
ESET APT Report Unveils Intensified Russian Cyberattacks on Ukraine
Gamaredon remained the most prolific actor targeting Ukraine, enhancing malware obfuscation and introducing PteroBox, a file stealer leveraging Dropbox. 'The infamous Sandworm group concentrated heavily on compromising Ukrainian energy infrastructure. In recent cases, it deployed the ZEROLOT wiper in Ukraine. For this, the attackers abused Active Directory Group Policy in the affected organizations,' says ESET Director of Threat Research Jean-Ian Boutin.
Sednit refined its exploitation of cross-site scripting vulnerabilities in webmail services, expanding Operation RoundPress from Roundcube to include Horde, MDaemon, and Zimbra. ESET discovered that the group successfully leveraged a zero-day vulnerability in MDaemon Email Server (CVE-2024-11182) against Ukrainian companies. Several Sednit attacks against defense companies located in Bulgaria and Ukraine used spearphishing email campaigns as a lure. Another Russia-aligned group, RomCom, demonstrated advanced capabilities by deploying zero-day exploits against Mozilla Firefox (CVE 2024 9680) and Microsoft Windows (CVE 2024 49039).
In Asia, China-aligned APT groups continued their campaigns against governmental and academic institutions. At the same time, North Korea-aligned threat actors significantly increased their operations directed at South Korea, placing particular emphasis on individuals, private companies, embassies, and diplomatic personnel. Mustang Panda remained the most active, targeting governmental institutions and maritime transportation companies via Korplug loaders and malicious USB drives. DigitalRecyclers continued targeting EU governmental entities, employing the KMA VPN anonymization network and deploying the RClient, HydroRShell, and GiftBox backdoors. PerplexedGoblin used its new espionage backdoor, which ESET named NanoSlate, against a Central European government entity, while Webworm targeted a Serbian government organization using SoftEther VPN, emphasizing the continued popularity of this tool among China-aligned groups.
Elsewhere in Asia, North Korea-aligned threat actors were particularly active in financially motivated campaigns. DeceptiveDevelopment significantly broadened its targeting, using fake job listings primarily within the cryptocurrency, blockchain, and finance sectors. The group employed innovative social engineering techniques to distribute the multiplatform WeaselStore malware. The Bybit cryptocurrency theft, attributed by the FBI to TraderTraitor APT group, involved a supply-chain compromise of Safe{Wallet} that caused losses of approximately USD 1.5 billion. Meanwhile, other North Korea-aligned groups saw fluctuations in their operational tempo: In early 2025, Kimsuky and Konni returned to their usual activity levels after a noticeable decline at the end of 2024, shifting their targeting away from English-speaking think tanks, NGOs, and North Korea experts to focus primarily on South Korean entities and diplomatic personnel; and Andariel resurfaced, after a year of inactivity, with a sophisticated attack against a South Korean industrial software company.
Iran-aligned APT groups maintained their primary focus on the Middle East region, predominantly targeting governmental organizations and entities within the manufacturing and engineering sectors in Israel. Additionally, ESET observed a significant global uptick in cyberattacks against technology companies, largely attributed to increased activity by North Korea-aligned DeceptiveDevelopment.
'The highlighted operations are representative of the broader threat landscape that we investigated during this period. They illustrate the key trends and developments, and contain only a small fraction of the cybersecurity intelligence data provided to customers of ESET APT reports,' adds Boutin.
Intelligence shared in the private reports is primarily based on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports PREMIUM, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks. More information about ESET APT Reports PREMIUM and its delivery of high-quality, actionable tactical and strategic cybersecurity threat intelligence is available at the ESET Threat Intelligence page. 0 0
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Gulf Today
an hour ago
- Gulf Today
Trapped Ukrainian soldier escapes on e-bike delivered by drone
An injured Ukrainian soldier stuck behind enemy lines for days was rescued after being delivered an e-bike by a drone. A video of the dramatic rescue showed a UAV drone airdropping the 40kg bike down to the wounded man, who was surrounded by Russian forces, before he cycled away. The soldier's Rubizh brigade said three men were killed by enemy fire during a skirmish in Siversk, northern Ukraine, leaving the soldier on his own for five days. In a video the soldier, call sign 'Tanker', said: 'Our drones covered us from above as best as they could. Then they threw two gas cylinders straight into our hole and a lighter. We caught fire. 'Every day, I was surrounded, from all sides. I fought back as best I could.' Brigade commander Mykola Hrytsenko explained the challenges they faced in trying to rescue their stranded comrade. 'The enemy was in front, behind, and on both flanks, completely surrounded,' the commander said. 'It was impossible to drive up with equipment because the enemy was everywhere. He couldn't get out on his own either, because he had to walk 1.5km to the nearest position. 'In his condition, with his injuries, he simply wouldn't have made it.' The bike was lowered to the wounded soldier so he could make his escape The bike was lowered to the wounded soldier so he could make his escape (Rubizh Brigade) The brigade then came up with the bold plan to deliver a vehicle to him by drone. The first two attempts to fly the bike in failed, with Russian forces shooting the first out of the sky and the second crashing. They managed to get the bike to the soldier on the third attempt – but his ordeal was not over yet. After fleeing 400m, he hit a remote mine. Tank limped a further 200m with a leg injury before he was rescued. A second e-bike was then delivered, which he rode for 15 minutes to an evacuation point. 'To carry out this operation, they had to calculate the right time of day, the right weather conditions that would allow him to do it,' Cdr Hrytsenko added. The soldier fled around 400m on an e-bike delivered by drone, before hitting a mine and limping the rest of the way The soldier fled around 400m on an e-bike delivered by drone, before hitting a mine and limping the rest of the way (YouTube/Rubizh Brigade) Reports of the rescue effort emerged after Vladimir Putin's forces launched a wave of missile attacks on the capital Kyiv in the early hours of Thursday, killing 16 people, including a six-year-old boy and his mother. Ukrainian president Volodymyr Zelensky urged his allies to bring about 'regime change' in Russia following the attack. 'If the world doesn't aim to change the regime in Russia, that means even after the war ends, Moscow will still try to destabilise neighbouring countries,' he said. 'Today the world has once again seen Russia's response to our desire for peace ... Therefore, peace without strength is impossible,' the Ukrainian president added. The Independent


The National
5 hours ago
- The National
AI chip smuggling 'gets more airtime than it should', White House official says
The idea of high-performance AI chips being smuggled into potentially nefarious hands gets more attention than it should, a White House official has said. Michael Kratsios, who serves as director for the Trump administration's Office of Science and Technology Policy, said on Wednesday that there are a lot of misconceptions and misguided fears about the 'physical diffusion' of artificial intelligence technology developed by the US. 'We're not talking about like a bag of diamonds or something,' he said during a discussion at the Centre for Strategic and International Studies think tank about Mr Trump's recently announced AI Action Plan. Some politicians have expressed concerns about the potential for recently announced US AI partnerships overseas to be exploited by countries like China to try to acquire powerful American-made technology. 'These are like massive racks that are tonnes in weight and you're not going to put it on a forklift or back it into a truck, or something," he explained, adding that the idea of chip smuggling "probably gets more airtime than it should." Mr Kratsios also said the hypothetical scenario of the US partnerships with other countries leading to the misuse of data centres by countries like China for 'training runs' to access the centres was overblown. 'What you're most worried about is large-scale runs that are for training sophisticated models and those are actually pretty easy to flag,' he said, adding that the US will make sure to implement what's known in IT circles as Know Your Customer policies to prevent bad actors from gaining access to data centres powered by US technology. Mr Kratsios said that Mr Trump's predecessor, Joe Biden, put too many chip export restrictions on allies, and that the export of US technology to countries with peaceful AI aspirations was critical to an overall AI strategy. During Mr Trump's visit to the Gulf in May, he announced the US-UAE AI Acceleration Partnership framework that will eventually lead to the construction of a 5GW UAE-US AI Campus in Abu Dhabi. 'The [Biden administration] limits made no sense at all,' he said, referring to President Biden's policies aimed at limiting the powerful CPUs and GPUs available to certain countries. Those policies were largely aimed at preventing the diffusion of US technology to China. It proved controversial, with companies like Microsoft and Nvidia claiming the policies hurt US efforts more than helping. Some US AI companies like Anthropic, however, have sought to keep the export controls. 'In some cases, smugglers have employed creative methods to circumvent export controls, including hiding processors in prosthetic baby bumps and packing GPUs [graphics processing units] alongside live lobsters,' read an April policy letter from Anthropic. That letter later came under criticism over what some called the oversimplification of how AI data centres work. Regardless, in keeping with that theme of reversing the Biden export policy, the Trump White House recently announced plans that would allow for Nvidia to resume sales of its H20 graphics processing unit to China. That decision, however, has come under criticism from several technology analysts and politicians. A group of Democratic senators this week sent a letter to Commerce Secretary Howard Lutnick urging him to reverse course. At the CSIS event, Mr Kratsios said the concerns from Democratic senators were oversimplified, adding that the H20 was designed to comply with US concerns about giving China too much computing power, among other things. 'It's not a free-for-all sale,' he said, referring to White House's H20 announcement. 'Any sale that Nvidia wants to make to China is one that's going to require an export licence.' Mr Kratsios added that the Commerce Department's Bureau of Industry and Security would be evaluating each of those licence applications and 'weight the costs' before giving Nvidia approval.


Gulf Today
6 hours ago
- Gulf Today
Kyiv mourns after deadliest attack in a year kills 31 people in Ukraine, including 5 children
The Ukrainian capital Kyiv observed an official day of mourning Friday, a day after a Russian drone and missile attack on the city killed 31 people, including five children, and injured more than 150, officials said. The youngest victim in Thursday's strikes was 2 years old, and 16 of the injured were children, Ukrainian President Volodymyr Zelensky said. It was the highest number of children killed and injured in a single attack on Kyiv since aerial attacks on the city began in October 2022, according to official casualty figures reported by The Associated Press. It was also the deadliest attack on the city since July last year, when 33 were killed. Women react outside a destroyed apartment building after a Russian missile attack in Kyiv. AP The death toll rose overnight as emergency crews continued to dig through rubble. The Russian barrage demolished a large part of a nine-story residential building in the city, while more than 100 other buildings were damaged, including homes, schools, kindergartens, medical facilities and universities, officials said. Russia has escalated its attacks on Ukrainian cities in recent months, ignoring calls from Western leaders including US President Donald Trump to stop striking civilian areas after more than three years of war. The Russian tactic aims to spread terror and wear down public appetite for the war. Rescuers carry a part of a Russian Iskander-K cruise missile which hit an apartment building in Kyiv. Reuters Russian forces are also pressing on with their grinding war of attrition along the 1,000-kilometre front line, where incremental gains over the past year have come at the cost of thousands of soldiers on both sides. Zelensky said that in July, Russia launched over 5,100 glide bombs, more than 3,800 Shahed drones, and nearly 260 missiles of various types, 128 of them ballistic, against Ukraine. He repeated his appeal for countries to impose heavier economic sanctions on Russia to deter the Kremlin, as U.S.-led peace efforts have failed to gain traction. "No matter how much the Kremlin denies (sanctions') effectiveness, they are working and must be stronger,' Zelensky said. People lay flowers and toys at a makeshift memorial outside a residential building in Kyiv. AFP His comments on Friday appeared to be a response to Trump's remarks the previous day, when the Republican president said the US plans to impose sanctions on Russia but added, "I don't know that sanctions bother him,' in reference to Russian President Vladimir Putin. In April, Trump urged the Russian leader to "STOP!' after an aerial attack on Kyiv killed 12 in what was the deadliest assault on the city since July 2024. "Lets get the Peace Deal DONE!' Trump said in a post on his Truth Social platform at the time, but Russia hasn't eased up on its barrages. Earlier this week, Trump gave Putin until Aug. 8 to stop the fighting. Those demands haven't persuaded the Kremlin to change strategy. "Any disappointments arise from excessive expectations,' Putin told the media Friday during a sit-down with Belarusian President Alexander Lukashenko at the 14th-century Valaam monastery in northwest Russia. He did not mention Trump by name. Ukrainian rescuers work among the rubble inside of a destroyed residential building at the site of an air attack in Kyiv. AFP Putin said that he regards recent direct talks in Istanbul between delegations from Russia and Ukraine as valuable, even though they made no progress beyond exchanges of prisoners of war, and made no reference to next week's deadline imposed by Trump. Ukraine also called for an urgent UN Security Council meeting to be convened on Friday, Foreign Minister Andrii Sybiha said, in an effort to push Putin into accepting "a full, immediate and unconditional ceasefire.' Meanwhile, Ukrainian forces are under heavy pressure in the strategic hilltop city of Chasiv Yar, in the eastern Donetsk region where Russia is making a concerted push to break through defenses after some 18 months of fighting. Zelensky said that Russian claims of capturing Chasiv Yar on Thursday were "disinformation.' "Ukrainian units are holding our positions,' Zelenskyy said in his daily video address on Thursday evening. "It is not easy, but it is the defense of Ukrainians' very right to life.' Russia's Defense Ministry said on Friday that air defenses shot down 60 Ukrainian drones overnight. More than half were destroyed over Russia's Belgorod region on the country's border with Ukraine, it said. Belgorod Gov. Vyacheslav Gladkov said that one person was injured. The Ukrainian air force, meanwhile, said Friday it downed 44 out of 72 Russian drones fired overnight. There were no immediate reports on casualties or damage. Associated Press