TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

ESET WeLiveSecurity

ESET APT Activity Report Q2 2025–Q3 2025

2025-11-06 · Read original ↗

ATT&CK techniques detected

3 predictions
T1566.002Spearphishing Link
88%
“campaign involved emails and signal messages delivering a trojanized eset installer that leads to the download of a legitimate eset product along with the kalambur backdoor. finally, notable activities by lesser - known groups included frostyneighbor exploiting an xss vulnerabili…”
T1566.002Spearphishing Link
51%
“##gato also introduced an interesting twist to its campaign by leveraging dll - search - order hijacking to steal credentials. north korea - aligned threat actors targeted the cryptocurrency sector and, notably, expanded their operations to uzbekistan – a country not previously o…”
T1566.001Spearphishing Attachment
48%
“##gato also introduced an interesting twist to its campaign by leveraging dll - search - order hijacking to steal credentials. north korea - aligned threat actors targeted the cryptocurrency sector and, notably, expanded their operations to uzbekistan – a country not previously o…”

Summary

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2025 and Q3 2025