Chinese APTs intensify espionage operations

ESET Research Center has published its latest APT Activity Report, which presents the actions of selected groups of advanced persistent threats (APTs) recorded by ESET researchers from October 2025 to March 2026.

During this period, China-linked threat actors remained highly active globally, conducting espionage campaigns shaped in part by geopolitical developments that affected Beijing’s economic and national interests. Following the US military operation in Venezuela and amid ongoing instability in the Gulf region, ESET identified indications that China-linked groups have intensified their activity, seeking to enhance intelligence collection on developments in the shipping and energy sectors, as well as political developments internationally.china hackers

See more articles from iGuRu.gr when you search for news on Google.

The North Korean-linked Andariel group attacked a company that appears to be involved in nuclear energy, while the Chinese-linked FamousSparrow targeted a Venezuelan state agency responsible for shipping, likely to monitor the resilience of oil shipments following the US intervention.

ESET also detected activity by SteppeDriver, another Chinese-linked APT group, which has focused its attention on Syria. This activity may reflect both China’s commercial interest in the country’s reconstruction projects and its security concerns related to Uyghur militants there.

Additionally, the SPAWN malware family of the UNC5221 group, also linked to China, attacked government agencies in Cambodia and Panama, as well as an artificial intelligence and robotics company in South Korea. This attack is consistent with Beijing’s long-standing interest in strategic technologies that are a priority under its “Made in China 2025” industrial policy.

“In Asia, campaigns focused primarily on government agencies, strategic industries, and high-tech sectors. In the Middle East, Israel remained the primary target of groups supported or affiliated with Iran. Attacks targeted state organizations and device manufacturers,” says Jean-Ian Boutin, Threat Research Director at ESET.

The conflict in Iran, which erupted in late February 2026, was the defining event for activity during this period. Surprisingly, the conflict coincided with a decrease in activity by established APT groups linked to Iran, according to ESET telemetry. A possible reason was the Iranian regime’s internet restrictions, which limited their operational capacity.

At the same time, this environment appears to have favored the mobilization of intermediaries and hacktivists targeting Israel, the United States, and other states perceived as hostile to Tehran. ESET Research also recorded an unusual increase in activity against Israeli targets, which it was unable to attribute with certainty to already known groups.

Two groups of unknown origin, Rusty Boots and MoKhargosh, demonstrated both espionage and offensive capabilities against Israel. Among other things, they developed a bootkit-style wiper, while maintaining tools of destruction ready for future use.

ESET researchers also discovered a breach at a defense company in the United Arab Emirates, as well as an attack on Arabic-speaking users via Android spyware. The attack appears to have targeted journalists or open source intelligence (OSINT) professionals, as the name of the Telegram channel used by the attackers was likely inspired by Live Universal Awareness Map (Liveuamap), a legitimate and widely known OSINT platform specializing in global incident reporting.

Meanwhile, North Korea-linked threat actors remained highly active on multiple fronts. Several of them continued to target developers and the cryptocurrency ecosystem through social engineering campaigns, which can yield both direct financial gain and opportunities for software supply chain breaches. ESET also uncovered the resurgence of the Andariel group in attacks against South Korea. According to the research, the group used TigerRAT and attempted to spread the Rook ransomware to a company that appears to manufacture equipment related to liquid hydrogen management and the nuclear power industry, technologies of interest to Pyongyang’s ballistic and nuclear ambitions.

Russia-linked threat actors continued to focus primarily on Ukraine and organizations supporting the country’s defense efforts. The Sednit group used the Covenant and BeardShell malware tools against Ukrainian military personnel, drone manufacturers, and organizations involved in research and development of unmanned aerial vehicles. It also targeted logistics and transportation companies outside of Ukraine.

The Sandworm group intensified its destructive activities over the winter, using several new data deletion malware against state and private entities in Ukraine. Of particular note was a data destruction incident in December 2025 that affected a Polish energy company, which ESET attributed to Sandworm with a moderate degree of certainty.

ESET products protect customers’ systems from the malicious activities described in this report. The information presented is based primarily on proprietary ESET telemetry data and has been verified by ESET researchers. Researchers produce detailed technical reports and regular activity updates that document the actions of specific groups of advanced persistent threats (APTs).

These analyses, known as APT Reports, support organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from cyberattacks originating from either criminal groups or state-backed actors.

More information about ESET's APT reports is available on the "ESET Threat Intelligence" page.

For more details on the activities of APT groups, read the full APT Activity Report, “ Conflict-informed espionage: Monitoring oil shipments, targeting drone makers, ” on WeLiveSecurity.com.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).