ESET APT Activity Report Q4 2025–Q1 2026
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
Search fresh public links, source activity, and post angles for Eset Research.
Fresh curated links around ESET research are collected here so marketers can spot useful updates and turn timely ideas into posts faster.
Recent items include:
Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
ESET MDR delivers industry-leading real-time detection and a mean-time-to-respond (MTTR) of 6 minutes to keep businesses secure ESET, a global leader in cybersecurity solutions, an...
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
Infrawatch says ProxySmart platform enables SIM farm activity at “industrial scale”
KELA claims infostealers remained the primary access vector for attacks in 2025
New research has exposed a search engine poisoning campaign that delivers a trojanized TestDisk installer, abuses a Microsoft-signed binary for DLL sideloading, and silently deploy...
<p style="text-align: justify;">Analitycy ESET informują o nowej kampanii cyberszpiegowskiej powiązanej z Białorusią. Najnowsze ataki z 2026 roku, opisane na przykł...
China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
Cybersecurity researchers have discovered a new iteration of an Android malware family called NGate that has been found to abuse a legitimate application called HandyPay instead of...
Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege...
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
ESET warns that North Korean hackers compromised a Yanbian gaming site in a supply‑chain attack, trojanizing Windows and Android software to spy on users
A recent report from Microsoft warns about two active cybersecurity threats: a fast-moving ransomware campaign and a Russian espionage operation that abuses small office and home o...
APT37 is running a new targeted intrusion campaign that abuses Facebook, Telegram, and a tampered Wondershare PDFelement installer to gain stealthy access and exfiltrate sensitive...
New research from Seqrite explains the ‘dual-use dilemma,’ where ransomware attackers repurpose legitimate IT tools like IOBit Unlocker…
Η ESET εντόπισε νέα παραλλαγή του κακόβουλου λογισμικού NGate, η οποία εκμεταλλεύεται τη νόμιμη εφαρμογή Android HandyPay, σύμφωνα με ανακοίνωση του Ερευνητικού Κέντρου της εταιρεί...
An active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM) software as a way to esta...
Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively....
Reach Security unveiled new research that exposes the scale and persistence of configuration drift across modern cybersecurity environments. It reveals
Security researchers warn of Mirax, an emerging Android banking trojan using MaaS, remote access and residential proxies to target European users
Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.