Threats · 109 days ago
State-aligned groups are no longer just breaking into named victims. They are working the trust points that let them stay hidden and spread influence: package maintainers, OEM and CRM footholds, and logistics-linked targets tied to energy, drone, government, and defense work.
ESET’s six-month report ties China-, North Korea-, Russia-, and Iran-aligned activity to those chokepoints. It cites oil-shipment and government intrusions, drone and robotics targeting, a poisoned npm library with about 100 million weekly downloads, and compromise activity against an OEM/CRM environment, including SmartOffice CRM server reporting.
The pattern matters because a single maintainer token or vendor foothold can outlive the original intrusion and carry access downstream. That makes the trust path itself part of the threat surface, not just the systems that first got hit.
2 sources covering this story
Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms
ESET’s 2026 APT Activity Report suggests China-backed APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe
ESET's APT activity report links China, North Korea, Russia, and Iran hacking campaigns to oil, drones, and a poisoned code library.
Part of the PlainSec briefing for 2026-05-30