Center has published the latest APT Activity Report, which presents the activities of selected advanced persistent threat (APT) groups recorded by ESET researchers from April to September 2025.cyber security

During this period, APT groups affiliated with China continued to serve Beijing’s geopolitical goals. ESET observed an increasing use of the “adversary-in-the-middle” technique. This development appears to be a response to the Trump administration’s increased strategic interest in Latin America and is likely influenced by the ongoing US-China confrontation. In this context, the FamousSparrow group launched a series of attacks in Latin America, targeting multiple state actors in the region.

See more articles from iGuRu.gr when you search for news on Google.

In Europe , state actors remained the primary target of cyberespionage by Russian-linked APT groups, as their operations intensified against Ukraine and several European Union member states. Russian-linked groups had targeted actors outside Ukraine that had strategic or operational ties to Ukraine, reinforcing the view that the country remains at the center of Russian operations.

The RomCom group exploited a zero-day vulnerability in WinRAR to install malicious DLLs and deliver multiple backdoors, primarily targeting the financial, manufacturing, defense, and logistics sectors in the EU and Canada. Given that zero-day exploits are costly, the Gamaredon and Sandworm groups relied primarily on spearphishing as a breach method. Gamaredon remained the most active APT group targeting Ukraine, showing a significant increase in the frequency and intensity of its operations. Sandworm, in turn, continued to focus on Ukraine, but with a primary motive of causing destruction rather than espionage. Its attacks targeted state entities, as well as the energy, logistics, and grain sectors, with the potential goal of weakening the Ukrainian economy.

The FrostyNeighbor group, linked to Belarus, exploited an XSS vulnerability in Roundcube. Polish and Lithuanian companies were targeted by spearphishing emails. The emails contained a distinctive combination of dots and emoji, a structure reminiscent of AI-generated content, suggesting the possible use of AI in the campaign. The delivered payloads included a credential-sniffing tool and an email-stealing program.

“Interestingly, a Russian-linked threat actor, InedibleOchotense, ran a spearphishing campaign impersonating ESET. The campaign included emails and Signal messages that delivered a modified ESET software installer, leading to the download of both a legitimate ESET product and the Kalambur backdoor,” says Jean-Ian Boutin, Threat Research Director at ESET.

In Asia , APT groups continued to target state actors, as well as the technology, engineering, and manufacturing sectors, a pattern that remains consistent from the previous reporting period. North Korea-linked groups remained particularly active in attacks against South Korea and its technology sector, with a particular focus on cryptocurrencies, a critical source of revenue for the regime.

“China-linked groups remain highly active, with campaigns in Asia, Europe, Latin America, and the US, as ESET researchers have observed. This global spread suggests that these threat actors continue to mobilize to serve the broad spectrum of Beijing’s current geopolitical priorities,” Boutin adds.

From June to September, ESET recorded increased activity by FamousSparrow in Latin America , primarily targeting state actors. These operations represent the majority of the activity attributed to the group during this period, indicating that the region has been a key focus of its operations in recent months. These activities may be linked to the ongoing US-China confrontation in the region, which is related to the Trump administration’s renewed interest in Latin America.

In total, FamousSparrow's victims in Latin America include multiple government agencies in Argentina, one government agency in Ecuador, one in Guatemala, multiple in Honduras, and one in Panama.

The information presented here is primarily based on ESET's proprietary telemetry data and has been verified by ESET researchers, who produce detailed technical reports and frequent updates with detailed information on the activities of specific APT groups.

These threat intelligence analyses, known as ESET APT Reports, help organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from cyberattacks by criminal organizations and states.

More information about ESET APT reporting and providing high-quality, actionable tactical and strategic cybersecurity threat intelligence is available on the ESET Threat Intelligence page.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).