
ESET Research APT Report: Russian cyberattacks in Ukraine intensify; Sandworm unleashes new destructive wiper
Russian APT groups intensified attacks against Ukraine and the EU, exploiting zero-day vulnerabilities and deploying wipers.
China-aligned groups like Mustang Panda and DigitalRecyclers continued their espionage campaigns targeting the EU government and maritime sectors.
North Korea-aligned groups expanded their financially motivated campaigns using fake job listings and social engineering.
ESET Research has released its latest APT Activity Report, which highlights activities of select APT groups that were documented by ESET researchers from October 2024 through March 2025. During the monitored period, Russia-aligned threat actors, notably Sednit and Gamaredon, maintained aggressive campaigns primarily targeting Ukraine and EU countries. Ukraine was subjected to the greatest intensity of cyberattacks against the country's critical infrastructure and governmental institutions. The Russia-aligned Sandworm group intensified destructive operations against Ukrainian energy companies, deploying a new wiper named ZEROLOT. China-aligned threat actors continued engaging in persistent espionage campaigns with a focus on European organizations.
Gamaredon remained the most prolific actor targeting Ukraine, enhancing malware obfuscation and introducing PteroBox, a file stealer leveraging Dropbox. 'The infamous Sandworm group concentrated heavily on compromising Ukrainian energy infrastructure. In recent cases, it deployed the ZEROLOT wiper in Ukraine. For this, the attackers abused Active Directory Group Policy in the affected organizations,' says ESET Director of Threat Research Jean-Ian Boutin.
Sednit refined its exploitation of cross-site scripting vulnerabilities in webmail services, expanding Operation RoundPress from Roundcube to include Horde, MDaemon, and Zimbra. ESET discovered that the group successfully leveraged a zero-day vulnerability in MDaemon Email Server (CVE-2024-11182) against Ukrainian companies. Several Sednit attacks against defense companies located in Bulgaria and Ukraine used spearphishing email campaigns as a lure. Another Russia-aligned group, RomCom, demonstrated advanced capabilities by deploying zero-day exploits against Mozilla Firefox (CVE 2024 9680) and Microsoft Windows (CVE 2024 49039).
In Asia, China-aligned APT groups continued their campaigns against governmental and academic institutions. At the same time, North Korea-aligned threat actors significantly increased their operations directed at South Korea, placing particular emphasis on individuals, private companies, embassies, and diplomatic personnel. Mustang Panda remained the most active, targeting governmental institutions and maritime transportation companies via Korplug loaders and malicious USB drives. DigitalRecyclers continued targeting EU governmental entities, employing the KMA VPN anonymization network and deploying the RClient, HydroRShell, and GiftBox backdoors. PerplexedGoblin used its new espionage backdoor, which ESET named NanoSlate, against a Central European government entity, while Webworm targeted a Serbian government organization using SoftEther VPN, emphasizing the continued popularity of this tool among China-aligned groups.
Elsewhere in Asia, North Korea-aligned threat actors were particularly active in financially motivated campaigns. DeceptiveDevelopment significantly broadened its targeting, using fake job listings primarily within the cryptocurrency, blockchain, and finance sectors. The group employed innovative social engineering techniques to distribute the multiplatform WeaselStore malware. The Bybit cryptocurrency theft, attributed by the FBI to TraderTraitor APT group, involved a supply-chain compromise of Safe{Wallet} that caused losses of approximately USD 1.5 billion. Meanwhile, other North Korea-aligned groups saw fluctuations in their operational tempo: In early 2025, Kimsuky and Konni returned to their usual activity levels after a noticeable decline at the end of 2024, shifting their targeting away from English-speaking think tanks, NGOs, and North Korea experts to focus primarily on South Korean entities and diplomatic personnel; and Andariel resurfaced, after a year of inactivity, with a sophisticated attack against a South Korean industrial software company.
Iran-aligned APT groups maintained their primary focus on the Middle East region, predominantly targeting governmental organizations and entities within the manufacturing and engineering sectors in Israel. Additionally, ESET observed a significant global uptick in cyberattacks against technology companies, largely attributed to increased activity by North Korea-aligned DeceptiveDevelopment.
'The highlighted operations are representative of the broader threat landscape that we investigated during this period. They illustrate the key trends and developments, and contain only a small fraction of the cybersecurity intelligence data provided to customers of ESET APT reports,' adds Boutin.
Intelligence shared in the private reports is primarily based on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports PREMIUM, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks. More information about ESET APT Reports PREMIUM and its delivery of high-quality, actionable tactical and strategic cybersecurity threat intelligence is available at the ESET Threat Intelligence page.
Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.
About ESET
ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it's endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Al-Ahram Weekly
13 hours ago
- Al-Ahram Weekly
EU says China's links with Russia now 'determining factor' in ties - International
EU chief Ursula von der Leyen warned on Thursday that China's ties with Russia were now the "determining" factor in its relations with the European Union, as she wrapped up a tense summit in Beijing that also saw China agree to speed up exports of rare earth minerals to the bloc. China's leadership has sought to draw the European Union closer as it positions itself as a more reliable partner than the United States and a bedrock of stability in a troubled world. But while nominally intended to celebrate 50 years of diplomatic ties, the EU has made clear there are deep divisions over trade, fears that cheap, subsidised Chinese goods could overwhelm European markets and Beijing's tacit support for Russia's war against Ukraine. Brussels says China's deepening political and economic relations with Moscow since the 2022 invasion have helped Russia's economy weather sweeping Western sanctions. Beijing denies that claim. Wrapping up that summit, von der Leyen told a news conference in Beijing that the bloc had made clear that the issue was now the "determining" factor in its relations with China. She and European Council President Antonio Costa expressed "our expectations that China would follow up on our concerns and the expectation that it would use its influence to bring Russia to accept a ceasefire, to come to the negotiation table, enter peace talks and put an end to the bloodshed", von der Leyen said. She also said the bloc agreed with Beijing to an "upgraded" mechanism for Chinese exports of rare earth minerals -- another key sticking point in ties. China dominates the global industry for extracting and refining rare earths. Since April, it has required licences to export some of the strategic materials, triggering anxiety among businesses worldwide. "If there is a delay... we have now established a mechanism where the companies can immediately ask us to mediate and to find out why there's a delay on the delivery of the critical raw materials," von der Leyen said. And Costa said the officials had raised human rights concerns with Chinese counterparts. 'Deepen cooperation' China, in contrast, framed Thursday's summit as a way for the bloc and Beijing to deepen trust in a turbulent world. Welcoming von der Leyen and Costa at Beijing's ornate Great Hall of the People, President Xi Jinping said "the more severe and complex the international situation is, the more important it is for China and the EU to strengthen communication, increase mutual trust and deepen cooperation". "The challenges facing Europe at present do not come from China," he said, calling on both sides to "make correct strategic choices". Costa also stressed to the Chinese leader that the EU wanted to see "concrete progress on issues related to trade and the economy, and we both want our relationship to be... mutually beneficial". Chinese Premier Li Qiang told the EU leaders in a separate meeting that "close cooperation" was a "natural choice" for the two major economies. "As long as both China and the EU earnestly uphold free trade, the international economy and trade will stay dynamic", he said. - Climate agreement - In rare agreement, China and the EU vowed to "step up" efforts to address climate change. The warming planet is historically an area of convergence between Brussels and Beijing, with both willing to cooperate on combating climate change. Chinese and European leaders agreed on enhancing bilateral cooperation in energy transition and committed to accelerating global renewable energy deployment, a joint statement said. The EU also flagged its yawning trade deficit with China that stood at around $360 billion last year and which von der Leyen described as "unsustainable". Beijing dismissed those concerns, insisting that Brussels must "rebalance its mentality", not its economic ties with China. If EU concerns were not addressed, "our industry and citizens will demand that we defend our interests", von der Leyen told Premier Li. The EU has imposed hefty tariffs on electric vehicles imported from China, arguing that Beijing's subsidies unfairly undercut European competitors. China has rebuffed that claim and announced what were widely seen as retaliatory probes into imported European pork, brandy and dairy products. Follow us on: Facebook Instagram Whatsapp Short link:


Tahya Masr
a day ago
- Tahya Masr
Crédit Agricole Egypt and Infinity Join Forces to Accelerate Transition to Solar Energy
Crédit Agricole Egypt has entered into a partnership with Infinity to accelerate the transition to solar energy for individuals by making clean energy solutions more accessible and affordable. The signing ceremony was attended by Mr. Jean-Pierre Trinelle, Managing Director of Crédit Agricole Egypt, and Mr. Ashraf El Bishry, General Manager of Infinity, along with senior representatives from both entities. Through this partnership, Infinity's customers will have access to Crédit Agricole Egypt's solar loan—a tailored financing solution offering preferential interest rates and repayment terms up to seven years. The loan enables individuals to invest in a range of solar products —including solar home solutions for residential clients — effectively reducing financial barriers and encouraging the adoption of sustainable energy systems. This agreement aims to raise awareness about the environmental and economic benefits of solar energy, empowering individuals to make more eco-conscious decisions and contribute to a greener future. It also aligns with Egypt's Vision 2030 and the Central Bank of Egypt's sustainable finance principles, reinforcing broader efforts to embed ESG principles into financial practices, diversify the energy mix, and reduce carbon emissions. Jean-Pierre Trinelle, Managing Director of Crédit Agricole Egypt said: 'At Crédit Agricole, sustainability is central to our mission, and we are committed to carbon neutrality by 2050 for both our own operations & financed emissions. Through this partnership, CAE continues to reflect its customer-centric approach by offering accessible green financing solutions tailored to meet our customers' evolving needs. By combining our financial expertise with Infinity's leadership in solar energy technology, we are expanding our impact, and advancing our long-term commitment to the energy transition.' Nevine Shokry, Head of proximity Banking of Crédit Agricole Egypt added: 'At Crédit Agricole Egypt, our green finance solutions reflect our commitment to helping customers take meaningful steps towards sustainability. This collaboration with Infinity embodies our shared belief that real success lies in empowering individuals, supporting communities, and protecting our planet.' Commenting on the strategic partnership, Mohamed Ismail Mansour, Co-Founder and CEO of Infinity, said: "At Infinity, we are committed to supporting the widespread adoption of clean, renewable energy solutions that can positively impact people's lives and the environment. This partnership with Crédit Agricole Egypt is an important step in making solar energy more accessible to households across the country. By combining financial innovation with practical, scalable technology, we are enabling individuals to become active participants in Egypt's clean energy future." Eng. Nayer Fouad, Co-Founder and CEO of Infinity, further added: "This collaboration reflects our mission to deliver real, tangible solutions that support Egypt's clean energy goals. By working alongside a trusted partner like Crédit Agricole Egypt, we are not only making renewable energy more attainable but also fostering greater awareness around the benefits of solar adoption at the individual and household levels. It's another milestone in our journey to drive long-term environmental and economic value.' Infinity, established in 2014, is Egypt's leading provider of renewable energy solutions, delivering clean power solutions across all sectors and scales. The company develops, finances, and operates utility-scale and decentralized solar projects. Infinity is the largest Egyptian contributor to the Benban Solar Park, Africa's largest photovoltaic power station, with an estimated capacity of 1,465 MW. Since 2018, Infinity has also built the largest and fastest-growing EV charging network in Egypt, with more than 700 charging points across 16 governorates. Backed by institutional shareholders such as Africa Finance Corporation (AFC) and the European Bank for Reconstruction and Development (EBRD), Infinity is positioned at the forefront of Egypt and Africa's energy transition journey . Crédit Agricole Egypt is a subsidiary of the Crédit Agricole Group, one of the largest banks worldwide, and is the sole French bank operating in Egypt. Established in 2006, Crédit Agricole Egypt has become an active player in Egypt's financial industry, serving around 500,000 individual, SME, and corporate clients. The bank offers a comprehensive range of banking products & services, as well as state-of-the-art digital banking solutions. Crédit Agricole Egypt's key goal is customer satisfaction, by valuing and prioritizing their best interests. Demonstrating its strong commitment to sustainability, Crédit Agricole Egypt was the first bank in Egypt and North Africa to receive the prestigious Platinum LEED certification for its head office in recognition of its environmentally responsible design, which incorporates a solar panel station that helps reduce CO₂ emissions. Further advancing the green transition, Crédit Agricole Egypt has signed a facility agreement with the European Bank for Reconstruction and Development (EBRD) under the Green Energy Finance Facility (GEFF) and the Global Climate Fund (GCF), to support businesses investing in energy efficiency and renewable energy projects'


Al-Ahram Weekly
2 days ago
- Al-Ahram Weekly
Global markets gain and deal on Trump's tariffs lifts Japan's Nikkei 3.5% - Markets & Companies
Global shares rallied on Wednesday, with Tokyo's benchmark Nikkei 225 index gaining 3.5% after Japan and the U.S. announced a deal on President Donald Trump's tariffs. France's CAC 40 added 1.4% in early trading to 7,854.75, while Germany's DAX gained 0.9% to 24,260.62. Britain's FTSE 100 rose 0.6% to 9,075.46. The future for the S&P 500 gained 0.4% while that for the Dow Jones Industrial Average was up 0.5%. The tariff agreement as announced calls for a 15% US import duty on goods from Japan, apart from certain products such as steel and aluminum that are subject to much higher tariffs. That's down from the 25% Trump had said would kick in on Aug. 1 if a deal was not reached. 'This Deal will create Hundreds of Thousands of Jobs — There has never been anything like it,' Trump posted on Truth Social, noting that Japan was also investing 'at my direction' $550 billion into the US He said Japan would 'open' its economy to American autos and rice. Japan's benchmark Nikkei 225 surged as much as 3.7%, closing at 41,171.32. Hong Kong's Hang Seng jumped 1.6% to 25,538.07, while the Shanghai Composite index was little changed, gaining less than 0.1% to 3,582.30. Australia's S&P/ASX 200 edged up 0.7% to 8,737.20 and the Kospi in South Korea edged 0.4% higher to 3,183.77. 'President Trump has signed two trade deals this week with the Philippines and Japan which is likely to keep market sentiment propped up despite deals with the likes of the EU and South Korea remaining elusive, for now at least,' Tim Waterer, chief market analyst at Kohle Capital Markets, said in a report. There was a chorus of no comments from the Japanese automakers, despite the latest announcement, including Toyota Motor Corp., Honda Motor Co and Nissan Motor Corp. Japanese companies tend to be cautious about their public reactions, and some business officials have privately remarked in off-record comments that they hesitate to say anything because Trump keeps changing his mind. The Japan Automobile Manufacturers' Association also said it had no comment, noting there was no official statement yet. Japan's Prime Minister Shigeru Ishiba welcomed the agreement as beneficial to both sides. Toyota stock jumped 14% in Tokyo trading, while Honda was up more than 11% and Nissan added 8%. In other sectors, Nippon Steel, which is acquiring US Steel, rose 2.7% while video game maker and significant exporter Nintendo Co. added 0.7%. Sony Group surged 4.3%. But Takeshi Niinami, chairman of the Japan Association of Corporate Executives, which groups about 1,600 top executives, issued a note of caution about the nation having to be resilient and pushing free trade, while welcoming the tariff deal. 'I hope this US-Japan tariff deal can work as a starting point to further strengthen US-Japan relations,' he said. He noted the US policy of putting America first was unlikely to change, and that meant Japan, too, must make policy adjustments, such as making an aggressive push in artificial intelligence. Trump has also said that he reached a trade agreement with the Philippines following a meeting Tuesday at the White House, that will see the US slightly drop its tariff rate for the Philippines without paying import taxes for what it sells there. On Tuesday, the S&P 500 added 0.1% to Monday's all-time high. The Dow Jones Industrial Average rose 0.4%, while the Nasdaq slipped 0.4%. Also early Wednesday, US benchmark crude oil lost 23 cents to $65.08 a barrel. Brent crude, the international standard fell 21 cents to $68.38 a barrel. The US dollar fell to 146.38 Japanese yen from 146.64 yen. The euro cost $1.1736, down from $1.1754. Follow us on: Facebook Instagram Whatsapp Short link: