# NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY

> NSFOCUS's Threat Intelligence Center (Fuying Lab) released its 2025 APT Group Research Annual Report, documenting 662 globally tracked APT groups (up 6.77% YoY), 42 newly disclosed groups, and 19,925 new IOCs added from 795 collected reports. Covert targeted information theft (24%) and remote XSS attacks (13%) led observed techniques, AI-driven attacks rose 89% YoY with AI-generated phishing achieving a 54% click-through rate versus 12% for traditional phishing, and Cleaver, TA505, and Lazarus Group were named among the most active groups, collectively linked to 10,753 attacked IP hosts.

- **Published:** 2026-07-20T00:00:00Z
- **Last reviewed:** 2026-07-20T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1559
- **ID:** TL-2026-1559
- **Severity:** MEDIUM
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Cleaver (Iran, North Korea)
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NSFOCUS's Threat Intelligence Center published its 2025 APT Group Research Annual Report (released 2026-07-20), a landscape-level synthesis rather than a single-incident advisory. The report tracked 662 APT groups globally (6.77% YoY growth), with 119 groups actively profiled during the year, 42 of them newly disclosed, and 38 groups continuously active throughout 2025 (peaking at 18 simultaneously active groups in April). Analysts ingested 795 related incident reports and added 19,925 new indicators of compromise to their tracking corpus.

On technique distribution, covert targeted information theft tied for the top spot at 24% of observed activity, followed by remote web-based cross-site scripting (XSS) attacks at 13%; a combined 'information gathering + script execution' penetration approach accounted for 61% of total observed attacks, indicating APT operators increasingly favor reconnaissance-driven, script-based intrusion chains over heavier custom tooling for initial compromise.

The most significant technique-trend finding is the acceleration of AI-weaponized attacks: AI-driven APT activity rose 89% year-on-year, and AI-generated phishing lures achieved a 54% click-through rate compared to 12% for traditionally authored phishing — evidence that generative-AI-crafted social engineering content is meaningfully more effective at eliciting victim interaction than legacy phishing kits. NSFOCUS frames this as part of a broader shift from automated, bulk-oriented operations toward intelligent, precision-guided targeting.

The report names Cleaver (Iranian state-linked, aka Operation Cleaver / TG-2889), TA505 (financially motivated cybercrime group, aka Hive0065 / Spandex Tempest / CHIMBORAZO), and Lazarus Group (North Korean state-sponsored, RGB-attributed, aka Labyrinth Chollima / HIDDEN COBRA / Diamond Sleet / ZINC) among the year's most active tracked groups, with this cohort collectively linked to 10,753 attacked IP hosts during 2025. These three groups span the full spectrum of APT motivation covered by the report: state espionage (Lazarus), regime-aligned destructive/espionage operations (Cleaver), and profit-driven cybercrime with ransomware monetization (TA505) — illustrating that the 'APT' designation in this landscape report spans nation-state and organized-crime actors alike.

A companion NSFOCUS mid-year landscape report (2025 APT Annual Landscape Report, released 2026-06-02) recorded 308 discrete APT incidents (a smaller, incident-level count distinct from the 662 tracked-group figure), a 4% YoY increase, and identified seven defining 2025 trends: (1) APT groups integrating AI tools and AI-generated content across the full attack lifecycle; (2) ClickFix-style social engineering proliferating as a primary phishing delivery gateway; (3) multi-signature wallet/transaction hijacking techniques weaponized for cryptocurrency-focused economic crime; (4) a 'door-knocking' covert communication mode used in China-targeting operations; (5) abuse of privileged Visual Studio tooling to bypass endpoint security controls; (6) continued exploitation of zero-day vulnerabilities in URL/shortcut file handling for one-click compromise; and (7) zero-day Chromium sandbox-escape exploitation becoming a growing APT focus area. That report also flagged a sharp rise in national defense/military sector targeting, up to 17% of observed targets (a 9-percentage-point increase from 2024).

Forward-looking, NSFOCUS forecasts five 2026 trend lines: AI transitioning from an auxiliary tool to APT groups' primary attack engine; accelerated weaponization of zero-day vulnerabilities; normalization of supply-chain attacks including increased open-source ecosystem poisoning; intensified geopolitically-bound APT targeting of critical infrastructure amid rising geopolitical competition; and cloud security / identity-based attack surfaces becoming a primary APT battleground. No specific CVEs, malware samples, or network infrastructure were disclosed for individual 2025 campaigns in the source reporting; this threat entry documents the landscape findings and grounds MITRE/IOC context in the well-documented historical TTPs, tooling, and infrastructure patterns of the three named most-active groups (Cleaver, TA505, Lazarus Group) as tracked by MITRE ATT&CK.

## MITRE ATT&CK

- T1587 Develop Capabilities
- T1585 Establish Accounts
- T1588 Obtain Capabilities
- T1566 Phishing
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1003 OS Credential Dumping
- T1557 Adversary-in-the-Middle
- T1027 Obfuscated Files or Information
- T1574 Hijack Execution Flow
- T1497 Virtualization/Sandbox Evasion
- T1553 Subvert Trust Controls
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1018 Remote System Discovery
- T1083 File and Directory Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1568 Dynamic Resolution
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1685 Disable or Modify Tools

## Sources

- [NSFOCUS Releases 2025 APT Group Research Annual Report](https://nsfocusglobal.com/nsfocus-releases-2025-apt-group-research-annual-report/)
- [7 New Trends Unveiled! NSFOCUS 2025 APT Annual Landscape Report is Released!](https://nsfocusglobal.com/7-new-trends-unveiled-nsfocus-2025-apt-annual-landscape-report-is-released/)
- [7 New Trends Unveiled! NSFOCUS 2025 APT Annual Landscape Report is Released! (Security Boulevard syndication)](https://securityboulevard.com/2026/06/7-new-trends-unveiled-nsfocus-2025-apt-annual-landscape-report-is-released/)
- [Lazarus Group, Group G0032 | MITRE ATT&CK](https://attack.mitre.org/groups/G0032/)
- [TA505, Hive0065, Group G0092 | MITRE ATT&CK](https://attack.mitre.org/groups/G0092/)
- [Cleaver, Threat Group 2889, TG-2889, Group G0003 | MITRE ATT&CK](https://attack.mitre.org/groups/G0003/)
- [Operation Cleaver — Grokipedia summary](https://grokipedia.com/page/operation_cleaver)
- [NSFOCUS Monthly APT Insights – March 2026](https://nsfocusglobal.com/nsfocus-monthly-apt-insights-march-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1559
