Emerging Cyber Espionage Threats in East Asia: Ransomware Groups and APTs
Recent cyber espionage activities in East Asia have seen increased ransomware attacks and advanced persistent threats targeting critical infrastructure and government entities.
Encrygma is selling the entire Full Cyber Weapon Research of Emerging Cyber Espionage Threats in East Asia: Ransomware Groups and APTs for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- Ransomware Group
- Geography:
- East Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of March 18, 2026, the cyber threat landscape in East Asia has experienced a notable uptick in cyber espionage activities. Ransomware groups and advanced persistent threats (APTs) have intensified operations, focusing on critical infrastructure and government entities across the region.
Ransomware Groups Targeting East Asia
Several ransomware groups have been active in East Asia, employing sophisticated tactics to infiltrate and disrupt operations. Notable among these are:
-
Qilin: This group has been particularly active, claiming 104 attacks in February 2026, with five confirmed incidents. Targets included Anabuki Housing Service Co., Ltd. in Japan and Kroll International, LLC in the United States. (comparitech.com)
-
The Gentlemen: Close behind Qilin, The Gentlemen claimed 84 attacks in the same period, with confirmed incidents affecting educational institutions and government organizations. (comparitech.com)
-
Tengu: This group has been active in Singapore, targeting professional services firms such as Dainty Cloud Inc. (purple-ops.io)
These groups employ a range of tactics, including phishing, malware distribution, and exploitation of vulnerabilities to gain unauthorized access to systems.
Advanced Persistent Threats (APTs) in the Region
In addition to ransomware activities, APTs have been observed targeting East Asia, often with objectives aligned to state interests. Notable APTs include:
-
Volt Typhoon: An APT attributed to the Chinese government, Volt Typhoon has been active since at least mid-2021, primarily targeting U.S. critical infrastructure. (en.wikipedia.org)
-
Silver Dragon: Linked to APT41, this group has targeted government and enterprise networks across Southeast Asia and Europe, utilizing tools like the GearDoor backdoor for remote access and data exfiltration. (research.checkpoint.com)
Impact on Critical Infrastructure and Government Entities
The activities of these ransomware groups and APTs have significant implications for critical infrastructure and government entities in East Asia. The attacks can lead to operational disruptions, data breaches, and potential national security risks. For instance, the targeting of Anabuki Housing Service Co., Ltd. in Japan and Kroll International, LLC in the U.S. underscores the global reach and impact of these cyber threats. (comparitech.com)
Conclusion
The cyber threat landscape in East Asia is evolving, with ransomware groups and APTs posing significant risks to critical infrastructure and government entities. Continuous monitoring, timely threat intelligence sharing, and robust cybersecurity measures are essential to mitigate these risks and enhance the region's cyber resilience.
Highlights:
- U.S. braces for cyberspace retaliation from Iran, Published on Tuesday, March 03
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



