ESET APT Activity Report Q4 2023–Q1 2024
ID: c2fa3bf9-0a43-5b37-86c6-31408b31a23f
STIX ID: report--c2fa3bf9-0a43-5b37-86c6-31408b31a23f
Feed Name: WeLiveSecurity (ESET Research)
ESET's APT Activity Report Q4 2023–Q1 2024 provides an intelligence overview of notable APT operations observed from October 2023 through March 2024, documenting China-, Iran-, North Korea-, Russia- and regionally-aligned actors exploiting VPNs, firewalls, Confluence, Microsoft Exchange and a zero-day in Roundcube, supply-chain compromises and trojanized installers, a confirmed data leak linked to I-SOON/FishMonger, the emergence of a new China-aligned group (CeranaKeeper), and shifts toward more aggressive access-brokering and impact operations; findings are based on ESET telemetry and analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
