Press Release

From threat detection to risk management and prevention, ThreatSonar Plus empowers enterprises to navigate the AI era Facing increasingly stealthy attacks driven by AI agents, traditional cybersecurity defenses are no longer sufficient. TeamT5, a leading threat intelligence provider in the Asia-Pacific region, today unveiled a new solution at CYBERSEC 2026 in Taiwan: ThreatSonar Plus , a ThreatSonar Plus Extensive Endpoint Assessment Platform built for AI environments. In addition to showcasing its advanced automated defense capabilities, TeamT5 also introduced its new brand identity, marking both a commitment to deep technological innovation and a milestone in its global expansion in AI cybersecurity. ThreatSonar Plus Eliminates Blind Spots in AI Agent Defense As enterprises accelerate the adoption of AI agents to drive automation, new forms of cybersecurity risk are emerging. Sung-ting Tsai, CEO of TeamT5, noted that improperly configured AI agents may lead to sensitive data leakage or exposure to malicious code injection. Given that AI agents often integrate with external services, insufficient access control can easily result in unauthorized access to confidential data. These threats are highly automated and difficult to detect, rendering traditional cybersecurity solutions ineffective. Enterprises must urgently reassess and establish protection mechanisms specifically designed for AI deployments. The newly launched ThreatSonar Plus platform directly addresses these defense gaps in AI environments. Built around three core pillars—asset inventory, risk detection, and AI agent identification—the platform enables enterprises to gain precise visibility into critical assets and AI deployments. Through in-depth analysis, administrators can quickly identify high-risk vulnerabilities and prioritize remediation strategies accordingly. Key features of ThreatSonar Plus include: AI agent risk identification, including sensitive data exposure, malicious commands, and autonomous agent behaviors Support for SEMI E187 to meet industry security and compliance requirements Rapid identification of high-risk vulnerabilities with severity-based prioritization for faster response System configuration assessment aligned with CIS benchmarks, with actionable hardening recommendations New ThreatVision Cybercrime Intelligence Reports Focus on Dark Web Cybercrime In addition to endpoint security, TeamT5 has recently introduced ThreatVision Cybercrime Intelligence. Built on TeamT5’s 20+ years of APAC threat research, it covers the Deep & Dark Web, underground forums, Telegram, and cybercrime communities, delivering expert-validated intelligence insights that analyze cybercrime operations, ransomware activity, data trades, and dark web developments from attacker’s perspective. ThreatVision Cybercrime Intelligence helps enterprises identify emerging cybercrime risks earlier, understand attacker tactics and targets, and prioritize defensive actions. By gaining visibility into cybercriminal activity across the Deep & Dark Web, enterprises can more accurately assess risk and shift from reactive response to proactive defense. From Asia-Pacific to Global Markets: Brand Transformation Signals Strategic Vision Another highlight was the debut of TeamT5’s new brand identity. Built on the concept of “focus insights and sharpened vision,” the redesign reflects its precision in threat detection and ability to help clients make decisive security decisions. CEO Sung-Ting Tsai said the rebrand marks TeamT5’s evolution into a more mature and trusted cybersecurity company, while reinforcing its global expansion strategy. Founded in Taiwan, TeamT5 has established a strong foothold in Japan and South Korea, and in recent years has expanded into Southeast Asia, including Thailand, Vietnam, Malaysia, and Singapore, with further extension into European markets. As its global footprint grows, the company continues to strengthen local partnerships and service capabilities to enhance competitiveness. TeamT5 has also initiated plans for a public offering, progressing according to schedule to support future capital market entry and long-term brand sustainability. About TeamT5 Founded in 2017, TeamT5 is a leading provider of cybersecurity threat intelligence and endpoint security solutions in the Asia-Pacific region. The company specializes in regional cyber threat research, including advanced persistent threats (APT) and ransomware. Leveraging high-precision threat intelligence and proprietary endpoint threat hunting technologies, TeamT5 delivers comprehensive security solutions to counter cyber espionage and ransomware attacks. In 2022, TeamT5 received strategic investments from JAFCO Group, ITOCHU Corporation, and MACNICA, demonstrating strong international growth potential. The company was also recognized by Frost & Sullivan as the Best Threat Intelligence Company in Taiwan for two consecutive years (2023–2024).
 getty-images-N9cgjAlzeAU-unsplash_1.jpg)
Taipei / FIRSTCON, June 14, 2026 — TeamT5, a leading threat intelligence company, today delivered a presentation at the FIRSTCON on June 16, one of the world’s premier incident response and cybersecurity events. The session focused on cybercrime campaigns leveraging short-video platforms and cryptocurrency applications. TeamT5 also showcased its latest ThreatVision Cybercrime Intelligence offering, aimed at helping organizations stay ahead of threats and reduce potential financial and reputational damage. TeamT5 Experts Analyze Emerging Cybercrime Tactics Telegram has emerged as a major hub in the underground cybercrime ecosystem. In TeamT5’s talk, we will present firsthand observations from our analysis of how malware is advertised and sold in Chinese Telegram channels. As short‑video platforms and cryptocurrency apps gain popularity, we’ve seen threat actors increasingly exploit these trends to trick users into installing malicious software. We will share two recent campaigns — one aimed at users in China and Malaysia, and another targeting South Korea — both of which distribute trojanized APKs masquerading as legitimate apps. By examining these operations, we aim to clarify how threat actors function in these regions and how they leverage trusted platforms to broaden their reach. From Cybercrime to APT Threats: Anticipating Attack Risks with ThreatVision Cybercrime is one of the most serious challenges facing the global digital economy. Many organizations remain constrained by the final stages of the Cyber Kill Chain, responding only after alerts are triggered. Built on TeamT5’s long-term threat research, ThreatVision Cybercrime Intelligence tracks criminal communities, ransomware activity, attack tools, and relevant APT-related infrastructure, techniques, and targeting shifts. It helps organizations identify risk signals earlier and support intelligence-driven defense planning. ThreatVision monitors high-risk activity across the Deep & Dark Web, Telegram, criminal communities, and other underground sources. By analyzing ransomware activity, data leaks, criminal services, adversary behavior, and APT-related context where relevant, it turns fragmented signals into intelligence for risk assessment, threat hunting, incident investigation, and response planning. Deep & Dark Web and Cybercrime Community Monitoring : Tracks high-risk underground activity to identify operational risk signals and potential APT-related links . Intelligence Analysis and IoC Extraction : Turns cybercrime activity into contextual intelligence and actionable IoCs for investigation, response, and remediation. Understanding Criminal Community Dynamics: ThreatVision Cybercrime Intelligence Enables Proactive Defense Criminal communities, ransomware groups, and APT operations do not always have clear boundaries. Similar tools, infrastructure, or techniques may appear across operations with different objectives. ThreatVision Cybercrime Intelligence helps organizations connect these signals, track ransomware activity, data leaks, attack tools, and criminal ecosystem dynamics, and turn them into intelligence for risk assessment and defense planning. Expert In-depth Analysis : Provides context and supporting evidence beyond standard alerts. Adversary Profiling : Profiles ransomware groups and criminal ecosystems. Attack Techniques and Tactics : Tracks attack tools, technique changes, and target selection. Intelligence-driven Decision Making : Connects intelligence to operational risk and strategy development. With ThreatVision Cybercrime Intelligence, organizations can identify risk signals earlier, guide defensive resources, accelerate investigations and threat hunting, and strengthen long-term cyber resilience. About TeamT5 TeamT5 is a threat intelligence research team focused on the Asia-Pacific region. Leveraging Taiwan’s geographic position, language capabilities, and over two decades of research experience, TeamT5 specializes in the analysis of major threats such as APT activity and ransomware, providing regionally grounded threat intelligence to government, financial, and technology sectors. With research at its core, TeamT5 continuously tracks the evolution of threat behavior and attack techniques, organizing complex activity into clear risk context. By monitoring both emerging and unknown threats and analyzing attacker behavior, TeamT5 helps organizations identify risks earlier, reduce exposure time, and strengthen preparedness. Research findings are shared across international security forums, while long-term partnerships are built on trust and practical collaboration. Media Inquiries & Business Partnerships : contact@teamt5.org

Taipei, Taiwan, April 24, 2026 - TeamT5, a cybersecurity company specializing in cyber threat research and intelligence analysis, and the Taiwan Network Information Center (TWNIC) announced today that they have signed a Memorandum of Understanding (MOU). Under the MOU, the two organizations will establish a threat intelligence sharing framework, integrate complementary resources and deepen collaboration to strengthen Taiwan’s overall cybersecurity resilience and support the development of the cybersecurity industry. The collaboration will cover intelligence exchange and joint research. TeamT5 will contribute expertise in advanced persistent threat (APT) research, including indicators of compromise (IOCs) and technical analysis of cybercrime activities. TWNIC will contribute DNS resolution-related data and anonymized datasets collected through honeypot mechanism, in accordance with applicable privacy, security, and internal governance requirement. Through high-quality intelligence sharing, both organizations aim to identify potential risks earlier and strengthen early warning and incident response capabilities. TeamT5 has long been dedicated to cybersecurity threat research in the Asia-Pacific region, with extensive experience in APT intelligence and malware analysis. TWNIC, as Taiwan’s national network information center and a key operator within Taiwan’s Internet infrastructure, TWNIC plays a critical role in domain name management and internet governance. By combining their respective strengths, this partnership is expected to further enhance Taiwan’s participation, visibility, and contribution within the global cybersecurity community. Sung-ting Tsai, Chief Executive Officer of TeamT5, said: “As cyber threats become increasingly sophisticated and persistent, no single organization can address them alone. Through our collaboration with TWNIC, we aim to establish a more robust intelligence exchange mechanism, transform research insights into actionable defense capabilities and help a more resilient cybersecurity environment for Taiwan. We also see this partnership as an opportunity to reinforce TeamT5’s role as a leading threat intelligence provider in the Asia-Pacific region and to expand our contribution tothe global cybersecurity landscape.” Jo-Fan YU, Managing Director and Chief Executive Officer of TWNIC, said: “As cyber threats continue to evolve, TWNIC, as a critical part of Taiwan’s Internet infrastructure, remains committed to strengthening DNS protection and advancing the collection, analysis, and application of threat intelligence. This collaboration with TeamT5 will broaden our intelligence sources and analytical depth, enabling more effective integration and use of information to detect and respond to malicious activities, and ultimately strengthen Taiwan’s overall cybersecurity resilience.” Looking ahead, TWNIC will continue to serve as a bridge connecting domestic and international cybersecurity communities, promoting collaboration and exchange to build a more stable and trustworthy internet environment for Taiwan. The two organizations will also explore additional areas of cooperation, including cybersecurity research and technical exchange, to support the long-term development of Taiwan’s cybersecurity ecosystem.

For nearly two decades, TeamT5 has been deeply rooted in the Asia-Pacific region—researching threat actors, tracking attack campaigns, and uncovering overlooked risks and signals. Today, we officially unveil TeamT5’s new brand identity. This transformation is more than a visual update; it is a definitive signal of our identity, our values, and our global trajectory. A Threat Intelligence Pioneer Rooted in Asia-Pacific TeamT5 is a threat intelligence pioneer born in Asia. Based in Taiwan, we leverage an unique geopolitical perspective and deep linguistic expertise to track Advanced Persistent Threats (APTs) and ransomware activity across the region. We provide more than just data to government agencies, financial institutions, and technology leaders ; we deliver actionable insights grounded in regional context—intelligence that organizations can immediately deploy in high-stakes environments. This rebranding does not change our direction. Instead, it is the purest expression of the mission we have upheld from the start: Transforming complex threats into decisive action. The Evolution: From Technical Roots to Global Trusted Partner TeamT5’s mission has always been clear, though never simple: Transform complex threats into actionable intelligence that enables organizations to move from reactive defense to smarter detection and response. As threats evolve faster and become harder to track and interpret, the value of intelligence cannot stop at simply telling organizations what has happened. This moment marks a pivotal step forward: A Mature Identity : We have evolved from a technical startup into a professional, trusted enterprise brand. Global Unity : We are establishing a unified presence as we expand our long-term footprint in international markets. Operational Focus : Our new visual identity reflects how we operate—remaining alert as threats evolve, acting swiftly in critical moments, and staying sharply focused on what truly matters. The concept of our new logo - The Spotlight: Sharpen the Sight. It symbolizes our role in the ecosystem. We are not defenders standing passively under the spotlight. Instead, we are intelligence hunters who precisely locate threats in the shadows, operating at the boundary between the visible and the unseen. Our goal is not to illuminate everything. Rather, we focus on the signals that truly matter—so our customers can see more clearly, assess risks confidently, and act decisively. Our Core Values: Threat Intelligence that Powers Proactive Defense We believe the value of threat intelligence lies not in the volume of information, but in whether it enables organizations to identify critical signals earlier. TeamT5’s vision is to become the most trusted threat intelligence partner in the Asia-Pacific region , helping organizations move from responding to attacks toward anticipating threats . Behind this vision are the four core values that have long guided TeamT5. These values are not just principles—they shape how we conduct research, build products, and collaborate with partners. Continuous Exploration We never stop exploring. Beyond monitoring known threats, we actively venture into the unknown—uncovering overlooked signals in complex threat landscapes and revealing emerging attack patterns and techniques. Precise Insight Precision is the foundation of proactive defense. We do more than track indicators—we analyze the logic behind threats so that intelligence can truly support critical decision-making. Agile Action Speed is essential when facing cyber threats. We track every step of the attacker, enabling action before threats escalate and transforming intelligence into real-time protection. Trusted Collaboration Threat intelligence becomes stronger when shared. Through open knowledge exchange and two-way communication, we build long-term partnerships with customers and collaborators based on trust—standing together against evolving threats. Continuing the Journey of Exploration TeamT5 is both an explorer and an innovator in threat intelligence. We lead the discovery of emerging threats, deconstruct adversary behavior, and build defensive capabilities that evolve as quickly as our adversaries. This rebranding represents our continued commitment to exploration, insight, action, and collaboration . It also reaffirms our belief: When intelligence is done right, organizations gain the advantage in cyber defense. TeamT5’s founding mission remains unchanged— more precise intelligence, earlier action. We are ready. The next chapter starts now.

Top threat analysts from the Asia-Pacific region gathered to share practical experience and forward-looking strategies, focusing on three key issues and urging all sectors to pay attention to threat intelligence and strengthen defense gaps. [Taipei, December 3, 2025] The 2025 Threat Analyst Summit (TAS), hosted by leading threat intelligence firm TeamT5, took place on December 3–4 in Taipei, Taiwan. This year’s summit surpassed previous editions in scale and international reach, with nearly two-thirds of participants traveling from abroad and representing more than 20 countries. Over 200 cybersecurity experts and practitioners attended the event, engaging in knowledge sharing, experience exchange, and in-depth discussions on the global threat landscape. The forum boasted a strong lineup of speakers, bringing together leading international cybersecurity and technology companies, including ITOCHU, MACNICA, LAC, Constella Security Japan, The Korea Financial Security Institute, Team Cymru, Recorded Future, Shreshta, Meta, DarkLab, Microlab.red , and Trend Micro, whose industry authorities provided insightful perspectives. Experts Highlight Persistent Security Gaps and Urge Stronger Commitment to Threat Intelligence The summit continued the focus of the previous two TAS events, providing an in-depth look at the latest activities of APT groups across the Asia-Pacific region. This year’s program also expanded to key themes including cybercrime trends and the evolving landscape of information operation. Looking back at the cybersecurity landscape in 2025, the year has been marked by a series of high-impact incidents, from the early-year CrazyHunter attack and the surge of APT campaigns exploiting VPN vulnerabilities, to the recent breach of a globally recognized beer manufacturer that forced a complete shutdown of its production lines. These events underscore that, despite rising cybersecurity awareness within enterprises, critical gaps in defense architectures persist, creating opportunities for attackers to exploit weaknesses. Strengthening these defenses proactively remains essential to mitigating future threats and reducing operational risk. VPN Vulnerabilities Emerge as Key Intrusion Vectors; Supply Chain Security Becomes a Critical Challenge In cybersecurity architecture, "threat intelligence collecting and application" has become a crucial area that enterprise cybersecurity personnel urgently need to strengthen. Only through systematic intelligence analysis and application can early warnings, rapid responses, and prevention be achieved before attacks occur, effectively reducing risks and operational damage. TeamT5 CEO Tsai Sung-ting (TT) stated that the most frequent cybersecurity threat this year is network device intrusion . Therefore, several case studies on VPN device intrusion were arranged for presentations. Currently, cybercriminal ransomware groups do not initially target specific companies. Instead, they determine their targets after obtaining vulnerability information on the original equipment manufacturer's (OEM) devices, often choosing high-value companies, attempting to gain root access, and then launching encrypted ransomware attacks. Tsai Sung-ting pointed out that in the past year, Chinese hacker activities have become increasingly rampant, frequently infiltrating enterprise network environments through hardware and software vulnerabilities. Many of these cases involve equipment hosted by external vendors, which can be categorized as supply chain intrusion. Even if enterprises have deployed numerous protective measures, they may still suffer losses if their hosting vendors are attacked. Cybersecurity Remains a Complex Undertaking, Requiring Determination from Strategy to Execution Tsai Sung-ting emphasized that in practice, even if the client company actively implements cybersecurity measures, if the vendor is negligent in management and lacks adequate protection, they are often unknowingly compromised by hackers, ultimately leading to serious losses. This shows that "supply chain cybersecurity management" is often the most easily overlooked aspect of corporate cybersecurity strategies, yet it is also a critical point with extremely high risks. He added that large companies don't necessarily have good cybersecurity practices, especially in manufacturing or traditional industries. Willingness to invest resources, having the right strategies, and finding a professional team to assist are all challenges companies face in promoting cybersecurity. Cybersecurity is a long-term and continuous endeavor; however, the reality is that many companies are still at the stage of wanting to do it, and the journey from that to wanting to understand how to do it, and then to serious implementation, is long, testing the determination of business owners and management teams. About TeamT5 Founded in 2017, TeamT5 is a leading provider of cybersecurity threat intelligence and endpoint security solutions in the Asia-Pacific region. Specializing in cyber threat research in the Asia-Pacific region, covering Advanced Persistent Threats (APTs) and ransomware, the company leverages precise threat intelligence and unique endpoint threat hunting technology to provide clients with comprehensive cybersecurity solutions for effectively countering cyber espionage and ransomware attacks. In 2022, it received joint investment from JAFCO, Japan's largest venture capital firm; ITOCHU, Japan's largest multinational corporation; and MACNICA, Japan's largest cybersecurity solutions provider, demonstrating its significant international potential. From 2023 to 2024, TeamT5 was consecutively recognized as Taiwan's Best Threat Intelligence Company by the international consulting firm Frost & Sullivan. To promote cyber threat research and international cybersecurity cooperation in the Asia-Pacific region, the company piloted the Threat Analyst Summit (TAS) in 2022 and officially held its first TAS Threat Analyst Summit in 2023, successfully establishing an important platform for Asia-Pacific cybersecurity experts to share the latest threat dynamics and forward-looking strategies.

Taipei, November 26, 2025 — TeamT5 has once again been recognized for its outstanding innovation and leadership in cybersecurity. Two of its flagship products—the ThreatVision (Threat Intelligence Platform) and the ThreatSonar Anti-Ransomware (Endpoint Detection & Response)—have both won the 34th Taiwan Excellence Award . This recognition highlights TeamT5’s research and development strength, as well as its market competitiveness in the global cybersecurity industry. ThreatVision: Empowering Organizations with Asia-Pacific Threat Intelligence ThreatVision is a threat intelligence platform designed for enterprises and government agencies. Built upon TeamT5’s years of advanced cyber threat research, it helps cybersecurity teams quickly identify and analyze advanced persistent threat (APT) activities, track dark web criminal trends, and address high-risk vulnerabilities before they can be exploited. With its localized Asia-Pacific threat insights , ThreatVision delivers precise indicators of compromise along with deep correlations between malware and attack behaviors. The platform empowers users to anticipate attack patterns and take preventive measures—strengthening the overall resilience of their cybersecurity defenses. ThreatSonar Anti-Ransomware: Proactive Defense Against Ransomware Attacks ThreatSonar Anti-Ransomware is an enterprise-grade, proactive defense solution that integrates malicious behavior detection, intrusion prevention, and incident response capabilities into a unified platform. Its core technology automatically interrupts malicious processes before ransomware can encrypt critical files, drastically minimizing potential damage. By leveraging TeamT5’s accurate threat intelligence, ThreatSonar Anti-Ransomware enhances its ability to identify suspicious endpoint behaviors in real time—delivering a complete defense lifecycle from detection and alert to active protection, safeguarding enterprise assets with precision and reliability. Advancing Taiwan’s Cybersecurity Innovation and Global Competitiveness The Taiwan Excellence Award, often regarded as the “Oscars of Taiwan’s Industry,” evaluates products based on R&D, design, quality, and marketing. TeamT5’s dual recognition demonstrates its commitment to innovation, excellence, and international expansion in cybersecurity technology and product development. Tsai Sung-ting, CEO of TeamT5, remarked:“Our mission is to protect the cybersecurity of global clients through world-class cybersecurity research and technology. Receiving the Taiwan Excellence Award affirms TeamT5’s enduring commitment to innovation and excellence.” About TeamT5 TeamT5 is a leading cybersecurity company specializing in threat intelligence and advanced malware analysis , with deep roots in the Asia-Pacific region. Leveraging Taiwan’s strategic location, linguistic diversity, and over 20 years of accumulated research expertise, TeamT5 focuses on analyzing APT attacks and ransomware threats to deliver the most localized intelligence and protection solutions for governments, financial institutions, and technology enterprises. TeamT5 has been recognized for two consecutive years by international research and consulting firm Frost & Sullivan as Taiwan’s Threat Intelligence Company of the Year . Media Contact: pr@teamt5.org

TeamT5 , a leading threat intelligence provider focused on the Asia-Pacific region, has integrated its ThreatVision platform with Filigran’s OpenCTI . This powerful collaboration enables modern security operations centers (SOCs) to harness the full power of contextual, actionable threat intelligence from both global and regional sources. Unmatched Visibility into Asia-Pacific Threats Twice recognized as "Taiwan's Best Threat Intelligence Company" by Frost & Sullivan, TeamT5 has built a reputation for delivering unique and deep intelligence on cyber threats originating from the APAC region, including China, North Korea, and Vietnam. With years of research and frontline investigation, TeamT5's ThreatVision delivers: In-depth insights into APAC threat actor TTPs : Gain visibility into the evolving tools and methods used by regional adversaries. Campaign tracking and attribution : Stay informed about threat actor operations and motivations through comprehensive adversary profiling. Technical vulnerability analysis : Understand the real-world impact and exploitation methods behind high-profile vulnerabilities. ThreatVision delivers this intelligence in enriched formats—from malware samples to actor profiles—helping analysts quickly contextualize and act on emerging threats. OpenCTI: The Foundation for Intelligence-Driven SOCs Filigran’s OpenCTI is a powerful open-source threat intelligence platform that centralizes and connects knowledge about cyber threats. Built to support intelligence-driven operations, OpenCTI provides: Structured knowledge modeling : Connect threat indicators, actor behaviors, attack techniques, and campaign data in a single dynamic knowledge graph. Collaborative workflows : Enhance analyst collaboration through shared investigation, annotation, and threat mapping. Flexible integrations and automation : Enrich and distribute intelligence across the security stack using API connectivity and automated playbooks. By integrating ThreatVision into OpenCTI, users benefit from enriched intelligence flows that directly enhance detection engineering, threat hunting, and incident response strategies. Real-World Use Cases Enhanced by the Integration The synergy between TeamT5 and Filigran supports multiple high-impact cybersecurity workflows, including: Threat Attribution : Analysts can now trace TTPs and infrastructure back to APAC adversaries using ThreatVision’s detailed actor insights. Correlated Intelligence : TeamT5’s contextual intelligence correlating to indicators of compromise (IOCs) within OpenCTI, accelerating triage and validation. Proactive Threat Hunting : Use ThreatVision’s flash reports and technical findings to guide hypothesis-driven threat hunting. About Filigran Filigran builds and maintains OpenCTI, an open-source platform designed to structure and operationalize cyber threat intelligence. Trusted by private and public sector organizations worldwide, Filigran supports intelligence-led security operations through open innovation, collaboration, and adaptability. About TeamT5 TeamT5 consists of elite cyber threat analysts specializing in Asia-Pacific threat actors. With deep regional insight and strong technical expertise, TeamT5 empowers security teams around the globe to stay ahead of sophisticated cyber threats. Trusted by government, defense, and enterprise customers, TeamT5 continues to deliver accurate, actionable threat intelligence and strategic guidance.
![[2025 H1 APT Threat Landscape Insights] Asia-Pacific Emerges as Cyberattack Hotspot: Experts Highlight Critical Defense Priorities](https://teamt5-back.e-s.tw/api/files/teamt5-from-an-apac-threat-intelligence-pioneer-to-a-global-leader_en_pic.png)
TeamT5, a leading threat intelligence brand in the Asia Pacific region, has released its latest cybersecurity threat insights, highlighting a continued rise in advanced persistent threat (APT) incidents. The information technology sector—including the semiconductor industry—remains the most targeted in the region. TeamT5 recommends that organizations stay informed with up-to-date threat intelligence and enhance their cybersecurity defenses by understanding attackers’ tactics, techniques, and procedures. In the first half of 2025, ongoing geopolitical tensions in the Asia-Pacific region—including China & Taiwan relations, intensified U.S.-China technological competition, and the India-Pakistan conflict—have extended into cyberspace. As a result, APT attacks have increased, with attackers employing more advanced techniques. Information Technology Sector is Top Targeted Industry in Asia-Pacific In the Asia-Pacific region, TeamT5 identified over 200 targeted attacks out of more than 150,000 detected incidents. By industry, the information technology sector—including the semiconductor industry—was the most frequently targeted, followed by government agencies and critical infrastructure (including telecommunications, healthcare, energy, and transportation). In Japan, the most targeted industry is manufacturing, with other sectors such as government, information technology, and financial institutions also facing persistent threats. In Southeast Asia, the most targeted industries include government agencies and the energy sector. And in Taiwan, the most targeted industries are the information technology sector (including the semiconductor industry) and critical infrastructure (including energy, healthcare, and transportation). Additionally, the CrazyHunter ransomware attack impacted several Taiwanese organizations, with victims spanning medical institutions, information technology sector and academic organizations. ( More analysis by TeamT5: [Case Study] CrazyHunter Ransomware Attacks Targeted Taiwan Hospitals ) Two Key Attack Methods Are Worth Noting Regarding attack methods, two key trends should be noted: first, the use of legitimate tools to deploy malicious software; and second, malware designed to target specific devices. Notably, the following critical vulnerabilities have been widely exploited by state-sponsored threat actors: Ivanti Connect Secure VPN: CVE-2025-0282 and CVE-2025-22457 Check Point VPN: CVE-2024-24919 SAP NetWeaver: CVE-2025-31324 TeamT5 recommends that organizations using related equipment and services apply patches as soon as possible to mitigate the risk of attack. TeamT5 also highlighted a key trend in cyberattacks during the first half of the year - China has escalated its own counter-narratives. They increasingly publicly attributed cyberattacks to the US and Taiwan. Such efforts serve to deflect scrutiny and delegitimize Western accusations of China’s malicious cyber operations.For example, in April, the Harbin Public Security Bureau (PSB) accused three US NSA agents of attacking the Harbin Asian Winter Games. In June, the Guangzhou PSB alleged that Taiwan’s Information, Communications and Electronic Force Command (ICEFCOM) was behind cyberattacks on Chinese tech firms, naming 20 ICEFCOM soldiers and linking the operation directly to Taiwan’s ruling Democratic Progressive Party (DPP). In addition, TeamT5’s expert team has observed that generative AI tools are increasingly being used in information operation, enabling the rapid creation of fake content and images that are difficult to distinguish from real ones, thereby increasing the complexity of defense. Establishing a Clear Cybersecurity Strategy is Crucial for Future Threat Defense Looking ahead to the second half of 2025, the cybersecurity landscape in the Asia-Pacific region will remain uncertain and challenging. To stay ahead and reduce risk in this ever-evolving threat environment, organizations must continuously leverage up-to-date threat intelligence and strengthen their detection and response capabilities. In the face of increasingly sophisticated attack methods, early adoption of threat intelligence-driven defense strategies will be key to ensuring operational stability and the security of digital assets. About TeamT5 TeamT5 consists of top cyber threat analysts. Leveraging our geographic and cultural advantages, we have the best understanding of cyber attackers in Asia Pacific. TeamT5 is frequently invited to share insights at top cybersecurity conferences. Our threat intelligence research expertise and solutions are recognized as the 2023-2024 Company of the Year Award in Taiwanese Threat Intelligence by Frost & Sullivan. Based on our research in malware & Advanced Persistent Threat (APT), we provide cyber threat intelligence reports and anti-ransomware solutions to clients in the USA and Asia Pacific region. Clients include government agencies, financial business, and high tech enterprises. press release contact: pr@teamt5.org

TeamT5 is a leading brand in Asia Pacific threat intelligence. Its threat intelligence platform, ThreatVision won the Best Choice Award at COMPUTEX TAIPEI . This recognition is the best proof of the long-term research results of TeamT5’s professional team, who excels at analyzing the attack methods of more than 165 advanced persistent threat (APT) groups to provide threat countermeasures and defense guidance. TeamT5 is the most reliable “intelligence-gathering team” who empowers enterprises and organizations to gain an upper hand in cybersecurity attacks. ThreatVision provides a wealth of cyber threat intelligence centered on the Asia-Pacific region based on more than 20 years of research experience on malware, APT groups and cyber threats. The platform provides strategic, practical and tactical threat intelligence to meet the needs of various roles in the cybersecurity field, including decision makers, risk managers and incident responders, helping them to accurately understand the threat landscape, identify malicious actors and deploy effective defenses. This product has been trusted and adopted by worldwide customers in government, finance, telecommunications, high-tech and other industries. The three major features are: 1. Diverse Intelligence to Grasp Key Threat Information Asia Pacific APT Intelligence : Release weekly and monthly. The weekly report provides real-time threat intelligence and indicators of compromise (IoC) to defend attacks. The monthly report analyzes recent APT incidents and malware to help enterprises and organizations to overview the threat landscape. Vulnerability Intelligence : Provide technical details about highly exploitable vulnerabilities with clear guidance to help enterprises and organizations to mitigate potential risks. Cyber Affairs : Provide strategic cyber intelligence regarding the Chinese-speaking cyber world.Through comprehensive analysis in cybersecurity news, policies, regulations, and incidents, giving insights into the emerging tech giant, China's cyber capabilities. 2. Informative Databases and Tools to Empower Threat Defense ThreatVision provides downloadable threat hunting tools that can quickly and effectively detect attacks; the automated sample analysis allows users to utilize the sandbox via API to instantly compare and analyze suspicious samples; the attack group and malware databases offer users a systematic way to gain insight into the sources, methods, and targets of attack groups, as well as to facilitate search and obtain key malware information. 3. Deep and Dark Web Monitoring to Timely Manage Leakage Risk The deep and dark web (DDW), which accounts for more than 90% of the Internet, are websites that require permission and special methods to access. Due to high anonymity and difficulty in tracking, DDW have become cybercrime hotspots. ThreatVision provides DDW monitoring service, which can monitor whether confidential information such as credentials and personal information of enterprises and organizations has been leaked to the DDW, with automatic email alerts to timely flag the relevant security risks. Sung-ting Tsai, founder and CEO of TeamT5, said: "After winning the Best Choice Award Gold Award in 2024 for the "ThreatSonar Anti-Ransomware" (endpoint detection and response platform), we are honored to receive high recognition again for the "ThreatVision" (threat intelligence platform). The company will uphold our faith in "intelligence-driven defense" and continue to assist enterprises and organizations in defending threats and foreseeing possible risks.” The Best Choice Award, one of the honors at the world’s 2nd largest (largest in Asia Pacific) ICT procurement platform - COMPUTEX TAIPEI. The award focuses on functionality, innovation, and market potential as the main judging guideline. The committee of the Best Choice Award is recruited from government representatives, academicians, research analysts, editor-in-chiefs and experts in order to be fair and credible. About TeamT5 TeamT5 consists of top cyber threat analysts. Leveraging our geographic and cultural advantages, we have the best understanding of cyber attackers in Asia Pacific. TeamT5 is frequently invited to share insights at top cybersecurity conferences. Our threat intelligence research expertise and solutions are recognized as the 2023-2024 Company of the Year Award in Taiwanese Threat Intelligence by Frost & Sullivan. Based on our research in malware & Advanced Persistent Threat (APT), we provide cyber threat intelligence reports and anti-ransomware solutions to clients in the USA and Asia Pacific region. Clients include government agencies, financial business, and high tech enterprises. Website: https://teamt5.org/en/ Contact: pr@teamt5.org TeamT5 will present Besr Choice Award winner "ThreatVision" in 2025 COMPUTEX - InnoVEX. Please visit our booth #S1025a at Taipei Nangang Exhibition Center - Hall 2 (Taiwan) for more info.
About TeamT5
TeamT5 is a threat intelligence research team focused on the Asia-Pacific region. Leveraging Taiwan’s geographic position, language capabilities, and over two decades of research experience, TeamT5 specializes in the analysis of major threats such as APT activity and ransomware, providing regionally grounded threat intelligence to government, financial, and technology sectors. With research at its core, TeamT5 continuously tracks the evolution of threat behavior and attack techniques, organizing complex activity into clear risk context. By monitoring both emerging and unknown threats and analyzing attacker behavior, TeamT5 helps organizations identify risks earlier, reduce exposure time, and strengthen preparedness. Research findings are shared across international security forums, while long-term partnerships are built on trust and practical collaboration.
Contact PR team
Email: pr@teamt5.org