XDSpy is a rarely documented APT group targeting Eastern European governments since 2011.
Analyst brief
XDSpy is a rarely documented APT group active since 2011, primarily targeting government and administration sectors. It conducts espionage operations focused on government agencies and private companies in Eastern Europe and the Balkans. Their TTPs remain largely unknown, but a 2020 BelarusCERT advisory indicates a focus on infiltrating core infrastructure. Defenders should be vigilant for unknown spear-phishing attempts and suspicious C2 traffic targeting government entities in their region.
XDSpy
unknown
Rare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since 2011. It has attracted very little public attention, with the exception of an advisory from the Belarusian CERT in February 2020. In the interim, the group has compromised many government agencies and private companies in Eastern Europe and the Balkans.