Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Survey indicates financial institutions already encountering agentic A...
Gambit Cyber Announces Strategic Partnership with BitCyber to Advance ...
Doppel Enters Japan, Marking Next Phase of Global Expansion
SU Group Announces Distribution Agreement with Germany’s GEZE, E...
Five years on, vulnerabilities can remain hidden in containerized soft...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Are the built-in restrictions in Claude Fable 5 sufficient?

      Are the built-in restrictions in Claude Fable 5 sufficient?

      Friday, June 12, 2026, 8:52 AM Asia/Singapore | Features, Opinions
    • Featured

      Bringing cybercriminals to justice in APAC

      Bringing cybercriminals to justice in APAC

      Thursday, June 11, 2026, 10:30 AM Asia/Singapore | Features
    • Featured

      Cyber resilience – a national security imperative

      Cyber resilience – a national security imperative

      Wednesday, June 10, 2026, 3:09 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

Six-month snapshot of state-sponsored threats shows continued APT resilience

By CybersecAsia editors | Friday, June 20, 2025, 11:54 AM Asia/Singapore

Six-month snapshot of state-sponsored threats shows continued APT resilience

Despite takedowns, law-enforcement efforts and geopolitical effects, Advanced Persistent Threats had continued to wreak damages and losses on the world.

Based on its internal research* on Advanced Persistent Threat activities from the Oct 2024 to March 2025 period, a cybersecurity firm has reported some findings to the public.

First, during the monitoring period, Russia-aligned threat actors such as Sednit and Gamaredon, had maintained aggressive campaigns primarily targeting Ukraine (critical infrastructure and governmental institutions) and EU countries. The Russia-aligned Sandworm group had intensified destructive operations against Ukrainian energy firms, deploying a new wiper named ZEROLOT.

Second, China-aligned threat actors were noted to have continued engaging in persistent espionage campaigns, with a focus on European organizations.

Other telemetry findings

In Asia, China-aligned APT groups had continued campaigns against governmental and academic institutions. Also:

  • North Korea-aligned threat actors had significantly increased their operations directed at South Korea, placing particular emphasis on individuals, private companies, embassies, and diplomatic personnel. Mustang Panda remained the most active, targeting governmental institutions and maritime transportation companies via Korplug loaders and malicious USB drives. DigitalRecyclers continued targeting EU governmental entities, employing the KMA VPN anonymization network and deploying the RClient, HydroRShell, and GiftBox backdoors. PerplexedGoblin had used its new espionage backdoor against a Central European government entity, while Webworm had targeted a Serbian government organization using SoftEther VPN, a popularity tool among China-aligned groups.
  • Elsewhere in Asia, North Korea-aligned threat actors were particularly active in financially motivated campaigns. DeceptiveDevelopment significantly broadened its targeting, using fake job listings primarily within the cryptocurrency, blockchain, and finance sectors. The Bybit cryptocurrency theft, attributed by the FBI to the TraderTraitor APT group, had caused losses of approximately US$1.5bn in this period.
  • Other North Korea-aligned groups had seen fluctuations in their operational tempo: In early 2025, Kimsuky and Konni had returned to their usual activity levels after a noted decline at the end of 2024, shifting their targeting away from English-speaking think tanks, non-governmental organizations and North Korea experts to focus primarily on South Korean entities and diplomatic personnel. Also, Andariel had resurfaced after a year of inactivity, with a sophisticated attack against a South Korean industrial software company.
  • Iran-aligned APT groups had maintained their primary focus on the Middle East region, predominantly targeting governmental organizations and entities within the manufacturing and engineering sectors in Israel. Additionally, there had been a significant global uptick in cyberattacks against technology firms during the monitoring period, largely attributed to increased activity by North Korea-aligned DeceptiveDevelopment.

According to Jean-Ian Boutin, Director of Threat Research, ESET, the firm releasing some of its data findings to the media: “The highlighted operations are representative of the broader threat landscape that we investigated during this period. They illustrate the key trends and developments, and contain only a small fraction of the cybersecurity intelligence data provided to customers…”

*based on proprietary telemetry and associated research on specific APT groups

Share:

PreviousCohesity Strengthens Resilience of Large, Mission-Critical MongoDB Workloads
NextNEC Indonesia Introduces Integrated Command Control Centre for Industrial Estate at the 9th HKI National Conference 2025

Related Posts

The greatest threat to industrial cybersecurity may actually be red tape!

The greatest threat to industrial cybersecurity may actually be red tape!

Tuesday, September 29, 2020

Three critical RCE flaws could have allowed malicious takeover of AI servers

Three critical RCE flaws could have allowed malicious takeover of AI servers

Tuesday, August 5, 2025

Can you tell cybersecurity fact from fiction? Take this challenge!

Can you tell cybersecurity fact from fiction? Take this challenge!

Monday, October 12, 2020

Surge in fraudulent scholarship scams targets students in Bangladesh

Surge in fraudulent scholarship scams targets students in Bangladesh

Friday, September 5, 2025

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Gambit Cyber Announces Strategic Partnership with BitCyber to Advance AI-Native and Risk-Centric Continuous Threat Exposure Management Across Singapore, ASEAN and Hong Kong

    Wednesday, June 17, 2026
    Strategic partnership brings Continuous Threat …Read More »
  • Doppel Enters Japan, Marking Next Phase of Global Expansion

    Tuesday, June 16, 2026
    Social engineering defense leader surpasses …Read More »
  • SU Group Announces Distribution Agreement with Germany’s GEZE, Expanding Smart Building and Safety Technology Portfolio

    Tuesday, June 16, 2026
    Agreement adds Globally Recognized Door, …Read More »
  • Hikvision Releases 2026 Cybersecurity White Paper, Fostering Digital Trust in the AIoT Era

    Friday, June 12, 2026
    HANGZHOU, China, June 12, 2026 …Read More »
  • Cohesity Gains Access to Anthropic’s Claude Mythos Preview Through Project Glasswing

    Tuesday, June 9, 2026
    Strengthening the Cohesity Data Cloud …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.