AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)
AhnLab ASEC April 2026 APT Group Trend Report (TL-2026-0745), also tracked as April 2026 APT Group Trend Report, is a high-severity advanced persistent threat campaign scored CVSS 9.9, first published 2026-06-10. It is attributed to APT28 with high confidence, affects Microsoft Windows Shell (Windows 10/11, Windows Server), references 4 CVEs (CVE-2026-32202, CVE-2021-26855, CVE-2025-20333), maps to 29 MITRE ATT&CK techniques (T1014, T1027, T1041), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0745
- Threat ID
- TL-2026-0745
- Also known as
- April 2026 APT Group Trend Report, Operation TrustTrap, ArcaneDoor, Contagious Interview, ProxyLogon
- Severity
- HIGH
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-06-10
- Last reviewed
- 2026-06-10
- Attribution
- APT28
- Attribution confidence
- HIGH
- Motivation
- ESPIONAGE
- Target sectors
- government, diplomacy, defense, military, energy, financial, advanced manufacturing, aerospace, technology, cryptocurrency, civil society
- Target regions
- Europe, Middle East, North America, East Asia, South Asia, Ukraine, India, Japan, Saudi Arabia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in AhnLab ASEC April 2026 APT Group Trend Report
Malware and tooling: BeaverTail - S1246, DeskRAT, FIRESTARTER, GoGra, InvisibleFerret - S1245, LINE VIPER, OtterCookie, PlugX, ProSpy, RayInitiator, ShadowGuard eBPF rootkit, ValleyRAT
AhnLab ASEC's April 2026 APT trend report tracks 15 state-sponsored groups across North Korea, China, Russia, Iran, and Pakistan conducting espionage and sabotage via supply-chain compromise, fake-job-interview social engineering, zero-click LNK/Windows Shell coercion, DLL sideloading, and DNS manipulation. Campaigns deliver InvisibleFerret, OtterCookie, BeaverTail, PlugX, ValleyRAT, ProSpy, DeskRAT, GoGra, FIRESTARTER, Cobalt Strike, VShell, and a ShadowGuard eBPF rootkit, leveraging CVE-2026-32202, CVE-2021-26855, and CVE-2025-20333/20362.
How AhnLab ASEC April 2026 APT Group Trend Report works
This report consolidates AhnLab ASEC's April 2026 tracking of 15 nation-state APT clusters and their active malware sets. NORTH KOREA: UNC1069 and Famous Chollima (Contagious Interview) ran software supply-chain attacks, publishing malicious packages across five open-source ecosystems (npm, PyPI, Go Modules, crates.io, Packagist) to steal developer credentials, browser data, password-manager contents, and cryptocurrency wallets; between April 6-9 2026 an npm cluster of obfuscated throwaway-account packages delivered OtterCookie infostealer variants exfiltrating to cloudflareinsights[.]vercel[.]app. VoidDokkaebi used fake job-interview social engineering to deliver DEV#POPPER, InvisibleFerret, OtterCookie, OmniStealer, and BeaverTail (merged BeaverTail/OtterCookie variants add keylogging and screenshot modules). CHINA: Mustang Panda deployed PlugX against European and Middle Eastern government/diplomatic targets using web-bug reconnaissance, OAuth redirect abuse, and fake Cloudflare Turnstile pages; Silver Fox delivered ValleyRAT to Japanese users via DLL side-loading of legitimate Dell/Waves MaxxAudio executables, lured with Rakuten billing invoices. RUSSIA: APT28 (Fancy Bear/Forest Blizzard) exploited the zero-click Windows Shell coercion flaw CVE-2026-32202 (an incomplete-patch successor to CVE-2026-21510) to harvest Net-NTLMv2 hashes via malicious LNK files that trigger automatic UNC/SMB authentication on folder browse, and manipulated SOHO router/network-equipment DNS settings; Sandworm (APT-C-13) used malicious LNK files in ZIP archives with nested Tor/SSH tunnels and onion-domain mappings for SMB/RDP/SSH. IRAN: Charming Kitten (APT35) exploited Exchange ProxyLogon CVE-2021-26855; OilRig (APT-C-49) hid C2 behind GitHub, Google Drive, and Telegram Bot using Excel macros; Bitter deployed the ProSpy Android spyware against Middle East civil-society and government targets. PAKISTAN: Transparent Tribe (APT36) ran Operation TrustTrap, large-scale domain spoofing impersonating government portals to deliver the Golang DeskRAT via weaponized .desktop files targeting BOSS Linux, with WebSocket C2 on port 8080. OTHER: Harvester used the GoGra Linux backdoor abusing Microsoft Graph API and Outlook mailboxes; TGR-STA-1030 used Cobalt Strike, VShell, and a ShadowGuard eBPF rootkit after phishing and public-vulnerability exploitation; UAT-4356 (ArcaneDoor) exploited Cisco Secure Firewall ASA/FTD n-days CVE-2025-20333 and CVE-2025-20362 to deploy the FIRESTARTER backdoor (LINA hook), LINE VIPER loader, and RayInitiator bootkit on Firepower FXOS devices, surviving firmware patches. Primary target sectors are security, energy, diplomacy, politics, advanced manufacturing, and aerospace.
MITRE ATT&CK techniques used in TL-2026-0745
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053.003 Cron; T1542.003 Bootkit; T1543.002 Systemd Service; T1547 Boot or Logon Autostart Execution
Collection
T1056.001 Keylogging; T1113 Screen Capture
Execution
T1059.004 Unix Shell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1102.002 Bidirectional Communication; T1572 Protocol Tunneling
Credential Access
T1187 Forced Authentication; T1555.003 Credentials from Web Browsers; T1555.005 Password Managers
Initial Access
T1190 Exploit Public-Facing Application; T1195.002 Compromise Software Supply Chain; T1566.001 Spearphishing Attachment; T1566.003 Spearphishing via Service
Impact
T1499 Endpoint Denial of Service
stealth
Resource Development
T1583.001 Domains; T1585 Establish Accounts; T1587.001 Malware
Reconnaissance
Affected products and versions in AhnLab ASEC April 2026 APT Group Trend Report
- Microsoft — Windows Shell (Windows 10/11, Windows Server)
Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 23H2/24H2/25H2/26H1; Windows Server 2012/2016/2019/2022/2025
Fixed in: April 14, 2026 update - Cisco — Secure Firewall ASA / Firepower Threat Defense (FXOS)
Vulnerable versions: ASA 9.12-9.23; FTD 7.0-7.7
Fixed in: ASA 9.20.3.7 / 9.22.1.3 et al.; FTD 7.2.9 / 7.4.2.4 et al. - Microsoft — Exchange Server
Vulnerable versions: 2013 CU21-23; 2016 CU8-19; 2019 RTM-CU8
Fixed in: March 2021 security update - Canonical/India BOSS — BOSS Linux (.desktop handling)
Vulnerable versions: Government BOSS Linux desktop
Fixed in: N/A - configuration hardening
Remediation for AhnLab ASEC April 2026 APT Group Trend Report
Patches
- Microsoft Windows Shell update for CVE-2026-32202 (April 14, 2026)
- Cisco ASA/FTD fixed releases for CVE-2025-20333 and CVE-2025-20362 (September 25, 2025)
- Microsoft Exchange security update for CVE-2021-26855
Immediate actions
- Apply Microsoft April 2026 patch for CVE-2026-32202 (Windows Shell NTLM coercion) and verify the 'Exploited' status; block outbound SMB (TCP 445) and WebDAV to untrusted hosts to stop NTLM relay/coercion
- Upgrade Cisco Secure Firewall ASA/FTD to fixed releases for CVE-2025-20333 and CVE-2025-20362; treat any device compromised before patching as still infected (FIRESTARTER survives firmware upgrades) and rebuild from known-good images
- Patch Exchange Server against ProxyLogon CVE-2021-26855 and audit for webshells/SSRF artifacts
- Audit developer workstations and CI/CD for malicious npm/PyPI/Go/crates.io/Packagist dependencies; block cloudflareinsights[.]vercel[.]app and rotate developer/crypto credentials
Workarounds
- Block LNK files at email/web gateways and disable automatic icon/UNC resolution
- Disable Cisco ASA/FTD VPN web server if not required pending patch
- Restrict execution of .desktop files and ZIP-delivered shortcuts on Linux
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading, LNK-triggered UNC authentication, and eBPF rootkit activity
- Enforce SMB signing and disable NTLM where feasible; segment network-perimeter devices
- Implement software supply-chain controls (dependency pinning, provenance/SLSA, package allow-listing)
- Harden Linux endpoints (e.g., BOSS Linux) against .desktop auto-execution and inspect cron/autostart/shell-profile persistence
CVEs associated with AhnLab ASEC April 2026 APT Group Trend Report
CVE-2026-32202, CVE-2021-26855, CVE-2025-20333, CVE-2025-20362
Weaknesses (CWE) in AhnLab ASEC April 2026 APT Group Trend Report
CWE-693, CWE-120, CWE-862, CWE-918
Timeline of AhnLab ASEC April 2026 APT Group Trend Report
- Exchange ProxyLogon CVE-2021-26855 disclosed; later reused by Iran's Charming Kitten (APT35) in this reporting period.
- Transparent Tribe (APT36) Operation TrustTrap DeskRAT campaign begins, weaponizing .desktop files against Indian government/BOSS Linux targets.
- Cisco ASA/FTD CVE-2025-20333 and CVE-2025-20362 published and added to CISA KEV; exploited by UAT-4356 (ArcaneDoor) to deploy FIRESTARTER.
- New CVE-2025-20362 attack variant reported causing unpatched Cisco devices to reload, triggering denial-of-service.
- APT28 begins exploiting Windows Shell zero-click flaw (CVE-2026-32202) against Ukraine and EU nations to steal Net-NTLMv2 hashes.
- Microsoft documents Contagious Interview fake-job-interview campaign delivering BeaverTail, InvisibleFerret, and OtterCookie.
- npm cluster of obfuscated throwaway-account packages (April 6-9) identified delivering OtterCookie infostealer variants exfiltrating to cloudflareinsights[.]vercel[.]app.
- Microsoft patches CVE-2026-32202 (incomplete-patch successor to CVE-2026-21510) but initially omits the 'Exploited' flag.
- Cisco Talos publishes UAT-4356 FIRESTARTER analysis; backdoor persists via CSP_MOUNT_LIST and survives firmware patches.
- CISA and Microsoft correct the advisory and add CVE-2026-32202 to the Known Exploited Vulnerabilities catalog (deadline May 12).
- AhnLab ASEC publishes the April 2026 APT Group Trend Report consolidating 15 tracked state-sponsored groups.
Sources cited for AhnLab ASEC April 2026 APT Group Trend Report
- 2026년 4월 APT 그룹 동향 보고서 (April 2026 APT Group Trend Report)
- A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202
- Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
- CISA orders feds to patch Windows flaw exploited as zero-day
- UAT-4356's Targeting of Cisco Firepower Devices (FIRESTARTER)
- Firestarter malware survives Cisco firewall updates, security patches
- Contagious Interview: Malware delivered through fake developer job interviews
- Tracking an OtterCookie Infostealer Campaign Across npm
- TransparentTribe Targets Indian Military Organisations With DeskRAT
- NVD - CVE-2025-20333 (Cisco ASA/FTD VPN web server buffer overflow)
- NVD - CVE-2025-20362 (Cisco ASA/FTD missing authorization)
- NVD - CVE-2021-26855 (Exchange ProxyLogon SSRF RCE)
- NVD - CVE-2026-32202 (Windows Shell protection-mechanism failure)
Threats related to AhnLab ASEC April 2026 APT Group Trend Report
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise
- Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories
Detection coverage for TL-2026-0745
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0745 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0745
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.