The new report highlights an intensification of espionage and sabotage activities: groups aligned with China expand operations in LATAM, while those linked to Russia focus attacks on Ukraine and the EU, with a spearphishing campaign that exploited the name of ESET
ESET, a global leader in the cybersecurity market, has released the new APT Activity Report, which highlights the activities of some APT groups monitored by ESET researchers between April and September 2025. In recent months, China-aligned APT groups have continued to act in line with Beijing's geopolitical objectives. ESET has observed an increasing use of the adversary-in-the-middle technique for both initial access and lateral movements, in what appears to be a response to the Trump administration's renewed strategic interest in Latin America and, more generally, as a reflection of the ongoing rivalry between the United States and China. The FamousSparrow group has launched a campaign against Latin America, targeting numerous government entities in the region. In Europe, government entities continued to be a prime target for cyber espionage operations by Russia-aligned APT groups, which intensified their activities against Ukraine and several EU member states.
In particular, even the non-Ukrainian targets of pro-Russian groups had strategic or operational links with Ukraine, confirming the central role that the country continues to play in Russian intelligence interests. The RomCom group exploited a zero-day vulnerability in WinRAR to distribute malicious DLLs and install multiple backdoors, primarily targeting the financial, manufacturing, defense and logistics sectors in the EU and Canada. Considering the high cost of zero-day exploits, the Gamaredon and Sandworm groups instead preferred to use spearphishing as their primary method of compromise. Gamaredon remained the most active APT group against Ukraine, with a clear increase in the intensity and frequency of operations. Sandworm, also focused on Ukraine, instead pursued destructive objectives, focusing attacks on government bodies, energy, logistics and the agricultural sector, with the likely intent of weakening the Ukrainian economy.
The Belarus-aligned group FrostyNeighbor exploited an XSS vulnerability in Roundcube. Polish and Lithuanian companies were targeted by spearphishing emails imitating communications from Polish companies. The messages stood out for the combined use of bullet points and emojis, a structure reminiscent of AI-generated content, thus suggesting a possible use of AI in the campaign. The payloads deployed included a credential stealer and an email message stealer.
"Interestingly, a Russian-aligned APT group, InedibleOchotense, conducted a spearphishing campaign impersonating ESET. The attack involved sending emails and messages via Signal containing a trojanized ESET installer, which installed the legitimate ESET product along with the Kalambur backdoor," explains Jean-Ian Boutin, Director of Threat Research at ESET.
In Asia, APT groups continued to target government entities and the technology, engineering and manufacturing sectors, consistent with what was observed in the previous period. North Korea-aligned APT groups have remained highly active against South Korea and its technology sector, with a particular focus on cryptocurrencies, which represent a crucial source of funding for the regime.
“China-aligned groups remain very active, with campaigns ESET has recently observed in Asia, Europe, Latin America and the United States. This global reach demonstrates how Beijing-aligned APT actors continue to be mobilized to support a wide range of the country's geopolitical priorities,” adds Boutin.
Between June and September, ESET also observed numerous operations by the FamousSparrow group in Latin America, mainly targeting government entities. These activities represent the main part of the operations attributed to the group in the analyzed period, suggesting that the region has been its main operational focus in recent months. The identified victims include several government entities in Argentina, one in Ecuador, one in Guatemala, several in Honduras, and one in Panama.
ESET products protect customer systems from the malicious activities described in the report. The information shared is mainly based on ESET's proprietary telemetry data, verified by researchers who write in-depth technical reports and periodic updates on the activities of individual APT groups. These threat intelligence analyses, known as ESET APT Reports, support organizations tasked with protecting citizens, critical infrastructure and high-value assets from cyberattacks conducted by criminals and state actors. Learn more about ESET APT Reports and providing high-quality, immediately applicable tactical and strategic threat intelligence at ESET Threat Intelligence.






