September 2025 APT Group Trends
ID: b160b056-460f-56b3-9a9d-0b25bf0bf113
STIX ID: report--b160b056-460f-56b3-9a9d-0b25bf0bf113
Feed Name: ASEC
Executive summary: This intelligence brief details multiple North Korea-linked APT campaigns (Kimsuky, Lazarus, TA-RedAnt/APT37) targeting defense, research, cryptocurrency, and retail sectors using advanced social engineering (spear-phishing, deepfake military IDs, ClickFix), repository-based distribution, and a range of malware (MSC/AutoIt/PowerShell loaders, BeaverTail, InvisibleFerret, Rustonotto, Chinotto, FadeStealer). The report lists tactics, persistence mechanisms, and sample artefacts/filenames, describing sustained information-stealing and remote-access operations with potential credential and sensitive data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
