NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY — Threadlinqs Intelligence
As of 2026-07-20, NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY is a medium-severity apt threat attributed to Cleaver (Iran / North Korea (Cleaver, Lazarus); TA505 is non-state financially motivated), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1559 · Severity: MEDIUM · Status: ACTIVE · Category: APT
Attribution: Cleaver · Iran / North Korea (Cleaver, Lazarus); TA505 is non-state financially motivated · ESPIONAGE
NSFOCUS's Threat Intelligence Center (Fuying Lab) released its 2025 APT Group Research Annual Report, documenting 662 globally tracked APT groups (up 6.77% YoY), 42 newly disclosed groups, and 19,925
NSFOCUS's Threat Intelligence Center published its 2025 APT Group Research Annual Report (released 2026-07-20), a landscape-level synthesis rather than a single-incident advisory. The report tracked 662 APT groups globally (6.77% YoY growth), with 119 groups actively profiled during the year, 42 of them newly disclosed, and 38 groups continuously active throughout 2025 (peaking at 18 simultaneously active groups in April). Analysts ingested 795 related incident reports and added 19,925 new indicators of compromise to their tracking corpus.
On technique distribution, covert targeted information theft tied for the top spot at 24% of observed activity, followed by remote web-based cross-site scripting (XSS) attacks at 13%; a combined 'information gathering + script execution' penetration approach accounted for 61% of total observed attacks, indicating APT operators increasingly favor reconnaissance-driven, script-based intrusion chains over heavier custom tooling for initial compromise.
The most significant technique-trend finding is the acceleration of AI-weaponized attacks: AI-driven APT activity rose 89% year-on-year, and AI-generated phishing lures achieved a 54% click-through rate compared to 12% for traditionally authored phishing — evidence that generative-AI-crafted social engineering content is meaningfully more effective at eliciting victim interaction than legacy phishing kits. NSFOCUS frames this as part of a broader shift from automated, bulk-oriented operations toward intelligent, precision-guided targeting.
The report names Cleaver (Iranian state-linked, aka Operation Cleaver / TG-2889), TA505 (financially motivated cybercrime group, aka Hive0065 / Spandex Tempest / CHIMBORAZO), and Lazarus Group (North Korean state-sponsored, RGB-attributed, aka Labyrinth Chollima / HIDDEN COBRA / Diamond Sleet / ZINC) among the year's most active tracked groups, with this cohort collectively linked to 10,753 attacked IP hosts during 2025. These three groups span the full spectrum of APT motivation covered by the report: state espionage (Lazarus), regime-aligned destructive/espionage operations (Cleaver), and profit-driven cybercrime with ransomware monetization (TA505) — illustrating that the 'APT' designation in this landscape report spans nation-state and organized-crime actors alike.
A companion NSFOCUS mid-year landscape report (2025 APT Annual Landscape Report, released 2026-06-02) recorded 308 discrete APT incidents (a smaller, incident-level count distinct from the 662 tracked-group figure), a 4% YoY increase, and identified seven defining 2025 trends: (1) APT groups integrating AI tools and AI-generated content across the full attack lifecycle; (2) ClickFix-style social engineering proliferating as a primary phishing delivery gateway; (3) multi-signature wallet/transaction hijacking techniques weaponized for cryptocurrency-focused economic crime; (4) a 'door-knocking' covert communication mode used in China-targeting operations; (5) abuse of privileged Visual Studio tooling to bypass endpoint security controls; (6) continued exploitation of zero-day vulnerabilities in URL/shortcut file handling for one-click compromise; and (7) zero-day Chromium sandbox-escape exploitation becoming a growing APT focus area. That report also flagged a sharp rise in national defense/military sector targeting, up to 17% of observed targets (a 9-percentage-point increase from 2024).
Forward-looking, NSFOCUS forecasts five 2026 trend lines: AI transitioning from an auxiliary tool to APT groups' primary attack engine; accelerated weaponization of zero-day vulnerabilities; normalization of supply-chain attacks including increased open-source ecosystem poisoning; intensified geopolitically-bound APT targeting of critical infrastructure amid rising geopolitical competition; and cloud security / identity-based attack surfaces becoming a primary APT battleground. No specific CVEs, malware samples, or network infrastructure were disclosed for in
Target sectors: government administration, defense, aerospace, finance, energy, telecoms, critical infrastructure, cryptocurrency
Target regions: Global, North America, Europe, Middle East, East Asia
Related threats
- Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector Server
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)
- Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign
- OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, MEDIUM, threat intelligence, cybersecurity, T1587, T1585, T1588, T1566, T1566, T1189, T1059, T1059, T1059, T1059