logo

ESET APT Activity Report Q4 2024–Q1 2025: Malware sharing, wipers and exploits

ID: f57b472b-2356-5e7e-9660-b8b576d1d89a

STIX ID: report--f57b472b-2356-5e7e-9660-b8b576d1d89a

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2025-07-01

Date Updated: 2026-05-01

...
...

ESET’s APT Activity Report (Q4 2024–Q1 2025) reviews active nation-state-aligned campaigns and tool-sharing that complicates attribution, highlighting UnsolicitedBooker’s persistent MarsSnake backdoor, Worok’s shared toolsets, Sednit’s Operation RoundPress targeting webmail platforms, Gamaredon’s ongoing activity in Ukraine, and Sandworm’s repeated deployment of the ZEROLOT data wiper.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.