AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855) — Threadlinqs Intelligence
As of 2026-06-10, AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855) is a high-severity apt threat attributed to APT28 (Multiple (North Korea, China, Russia, Iran, Pakistan)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0745 · Severity: HIGH · CVSS: 9.9 · Status: ACTIVE · Category: APT
Attribution: APT28 · Multiple (North Korea, China, Russia, Iran, Pakistan) · ESPIONAGE
AhnLab ASEC's April 2026 APT trend report tracks 15 state-sponsored groups across North Korea, China, Russia, Iran, and Pakistan conducting espionage and sabotage via supply-chain compromise,
This report consolidates AhnLab ASEC's April 2026 tracking of 15 nation-state APT clusters and their active malware sets. NORTH KOREA: UNC1069 and Famous Chollima (Contagious Interview) ran software supply-chain attacks, publishing malicious packages across five open-source ecosystems (npm, PyPI, Go Modules, crates.io, Packagist) to steal developer credentials, browser data, password-manager contents, and cryptocurrency wallets; between April 6-9 2026 an npm cluster of obfuscated throwaway-account packages delivered OtterCookie infostealer variants exfiltrating to cloudflareinsights[.]vercel[.]app. VoidDokkaebi used fake job-interview social engineering to deliver DEV#POPPER, InvisibleFerret, OtterCookie, OmniStealer, and BeaverTail (merged BeaverTail/OtterCookie variants add keylogging and screenshot modules). CHINA: Mustang Panda deployed PlugX against European and Middle Eastern government/diplomatic targets using web-bug reconnaissance, OAuth redirect abuse, and fake Cloudflare Turnstile pages; Silver Fox delivered ValleyRAT to Japanese users via DLL side-loading of legitimate Dell/Waves MaxxAudio executables, lured with Rakuten billing invoices. RUSSIA: APT28 (Fancy Bear/Forest Blizzard) exploited the zero-click Windows Shell coercion flaw CVE-2026-32202 (an incomplete-patch successor to CVE-2026-21510) to harvest Net-NTLMv2 hashes via malicious LNK files that trigger automatic UNC/SMB authentication on folder browse, and manipulated SOHO router/network-equipment DNS settings; Sandworm (APT-C-13) used malicious LNK files in ZIP archives with nested Tor/SSH tunnels and onion-domain mappings for SMB/RDP/SSH. IRAN: Charming Kitten (APT35) exploited Exchange ProxyLogon CVE-2021-26855; OilRig (APT-C-49) hid C2 behind GitHub, Google Drive, and Telegram Bot using Excel macros; Bitter deployed the ProSpy Android spyware against Middle East civil-society and government targets. PAKISTAN: Transparent Tribe (APT36) ran Operation TrustTrap, large-scale domain spoofing impersonating government portals to deliver the Golang DeskRAT via weaponized .desktop files targeting BOSS Linux, with WebSocket C2 on port 8080. OTHER: Harvester used the GoGra Linux backdoor abusing Microsoft Graph API and Outlook mailboxes; TGR-STA-1030 used Cobalt Strike, VShell, and a ShadowGuard eBPF rootkit after phishing and public-vulnerability exploitation; UAT-4356 (ArcaneDoor) exploited Cisco Secure Firewall ASA/FTD n-days CVE-2025-20333 and CVE-2025-20362 to deploy the FIRESTARTER backdoor (LINA hook), LINE VIPER loader, and RayInitiator bootkit on Firepower FXOS devices, surviving firmware patches. Primary target sectors are security, energy, diplomacy, politics, advanced manufacturing, and aerospace.
Weaknesses (CWE)
CWE-693, CWE-120, CWE-862, CWE-918
Target sectors: government, diplomacy, defense, military, energy, financial, advanced manufacturing, aerospace, technology, cryptocurrency, civil society
Target regions: Europe, Middle East, North America, East Asia, South Asia, Ukraine, India, Japan, Saudi Arabia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, CVE-2026-32202, CVE-2021-26855, CVE-2025-20333, CVE-2025-20362, T1598, T1583.001, T1585, T1587.001, T1190, T1195.002, T1566.001, T1566.003, T1204.002, T1059.004