×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET releases the latest APT report: the pro-Cinese groups expand the range of action, Iran intensifies diplomatic espionage

Customer Press Room

ESET releases the latest APT report: the pro-Cinese groups expand the range of action, Iran intensifies diplomatic espionage

by Grandangolo Communications / Thursday, 07 November 2024 / Published in Eset

The report summarizes the activities of the APT groups in the period April-September 2024

ESET, a global European leader in the cybersecurity market, has published l’ESET APT Activity Report, which summarizes the most relevant activities of groups specialized in Advanced Persistent Threats (APTs), which were documented between April and the end of September 2024.

ESET has observed significant expansion in its China-aligned MirrorFace Group targets. Usually focused on Japanese entities, it extended operations to a diplomatic organization in the European Union for the first time, while continuing to maintain focus on targets in Japan. Additionally, pro-China APT groups are increasingly using the open-source, cross-platform VPN SoftEther to maintain access to victims' networks. Researchers have also detected signs that Iranian groups are leveraging their cyber capabilities to support diplomatic espionage and, potentially, kinetic operations.

“Regarding China-aligned threat groups, we have detected extensive use of the SoftEther VPN by Flax Typhoon, we have observed Webworm move from its full backdoor to the use of SoftEther VPN Bridge on machines belonging to government organizations in the EU, and we have seen GALLIUM deploy SoftEther VPN servers at telecom operators in Africa,” he says Jean-Ian Boutin, Director of Threat Research di ESET. "For the first time, we observed MirrorFace targeting a diplomatic organization within the EU, a region that remains a focal point for several threat actors aligned with China, North Korea and Russia. Many of these groups are particularly focused on government entities and the defense sector," he adds.

Iran-aligned groups, however, have compromised several financial services companies in Africa – a continent of geopolitical importance to Iran – conducted cyber espionage operations against Iraq and Azerbaijan, neighboring countries with which Iran has complex relations, and intensified their interest in Israel's transportation sector. Despite the apparent geographic limitation, Iranian groups maintain a global focus, targeting diplomatic missions in France and educational institutions in the United States.

North Korea-aligned threat actors have continued their attempts to steal funds – both in traditional currencies and cryptocurrencies. We have observed these groups continue attacks against defense and aerospace companies in Europe and the United States, targeting cryptocurrency developers, think tanks and NGOs. One of these groups, Kimsuky, began exploiting Microsoft Management Console files, usually used by system administrators but capable of executing any command on Windows. Additionally, several North Korea-aligned groups have frequently abused popular cloud-based services.

Finally, ESET Research found that Russian-aligned cyberespionage groups frequently target webmail servers, such as Roundcube and Zimbra, usually with spearphishing emails that trigger known XSS vulnerabilities. In addition to Sednit, which targets government, academic and defense-related entities around the world, ESET has identified another Russian group, GreenCube, which steals email messages via XSS vulnerabilities in Roundcube. Other pro-Russian groups continue to focus on Ukraine, with Gamaredon having deployed massive spearphishing campaigns and updating its tools also using messaging apps such as Telegram and Signal. Additionally, Sandworm used a new backdoor for Windows called WrongSens. ESET also analyzed the public hacking and data leak of the Polish Anti-Doping Agency, likely compromised by a broker who shared access with the Belarus-aligned APT FrostyNeighbor group involved in disinformation campaigns against NATO.

In Asia, ESET noted that campaigns continue to focus primarily on government organizations. However, an increase in attacks on the education sector has been noted, particularly against researchers and academics from the Korean Peninsula and Southeast Asia. This shift is driven by threat actors aligned with the interests of China and North Korea. Lazarus, one of the North Korea-aligned groups, has continued to target organizations around the world in the financial and technology sectors. In the Middle East, several Iranian APT groups continued to target government organizations, with Israel as the most targeted country.

Over the past two decades, Africa has become an important geopolitical partner for China, and Chinese groups have been observed to be expanding their activities on that continent. In Ukraine, Russian-aligned groups remained the most active, hitting government bodies, the defense sector and essential services such as energy, water and heating hard.

The highlighted operations represent a cross-section of the threat landscape that ESET has analyzed in this period.

ESET solutions protect our customers' systems from the malicious activities described in the report. The information shared here is primarily based on ESET's proprietary telemetry data. Threat intelligence analyses, known as ESET APT Reports PREMIUM, help organizations tasked with protecting citizens, national critical infrastructure and high-value assets from criminally motivated, nation-state-directed cyber attacks. More information about ESET APT Reports PREMIUM, and its offering of high-quality, strategic, tactical and actionable information on cybersecurity threats, can be found at ESET Threat Intelligence.

Tagged under: Eset

About Grandangolo Communications

What you can read next

IDC MarketScape names ESET Major Player in two next-generation endpoint security reports
ESET announces the winners of Heroes of Progress 2022
ESET wins the title of Product of the Year 2024 of AV-COMPARATIVES

Customer Press Room

  • Acronis Introduces MDR by Acronis TRU to Offer MSPs 24/7 Threat Detection and Response

    The service allows MSPs to offer customers...
  • SentinelOne expands strategic partnership with Google Cloud to deliver AI-powered autonomous security on a global scale

    The partnership will lead to the development of new...
  • Vertiv Announces Expansion of Manufacturing Capacity in Infrastructure Solutions, Energy and Rack Systems to Meet Growing Demand

    New and expanded production facilities in America...
  • Eon and SentinelOne partner to improve cloud data security and AI resilience

    The combination of features will broaden the ...
  • Vertiv expands thermal portfolio with new wall cooling system for edge and small data rooms in EMEA

    Designed to operate 24/7 in busy environments...

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP