logo

ESET APT Activity Report Q2 2025–Q3 2025

ID: 5ab5c329-46b8-5bf0-8daf-c625d0a50098

STIX ID: report--5ab5c329-46b8-5bf0-8daf-c625d0a50098

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-11-06

Date Updated: 2026-05-01

...
...

ESET's APT Activity Report Q2–Q3 2025 summarizes active nation-state-aligned and other APT campaigns observed April–September 2025, documenting China-, Russia-, Iran-, and North Korea-aligned actors (and others) targeting government, energy, healthcare, maritime, financial, and academic sectors across multiple regions; notable findings include a WinRAR zero-day exploited by RomCom, destructive wipers against Ukrainian targets, widespread spearphishing and adversary-in-the-middle techniques, credential- and email-stealers, new backdoors (e.g., BLOODALCHEMY, Kalambur), and an Android spyware family (Wibag) masquerading as YouTube.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.