Discovering many targeted cyber attack groups in APAC

NGUYỄN ĐĂNG |

The Asia-Pacific (APAC) is an area with many targeted cyber attack groups, targeting many key areas in countries.

According to global cybersecurity and digital security company Kaspersky, from 2024 to the first half of 2025, online intelligence exploitation will continue to be the main engine of targeted cybersecurity attack groups (APT) operating in the APAC region.

Ms. Noushin Shabab, Head of the Security Research Team of Kaspersky Global Research and Analysis Group (GReAT), revealed at a recent event that many cybercrime groups and APT cyber attack campaigns are active in the APAC region.

In particular, the SideWinder group - known as the "most aggressive threat in the Asia-Pacific region" - is a cybersecurity attack group that targets government agencies, the military and diplomatic organizations in the region through email fraud (spear-phishing) and sophisticated attack platforms.

This group is particularly interested in the maritime sector (Bangladesh, Cambodia...) and logistics (China, India and Maldives). In March, Kaspersky's GReAT experts also revealed that SideWinder has increased its focus on nuclear power plants and energy facilities in the South Asian region.

SideWinder constantly adjusts its attack tools to avoid detection by the system, making the group a worrying persistent threat.

When targeting nuclear infrastructure, SideWinder uses custom-designed fraudulent emails, often with content related to regulations or factory operations. Opening these emails can trigger a malware chain, allowing hackers to access sensitive operational data, research documents, and personnel information.

In addition, Sri Lanka, Nepal, Myanmar, Indonesia and the Philippines are also on SideWinder's target list.

Some other cyber attack groups such as Spring Dragon, Tetris Phantom, HoneyMyte, Lazarus, Mysterious Elephant... also carried out many APT cyber attack campaigns, using many sophisticated methods, targeting many countries in Southeast Asia in particular and APAC in general.

Over the past decade, researchers have discovered more than 1,000 malware used by Spring Dragon alone to attack government agencies in Southeast Asia, according to Kaspersky.

To protect against targeted cyber attacks, Kaspersky recommends that organizations focus on accurate detection, quick response to familiar tactics, and timely handling of security vulnerabilities. In addition, some measures include:

- Always update the software on all devices, to prevent hackers from taking advantage of vulnerabilities to break into the network system.

- Conduct a comprehensive cybersecurity review of infrastructure and digital assets to detect potential vulnerabilities, thereby overcoming weaknesses in both the external and internal protective layer of the system.

- Use solutions in the high-end product line, providing real-time protection, threat monitoring and investigation - response capabilities at EDR and XDR levels, suitable for all organizational and field scales.

- Equip the information security team (InfoSec) with an in-depth view of the threats targeting the organization.

NGUYỄN ĐĂNG
RELATED NEWS

Risk of new cyber attacks from the rise of Dark AI

|

Organizations and individuals need to prepare for increasingly sophisticated cyber attacks, due to the rise of Dark AI in the Asia-Pacific (APAC).

Apple warns users to update this software to avoid cyber attacks

|

Apple has implemented software improvements and patched more than 20 serious security vulnerabilities to protect iPhone users.

Allianz Life attacked by cyberattack: Personal data of millions of customers stolen

|

Allianz Life confirmed that most of the company's 1.4 million customers' personal data was stolen after a cyberattack.

The Cuban people's support program is about to reach the 350 billion VND mark

|

According to the Central Committee of the Vietnam Red Cross Society, the campaign to support the Cuban people is approaching the 350 billion VND mark, reaching more than 500% of the set target.

Chairman of Ho Chi Minh City People's Committee directs enforcement of illegal construction works in 2 wards

|

HCMC - Phuoc Thang and Tam Thang Wards must completely dismantle illegal and unauthorized construction works, including issuing a decision on enforcement.

Determined to successfully implement the Resolution of the Party Congress of the Vietnam General Confederation of Labor for the 2025-2030 term

|

On the afternoon of August 19, the 1st Congress of the Party Committee of the Vietnam General Confederation of Labor, term 2025 - 2030, was a great success.

HCMC continues to collect tolls, rent sidewalks and roads

|

HCMC - The licensing of temporary lease and use of roadways and sidewalks is still being implemented according to current resolutions, while waiting for a new management mechanism to be issued.

Body of missing male tourist found in Cuc Phuong National Park in Ninh Binh

|

Ninh Binh - After many days of searching, the authorities found the body of a male tourist missing in Cuc Phuong National Park.

Risk of new cyber attacks from the rise of Dark AI

NGUYỄN ĐĂNG |

Organizations and individuals need to prepare for increasingly sophisticated cyber attacks, due to the rise of Dark AI in the Asia-Pacific (APAC).

Apple warns users to update this software to avoid cyber attacks

Cát Tiên (THEO hindustantimes) |

Apple has implemented software improvements and patched more than 20 serious security vulnerabilities to protect iPhone users.

Allianz Life attacked by cyberattack: Personal data of millions of customers stolen

Hạo Thiên (theo techcrunch) |

Allianz Life confirmed that most of the company's 1.4 million customers' personal data was stolen after a cyberattack.