Back to Intel

Intel Node

State-sponsored threats: Different objectives, similar access paths

lowtradecraft2026-04-14T13:49:46+00:00source excerpt
aptmalwaretradecraftidentity

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A look at 2025 state-sponsored threats, exploring how actors linked to China, Russia, North Korea, and Iran use vulnerabilities, identity, and trusted access paths to achieve their goals.

Across the  Talos 2025 Year in Review , state-sponsored threat activity from China, Russia, North Korea, and Iran all had varying motivations, such as espionage, disruption, financial gain, and geopolitical influence. But when you look at how these operations actually unfold, similar tactics, techniques, and procedures (TTPs) keep appearing: access through vulnerabilities and identity, and access that remains under the radar for a considerable period of time. Here are the dominant themes from the state-sponsored section of the Talos Year in Review,  available now.

China China-nexus threat activity stood out this year for both volume and efficiency, with Talos investigations increasing by nearly 75% compared to 2024. Newly disclosed vulnerabilities were exploited almost immediately (e. g. , ToolShell), sometimes before patches were widely available.

Read Original Source