Thursday, May 28, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea

May 28, 2026
in Artificial Intelligence, Cryptocurrencies, GlobeNewswire, Web3
Reading Time: 8 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET Research has released its latest APT Activity Report covering October 2025 – March 2026.
  • China-aligned threat actors remained highly active, including in geopolitical hotspots like Venezuela, Syria, and the Gulf states, spying on maritime, energy industries, an AI robotics company in South Korea, and governmental targets.
  • A defense company in the United Arab Emirates was compromised; possibly aimed at journalists, Arabic-speaking users being targeted with Android spyware. North Korea-aligned Andariel attacked a company that appears to be involved in nuclear industry.
  • Russia-aligned threat actors continued to focus overwhelmingly on Ukraine. Sednit deployed implants against Ukrainian military personnel, drone manufacturers, and organizations involved in drone research and development.

BRATISLAVA, Montreal, May 28, 2026 (GLOBE NEWSWIRE) — ESET Research has released its latest APT Activity Report, which highlights activities of select APT groups that were documented by ESET researchers from October 2025 through March 2026. During the monitored time frame, China-aligned threat actors remained highly active worldwide, conducting espionage campaigns shaped in part by geopolitical developments affecting Beijing’s economic and security interests. Following the US military operation in Venezuela and amid continuing instability in the Gulf region, ESET spotted signs that China-aligned groups were being mobilized to improve Beijing’s visibility into maritime, energy, and political developments abroad. North Korea-aligned Andariel attacked a company that appears to be involved in the nuclear power industry.

China-aligned FamousSparrow targeted a Venezuelan governmental entity connected to maritime affairs, likely to monitor the resilience of oil shipments after the US intervention. There, ESET also noticed SteppeDriver, another China-aligned APT group targeting a Syrian governmental network, activity that may reflect both Chinese commercial interest in Syria’s reconstruction projects and security concerns surrounding Uyghur fighters present in that country. China-aligned UNC5221’s SPAWN malware family targeted governmental entities in Cambodia and Panama, as well as an AI and robotics company in South Korea. The latter targeting South Korea aligns with Beijing’s enduring interest in strategic technologies prioritized under the Made in China 2025 industrial development policy.

“In Asia, the campaigns primarily focused on governmental organizations, strategic industries, and advanced technology sectors. In the Middle East, Israel remained the principal focus of Iran-aligned and Iran-linked activities, with targets ranging from organizations affected by espionage intrusions to device manufacturers hit by destructive tooling,” says Jean-Ian Boutin, Director of Threat Research at ESET.

The war in Iran that began in late February 2026 was the defining event for Iran-aligned activity during this period. Paradoxically, the conflict coincided with a decline in activity from established Iran-aligned APT groups in ESET telemetry, most likely because internet restrictions imposed by the Iranian regime hindered their ability to operate effectively. At the same time, this environment appears to have favored the mobilization of proxy and hacktivist actors targeting Israel, the United States, and other states seen as hostile to Tehran. ESET Research also documented an unusual spike in activity against Israeli targets that it could not confidently link to previously known groups. Two unattributed activity clusters, Rusty Boots and MoKhargosh, demonstrated both espionage capabilities and destructive potential against Israel – including deployment of a bootkit-style wiper while retaining destructive tooling for later use.

ESET Research also found a defense company in the United Arab Emirates being compromised, and Arabic-speaking users being targeted with Android spyware. It was possibly aimed at journalists or open-source intelligence practitioners since the name of attacker’s Telegram channel was likely inspired by Live Universal Awareness Map (Liveuamap), a legitimate, well-known OSINT platform dedicated to mapping military incidents worldwide.

North Korea-aligned threat actors remained active on several fronts. Multiple groups continued targeting developers and the cryptocurrency ecosystem with social engineering schemes that can yield both direct financial gain and opportunities for software supply-chain compromise. ESET also uncovered the reemergence of the Andariel group in attacks against South Korea, where the group deployed TigerRAT and attempted to spread Rook ransomware within an engineering company that appears to manufacture equipment relevant to liquid hydrogen handling and the nuclear power industry – technologies that are obviously of interest to Pyongyang’s ballistic and nuclear ambitions.

Russia-aligned threat actors continued to focus overwhelmingly on Ukraine and entities connected to that country’s defense efforts. Sednit deployed its Covenant and BeardShell implants against Ukrainian military personnel, drone manufacturers, and organizations involved in drone research and development, while also targeting logistics and transportation companies outside Ukraine. Sandworm intensified destructive activity over the winter, deploying several new wipers in Ukraine against governmental and private sector targets. Particularly notable was a December 2025 data destruction incident affecting a Polish energy company, which ESET attributed to Sandworm with medium confidence.

ESET products protect our customers’ systems from the malicious activities described in this released report. Intelligence shared here is based mostly on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks.

More information about ESET APT Reports, which deliver high-quality, strategic, actionable, and tactical cybersecurity threat intelligence, is available on the ESET Threat Intelligence page.

For more details about the mentioned and other APT groups’ activities, read the full APT Activity Report, “Conflict-informed espionage: Monitoring oil shipments, targeting drone makers,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts, and blogs.

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/d3f2c874-4011-4728-aa0f-17adaad9deec

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea

Next Post

Patton and Probity Partner to Protect Critical Infrastructure with Revolutionary New Data Diode Kit that Delivers NSA-Listed Security

Related Posts

Patton and Probity Partner to Protect Critical Infrastructure with Revolutionary New Data Diode Kit that Delivers NSA-Listed Security

Patton®... Let's Connect! GAITHERSBURG, Md. and HERNDON, Va., May 28, 2026 (GLOBE NEWSWIRE) -- Patton®—US manufacturer of secure networking solutions—and Probity—a leader in national security software engineering—have joined forces to deliver a revolutionary new 10-Gigabit data diode kit for secure, unidirectional data transfer. NSA-Listed Security. The secure data-transfer solution combines Patton's NSA-listed...

Read moreDetails

Patton and Probity Partner to Protect Critical Infrastructure with Revolutionary New Data Diode Kit that Delivers NSA-Listed Security

Patton®... Let's Connect! GAITHERSBURG, Md. and HERNDON, Va., May 28, 2026 (GLOBE NEWSWIRE) -- Patton®—US manufacturer of secure networking solutions—and Probity—a leader in national security software engineering—have joined forces to deliver a revolutionary new 10-Gigabit data diode kit for secure, unidirectional data transfer. NSA-Listed Security. The secure data-transfer solution combines Patton's NSA-listed...

Read moreDetails

ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea

ESET Research has released its latest APT Activity Report covering October 2025 – March 2026. China-aligned threat actors remained highly active, including in geopolitical hotspots like Venezuela, Syria, and the Gulf states, spying on maritime, energy industries, an AI robotics company in South Korea, and governmental targets. A defense company...

Read moreDetails

Atos Supports CONMEBOL eLibertadores Shaping the Future of Football eSports and Fan Engagement

Press Release Atos Supports CONMEBOL eLibertadores Shaping the Future of Football eSports and Fan Engagement Through the CONMEBOL eLibertadores, Atos is helping CONMEBOL create new digital-first and interactive experiences for football fans Paris, France, May 28, 2026 – Atos, a global leader in AI-powered digital transformation, with more than three...

Read moreDetails

Atos Supports CONMEBOL eLibertadores Shaping the Future of Football eSports and Fan Engagement

Press Release Atos Supports CONMEBOL eLibertadores Shaping the Future of Football eSports and Fan Engagement Through the CONMEBOL eLibertadores, Atos is helping CONMEBOL create new digital-first and interactive experiences for football fans Paris, France, May 28, 2026 – Atos, a global leader in AI-powered digital transformation, with more than three...

Read moreDetails

DouYu International Holdings Limited Reports First Quarter 2026 Unaudited Financial Results

WUHAN, China, May 28, 2026 (GLOBE NEWSWIRE) -- DouYu International Holdings Limited (“DouYu” or the “Company”) (Nasdaq: DOYU), a leading game-centric live streaming platform in China and a pioneer in the eSports value chain, today announced its unaudited financial results for the first quarter ended March 31, 2026. First Quarter...

Read moreDetails

DouYu International Holdings Limited Reports First Quarter 2026 Unaudited Financial Results

WUHAN, China, May 28, 2026 (GLOBE NEWSWIRE) -- DouYu International Holdings Limited (“DouYu” or the “Company”) (Nasdaq: DOYU), a leading game-centric live streaming platform in China and a pioneer in the eSports value chain, today announced its unaudited financial results for the first quarter ended March 31, 2026. First Quarter...

Read moreDetails

Fixico and Caliber join forces to reshape fleet repair in the United States

AMSTERDAM and LEWISVILLE, Texas, May 28, 2026 (GLOBE NEWSWIRE) -- Fixico, Europe's digital platform for car repair management, and Caliber, the largest auto collision repair provider in the United States, today announced a strategic partnership to introduce a dedicated offering designed to help fleet operators manage increasing repair complexity through...

Read moreDetails

Fixico and Caliber join forces to reshape fleet repair in the United States

AMSTERDAM and LEWISVILLE, Texas, May 28, 2026 (GLOBE NEWSWIRE) -- Fixico, Europe's digital platform for car repair management, and Caliber, the largest auto collision repair provider in the United States, today announced a strategic partnership to introduce a dedicated offering designed to help fleet operators manage increasing repair complexity through...

Read moreDetails

Virtune informs about a technical update regarding the review date for the Virtune Stablecoin Index (STABLEI) in the index methodology provided by the index provider MarketVector

This information is such that the issuer is obliged to make public pursuant to Chapter 15, Section 8 of the Swedish Securities Market Act (2007:528). Stockholm, 28 May 2026 – Virtune announces that the issuer's index provider, MarketVector Indexes™ ("MarketVector"), will carry out a change to the review date for...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Top Cross-Chain DeFi Solutions to Watch by 2025

    108 shares
    Share 43 Tweet 27
  • What is a Gold IRA? (Guide Released)

    7 shares
    Share 3 Tweet 2
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    60 shares
    Share 24 Tweet 15
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    168 shares
    Share 67 Tweet 42
  • Top Layer 1 Crypto Projects to Watch in 2025

    10 shares
    Share 4 Tweet 3
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Patton and Probity Partner to Protect Critical Infrastructure with Revolutionary New Data Diode Kit that Delivers NSA-Listed Security
  • Patton and Probity Partner to Protect Critical Infrastructure with Revolutionary New Data Diode Kit that Delivers NSA-Listed Security
  • ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea
  • ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea
  • Atos Supports CONMEBOL eLibertadores Shaping the Future of Football eSports and Fan Engagement

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.