The Containment Era is here. →Explore

Executive Summary

In 2025, cyber threat groups linked to North Korea and China intensified their attacks on financial institutions and cryptocurrency assets in the Asia-Pacific region. North Korean adversaries, notably PRESSURE CHOLLIMA, executed the largest financial theft to date, stealing $1.46 billion in cryptocurrency through a supply chain compromise. Concurrently, Chinese threat actors like HOLLOW PANDA targeted financial institutions across multiple countries, including the Philippines, Indonesia, and Brazil. These operations leveraged advanced techniques, including AI-generated identities and sophisticated social engineering tactics, to infiltrate organizations and exfiltrate sensitive data. (crowdstrike.com)

The escalation of these cyber activities underscores a growing trend of state-sponsored cybercrime aimed at financial gain and intelligence collection. The increasing sophistication and frequency of these attacks highlight the urgent need for enhanced cybersecurity measures and international collaboration to protect financial infrastructures from such persistent threats.

Why This Matters Now

The surge in state-sponsored cyberattacks targeting financial institutions, especially in the Asia-Pacific region, poses significant risks to global financial stability. The use of AI and advanced social engineering by these threat actors necessitates immediate and robust cybersecurity strategies to mitigate potential economic and operational disruptions.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

They employed AI-generated identities, sophisticated social engineering tactics, and supply chain compromises to infiltrate financial institutions and exfiltrate sensitive data.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attackers' ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial compromise via spear-phishing may still occur, subsequent unauthorized access to other workloads could be significantly constrained.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Even if attackers escalate privileges within a compromised workload, their ability to access other workloads would likely be restricted.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement across the network would likely be significantly limited, reducing the attacker's ability to reach critical systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Establishing and maintaining command and control channels would likely be more challenging due to enhanced monitoring and control.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be detected and blocked, reducing the risk of data loss.

Impact (Mitigations)

While some impact may still occur, the overall damage would likely be reduced due to constrained attacker activities.

Impact at a Glance

Affected Business Functions

  • Digital Asset Management
  • Online Banking Services
  • Customer Data Management
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $2,020,000,000

Data Exposure

Personal and financial information of customers, including account details and transaction histories.

Recommended Actions

  • Implement Zero Trust Segmentation to limit lateral movement within the network.
  • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows.
  • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
  • Establish Multicloud Visibility & Control to maintain oversight across all cloud environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image