ESET, a global leader in the cybersecurity market, following the success achieved with l’ESET Threat Report, introduce l’ESET APT Activity Report, with the aim of providing a periodic analysis of ESET's research on the activities of APT - advanced persistent threat groups. In the first edition, covering Q2 2022 (May-August 2022), ESET Research found no decline in APT activity carried out by groups aligned with Russia, China, Iran and North Korea. Even more than eight months after the Russian invasion, Ukraine remains a primary target of APT groups close to Russia, such as the infamous Sandworm, but also Gamaredon, InvisiMole, Callisto and Turla. The aerospace and defense industry, as well as financial and cryptocurrency businesses and exchanges, continue to be of great interest to North Korea-affiliated groups.
"We noticed that in Q2 2022, several groups close to Russia used the Russian cross-platform messaging service Telegram to access C&C servers or as a tool to leak information. Threat actors from other areas also sought access to Ukrainian organizations, both for cyber espionage activities and intellectual property theft," he explains Jean-Ian Boutin, Direttore di ESET Threat Research.
"The aerospace and defense industry remains of interest to groups affiliated with North Korea: Lazarus targeted an employee of an aerospace company in the Netherlands. According to our research, the group exploited a vulnerability in a legitimate Dell driver to infiltrate the company, and we believe this is the first documented case of abuse of this vulnerability in the world," continues Boutin.
Financial institutions and entities that operate with cryptocurrencies have been targeted by Kimsuky, aligned with North Korea, and by two Lazarus campaigns. One of these, called Operation In(ter)ception by ESET researchers, broke away from the usual target of the aerospace and defense industries by hitting an Argentine user with malware disguised as a job offer on Coinbase. ESET also spotted Konni using a technique employed by Lazarus in the past: a trojanized version of the Sumatra PDF viewer.
China-aligned groups continue to be very active, using various previously unreported vulnerabilities and backdoors. ESET has identified a Linux variant of a backdoor used by SparklingGoblin against a Hong Kong university. The same group exploited a Confluence vulnerability to target a food manufacturing company in Germany and a U.S.-based engineering firm. ESET Research also suspects that a ManageEngine ADSelfService Plus vulnerability is behind the breach of a US defense contractor, whose systems were compromised just two days after the vulnerability was publicly disclosed. In Japan, ESET Research identified several MirrorFace campaigns, one of which was directly linked to the House of Councilors elections.
The growing number of Iran-aligned groups continued to focus their efforts primarily on several Israeli verticals. ESET researchers were able to attribute a campaign that affected a dozen organizations in Israel to POLONIUM and identify several previously undocumented backdoors. Diamond industry and diamond-related organizations in South Africa, Hong Kong and Israel were targeted by Agrius in what ESET Research considers to be a supply-chain attack that exploited an Israeli software suite in use in the industry. In another campaign in Israel, indicators of a possible combination of tool use between the MuddyWater and APT35 groups were detected. ESET Research also discovered a new version of Android malware in a campaign led by the APT-C-50 group; it was distributed by an Iranian website emulator and has limited spying capabilities.






