SANTA CLARA, Calif., July 20, 2026 – In 2025, geopolitical conflict and technological transformation have become deeply intertwined, and the iterative leaps in artificial intelligence (AI) have reshaped the landscape of cybersecurity offense and defense. Empowered by AI, Advanced Persistent Threats (APTs) now exhibit greater stealth and destructive power, becoming a core risk source threatening national sovereignty and development interests.

NSFOCUS has officially released the “2025 APT Group Research Annual Report,” conducting comprehensive monitoring of global APT activity throughout 2025. The report presents a full picture of activity trends and attribution tracking results, and includes profiles of 42 newly identified APT groups, offering an in-depth analysis of evolving attack techniques. It serves as an authoritative reference for cybersecurity practitioners, helping to enhance the protective effectiveness of critical information infrastructure.
Threat Landscape Overview: Global APT Threat Situation
Global APT activity continued to rise throughout 2025: over 700 public APT reports were published for the year, covering 119 groups, 42 of which were disclosed for the first time. NSFOCUS’s Threat Intelligence Center collected 795 related reports and added 19,925 new threat IOCs. The total number of global APT groups reached 662, a year-on-year increase of 6.77%.
In terms of activity levels, 38 continuously active groups were monitored throughout the year, with April marking the peak of activity (18 groups active simultaneously). January and February saw the highest frequency of attacks, with the number of attack sources peaking in February. Ten groups—including Cleaver, TA505, and Lazarus—were the most active entities of the year, with a cumulative total of 10,753 IP hosts attacked over the year.
Technical Evolution: Core Trends in Global APT Attack Techniques in 2025
The report conducted statistical analysis on the attack techniques used by APT groups. In 2025, APT attack methods displayed a dual characteristic of “traditional techniques holding steady, AI providing deep empowerment”:
- Traditional attacks: Covert targeted information theft tied for first place at 24%, while remote web-based cross-site scripting (XSS) accounted for 13%. These three categories together accounted for 61% of attacks, with the core logic being a combined penetration approach of “information gathering + script execution.”
- AI technology has fundamentally reshaped the attack chain: nation-state APT groups have widely weaponized AI, with AI-driven attack activity surging 89% year-on-year. AI-generated phishing emails achieved a click-through rate as high as 54%, far exceeding the 12% rate of traditional emails. Attacks are rapidly evolving from “automated bulk operations” toward “intelligent, precision-guided targeting.”
Future Outlook: Forecast of Global APT Threat Trends
The report forecasts five major trends in global APT threats for 2026:
- AI will upgrade from an auxiliary tool to a core attack engine, with attacks targeting AI systems and enterprise AI agents becoming the new normal;
- AI-driven weaponization of zero-day vulnerabilities will accelerate, placing increasing attack pressure on enterprise technology products;
- Supply chain attacks will become normalized, with open-source poisoning and threats to trusted/localized IT infrastructure becoming a major challenge for technological self-reliance and controllability;
- APT activity will become increasingly bound to geopolitical competition, with critical infrastructure becoming a core attack target;
- Cloud security and identity-based attacks will become the primary battleground for offense and defense, with cloud misconfigurations and privilege abuse emerging as major attack vectors.
In the face of systematic, intelligent threats, defenders need to accelerate the construction of an “AI vs. AI” active defense system—integrating Zero Trust architecture, supply chain security controls, cloud-native protection, and critical infrastructure resilience—to drive the defense model’s transformation from “passive response” to an integrated “predict–defend–respond–recover” approach, comprehensively enhancing the ability to counter nation-state-level advanced threats.
Download link: 2025 APT Group Research Annual Report – NSFOCUS