Two threat-landscape reports describe an increasingly aggressive nation-state/APT environment, emphasizing how stolen credentials and access sold in underground markets reduce the need for bespoke initial access while enabling long-dwell espionage. SOCRadar’s U.S.-focused writeup frames state-linked operations as prioritizing persistent visibility into high-value environments such as email, identity systems, telecom, and government-adjacent infrastructure, citing China-nexus activity (including Salt Typhoon) as emblematic of strategic access over smash-and-grab theft.
NSFOCUS’s 2025 global APT overview highlights a marked increase in 0-day vulnerability use across operating systems, browsers, network devices, and even security software, enabling extended stealth and broad impact. It cites examples including BlindEagle targeting Colombian judicial/government entities by exploiting a variant of CVE-2024-43451 (Windows shortcut/SMB link behavior enabling NTLMv2 hash capture with low-interaction triggers), Lazarus Group weaponizing a 0-day in South Korea’s widely deployed CrossEX banking/security software for large-scale intrusion and data theft, and Turkey-linked Marbled Dust/Sea Turtle conducting an operation against the Iraqi Kurdish military (disclosed later) using vulnerability exploitation as part of the intrusion chain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
In Q1 2026, the global education sector appeared in 20% of observed APT campaigns after being absent the previous quarter, with China-linked groups including MISSION2074, Stone Panda, Hafnium, and Lotus Blossom, as well as Iran-linked Charming Kitten, driving activity. Victims in 27 countries were targeted through email, FTP, and SSHD servers to access research data and institutional communications, alongside related spear-phishing and supply-chain threats.
Google reported that Iran-linked UNC1549 and UNC6446 used recruitment-themed lures and career-workflow tools such as job portals, resume builders, and personality tests to target aerospace and defense personnel. The activity also sought to exploit third-party relationships for access.
North Korea-linked Kimsuky used QR-code phishing, or quishing, to target U.S. NGOs, think tanks, academic institutions, and government entities focused on North Korea issues. The campaign reflected evolving social-engineering tactics in espionage operations.
A campaign referenced by CISA was attributed to Russia's GRU Unit 26165, also known as APT28, using password spraying, spearphishing, and Microsoft Exchange mailbox permission manipulation. The activity targeted U.S.-relevant strategic sectors such as logistics and technology.
Apple released a patch for an ImageIO zero-day vulnerability that had been exploited in the wild and could enable zero-click remote code execution. The fix was highlighted as a notable 2025 response to active exploitation.
XE Group carried out a supply-chain compromise involving VeraCore and used two zero-day vulnerabilities in the operation. The incident illustrated the growing use of zero-days in software supply-chain attacks.
A SharePoint remote code execution exploit chain was commoditized and adopted by groups including Mimo and Warlock, which also updated the chain to bypass patches. The development showed how quickly advanced exploit techniques spread beyond their original operators.
Cisco disclosed ArcaneDoor-linked cyberespionage activity exploiting three zero-days affecting Cisco devices, including two high-severity remote code execution flaws. The campaign targeted global critical infrastructure and U.S. federal agencies.
StealthFalcon conducted a spear-phishing campaign against a Turkish defense contractor, abusing a network shortcut zero-day to install a custom backdoor. The attack highlighted continued targeting of defense-sector organizations with tailored initial access techniques.
Marbled Dust, also known as Sea Turtle, exploited a directory traversal zero-day in Output Messenger to deploy a Golang backdoor against the Iraqi Kurdish military. The operation demonstrated nation-state use of messaging software vulnerabilities for espionage.
North Korea-linked Lazarus exploited a zero-day in CrossEX software in attacks in South Korea. The activity was cited as an example of APT groups using trusted local software to gain stealthy access.
BlindEagle used a Windows shortcut/SMB NTLMv2-hash capture zero-day to target Colombian judicial and government entities, seeking credential theft and access. The campaign was identified as part of the 2025 APT threat landscape.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyfirma.com
Open sourceasec.ahnlab.com
Open sourcecert.europa.eu
Open sourcesocradar.io
Open sourcensfocusglobal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.