None
EN
ESET APT Activity Report Q4 2024–Q1 2025
[]
WeLiveSecurity
ESET APT Activity Report Q4 2024–Q1 2025 summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from October 2024 until the end of March 2025.
During the monitored period, China-aligned threat actors continued engaging in persistent espionage campaigns with a focus on European organizations.
CyberToufan conducted destructive operations, deploying a wiper attack against multiple organizations in Israel.
Russia-aligned threat actors, notably Sednit and Gamaredon, maintained aggressive campaigns primarily targeting Ukraine and EU countries.
Malicious activities described in ESET APT Activity Report Q4 2024–Q1 2025 are detected by ESET products; shared intelligence is based mostly on proprietary ESET telemetry data and has been verified by ESET researchers.
['espionage'
'q4'
'threat'
'report'
'2025'
'primarily'
'operations'
'eset'
'group'
'targeting'
'activity'
'campaigns'
'2024q1'
'groups'
'apt'
'deploying']