×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET APT Activity Report: Pro-Chinese groups targeting EU targets, Russia still focused on Ukraine

Customer Press Room

ESET APT Activity Report: Pro-Chinese groups targeting EU targets, Russia still focused on Ukraine

by Grandangolo Communications / Thursday, 26 October 2023 / Published in Eset

The report analyzes the activities of APT groups from April to September 2023. Highlighting the campaigns of pro-Chinese groups in the EU and the evolution of the Russian-Ukrainian cyber-war. Exploited WinRAR vulnerabilities in Microsoft Exchange and IIS servers. New groups close to China discovered

ESET, a global European leader in the cybersecurity market, has published the latest report on the activities of the APT (Advanced Persistent Threat) groups analyzed by researchers between April and September of this year. In particular, ESET Research has observed several APT groups exploiting known vulnerabilities to exfiltrate data from government agencies or related organizations. The report analyzes the persistent campaigns of China-aligned groups in the European Union and the evolution of Russia's cyber-war in Ukraine which is moving from sabotage towards espionage.

The pro-Russian Sednit and Sandworm, the North Korea-aligned Konni, and the geographically unattributable Winter Vivern and SturgeonPhisher took the opportunity to exploit vulnerabilities in WinRAR (Sednit, SturgeonPhisher, and Konni), Roundcube (Sednit and Winter Vivern), Zimbra (Winter Vivern), and Outlook for Windows (Sednit) to target various government organizations, not only in Ukraine but also in Europe and Asia central. As for China-affiliated threat actors, GALLIUM has likely exploited vulnerabilities in Microsoft Exchange or IIS servers, extending its target from telecom operators to government organizations around the world. MirrorFace likely took advantage of flaws in the online storage service Proself, and TA410 is alleged to have exploited vulnerabilities in the Adobe ColdFusion application server.

Iran- and Middle East-aligned groups continued to operate at full speed, focusing primarily on espionage and theft of data from organizations in Israel. Notably, Iran-affiliated MuddyWater also targeted an unknown target in Saudi Arabia, deploying a payload that raises the possibility that the attacker serves as a development team for a more advanced group.

The main target of the Russian-aligned groups remained Ukraine, where ESET detected new versions of the familiar wipers RoarBat and NikoWiper and a new wiper that was named SharpNikoWiper, all distributed by Sandworm. Interestingly, while other groups – such as Gamaredon, GREF and SturgeonPhisher – target Telegram users to try to exfiltrate information, or at least some Telegram-related metadata, Sandworm actively uses this service in order to publicize its cybersabotage operations. However, the most active group in Ukraine continued to be Gamaredon, which significantly improved its data collection capabilities, reworking existing tools and implementing new ones.

North Korea-aligned groups continued to focus on Japan, South Korea, and organizations in the country, using carefully crafted spear phishing emails. The most active Lazarus scheme observed is Operation DreamJob, which lured targets with fake job offers for lucrative positions. This group has demonstrated the ability to create malware for all major desktop platforms.

Finally, ESET researchers uncovered the activities of three previously unidentified China-aligned groups: DigitalRecyclers, which repeatedly compromised a government organization in the EU; TheWizards, which conducted adversary-in-the-middle attacks, and PerplexedGoblin, which targeted another government organization in the EU.

ESET APT Activity Reports contain only a portion of the cybersecurity intelligence data provided to customers. ESET produces in-depth technical reports and frequent updates on the activities of specific APT groups in the form of ESET APT Reports PREMIUM to help organizations tasked with protecting citizens, national critical infrastructure and high-value assets from criminal and nation-state-directed cyberattacks. Detailed information on the tasks described in this document has therefore previously been provided exclusively to ESET Premium customers. Further information on ESET APT PREMIUM Reports, which provide high-quality information on strategic and tactical cybersecurity threats, is available at ESET Threat Intelligence.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET presents the new features for contrasting ransomware and Ai Advisor updates
ESET's detection & response capabilities put to the test in the MITER Engenuity ATT&CK® Evaluations
ESET Mobile Security for a safe return to class

Customer Press Room

  • ESET releases SMB IT Readiness Index 2026, highlighting growing confidence but also concerns about AI technologies

    The majority of SMEs declare themselves optimistic...
  • ESET discovers the new arsenal of Webworm, a pro-Chinese APT active against European governments

    ESET Research analyzed recent activity…
  • Arrow Electronics expands distribution agreement with Veeam in EMEA

    Arrow Electronics, a global supplier of technology...
  • ESET Research APT Report: China-aligned groups spy on Venezuela and Gulf, targeting AI robotics in South Korea

    L’ultimo APT Activity Report di ESET Research t...
  • ESET accelerates AI innovation with investments aimed at managing a rapidly expanding attack surface

    ESET announces a 40 million investment ...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP