2025年国家级高级持续性威胁(APT)组织态势报告_43页_2mb
报告摘要
2025 Nation-Aligned APTs Summary
Core Content
The TrendAI™ 2025-APT Annual Report provides a strategic analysis of advanced persistent threat (APT) campaigns in 2025 and early 2026. It highlights the increasing integration of AI in APT operations, the rise of collaborative attack models, and the alignment of cyber activities with geopolitical objectives. The report focuses on APT groups aligned with China, North Korea (DPRK), and Russia, emphasizing their evolving strategies and the challenges they pose to global cybersecurity.
Key Takeaways
- Cyber operations are now tightly coupled with geopolitical objectives, with APT activity increasingly aligned to geopolitical events and military operations.
- Collaboration among APT groups is increasing attack speed and complexity, as access-sharing models such as “Premier Pass-as-a-Service” allow secondary actors to bypass initial compromise stages and complicate attribution.
- AI is now embedded directly in APT operations, with some nation-state-aligned actors deploying AI-assisted and semi-autonomous attack components that accelerate campaigns and sharply reduce defender response windows.
- Resilience at machine speed has become a defensive requirement, forcing organizations to shift from prevention-centric security toward rapid visibility, containment, and recovery in the face of AI-enabled threats.
Strategic Forecast
The next 24 months will be a race for “resilience at machine speed.” As APT actors move towards fully autonomous kill chains, the window for human intervention is closing. Successful defensive measures will depend on the deployment of “defensive AI” that can anticipate and neutralize agentic threats before they can perform lateral movement. No nation can afford to let their rivals get too far ahead in AI technologies.
Geopolitical Threat Landscape
A “Digital Autocracy” bloc has formed, consisting of China, Russia, Iran, and North Korea, with the aim of achieving “digital sovereignty” using AI as a force multiplier to bypass Western sanctions and modernize their military and cyber capabilities.
APT Strategies by Nation
| Feature | China (CN) | North Korea (DPRK) | Russia (RU) |
|---|---|---|---|
| Primary Goal | Global hegemony and self reliance | Regime survival and sabotaging others | National sovereignty |
| AI Infrastructure | Sovereign stack (Huawei/SMIC) | Illicit/Russia-aided | Grey market/nuclear-backed |
| APT Style | Industrialized espionage | Financial and military asymmetry | Financial and military asymmetry, strategic sabotage |
China-Aligned APT Activities
Political Trends
- Strategic diplomacy and resource security: China deepened ties with Russia and the Global South, securing mining rights in the “Lithium Triangle” to maintain a competitive edge in the global energy transition.
- Economic resilience: China achieved its 5.0% GDP growth target through high-tech investments and expanding exports to emerging markets.
- Military modernization: China increased its defense budget by 7.2%, projecting power through high-frequency exercises around Taiwan and long-range drills in distant waters.
APT Activities
- Earth Kasha (APT10): Continued spear-phishing attacks against government and research institutions in Taiwan and Japan, using ANEL malware and ROAMINGMOUSE macros.
- Earth Preta (Mustang Panda): Used DLL sideloading with trusted programs like VLC Media Player to execute malware such as PubLoad or MQsSrv.
- Earth Estries and Earth Naga: Deployed the “Premier Pass-as-a-Service” model, allowing secondary groups to bypass initial intrusion stages and gain direct access to sensitive assets.
- Void Dokkaebi (Famous Chollima): Lured developers with fake job offers, distributing malware through NPM packages and Web3/blockchain communities.
- Earth Kumiho (Kimsuky): Targeted think tanks and diplomatic entities, using LNK files and PowerShell scripts to exfiltrate data and deploy backdoors like KimJongRAT or HttpTroy.
- Earth Imp (KONNI Group): Conducted espionage against South Korea and Russia, using LNK files with Russian filenames to target the Russian Ministry of Foreign Affairs.
- Earth Manticore (APT37): Targeted South Korean government and military, using malicious .HWP documents and browser exploits.
Impact
- Intellectual property and confidential information stolen through cyberespionage strengthen defense capabilities and high-tech industries.
- Supply chain infiltration and cybercrime for financial gain are significant risks, especially for companies in the crypto and fintech sectors.
- Early detection and containment are increasingly difficult due to the collaborative nature of attacks and the use of trusted services like Dropbox and GitHub.
- International response includes sanctions and law enforcement actions, but APT actors are likely to adapt and find new methods to sustain their operations.
DPRK-Aligned APT Activities
Political Trends
- Deepening “Russia-First” diplomacy: North Korea provided unconditional support for the invasion of Ukraine and strengthened its alliance with Russia and Belarus.
- Missile technology advancements: North Korea unveiled the Hwasong-20 ICBM and conducted successful hypersonic missile tests.
- Survival tactics: North Korea attempted to bypass sanctions through tourism diplomacy but still faces domestic food and energy shortages.
APT Activities
- Void Dokkaebi (Famous Chollima): Targeted software developers and IT companies, using fake job offers and malicious NPM packages.
- Earth Kumiho (Kimsuky): Targeted geopolitical think tanks and used LNK files and PowerShell scripts to exfiltrate data.
- Earth Imp (KONNI Group): Conducted espionage against South Korea and Russia, using LNK files with Russian filenames to target the Russian Ministry of Foreign Affairs.
- Earth Manticore (APT37): Targeted South Korean government and military, using malicious .HWP documents and browser exploits.
Impact
- Financial impact: North Korea generates substantial funds through cybercrime, including stolen cryptocurrency and social engineering.
- Information security threats: Military secrets, diplomatic information, and personal data of activists are targeted, with potential leakage leading to human damage.
- International response: The US and South Korea have taken actions against Kimsuky and cybercrime-linked entities, but APT actors are likely to evolve and find new ways to sustain their operations.
Russian-Aligned APT Activities
Political Trends
- Wartime attrition: Russia focused on targeting Ukraine's energy infrastructure and maintaining large-scale ground offensives.
- Economic control: Implemented VAT hikes and Yuan-denominated bonds to sustain the war budget.
- Domestic surveillance: Expanded FSB's internet surveillance powers and criminalized extremist content.
- Dual diplomacy: Deepened ties with North Korea and China, but faced domestic and regional vulnerabilities.
APT Activities
- Pawn Storm (APT28): Conducted cyberattacks on Ukraine and Western nations, using LLMs in LAMEHUG malware and Outlook macros for C&C.
- Earth Dahu (Gamaredon): Used HTA files for initial intrusion and CVE-2025-8088 for deploying malicious HTA files.
- Sandworm: Carried out destructive malware attacks on Ukraine's critical infrastructure, including Industroyer2 and CaddyWiper, and used PathWiper to overwrite critical data.
Impact
- Critical infrastructure attacks are a growing concern, with destructive APTs like Sandworm targeting energy, water, and heating systems.
- Stealth and persistence are key features, with attackers using DLL sideloading and steganography to hide their presence.
- Defensive AI is essential for detecting and neutralizing agentic threats before they can cause significant damage.
Conclusion
The report concludes that resilience, not perfection, is the key to defending against AI-enabled APTs. Organizations must adopt rapid visibility, containment, and recovery strategies. Cross-domain defense, including supply chain risk management and information-sharing systems, is necessary. CISOs and senior management must continuously review their defense postures and threat intelligence to stay ahead of these evolving threats.
试读结束,高清完整版pdf/doc/ppt,请点下载