APT Campaigns Shift to Trust Chokepoints

State-aligned groups are no longer just breaking into named victims. They are working the trust points that let them stay hidden and spread influence: package maintainers, OEM and CRM footholds, and logistics-linked targets tied to energy, drone, government, and defense work. ESET’s six-month report ties China-, North Korea-, Russia-, and Iran-aligned activity to those chokepoints. It cites oil-shipment and government intrusions, drone and robotics targeting, a poisoned npm library with about 100 million weekly downloads, and compromise activity against an OEM/CRM environment, including SmartOffice CRM server reporting. The pattern matters because a single maintainer token or vendor foothold can outlive the original intrusion and carry access downstream. That makes the trust path itself part of the threat surface, not just the systems that first got hit.

Part of the PlainSec briefing for 2026-05-30

Sources