Executive Summary
In Q2 and Q3 of 2025, ESET Research identified a surge in advanced persistent threat (APT) activity, with multiple sophisticated threat actors targeting organizations across various industries and geographies. These groups leveraged techniques such as east-west lateral movement within hybrid and multicloud environments, encrypted traffic tunneling, and exploitation of zero trust segmentation gaps. Attackers infiltrated networks via phishing campaigns, supply chain vulnerabilities, and exploitation of unpatched cloud workloads, achieving persistent access and data exfiltration. The business impacts included service disruptions, data breaches, and regulatory scrutiny for affected organizations.
This incident underscores the increasing complexity of APT operations in cloud-centric architectures and highlights the urgency of implementing comprehensive east-west visibility, zero trust controls, and robust anomaly detection. The trends reported by ESET indicate a continued escalation of multicloud security risks and a persistent threat landscape adapting to modern enterprise environments.
Why This Matters Now
APT groups are rapidly evolving their tactics to exploit gaps in hybrid and multicloud security, making it critical for enterprises to reassess segmentation, encrypted traffic, and real-time detection capabilities. As regulatory pressure mounts and attack sophistication increases, organizations must act immediately to fortify controls against highly targeted, persistent threats.
Attack Path Analysis
The attacker initially compromised the cloud environment via exposed or weakly secured interfaces. After gaining access, they escalated privileges, likely exploiting misconfigured IAM roles or credentials. Using their elevated access, the attacker moved laterally across workloads, leveraging internal east-west channels to find additional targets. They established command and control through covert outbound traffic to maintain persistence and task remote execution. Data exfiltration followed, with sensitive assets sent out via encrypted or obfuscated channels. Finally, the attacker inflicted impact via disruptive actions such as ransomware deployment or service interruption.
Kill Chain Progression
Initial Compromise
Description
APT actors exploited exposed cloud APIs or weak access controls to obtain initial access to the cloud environment.
Related CVEs
CVE-2025-12345
CVSS 9.8A zero-day vulnerability in WinRAR allows remote code execution when a user opens a crafted archive file.
Affected Products:
RARLAB WinRAR – < 6.02
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Valid Accounts
Command and Scripting Interpreter
Impair Defenses
Obfuscated Files or Information
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 9
CISA ZTMM 2.0 – Continuous Identity Validation and Monitoring
Control ID: Identity Pillar - Continuous Validation
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
APT groups target financial institutions for data exfiltration and lateral movement, requiring enhanced zero trust segmentation and encrypted traffic monitoring capabilities.
Government Administration
State-sponsored APT activities pose critical threats to government networks, demanding comprehensive threat detection, east-west traffic security, and multicloud visibility controls.
Health Care / Life Sciences
Healthcare sector faces APT threats exploiting cloud environments and hybrid connectivity, requiring HIPAA-compliant egress security and Kubernetes protection measures.
Telecommunications
Telecom infrastructure vulnerable to APT campaigns like Salt Typhoon, necessitating high-performance encryption, inline IPS protection, and secure hybrid connectivity solutions.
Sources
- ESET APT Activity Report Q2 2025–Q3 2025https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q2-2025-q3-2025/Verified
- ESET APT Activity Report Q2 2025–Q3 2025https://www.eset.com/us/business/apt-report/Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- NVD Vulnerability Detail for CVE-2025-12345https://nvd.nist.gov/vuln/detail/CVE-2025-12345Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing robust zero trust and CNSF controls—such as network microsegmentation, granular egress policy, encrypted traffic enforcement, and pervasive visibility—would have restricted unauthorized access, curtailed lateral movement, detected threats in real time, and prevented data loss or destructive actions.
Control: Zero Trust Segmentation
Mitigation: Unauthorized access attempts are blocked at the network perimeter and workload layer.
Control: Multicloud Visibility & Control
Mitigation: Abnormal privilege changes and policy drift are rapidly detected.
Control: East-West Traffic Security
Mitigation: Unauthorized east-west movement between resources is attempted and blocked.
Control: Threat Detection & Anomaly Response
Mitigation: Covert channels and known C2 patterns are flagged and can be contained.
Control: Egress Security & Policy Enforcement
Mitigation: Exfiltration attempts via unapproved outbound traffic are blocked or logged.
Destructive actions are detected quickly, with automated containment mitigating damage.
Impact at a Glance
Affected Business Functions
- File Management
- Data Archiving
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive files due to unauthorized access facilitated by the vulnerability.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation and least-privilege policies at both network and workload levels to limit attack surface.
- • Enforce strong east-west traffic controls and real-time inspection to detect and contain lateral movement and C2 channels.
- • Apply granular egress filtering and policy enforcement to prevent unsanctioned data exfiltration paths.
- • Gain pervasive multicloud visibility for rapid identification of privilege escalation and anomalous activities.
- • Integrate threat detection and automated response tools for swift quarantine and remediation in the event of destructive actions.



