Russian activities associated with APT29 and APT28 Activities associated with the Russian Federation were almost certainly (90–100 %) part of long-standing campaigns also affecting allies. These malicious activities have tradecraft, motivation and objectives that overlap significantly with APT29 (known as Midnight Blizzard, BlueBravo and Cozy Bear) and APT28 (known as Forest Blizzard, BlueDelta and Fancy Bear). The first of the above-mentioned actors is associated with Russia’s foreign intelligence service (SVR) and the second with Russian military intelligence (GRU).⁴ Increased activity of PRC-related actors Over the past several years, NÚKIB has also detected increased activity from actors associated with the People’s Republic of China (PRC), driven by their heightened focus on European objectives in the context of the war in Ukraine. In 2023, an intrusion into a strategic institution’s network was highly likely (75–85 %) perpetrated by a Chinese-origin attacker. Mustang Panda’s phishing campaign (known as RedDelta) has directed significant effort against European objectives, including those in the Czech Republic, at least since the beginning of Russia’s invasion of Ukraine. North Korean interest in the defence sector The Czech Republic was targeted by the North Korean group Lazarus (known as Diamond Sleet or Labyrinth Chollima) in 2023. The group’s objective was to compromise defence companies in the Czech Republic and other NATO/EU countries. The group is associated with the Reconnaissance General Bureau (RGB).⁵ and their campaign verifies the interest of selected threat actors in specific sectors of the Czech industry. Lower activity of Iran In the context of the escalation of the Israeli-Palestinian conflict, activities by Iranian actors targeting the technologies of specific producers in the water sector have been detected. However, the activity of sophisticated actors operating in line with Tehran’s interests was lower than in the past. ⁴ See, for example: SVR cyber actors adapt tactics for initial cloud access - NCSC.GOV.UK / BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware | Recorded Future / Office of Public Affairs | Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU) | United States Department of Justice / Vojenské zpravodajství | Tiskové zprávy - Vojenské zpravodajství provedlo aktivní zásah v kybernetickém prostoru (vzcr.cz) ⁵ See, for example: Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups | U.S. Department of the Treasury / Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations | Mandiant 23

Select target paragraph3