logo
ESET Research APT Report: Russian cyberattacks in Ukraine intensify; Sandworm unleashes new destructive wiper

ESET Research APT Report: Russian cyberattacks in Ukraine intensify; Sandworm unleashes new destructive wiper

Mid East Info22-05-2025

ESET has released its latest advanced persistent threat (APT) report.
Russian APT groups intensified attacks against Ukraine and the EU, exploiting zero-day vulnerabilities and deploying wipers.
China-aligned groups like Mustang Panda and DigitalRecyclers continued their espionage campaigns targeting the EU government and maritime sectors.
North Korea-aligned groups expanded their financially motivated campaigns using fake job listings and social engineering.
ESET Research has released its latest APT Activity Report, which highlights activities of select APT groups that were documented by ESET researchers from October 2024 through March 2025. During the monitored period, Russia-aligned threat actors, notably Sednit and Gamaredon, maintained aggressive campaigns primarily targeting Ukraine and EU countries. Ukraine was subjected to the greatest intensity of cyberattacks against the country's critical infrastructure and governmental institutions. The Russia-aligned Sandworm group intensified destructive operations against Ukrainian energy companies, deploying a new wiper named ZEROLOT. China-aligned threat actors continued engaging in persistent espionage campaigns with a focus on European organizations.
Gamaredon remained the most prolific actor targeting Ukraine, enhancing malware obfuscation and introducing PteroBox, a file stealer leveraging Dropbox. 'The infamous Sandworm group concentrated heavily on compromising Ukrainian energy infrastructure. In recent cases, it deployed the ZEROLOT wiper in Ukraine. For this, the attackers abused Active Directory Group Policy in the affected organizations,' says ESET Director of Threat Research Jean-Ian Boutin.
Sednit refined its exploitation of cross-site scripting vulnerabilities in webmail services, expanding Operation RoundPress from Roundcube to include Horde, MDaemon, and Zimbra. ESET discovered that the group successfully leveraged a zero-day vulnerability in MDaemon Email Server (CVE-2024-11182) against Ukrainian companies. Several Sednit attacks against defense companies located in Bulgaria and Ukraine used spearphishing email campaigns as a lure. Another Russia-aligned group, RomCom, demonstrated advanced capabilities by deploying zero-day exploits against Mozilla Firefox (CVE 2024 9680) and Microsoft Windows (CVE 2024 49039).
In Asia, China-aligned APT groups continued their campaigns against governmental and academic institutions. At the same time, North Korea-aligned threat actors significantly increased their operations directed at South Korea, placing particular emphasis on individuals, private companies, embassies, and diplomatic personnel. Mustang Panda remained the most active, targeting governmental institutions and maritime transportation companies via Korplug loaders and malicious USB drives. DigitalRecyclers continued targeting EU governmental entities, employing the KMA VPN anonymization network and deploying the RClient, HydroRShell, and GiftBox backdoors. PerplexedGoblin used its new espionage backdoor, which ESET named NanoSlate, against a Central European government entity, while Webworm targeted a Serbian government organization using SoftEther VPN, emphasizing the continued popularity of this tool among China-aligned groups.
Elsewhere in Asia, North Korea-aligned threat actors were particularly active in financially motivated campaigns. DeceptiveDevelopment significantly broadened its targeting, using fake job listings primarily within the cryptocurrency, blockchain, and finance sectors. The group employed innovative social engineering techniques to distribute the multiplatform WeaselStore malware. The Bybit cryptocurrency theft, attributed by the FBI to TraderTraitor APT group, involved a supply-chain compromise of Safe{Wallet} that caused losses of approximately USD 1.5 billion. Meanwhile, other North Korea-aligned groups saw fluctuations in their operational tempo: In early 2025, Kimsuky and Konni returned to their usual activity levels after a noticeable decline at the end of 2024, shifting their targeting away from English-speaking think tanks, NGOs, and North Korea experts to focus primarily on South Korean entities and diplomatic personnel; and Andariel resurfaced, after a year of inactivity, with a sophisticated attack against a South Korean industrial software company.
Iran-aligned APT groups maintained their primary focus on the Middle East region, predominantly targeting governmental organizations and entities within the manufacturing and engineering sectors in Israel. Additionally, ESET observed a significant global uptick in cyberattacks against technology companies, largely attributed to increased activity by North Korea-aligned DeceptiveDevelopment.
'The highlighted operations are representative of the broader threat landscape that we investigated during this period. They illustrate the key trends and developments, and contain only a small fraction of the cybersecurity intelligence data provided to customers of ESET APT reports,' adds Boutin.
Intelligence shared in the private reports is primarily based on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports PREMIUM, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks. More information about ESET APT Reports PREMIUM and its delivery of high-quality, actionable tactical and strategic cybersecurity threat intelligence is available at the ESET Threat Intelligence page.
Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.
About ESET
ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it's endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Bridge Collapses in Russia Raise Fears of Ukrainian Sabotage
Bridge Collapses in Russia Raise Fears of Ukrainian Sabotage

See - Sada Elbalad

time5 hours ago

  • See - Sada Elbalad

Bridge Collapses in Russia Raise Fears of Ukrainian Sabotage

Ahmed Emam Two separate bridge collapses in Russia's Bryansk and Kursk regions have prompted serious concerns among Russian authorities, who suspect Ukrainian sabotage behind the incidents. The twin disasters, which occurred within hours of each other, have left several dead and dozens injured, intensifying already heightened tensions between Moscow and Kyiv. According to Alqahera News, Russian officials believe the two incidents may be linked and deliberate. The first collapse occurred in Bryansk, where a bridge gave way just as a passenger train was passing underneath. Russian authorities confirmed that the incident killed seven people and injured at least 63 others, with local media later reporting the number of injured had risen to 73. The governor of Bryansk said that the collapse was the result of an explosion caused by explosive devices planted beneath the bridge. The devices reportedly detonated just as the train, en route to Moscow, was beneath the structure, causing it to fall onto the carriages. All passengers were civilians. A member of Russia's Federation Council described the event as a 'terrorist act,' blaming Ukrainian intelligence and calling for an expansion of Russia's buffer zone to encompass the entirety of Ukrainian territory in response to the attack. Security sources in Russia also told local outlets that a group linked to Ukrainian intelligence had recently infiltrated Bryansk and was being actively pursued by Russian security forces in the days leading up to the incident, bolstering the theory of direct Ukrainian involvement. In the neighboring Kursk region, another bridge collapsed as a freight train was passing over it. While no casualties have been reported so far, authorities have yet to confirm the cause of the collapse. However, Russian media noted striking similarities between the circumstances of the two incidents, raising suspicions that the Kursk bridge may have also been sabotaged. In a related development, unconfirmed reports surfaced of a Russian military train being targeted in Melitopol, a city under Russian control in southeastern Ukraine. The reports claim Ukrainian intelligence may have been behind the attack, a development that could mark a serious escalation in hostilities between the two countries. These incidents come amid renewed tensions along the Russia-Ukraine frontlines, as both sides brace for further confrontations. Moscow has not ruled out a forceful response if Ukrainian involvement in the attacks is confirmed. read more Gold prices rise, 21 Karat at EGP 3685 NATO's Role in Israeli-Palestinian Conflict US Expresses 'Strong Opposition' to New Turkish Military Operation in Syria Shoukry Meets Director-General of FAO Lavrov: confrontation bet. nuclear powers must be avoided News Iran Summons French Ambassador over Foreign Minister Remarks News Aboul Gheit Condemns Israeli Escalation in West Bank News Greek PM: Athens Plays Key Role in Improving Energy Security in Region News One Person Injured in Explosion at Ukrainian Embassy in Madrid News Ayat Khaddoura's Final Video Captures Bombardment of Beit Lahia News Australia Fines Telegram $600,000 Over Terrorism, Child Abuse Content Sports Former Al Zamalek Player Ibrahim Shika Passes away after Long Battle with Cancer Sports Neymar Announced for Brazil's Preliminary List for 2026 FIFA World Cup Qualifiers News Prime Minister Moustafa Madbouly Inaugurates Two Indian Companies Arts & Culture New Archaeological Discovery from 26th Dynasty Uncovered in Karnak Temple Business Fear & Greed Index Plummets to Lowest Level Ever Recorded amid Global Trade War Arts & Culture Zahi Hawass: Claims of Columns Beneath the Pyramid of Khafre Are Lies News Flights suspended at Port Sudan Airport after Drone Attacks News Shell Unveils Cost-Cutting, LNG Growth Plan

Opportunities for Chinese investments - Economy - Al-Ahram Weekly
Opportunities for Chinese investments - Economy - Al-Ahram Weekly

Al-Ahram Weekly

timea day ago

  • Al-Ahram Weekly

Opportunities for Chinese investments - Economy - Al-Ahram Weekly

A delegation from Egypt is set to visit China next month following last week's visit of a Chinese investment delegation to Egypt A delegation from the Suez Canal Economic Zone (SCZONE) is scheduled to visit China next month to promote the industrial opportunities available in the SCZONE, Mustafa Ibrahim, vice chair of the China-Egypt Relations Committee at the Egyptian Businessmen's Association (EBA), told Al-Ahram Weekly. The visit is part of ongoing efforts to boost Chinese investments in Egypt. Wang Weizhong, governor of Guangdong Province in China, was also in Cairo last week with a delegation representing Chinese government agencies and Chinese companies interested in investing in the Egyptian market. The delegation also included representatives from Chinese companies already operating in Egypt. Some 2,800 Chinese companies currently operate in Egypt, with total investments exceeding $8 billion, according to the General Authority for Investment and Free Zones (GAFI). Ibrahim expects Chinese investments to reach $12 billion by the end of 2025. The Chinese delegation explored investment opportunities in various sectors, including electric vehicles. The visit aimed to support the Chinese government's Belt and Road Initiative and to study investment opportunities in the Egyptian market. China plans to move many of its factories abroad due to its commitment to reduce carbon emissions by 2026 and to avoid obstacles that could affect its exports to various countries, including members of the European Union, Ibrahim explained. China is also keen on redirecting its labour force towards high value-added industrial sectors such as the technology industry, in which it has outperformed many of its competitors, he added. Chinese companies are interested in investing across several sectors in Egypt, including textiles, ready-made garments, electrical appliances, the automotive industry, and natural gas exploration. Ibrahim said that China has moved into a new era, transitioning from product imitation to innovation, which has made countries like Germany eager to learn about the technologies used in Chinese robots, for example. China is seeking partners with whom it can strengthen its ties, and Egypt stands out with its large market and trade agreements with many other countries that enable access to nearly three billion consumers, Ibrahim said. He noted that over the past year and a half visits from Chinese delegations have taken a new and more serious turn, with provincial governors and leaders from the ruling party heading the delegations. Chinese investors are also planning to invest in new sectors, including tourism and the establishment of hotels and are currently studying investment opportunities in that field. Ibrahim said that cooperation between Egypt and China takes three main forms, with China exporting production inputs and finished products to Egypt, undertaking projects managed by Chinese companies for implementation in Egypt, and injecting direct investments into the Egyptian economy. He stressed the need for consistent laws and a stable economy to attract foreign investors, making the investment climate more appealing. Ahmed Mounir Ezzeddin, chair of the China-Egypt Relations Committee at the Egyptian Businessmen's Association (EBA), told the Weekly that Egypt's infrastructural development, both in terms of urban expansion and power networks, has opened the door for the establishment of large and medium-sized factories and has encouraged various investments, including those from China. China's only industrial city on the African continent is in Egypt in the shape of the China-Egypt TEDA Suez Economic and Trade Cooperation Zone on the shores of the Red Sea and south of the Suez Canal. This started on an area of three million square metres and has now expanded to 10 million, reflecting Egypt's importance to Chinese investors. Ezzeddin said that Egypt possesses several factors that attract Chinese investments, such as the new investment law, an improved business environment and a competitive labour force, in addition to competitive electricity and fuel prices. He highlighted that recent measures to regulate the import of finished products have encouraged Chinese investors to inject capital into the home appliance sector, aligning with Egypt's goal to provide competitively priced locally produced products for both domestic consumption and export. * A version of this article appears in print in the 29 May, 2025 edition of Al-Ahram Weekly Follow us on: Facebook Instagram Whatsapp Short link:

China thought it had a truce with the US. Then Trump dropped two bombshells
China thought it had a truce with the US. Then Trump dropped two bombshells

Egypt Independent

time3 days ago

  • Egypt Independent

China thought it had a truce with the US. Then Trump dropped two bombshells

Beijing CNN — A one-two punch from the United States risks shattering the already fragile trade war truce between Washington and Beijing, with Chinese tech companies and students both dealt shock blows by the Trump administration Wednesday night. Viewed from within China, things had been looking up after the world's two largest economies agreed to dramatically roll back steep tariffs – a conciliatory step in a trade war that had threatened the entire global trading system. Factories started whirring again. Long-delayed shipping containers began leaving Chinese ports, destined for the US. Chinese media celebrated the agreement as a national victory, while top officials adopted an upbeat tone in describing cooperation between the two superpower rivals. But the two jabs from Washington on Wednesday will have far-reaching effects across China, angering families and authorities alike. They also throw into question the future of US-China trade talks; the temporary truce only lasts 90 days, and the clock is ticking to reach a longer-term agreement. The first hit came in a Financial Times report on Wednesday that said moves by US President Donald Trump had effectively cut off some American companies from selling software used to design semiconductors to China. A Siemens spokesperson later told CNN that the US government on Friday informed the industry about new export controls on chip designing software to China and Chinese military end users globally. These small chips – which power our smartphones, computers, automobiles and home appliances – have been at the fore of the US-China tech battle in recent years. The Biden administration had blocked China from accessing US-made semiconductors, and earlier this month, Washington warned companies against using AI chips made by Chinese tech giant Huawei. A semiconductor silicon wafer fabricated with several microchip microprocessors, seen at the Rochester Institute of Technology in Henrietta, New York, on April 14, 2025. Ted Shaffrey/AP/File The obstacles were infuriating for Beijing, especially since it has poured tens of billions of dollars into its semiconductor industry, aiming to boost production at home and become less reliant on the US and other countries. Liu Pengyu, a spokesperson for the Chinese Embassy in the US, declined to comment on the reported chip software move but accused the US of 'overstretching the concept of national security, abusing export controls, and maliciously blocking and suppressing China' in a statement to CNN. But it was the second blow from the White House that landed right in the living rooms of Chinese families, with US State Secretary Marco Rubio saying the US will 'aggressively revoke visas for Chinese students' – especially those in critical fields or with connections to the Chinese Communist Party. It's hard to overstate the impact. There were more than 270,000 Chinese students in the US in 2024, and even more before the pandemic. While some hail from China's political and business elites, many also come from middle-class families. The path to the US is attractive, but arduous. Chinese families save for years and spend exorbitant amounts of money to send their kids abroad, with students attending cram schools or hiring tutors to polish their applications. Rubio's announcement jeopardizes all of that – with students now facing potential deportation in the middle of their hard-won education. Given China is a one-party state that reaches deep into nearly every aspect of society, it can be difficult or impossible for many students to disprove any claims that they're connected to the Communist Party – especially if the State Department defines that term loosely. A spokesperson for China's foreign ministry said on Thursday it 'strongly opposes' the move, accusing the US of 'unjustly' revoking visas 'under the pretext of ideology and national security.' Candy, a statistics student at the University of Michigan, who did not want to give her full name, said she feared her visa would be canceled before she graduates. 'Ending up with only a high school diploma is something I dread,' she said from China, where she's visiting family. 'I pray to make it through my undergraduate study safely and smoothly.' 'When I first heard the news, I wanted to curse Trump.' While the visa threat comes as a shock, some argue the targeting of students may in fact be a boon to China in the end. The number of Chinese students in the US had been declining in recent years, partly because of significant shifts in both policy and public perception. Experts say many Chinese students and families now worry about safety, racism and discrimination, and immigration difficulties in the US – especially as more competitive higher education options open in other countries, including in China itself. Trump's crackdown could see more Chinese scholars, including some of the brightest minds in their fields, return to their home country – or choose to stay in the first place, rejecting a US education for a Chinese degree instead. And these researchers – including key leaders in technological fields – could be the key to China catching up with, or surpassing the US – the very thing many Trump officials are trying to prevent. Wednesday did bring one bit of good news for China; a federal court blocked Trump from imposing most of his global tariffs, including the current 30% tariffs on China. But the administration immediately appealed the decision, leaving the status of those tariffs – and the trade war – up in the air.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store