Threadlinqs IntelligenceStart free

Threat actorUnknown (South Asia-aligned)Tracked since 2026-04

Harvester

Also known as:Harvester APTUNC1151-adjacent South Asia clusterSymantec-Harvester

As of 2026-06-10, Harvester is a Unknown (South Asia-aligned)-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as Harvester APT, UNC1151-adjacent South Asia cluster, Symantec-Harvester. ATT&CK coverage spans 25 techniques across 11 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1041 (Exfiltration Over C2 Channel).

Tracked threats
22 high
First seen
2026-04-22
Last seen
2026-06-10
ATT&CK techniques
25across 2 of 2 threats
Related CVEs
0None referenced
Attribution
Unknown (South Asia-aligned)Nation or origin
Nation: Unknown (South Asia-aligned) · 2 tracked threat(s) · Categories: MALWARE

Activity timeline

Harvester appears in 2 tracked threats between and ; the busiest month was 2026-04 with 1 report.

ATT&CK techniques observed

25 techniques observed across 2 of 2 tracked threats · Command and Control (4), Stealth (formerly Defense Evasion) (4), Persistence (3), Resource Development (3), Discovery (2), Execution (2)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 2 tracked threats
  • T1132 Data Encoding — Command and Controlobserved in 2 of 2 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1543 Create or Modify System Process — Persistenceobserved in 2 of 2 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 2 of 2 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 2 tracked threats
  • T1573 Encrypted Channel — Command and Controlobserved in 2 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 1 of 2 tracked threats

Tracked threats