Threat reportAPTTL-2026-1559

NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY

mediumACTIVE

NSFOCUS 2025 APT Group Research Annual Report (TL-2026-1559), also tracked as NSFOCUS 2025 APT Group Research Annual Report, is a medium-severity advanced persistent threat campaign, first published 2026-07-20. It is attributed to Cleaver (Iran, North Korea) with medium confidence, maps to 27 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
3Cleaver
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1559

Threat ID
TL-2026-1559
Also known as
NSFOCUS 2025 APT Group Research Annual Report, NSFOCUS 2025 APT Annual Landscape Report
Severity
MEDIUM
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Cleaver, TA505, Lazarus Group
Attribution confidence
MEDIUM
Nation-state nexus
Iran, North Korea
Motivation
ESPIONAGE
Target sectors
government administration, defense, aerospace, finance, energy, telecoms, critical infrastructure, cryptocurrency
Target regions
Global, North America, Europe, Middle East, East Asia
Detection rules
9
Indicators of compromise
28

Malware and tooling in NSFOCUS 2025 APT Group Research Annual Report

Malware and tooling: AppleJeus, BLINDINGCAN - S0520, Clop, Dacls - S0497, Dridex, Dtrack, FlawedAmmyy, SDBbot, ServHelper, TinyZbot, TrickBot, AdFind - S0552

How NSFOCUS 2025 APT Group Research Annual Report works

NSFOCUS's Threat Intelligence Center (Fuying Lab) released its 2025 APT Group Research Annual Report, documenting 662 globally tracked APT groups (up 6.77% YoY), 42 newly disclosed groups, and 19,925 new IOCs added from 795 collected reports. Covert targeted information theft (24%) and remote XSS attacks (13%) led observed techniques, AI-driven attacks rose 89% YoY with AI-generated phishing achieving a 54% click-through rate versus 12% for traditional phishing, and Cleaver, TA505, and Lazarus Group were named among the most active groups, collectively linked to 10,753 attacked IP hosts.

NSFOCUS's Threat Intelligence Center published its 2025 APT Group Research Annual Report (released 2026-07-20), a landscape-level synthesis rather than a single-incident advisory. The report tracked 662 APT groups globally (6.77% YoY growth), with 119 groups actively profiled during the year, 42 of them newly disclosed, and 38 groups continuously active throughout 2025 (peaking at 18 simultaneously active groups in April). Analysts ingested 795 related incident reports and added 19,925 new indicators of compromise to their tracking corpus.

On technique distribution, covert targeted information theft tied for the top spot at 24% of observed activity, followed by remote web-based cross-site scripting (XSS) attacks at 13%; a combined 'information gathering + script execution' penetration approach accounted for 61% of total observed attacks, indicating APT operators increasingly favor reconnaissance-driven, script-based intrusion chains over heavier custom tooling for initial compromise.

The most significant technique-trend finding is the acceleration of AI-weaponized attacks: AI-driven APT activity rose 89% year-on-year, and AI-generated phishing lures achieved a 54% click-through rate compared to 12% for traditionally authored phishing — evidence that generative-AI-crafted social engineering content is meaningfully more effective at eliciting victim interaction than legacy phishing kits. NSFOCUS frames this as part of a broader shift from automated, bulk-oriented operations toward intelligent, precision-guided targeting.

The report names Cleaver (Iranian state-linked, aka Operation Cleaver / TG-2889), TA505 (financially motivated cybercrime group, aka Hive0065 / Spandex Tempest / CHIMBORAZO), and Lazarus Group (North Korean state-sponsored, RGB-attributed, aka Labyrinth Chollima / HIDDEN COBRA / Diamond Sleet / ZINC) among the year's most active tracked groups, with this cohort collectively linked to 10,753 attacked IP hosts during 2025. These three groups span the full spectrum of APT motivation covered by the report: state espionage (Lazarus), regime-aligned destructive/espionage operations (Cleaver), and profit-driven cybercrime with ransomware monetization (TA505) — illustrating that the 'APT' designation in this landscape report spans nation-state and organized-crime actors alike.

A companion NSFOCUS mid-year landscape report (2025 APT Annual Landscape Report, released 2026-06-02) recorded 308 discrete APT incidents (a smaller, incident-level count distinct from the 662 tracked-group figure), a 4% YoY increase, and identified seven defining 2025 trends: (1) APT groups integrating AI tools and AI-generated content across the full attack lifecycle; (2) ClickFix-style social engineering proliferating as a primary phishing delivery gateway; (3) multi-signature wallet/transaction hijacking techniques weaponized for cryptocurrency-focused economic crime; (4) a 'door-knocking' covert communication mode used in China-targeting operations; (5) abuse of privileged Visual Studio tooling to bypass endpoint security controls; (6) continued exploitation of zero-day vulnerabilities in URL/shortcut file handling for one-click compromise; and (7) zero-day Chromium sandbox-escape exploitation becoming a growing APT focus area. That report also flagged a sharp rise in national defense/military sector targeting, up to 17% of observed targets (a 9-percentage-point increase from 2024).

Forward-looking, NSFOCUS forecasts five 2026 trend lines: AI transitioning from an auxiliary tool to APT groups' primary attack engine; accelerated weaponization of zero-day vulnerabilities; normalization of supply-chain attacks including increased open-source ecosystem poisoning; intensified geopolitically-bound APT targeting of critical infrastructure amid rising geopolitical competition; and cloud security / identity-based attack surfaces becoming a primary APT battleground. No specific CVEs, malware samples, or network infrastructure were disclosed for individual 2025 campaigns in the source reporting; this threat entry documents the landscape findings and grounds MITRE/IOC context in the well-documented historical TTPs, tooling, and infrastructure patterns of the three named most-active groups (Cleaver, TA505, Lazarus Group) as tracked by MITRE ATT&CK.

MITRE ATT&CK techniques used in TL-2026-1559

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Discovery

T1018 Remote System Discovery; T1069 Permission Groups Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1568 Dynamic Resolution

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Impact

T1486 Data Encrypted for Impact

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

credential-access

T1557 Adversary-in-the-Middle

Resource Development

T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Remediation for NSFOCUS 2025 APT Group Research Annual Report

Immediate actions

  • Deploy AI-aware phishing detection and banner warnings on external mail given documented 54% click-through on AI-generated lures vs 12% traditional
  • Hunt for LSASS credential-dumping activity (Mimikatz, Windows Credential Editor) and PsExec/Net Crawler lateral movement consistent with Cleaver tradecraft
  • Monitor for TA505 loader/backdoor families (Dridex, TrickBot, ServHelper, FlawedAmmyy, Get2, SDBbot) and Clop ransomware precursors
  • Review DLL side-loading and KernelCallbackTable hijack detections associated with Lazarus Group defense-evasion tradecraft
  • Restrict/monitor execution of Visual Studio developer tooling and URL/shortcut file handling given reported abuse for security-control bypass

Workarounds

  • Apply enhanced scrutiny/sandboxing to inbound URL and shortcut files pending vendor mitigations for reported zero-day URL-file exploitation trends
  • Restrict Chromium-based browser sandbox exposure and keep browsers current given reported sandbox-escape zero-day focus

Longer-term hardening

  • Build detection content for combined 'information gathering + script execution' intrusion chains, which the report attributes to 61% of observed 2025 APT activity
  • Expand identity and cloud-workload detection coverage ahead of the forecast 2026 shift toward cloud/identity-based APT targeting
  • Establish a generative-AI-phishing detection and user-training program addressing higher-fidelity AI-crafted lures
  • Track open-source supply-chain package integrity given the forecast normalization of supply-chain/open-source poisoning attacks

Timeline of NSFOCUS 2025 APT Group Research Annual Report

  • Lazarus Group (North Korean, RGB-attributed) begins tracked activity, later linked to the 2014 Sony Pictures Entertainment breach and Operation Dream Job.
  • Cleaver (Operation Cleaver / TG-2889), Iranian state-linked actor, begins tracked activity, later targeting aviation, energy, defense, and telecommunications sectors.
  • TA505 (Hive0065 / Spandex Tempest / CHIMBORAZO) begins tracked activity as a financially motivated cybercrime group known for frequently changing malware distribution.
  • Lazarus Group conducts the Sony Pictures Entertainment breach, one of its earliest publicly attributed high-profile operations, deploying destructive wiper malware alongside data theft.
  • Cylance publishes the 'Operation Cleaver' report, the first major public disclosure documenting the Iranian state-linked Cleaver group's multi-year campaign against aviation, energy, defense, and telecommunications targets across 16+ countries.
  • TA505 begins large-scale distribution of Locky ransomware via mass spam campaigns, establishing its reputation as a high-volume financially motivated threat actor.
  • The WannaCry ransomware worm, attributed to Lazarus Group, causes a global outbreak affecting organizations across 150+ countries, including healthcare and critical infrastructure sectors.
  • TA505 pivots to deploying Clop ransomware in targeted extortion operations, moving from earlier banking-trojan-centric campaigns (Dridex, TrickBot) toward direct ransomware monetization.
  • NSFOCUS records April 2025 as the peak month with 18 APT groups simultaneously active.
  • Close of the 2025 reporting period covered by the NSFOCUS APT Group Research Annual Report: 662 tracked groups, 42 newly disclosed, 19,925 new IOCs from 795 reports.
  • NSFOCUS Fuying Lab releases the companion '2025 APT Annual Landscape Report' detailing 308 incidents and seven defining 2025 APT trends, including AI/AIGC integration, ClickFix phishing, and Chromium sandbox-escape zero-days.
  • NSFOCUS releases the '2025 APT Group Research Annual Report,' naming Cleaver, TA505, and Lazarus Group among the year's most active tracked APT actors.

Sources cited for NSFOCUS 2025 APT Group Research Annual Report

Detection coverage for TL-2026-1559

As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1559 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats