ESET Resource Center

APT Activity Report T3 2022: Sandworm Deploying its Enhanced Wiper Arsenal

January 2023

APT Activity Report T3 2022: Sandworm Deploying its Enhanced Wiper Arsenal

ESET APT Activity Report T3 2022 summarizes the activities of selected advanced persistent threat (APT) groups that were observed, investigated, and analyzed by ESET researchers from September until the end of December 2022.

In the monitored timespan, Russia-aligned APT groups continued to be particularly involved in operations targeting Ukraine, deploying destructive wipers and ransomware. Among many other cases, ESET researchers detected the infamous Sandworm group using a previously unknown wiper against an energy sector company in Ukraine.

ESET researchers also detected a MirrorFace spearphishing campaign targeting political entities in Japan and noticed a gradual change in the targeting of some China-aligned groups. Iran-aligned groups continued to operate at a high volume – besides Israeli companies, POLONIUM also started targeting foreign subsidiaries of Israeli companies. In various parts of the world, North Korea-aligned groups used old exploits to compromise cryptocurrency firms and exchanges.

In addition, a cyberespionage group that targets high-profile government entities in Central Asia has been discovered, and ESET researchers named it SturgeonPhisher.

Don't miss out

PREMIUM CONTENT

WHITE PAPERS


Navigating Ransomware in 2025: Key Insights & Prevention Strategies

Stay ahead of ransomware threats! Explore the latest trends, prevention strategies, and discover our new tool—ESET Ransomware & Remediation.

PREMIUM CONTENT

WHITE PAPERS


Prevention first: Mastering Cybersecurity with MDR

Discover the critical role of Managed Detection & Response (MDR) in prevention and see how ESET PROTECT MDR can strengthen your security in this Buyer’s Guide.

REPORTS


ESET PROTECT is Top 3 in the G2 Winter 2025 Grid® Report for Extended Detection and Response (XDR) Platforms

Discover why ESET PROTECT earned a top 3 leader position in the G2 Winter 2025 Grid® Report for Extended Detection and Response (XDR) Platforms, based on the latest customer reviews.

Ready for next step?

Enter the world of enterprise protection