×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Information Tecnology
  • ESET APT Activity Report: Attacks by groups affiliated with China, North Korea and Iran. Russia looks to Ukraine and the EU

Customer Press Room

ESET APT Activity Report: Attacks by groups affiliated with China, North Korea and Iran. Russia looks to Ukraine and the EU

by Grandangolo Communications / Wednesday, 10 May 2023 / Published in Information Tecnology

The report summarizing the activities of the APT groups in Q4 2022 and Q1 2023 has been published

Milan, 10 May 2023 – ESET, a global European leader in the cybersecurity market, has published l’ESET APT Activity Reportwhich provides an analysis of ESET's research on the activities of Advanced Persistent Threat Groups (APTs), covering the period October 2022 – March 2023. The Report is released on a semi-annual basis. During this time, several China-affiliated groups, such as e3chang and Mustang Panda, focused on European organizations. In Israel, Iran-aligned group OilRig has implemented a new custom backdoor. Groups pro-North Korea continued to focus on South Korean and South Korean-related subjects. Pro-Russian APT groups were particularly active in Ukraine and European Union countries, with Sandworm distributing wipers.

The activities described in the report are detected by ESET technology. “ESET products protect our customers' systems from the malicious activity described in this report. The shared information is mainly based on ESET's proprietary telemetry data and has been verified by ESET researchers,” he explains Jean-Ian Boutin, Direttore di ESET Threat Research.

China-affiliated Ke3chang resorted to distributing a new variant of Ketrican, while Mustang Panda used two new backdoors. MirrorFace targeted Japan and implemented new malware distribution approaches, while Operation ChattyGoblin compromised a gambling company in the Philippines by targeting its support workers. The India-aligned SideWinder and Donot Team continued to target government institutions in South Asia: the former targeted the education sector in China, while the latter continued to develop the infamous yty framework, but also implemented the commercially available Remcos RAT. Also in South Asia, ESET Research has detected a high number of Zimbra webmail phishing attempts.

In addition to targeting employees of a defense contractor in Poland with a bogus Boeing-themed job offer, the Lazarus Group, near North Korea, has also shifted its focus from its usual vertical targets to a data management in India, using an Accenture themed lure. ESET has also identified a component of Linux malware exploited in one of their campaigns. The similarities to this newly discovered malware support the notion that the group is responsible for the attack on the 3CX supply chain.

Russian-aligned APT groups have been particularly active in Ukraine and EU countries, with Sandworm deploying wipers (including a new one that ESET calls SwiftSlicer) and Gamaredon, Sednit and Dukes using spearphishing emails that , in the case of Dukes, led to the execution of a red team rig known as Brute Ratel. Finally, ESET found that the aforementioned Zimbra email platform was also being exploited by Winter Vivern, a group particularly active in Europe, and researchers noticed a significant drop in the activity of SturgeonPhisher, a group that targets government of Central Asian countries with spearphishing emails, suggesting that the group is currently reorganizing.

For more technical information, consult the full version of theESET APT Activity Report su WeLiveSecurity.

ESET APT Activity Reports contain only a fraction of the cybersecurity intelligence data provided to customers. ESET produces in-depth technical reports and frequent updates on the activities of specific APT groups in the form of ESET APT Reports PREMIUM to help organizations charged with protecting citizens, critical national infrastructure and high-value assets from criminal and nation-state-directed cyber-attacks. More information on ESET APT Reports PREMIUM, which provides high-quality information on strategic and tactical cybersecurity threats, can be found at ESET Threat Intelligence.

Tagged under: ESET APT Activity Report

About Grandangolo Communications

What you can read next

ESET discovers the first UEFI bootkit for Linux
ESET releases latest APT Activity Report highlighting cyber warfare from groups affiliated with Russia, China and Iran
HiSolution formalizes the appointment of Andrea Mariotti as CTO

Customer Press Room

  • VERTIV presents the range of overhead prefabricated infrastructures on a global level, to accelerate the implementation of data centers

    VERTIV ™ Smartrun facilitates installation ...
  • Axiante is a partner of the "Virtual Job Meeting Stem Girls" event

    Participation in the initiative dedicated to ...
  • Vertivia enhances the pre-engineered solution of data centers for EMEA Edge Computing to promote energy efficiency and fastest on-site installations

    La nuova soluzione Vertiv™ SmartAisle&#x...
  • ESET expands the Cyber ​​Threat Intelligence: new feeds and APT reports for companies of all sizes

    Announced at ESET World 2025, the expansion of ...
  • Sentinelone gives a change to the role of partners with the new Global Partnerone Program

    The program provides partners with the tools, ...

Archives

  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP