Russian APT Groups Intensify Attacks in Europe with Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-11182 | Unauthenticated Cross-Site Scripting (XSS) in MDaemon Email Server Webmail MDaemon Email Server versions before 24.5.1c contain a cross-site scripting flaw (CWE-79) in its handling of HTML email: JavaScript embedded in an img tag is not properly sanitized. A remote, unauthenticated attacker can trigger it simply by sending a crafted HTML email that a webmail user then opens, requiring no privileges but relying on user interaction. Successful exploitation loads attacker-supplied JavaScript in the context of the webmail user's browser window, which could enable session or credential theft and further intrusions from that user's session. Any organization running an affected MDaemon version with users of its webmail client is affected; MDaemon is a commercial on-premises Windows mail server used mainly by small and mid-sized organizations. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19, and public reporting ties MDaemon exploitation to Russia-linked APT28 (Fancy Bear) campaigns that targeted the email of high-level Ukrainians and their military suppliers. Do: Upgrade to MDaemon Email Server 24.5.1c or later, prioritizing installations whose webmail is exposed to the internet, since the flaw is actively exploited and KEV-listed. Review webmail access and message-viewing logs for suspicious activity, especially in organizations that may be targeted by APT28 (Ukrainian government, military, or defense-supply interests). Federal agencies must follow CISA KEV required actions (apply vendor mitigations per instructions and applicable BOD 22-01 guidance, or discontinue use if mitigations are unavailable) by the required due date. | 5.3 | 18% | KEV |
| moderatetens of thousands of on-premises deployments; plausibly on the order of 10,000–100,000 webmail users | |
| CVE-2024-49039 | Windows Task Scheduler Elevation-of-Privilege Flaw Actively Exploited in the Wild CVE-2024-49039 is an elevation-of-privilege vulnerability (CWE-287, improper authentication) in the Microsoft Windows Task Scheduler, scored 8.8 (High) with a local attack vector, low required privileges, and a changed scope indicating the exploit crosses a security boundary. A local attacker with limited user privileges can trigger the flaw through Task Scheduler to gain elevated rights on the affected system, typically SYSTEM- or administrator-level control, with no user interaction required. Every supported Windows desktop and server release in the vendor's affected list is impacted, since Task Scheduler is a core component of the operating system. The flaw was patched as an actively exploited zero-day in the November 2024 Patch Tuesday release, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, and ransomware operators are known to use it. With an EPSS of 14.2% (96th percentile), defenders should treat this as a high-priority local privilege escalation for privilege-chaining and ransomware campaigns. Do: Apply the November 2024 Windows security updates across all affected Windows 10, Windows 11, and Windows Server branches, prioritizing servers, jump hosts, and machines used by privileged users given confirmed ransomware use. Confirm no supported Windows host is left unpatched, review local task creation and authentication logs for signs of privilege escalation, and follow CISA's required action to apply vendor mitigations or discontinue use if patches are unavailable. | 8.8 | 14% | KEV ransomware |
| masshundreds of millions of Windows systems (Task Scheduler ships with every Windows 10, Windows 11, and Windows Server installation) | |
| CVE-2024-9680 | Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile). Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability. | 9.8 | 23% | KEV ransomware |
| masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments) |
Full article685 words · extracted from infosecurity-magazine.com · click to collapse
The end of 2024 and the start of 2025 were marked by the strengthened intensity of malicious cyber activity by Russian-aligned hacking groups, according to ESET.
In its APT Activity Report Q4 2024–Q1 2025, ESET Research documented the activity of some of the major advanced persistent threat (APT) groups from China, North Korea, Iran, Russia and a few other countries between October 2024 and March 2025.
The research team observed that Russian APT groups intensified attacks against Ukraine and the EU during that period, exploiting zero-day vulnerabilities and deploying new wipers.
In Asia, China-aligned actors, responsible for the most APT campaigns (40.1%), continued their espionage campaigns, primarily targeting the EU government and the maritime sector.
Meanwhile, North Korea-backed groups expanded their campaigns aimed at making money for the regime using fake job listings and social engineering.

Iranian APT groups maintained their primary focus on the Middle East region, predominantly targeting governmental organizations and entities within the manufacturing and engineering sectors in Israel.
The report, published on May 19, is a snapshot of data available for ESET customers, collected through ESET products and shared intelligence verified by ESET researchers.
Fancy Bear, Gamaredon and Sandworm at the Russian Forefront
During the monitored period, Russia-aligned threat actors, notably Fancy Bear, Gamaredon and Sandworm continued their aggressive campaigns, primarily targeting Ukraine and EU countries. Ukraine faced the most intense cyber-attacks against its critical infrastructure and government institutions.
Gamaredon, a hacking unit believed to be affiliated with Russia's Federal Security Service (FSB), remained the most prolific actor targeting Ukraine. Notably, the group, also known as Primitive Bear, UNC530 and Aqua Blizzard, improved its malware obfuscation toolset and introduced PteroBox, a file stealer that leverages Dropbox.
Fancy Bear (APT28), a group associated with the Russian military intelligence agency (GRU), refined its exploitation of cross-site scripting (XSS) vulnerabilities in webmail services, expanding its Operation RoundPress to include multiple email services. The group, also known as Sednit, Pawn Storm, Forest Blizzard and Sofacy Group, successfully leveraged a zero-day vulnerability in MDaemon Email Server (CVE-2024-11182) against Ukrainian companies.
Read more: Russian Espionage Operation Targets Organizations Linked to Ukraine War
Sandworm (APT44), another group associated with the GRU, primarily concentrated on compromising Ukrainian energy infrastructure. The group, also known as Voodoo Bear, Iron Viking, Telebots and Seashell Blizzard, leveraged weaknesses in Active Directory Group Policy to deploy ZEROLOT, a new wiper.
Other Russia-aligned groups, such as RomCom, demonstrated advanced capabilities by deploying zero-day exploits against prominent software, including Mozilla Firefox (CVE-2024-9680) and Microsoft Windows (CVE-2024-49039).
Other Key APT Campaigns Observed by ESET
Other key takeaways from the report included:
- Mustang Panda remained the most active China-backed APT group, targeting governmental institutions and maritime transportation companies via Korplug loaders and malicious USB drives
- PerplexedGoblin, another Chinese-aligned group, distributed a new espionage backdoor, which ESET named NanoSlate, against a Central European government entity
- North Korea-aligned threat group DeceptiveDevelopment significantly broadened its targeting, using fake job listings primarily within the cryptocurrency, blockchain and finance sectors to distribute the multiplatform WeaselStore malwar.
- Kimsuky and Konni returned to their usual activity levels in early 2025 after a noticeable decline at the end of 2024, shifting their targeting away from English-speaking think tanks, NGOs and North Korea experts to focus primarily on South Korean entities and diplomatic personnel
- North Korean group Andariel resurfaced after a year of inactivity with a sophisticated attack against a South Korean industrial software company
Interestingly, ESET also observed that on February 28, 2025, a VHDX file containing a malicious shortcut and an encrypted downloader, which the firm referred to as RadialAgent, was uploaded to VirusTotal from Japan by APT-C-60, a cyber espionage group aligned with South Korea.
Jean-Ian Boutin, the ESET Director of Threat Research, said, “The highlighted operations are representative of the broader threat landscape that we investigated during this period. They illustrate the key trends and development and contain only a small fraction of the cybersecurity intelligence data provided to customers of ESET APT reports.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/russian-apt-intensify-cyber/