No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Attacks by China-, North Korea-, and Iran-aligned Threat Actors; Russia Eyes Ukraine and the EU

May 9, 2023
in Protection
0
KnowBe4 Launches Password Kit to Celebrate World Password Day


BRATISLAVA — ESET has released its APT Activity Report, which summarizes the activities of selected advanced persistent threat (APT) groups that were observed, investigated, and analyzed by ESET researchers from October 2022 until the end of March 2023. The report is being published on a semi-annual basis. During this period, several China-aligned threat actors such as Ke3chang and Mustang Panda focused on European organizations. In Israel, Iran-aligned group OilRig deployed a new custom backdoor. North Korea-aligned groups continued to focus on South Korean and South Korea-related entities. Russia-aligned APT groups were especially active in Ukraine and EU countries, with Sandworm deploying wipers.

Malicious activities described in the ESET APT Activity Report are detected by ESET technology. “ESET products protect our customers’ systems from the malicious activities described in this report. The intelligence shared here is based mostly on proprietary ESET telemetry data and has been verified by ESET researchers,” says Director of ESET Threat Research Jean-Ian Boutin.

China-aligned Ke3chang employed tactics such as the deployment of a new Ketrican variant, and Mustang Panda used two new backdoors. MirrorFace targeted Japan and implemented new malware delivery approaches, while Operation ChattyGoblin compromised a gambling company in the Philippines by targeting its support agents. India-aligned groups SideWinder and Donot Team continued to target governmental institutions in South Asia with the former targeting the education sector in China, and the latter continuing to develop its infamous yty framework, but also deploying the commercially available Remcos RAT. Also in South Asia, ESET Research detected a high number of Zimbra webmail phishing attempts.

In addition to targeting the employees of a defense contractor in Poland with a fake Boeing-themed job offer, North Korea-aligned group Lazarus also shifted its focus from its usual target verticals to a data management company in India, utilizing an Accenture-themed lure. ESET also identified a piece of Linux malware being leveraged in one of their campaigns. Similarities with this newly discovered malware corroborate the theory that the infamous North Korea–aligned group is behind the 3CX supply-chain attack.

Russia-aligned APT groups were especially active in Ukraine and EU countries, with Sandworm deploying wipers (including a new one ESET calls SwiftSlicer), and Gamaredon, Sednit, and the Dukes utilizing spearphishing emails that, in the case of the Dukes, led to the execution of a red team implant known as Brute Ratel. Finally, ESET detected that the previously mentioned Zimbra email platform was also exploited by Winter Vivern, a group particularly active in Europe, and researchers noted a significant drop in the activity of SturgeonPhisher, a group targeting government staff of Central Asian countries with spearphishing emails, leading to our belief that the group is currently retooling.

For more technical information, check the full “ESET APT Activity Report” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

ESET APT Activity Reports contain only a fraction of the cybersecurity intelligence data provided to customers of ESET’s private APT reports. ESET researchers prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups in the form of ESET APT Reports PREMIUM to help organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks. Comprehensive descriptions of activities described in this document were therefore previously provided exclusively to our premium customers. More information about ESET APT Reports PREMIUM that deliver high-quality strategic, actionable, and tactical cybersecurity threat intelligence is available at the ESET Threat Intelligence page.

About ESET

For more than 30 years, ESET® has been developing industry-leading IT security software and services to protect businesses, critical infrastructure, and consumers worldwide from increasingly sophisticated digital threats. From endpoint and mobile security to endpoint detection and response, as well as encryption and multifactor authentication, ESET’s high-performing, easy-to-use solutions unobtrusively protect and monitor 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company that enables the safe use of technology. This is backed by ESET’s R&D centers worldwide, working in support of our shared future. For more information, visit www.eset.com or follow us on LinkedIn, Facebook, and Twitter.



Editorial Team

Editorial Team

Related Posts

The Top 10 TV Series in January 2026, According to Streaming Data
Protection

The Top 10 TV Series in January 2026, According to Streaming Data

February 6, 2026
These Sony Over-Ear Headphones Come in Three Colors and Are Under $100 Right Now
Protection

These Sony Over-Ear Headphones Come in Three Colors and Are Under $100 Right Now

February 6, 2026
A Sling One-Day Pass Is the Best Way to Catch a Major Sporting Event Without Cable
Protection

A Sling One-Day Pass Is the Best Way to Catch a Major Sporting Event Without Cable

February 6, 2026
The TCL QM5K Was Already Affordable, and Now It's an Extra $450 Off
Protection

The TCL QM5K Was Already Affordable, and Now It’s an Extra $450 Off

February 5, 2026
What to Do If Your Car Icon Disappears From Google Maps in Android Auto
Protection

What to Do If Your Car Icon Disappears From Google Maps in Android Auto

February 5, 2026
Apple's 'Lockdown Mode' Could Stop the Government From Breaking Into Your iPhone
Protection

Apple’s ‘Lockdown Mode’ Could Stop the Government From Breaking Into Your iPhone

February 5, 2026
Load More
Next Post
Stock tanks 8% after bookings miss

Stock tanks 8% after bookings miss

Popular News

  • Hargreaves Lansdown hits 2m clients and record AUA

    Hargreaves Lansdown hits 2m clients and record AUA

    0 shares
    Share 0 Tweet 0
  • I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0
  • My brother, a corporate lawyer, refuses to sell our family’s $175K lake house. Do I push the issue and risk ruining our relationship?

    0 shares
    Share 0 Tweet 0
  • As Jamie Dimon stakes his reputation, are more banks about to fall?

    0 shares
    Share 0 Tweet 0
  • Meet the billionaire with close royal ties behind Trump’s tariffs: How Scott Bessent made his name by almost bankrupting British homeowners but could now be the UK’s economic lifeline

    0 shares
    Share 0 Tweet 0

Latest News

‘I love being debt-free’: I’m in my mid-50s and buying a house. Do I take out a $400K mortgage or use my Roth IRA?

‘I love being debt-free’: I’m in my mid-50s and buying a house. Do I take out a $400K mortgage or use my Roth IRA?

February 6, 2026
0

“I’ll fund $500,000 of that from the sale of my current house.”

Circle Partners Polymarket to Integrate Native USDC, Eliminating Bridge Risk

Circle Partners Polymarket to Integrate Native USDC, Eliminating Bridge Risk

February 6, 2026
0

Key NotesThe platform transitions from Polygon-bridged USDC.e to Circle's native stablecoin for direct dollar redemption.Native integration removes vulnerabilities associated with...

Starbucks wins dismissal of Missouri lawsuit over DEI policies

Starbucks wins dismissal of Missouri lawsuit over DEI policies

February 6, 2026
0

Starbucks wins dismissal of Missouri lawsuit over DEI policies

The Top 10 TV Series in January 2026, According to Streaming Data

The Top 10 TV Series in January 2026, According to Streaming Data

February 6, 2026
0

We may earn a commission from links on this page. January 2026's ten most-streamed TV series are a balanced group,...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.