AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)

AhnLab ASEC April 2026 APT Group Trend Report (TL-2026-0745), also tracked as April 2026 APT Group Trend Report, is a high-severity advanced persistent threat campaign scored CVSS 9.9, first published 2026-06-10. It is attributed to APT28 with high confidence, affects Microsoft Windows Shell (Windows 10/11, Windows Server), references 4 CVEs (CVE-2026-32202, CVE-2021-26855, CVE-2025-20333), maps to 29 MITRE ATT&CK techniques (T1014, T1027, T1041), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-0745

Threat ID
TL-2026-0745
Also known as
April 2026 APT Group Trend Report, Operation TrustTrap, ArcaneDoor, Contagious Interview, ProxyLogon
Severity
HIGH
CVSS
9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-06-10
Last reviewed
2026-06-10
Attribution
APT28
Attribution confidence
HIGH
Motivation
ESPIONAGE
Target sectors
government, diplomacy, defense, military, energy, financial, advanced manufacturing, aerospace, technology, cryptocurrency, civil society
Target regions
Europe, Middle East, North America, East Asia, South Asia, Ukraine, India, Japan, Saudi Arabia
Detection rules
9
Indicators of compromise
30

Malware and tooling in AhnLab ASEC April 2026 APT Group Trend Report

Malware and tooling: BeaverTail - S1246, DeskRAT, FIRESTARTER, GoGra, InvisibleFerret - S1245, LINE VIPER, OtterCookie, PlugX, ProSpy, RayInitiator, ShadowGuard eBPF rootkit, ValleyRAT

AhnLab ASEC's April 2026 APT trend report tracks 15 state-sponsored groups across North Korea, China, Russia, Iran, and Pakistan conducting espionage and sabotage via supply-chain compromise, fake-job-interview social engineering, zero-click LNK/Windows Shell coercion, DLL sideloading, and DNS manipulation. Campaigns deliver InvisibleFerret, OtterCookie, BeaverTail, PlugX, ValleyRAT, ProSpy, DeskRAT, GoGra, FIRESTARTER, Cobalt Strike, VShell, and a ShadowGuard eBPF rootkit, leveraging CVE-2026-32202, CVE-2021-26855, and CVE-2025-20333/20362.

How AhnLab ASEC April 2026 APT Group Trend Report works

This report consolidates AhnLab ASEC's April 2026 tracking of 15 nation-state APT clusters and their active malware sets. NORTH KOREA: UNC1069 and Famous Chollima (Contagious Interview) ran software supply-chain attacks, publishing malicious packages across five open-source ecosystems (npm, PyPI, Go Modules, crates.io, Packagist) to steal developer credentials, browser data, password-manager contents, and cryptocurrency wallets; between April 6-9 2026 an npm cluster of obfuscated throwaway-account packages delivered OtterCookie infostealer variants exfiltrating to cloudflareinsights[.]vercel[.]app. VoidDokkaebi used fake job-interview social engineering to deliver DEV#POPPER, InvisibleFerret, OtterCookie, OmniStealer, and BeaverTail (merged BeaverTail/OtterCookie variants add keylogging and screenshot modules). CHINA: Mustang Panda deployed PlugX against European and Middle Eastern government/diplomatic targets using web-bug reconnaissance, OAuth redirect abuse, and fake Cloudflare Turnstile pages; Silver Fox delivered ValleyRAT to Japanese users via DLL side-loading of legitimate Dell/Waves MaxxAudio executables, lured with Rakuten billing invoices. RUSSIA: APT28 (Fancy Bear/Forest Blizzard) exploited the zero-click Windows Shell coercion flaw CVE-2026-32202 (an incomplete-patch successor to CVE-2026-21510) to harvest Net-NTLMv2 hashes via malicious LNK files that trigger automatic UNC/SMB authentication on folder browse, and manipulated SOHO router/network-equipment DNS settings; Sandworm (APT-C-13) used malicious LNK files in ZIP archives with nested Tor/SSH tunnels and onion-domain mappings for SMB/RDP/SSH. IRAN: Charming Kitten (APT35) exploited Exchange ProxyLogon CVE-2021-26855; OilRig (APT-C-49) hid C2 behind GitHub, Google Drive, and Telegram Bot using Excel macros; Bitter deployed the ProSpy Android spyware against Middle East civil-society and government targets. PAKISTAN: Transparent Tribe (APT36) ran Operation TrustTrap, large-scale domain spoofing impersonating government portals to deliver the Golang DeskRAT via weaponized .desktop files targeting BOSS Linux, with WebSocket C2 on port 8080. OTHER: Harvester used the GoGra Linux backdoor abusing Microsoft Graph API and Outlook mailboxes; TGR-STA-1030 used Cobalt Strike, VShell, and a ShadowGuard eBPF rootkit after phishing and public-vulnerability exploitation; UAT-4356 (ArcaneDoor) exploited Cisco Secure Firewall ASA/FTD n-days CVE-2025-20333 and CVE-2025-20362 to deploy the FIRESTARTER backdoor (LINA hook), LINE VIPER loader, and RayInitiator bootkit on Firepower FXOS devices, surviving firmware patches. Primary target sectors are security, energy, diplomacy, politics, advanced manufacturing, and aerospace.

MITRE ATT&CK techniques used in TL-2026-0745

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053.003 Cron; T1542.003 Bootkit; T1543.002 Systemd Service; T1547 Boot or Logon Autostart Execution

Collection

T1056.001 Keylogging; T1113 Screen Capture

Execution

T1059.004 Unix Shell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1102.002 Bidirectional Communication; T1572 Protocol Tunneling

Credential Access

T1187 Forced Authentication; T1555.003 Credentials from Web Browsers; T1555.005 Password Managers

Initial Access

T1190 Exploit Public-Facing Application; T1195.002 Compromise Software Supply Chain; T1566.001 Spearphishing Attachment; T1566.003 Spearphishing via Service

Impact

T1499 Endpoint Denial of Service

stealth

T1574.001 DLL

Resource Development

T1583.001 Domains; T1585 Establish Accounts; T1587.001 Malware

Reconnaissance

T1598 Phishing for Information

Affected products and versions in AhnLab ASEC April 2026 APT Group Trend Report

  • Microsoft — Windows Shell (Windows 10/11, Windows Server)
    Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 23H2/24H2/25H2/26H1; Windows Server 2012/2016/2019/2022/2025
    Fixed in: April 14, 2026 update
  • Cisco — Secure Firewall ASA / Firepower Threat Defense (FXOS)
    Vulnerable versions: ASA 9.12-9.23; FTD 7.0-7.7
    Fixed in: ASA 9.20.3.7 / 9.22.1.3 et al.; FTD 7.2.9 / 7.4.2.4 et al.
  • Microsoft — Exchange Server
    Vulnerable versions: 2013 CU21-23; 2016 CU8-19; 2019 RTM-CU8
    Fixed in: March 2021 security update
  • Canonical/India BOSS — BOSS Linux (.desktop handling)
    Vulnerable versions: Government BOSS Linux desktop
    Fixed in: N/A - configuration hardening

Remediation for AhnLab ASEC April 2026 APT Group Trend Report

Patches

  • Microsoft Windows Shell update for CVE-2026-32202 (April 14, 2026)
  • Cisco ASA/FTD fixed releases for CVE-2025-20333 and CVE-2025-20362 (September 25, 2025)
  • Microsoft Exchange security update for CVE-2021-26855

Immediate actions

  • Apply Microsoft April 2026 patch for CVE-2026-32202 (Windows Shell NTLM coercion) and verify the 'Exploited' status; block outbound SMB (TCP 445) and WebDAV to untrusted hosts to stop NTLM relay/coercion
  • Upgrade Cisco Secure Firewall ASA/FTD to fixed releases for CVE-2025-20333 and CVE-2025-20362; treat any device compromised before patching as still infected (FIRESTARTER survives firmware upgrades) and rebuild from known-good images
  • Patch Exchange Server against ProxyLogon CVE-2021-26855 and audit for webshells/SSRF artifacts
  • Audit developer workstations and CI/CD for malicious npm/PyPI/Go/crates.io/Packagist dependencies; block cloudflareinsights[.]vercel[.]app and rotate developer/crypto credentials

Workarounds

  • Block LNK files at email/web gateways and disable automatic icon/UNC resolution
  • Disable Cisco ASA/FTD VPN web server if not required pending patch
  • Restrict execution of .desktop files and ZIP-delivered shortcuts on Linux

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading, LNK-triggered UNC authentication, and eBPF rootkit activity
  • Enforce SMB signing and disable NTLM where feasible; segment network-perimeter devices
  • Implement software supply-chain controls (dependency pinning, provenance/SLSA, package allow-listing)
  • Harden Linux endpoints (e.g., BOSS Linux) against .desktop auto-execution and inspect cron/autostart/shell-profile persistence

CVEs associated with AhnLab ASEC April 2026 APT Group Trend Report

CVE-2026-32202, CVE-2021-26855, CVE-2025-20333, CVE-2025-20362

Weaknesses (CWE) in AhnLab ASEC April 2026 APT Group Trend Report

CWE-693, CWE-120, CWE-862, CWE-918

Timeline of AhnLab ASEC April 2026 APT Group Trend Report

  • Exchange ProxyLogon CVE-2021-26855 disclosed; later reused by Iran's Charming Kitten (APT35) in this reporting period.
  • Transparent Tribe (APT36) Operation TrustTrap DeskRAT campaign begins, weaponizing .desktop files against Indian government/BOSS Linux targets.
  • Cisco ASA/FTD CVE-2025-20333 and CVE-2025-20362 published and added to CISA KEV; exploited by UAT-4356 (ArcaneDoor) to deploy FIRESTARTER.
  • New CVE-2025-20362 attack variant reported causing unpatched Cisco devices to reload, triggering denial-of-service.
  • APT28 begins exploiting Windows Shell zero-click flaw (CVE-2026-32202) against Ukraine and EU nations to steal Net-NTLMv2 hashes.
  • Microsoft documents Contagious Interview fake-job-interview campaign delivering BeaverTail, InvisibleFerret, and OtterCookie.
  • npm cluster of obfuscated throwaway-account packages (April 6-9) identified delivering OtterCookie infostealer variants exfiltrating to cloudflareinsights[.]vercel[.]app.
  • Microsoft patches CVE-2026-32202 (incomplete-patch successor to CVE-2026-21510) but initially omits the 'Exploited' flag.
  • Cisco Talos publishes UAT-4356 FIRESTARTER analysis; backdoor persists via CSP_MOUNT_LIST and survives firmware patches.
  • CISA and Microsoft correct the advisory and add CVE-2026-32202 to the Known Exploited Vulnerabilities catalog (deadline May 12).
  • AhnLab ASEC publishes the April 2026 APT Group Trend Report consolidating 15 tracked state-sponsored groups.

Sources cited for AhnLab ASEC April 2026 APT Group Trend Report

Threats related to AhnLab ASEC April 2026 APT Group Trend Report

Detection coverage for TL-2026-0745

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0745 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0745

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats