ESET APT Activity Report Q4 2025–Q1 2026
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
20 articles
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.
The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some ...
A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI
An attack is what you see, but a business operation is what you’re up against
Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.
Your biggest risk may be a vendor you trust. How can SMBs map their third-party blind spots and build operational resilience?
If you’ve been a victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse.
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay.
The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan
This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven't caught up with