A new surge of advanced persistent threat (APT) activity driven by Chinese state-affiliated hacking groups has been observed targeting European organizations, government bodies, and critical infrastructure, according to the recently published ESET APT Activity Report for Q4 2024 to Q1 2025.
The report, summarizing intelligence from October 2024 through March 2025, highlights a remarkable escalation in espionage campaigns and the introduction of new and enhanced malware toolsets by APT actors.
Threat Actors Boost Espionage Campaigns
The threat group Mustang Panda emerged as the most active China-aligned actor, consistently focusing on government institutions and key maritime transportation firms within Europe.
Employing a combination of Korplug loaders-a well-known remote access trojan (RAT) variant-and the strategic use of malicious USB drives, Mustang Panda continues to exploit both digital and physical vectors to gain initial footholds within their targeted environments.
These operations underscore the group’s tactical adaptability as it leverages removable media to bypass perimeter defenses and propagate laterally across networks.

Other China-linked groups echoed this drive for espionage against high-value European targets.
The DigitalRecyclers group notably intensified its efforts against European Union government entities, utilizing the KMA VPN anonymization network to cloak their operations while deploying a sophisticated arsenal of backdoors, including RClient, HydroRShell, and GiftBox.
The group dubbed PerplexedGoblin surfaced with a previously unknown espionage backdoor, NanoSlate, which it deployed in operations against a central European government entity.
Meanwhile, Webworm targeted a Serbian government organization using SoftEther VPN, reinforcing the persistent trend of leveraging trusted third-party tools for covert access.
ESET researchers also identified a ShadowPad malware cluster, suggesting links to both espionage operations and sporadic ransomware deployment, primarily for financial gain.
The proliferation and frequent use of shared toolsets such as HDMan, PhantomNet, and Sonifake by the group Worok led ESET analysts to clarify attribution ambiguities in several recent campaigns, challenging inconsistent third-party reporting on the involvement of other actors.
Attack Vectors Fuel Sophisticated Intrusions
While China-aligned APTs dominated the espionage landscape, parallel activity was noted among threat actors from Iran, North Korea, and Russia.
Iran-aligned MuddyWater was observed leveraging remote monitoring and management (RMM) software in spearphishing campaigns, often in cooperation with Lyceum-targeting Israeli manufacturing interests.
There was also destructive activity by CyberToufan, which executed wiper malware attacks against Israeli organizations, and a resurgence of BladedFeline targeting telecommunications in Uzbekistan.
North Korea-aligned groups, meanwhile, were active in high-scale financially motivated attacks.
DeceptiveDevelopment expanded its targeting scope through social engineering tactics centered on cryptocurrency, blockchain, and finance sectors, using innovative methods such as bogus GitHub issue posts and the deployment of WeaselStore malware.
The Bybit cryptocurrency theft, attributed to the TraderTraitor group, was especially significant, resulting in losses nearing USD 1.5 billion due to a supply-chain compromise.
Russian-aligned APTs maintained their aggressive posture against Ukraine and the broader EU, with groups like Sednit and Gamaredon innovating new methods of exploiting webmail and software vulnerabilities.
Sednit made notable advances by leveraging a zero-day exploit (CVE‑2024‑11182) in the MDaemon Email Server, while Gamaredon introduced new file stealer malware leveraging Dropbox called PteroBox.
The infamous Sandworm group intensified its destructive campaigns against Ukrainian energy companies using the ZEROLOT wiper and remote management tools to facilitate initial compromise and lateral movement.
Finally, lesser-known actors such as APT‑C‑60, StealthFalcon, and an unidentified group targeting Ukrainian diplomats and officials with phishing campaigns were also noted in the report.
These findings demonstrate a broadening threat landscape characterized by sophisticated techniques, shared tooling, and persistent targeting of government and critical infrastructure worldwide.
ESET notes that these activities were detected via their products, and all intelligence is corroborated by proprietary telemetry verified by ESET researchers, reflecting only a fraction of the broader cyber threat intelligence accessible to ESET’s private clients.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates