Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled

Cyble H1 2026 Threat Actor Landscape (TL-2026-1721), also tracked as Cyble H1 2026 Global Threat Landscape Report, is a high-severity tracked intrusion set, first published 2026-07-27. It is attributed to APT38 (North Korea, China, Palestine, Pakistan) with high confidence, affects Fortinet FortiOS / FortiProxy SSL-VPN, references 4 CVEs (CVE-2023-27997, CVE-2024-39717, CVE-2023-38831), maps to 51 MITRE ATT&CK techniques (T1003.001, T1016, T1020), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-1721

Threat ID
TL-2026-1721
Also known as
Cyble H1 2026 Global Threat Landscape Report
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-27
Last reviewed
2026-07-27
Attribution
APT38
Attribution confidence
HIGH
Nation-state nexus
North Korea, China, Palestine, Pakistan
Motivation
ESPIONAGE
Target sectors
cryptocurrency, financial services, web3, education, health, government administration, aerospace defense, communications, energy, manufacturing, information technology, police - law enforcement
Target regions
North America, Middle East, South Asia, East Asia, Global
Detection rules
9
Indicators of compromise
31

Malware and tooling in Cyble H1 2026 Threat Actor Landscape

Malware and tooling: AllaKore RAT, Ares RAT (Linux variant), Crimson RAT, FrozenCell - S0577, INFINITERED, Micropsia - S0339, RustBucket (OS X), VersaMem - S1154, Impacket - S0357, KV Botnet, Mimikatz

Cyble Research tracked 261 distinct threat actor profiles active in H1 2026 (118 nation-state APT groups, 75 ransomware groups, 34 hacktivist collectives, 31 cybercriminal groups, 3 extortion-only groups) and named five of the most active: BlueNoroff/APT38 (North Korea), UNC6508 (China), Volt Typhoon (China), Desert Falcons/APT-C-23 (Palestine), and SideCopy (Pakistan). Cross-referencing each named actor against MITRE ATT&CK, CISA, Google Threat Intelligence Group, and vendor research fills in the malware, infrastructure, exploited CVEs, and ATT&CK techniques the original vendor report did not itemize.

How Cyble H1 2026 Threat Actor Landscape works

Cyble's H1 2026 threat-actor landscape report profiles the composition of 261 tracked adversary groups and calls out five as the most operationally active during the period, each with a distinct nexus, targeting set, and tradecraft.

BlueNoroff (APT38/Lazarus subgroup, North Korea) ran a Web3/cryptocurrency-focused social-engineering campaign beginning January 23, 2026: a manipulated Calendly invite posing as a legal/consulting contact led victims to a typosquatted Zoom or Microsoft Teams meeting link. A fake 'SDK update' prompt triggered a ClickFix-style clipboard-hijack that ran fileless PowerShell, deployed a UAC-bypass DLL, disabled Microsoft Defender, and ultimately harvested browser-stored credentials, Telegram sessions, and cryptocurrency wallet extension data, while covertly capturing webcam video via mediasoup WebRTC for deepfake material. The actor escalated from May 31 to July 14, 2026 with a structured, AI-assisted (GPT-4o-generated headshots) Zoom/Teams phishing kit, compromising 100+ executives (45% CEO/founder) across 20+ countries, persisting up to 66 days per victim before detection.

UNC6508 (PRC-nexus espionage actor) compromised externally facing REDCap (Research Electronic Data Capture) research servers starting in September 2023, deploying custom INFINITERED malware — a three-part implant (upgrade-hijacking dropper, POST-login credential harvester, and a Cookie-triggered web-shell/SQL backdoor) — to persist inside North American academic, medical, and defense-research networks for over a year, through at least November 2025. The actor then abused Google Workspace and Microsoft 365 content-compliance / mail-forwarding rules (one named 'Patroit') to silently BCC-exfiltrate correspondence matching ~150 defense, AI, unmanned-systems, and medical-research keywords, routing access through a hijacked residential ASUS router and other U.S.-based proxies to obscure PRC attribution.

Volt Typhoon (PRC state-sponsored, aka Vanguard Panda/BRONZE SILHOUETTE/Insidious Taurus) continued long-term, living-off-the-land pre-positioning inside U.S. and allied critical-infrastructure IT networks (communications, energy, manufacturing, government, IT), some footholds persisting 5+ years. The group relies on LOLBins (certutil, PsExec, Impacket, WMI, Mimikatz) rather than custom malware, routes C2 through the KV Botnet of compromised SOHO routers, and has exploited edge-device zero-days for initial access, including CVE-2023-27997 (FortiOS/FortiProxy SSL-VPN heap overflow) and, from June through August 2024, CVE-2024-39717 in Versa Director SD-WAN management servers at MSPs/ISPs, deploying the custom VersaMem web shell to harvest downstream client credentials.

Desert Falcons (APT-C-23, aka Arid Viper/Mantis/Bearded Barbie, Palestine-nexus, active since at least 2014) targeted UAE, Israel, Jordan, and other MEA governments, aerospace/defense, and law-enforcement organizations using phishing-delivered Windows backdoors (Micropsia, KasperAgent) and mobile spyware (FrozenCell, Desert Scorpion, GnatSpy, AridSpy), often distributed through trojanized third-party Android app installs impersonating legitimate Palestinian apps.

SideCopy (Pakistan-nexus, active since at least 2019, operationally linked to/overlapping with Transparent Tribe/APT36) targeted Indian and Afghan government and defense entities via spearphishing and honeytrap lures, exploiting the WinRAR path-traversal zero-day CVE-2023-38831 to deploy a Linux variant of the open-source Ares RAT alongside AllaKore RAT, DRat, Action RAT, and Reverse RAT, with C2 infrastructure hosted primarily on Contabo GmbH (Germany) IP space and deliberately mimicking rival group SideWinder's infection chain to confuse attribution.

Cyble's original report provided no CVEs, malware names, or IOCs — this research fills that gap using MITRE ATT&CK group pages (G0082, G1008, G1017, G1028, G0134), CISA advisories, Google Threat Intelligence Group / Mandiant reporting, and vendor research (Arctic Wolf, Seqrite, Kaspersky Securelist, The Hacker News, Fortinet PSIRT).

MITRE ATT&CK techniques used in TL-2026-1721

Credential Access

T1003.001 LSASS Memory; T1110 Brute Force; T1555.003 Credentials from Web Browsers

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel

Defense Evasion

T1027.002 Software Packing; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1218.005 Mshta; T1564.001 Hidden Files and Directories

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.005 Visual Basic; T1106 Native API; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File

Collection

T1056.001 Keylogging; T1074.001 Local Data Staging; T1113 Screen Capture; T1115 Clipboard Data

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548.002 Bypass User Account Control

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer

Persistence

T1078 Valid Accounts; T1505.003 Web Shell; T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1133 External Remote Services; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact

defense-impairment

T1553.005 Mark-of-the-Web Bypass; T1685 Disable or Modify Tools

stealth

T1574.001 DLL

Resource Development

T1583.001 Domains; T1584.001 Domains; T1587.003 Digital Certificates; T1608.001 Upload Malware

Reconnaissance

T1591.004 Identify Roles; T1598.002 Spearphishing Attachment

initial-access

T1660 Phishing

Affected products and versions in Cyble H1 2026 Threat Actor Landscape

  • Fortinet — FortiOS / FortiProxy SSL-VPN
    Vulnerable versions: Pre-patch FortiOS/FortiProxy branches affected by CVE-2023-27997
    Fixed in: FortiOS 7.2.5, 7.0.12, 6.4.13, 6.2.15, 6.0.17 and later
  • Versa Networks — Versa Director
    Vulnerable versions: Versa Director prior to 22.1.4 (CVE-2024-39717)
    Fixed in: 22.1.4 and later
  • RARLAB — WinRAR
    Vulnerable versions: Versions prior to the CVE-2023-38831 fix
    Fixed in: WinRAR 6.23 and later
  • Vanderbilt University — REDCap (Research Electronic Data Capture)
    Vulnerable versions: Self-hosted, externally facing REDCap deployments with weak perimeter/credential controls
    Fixed in: N/A - deployment hardening, not a REDCap software patch

Remediation for Cyble H1 2026 Threat Actor Landscape

Patches

  • Fortinet FortiOS/FortiProxy patch for CVE-2023-27997
  • Versa Director 22.1.4+ for CVE-2024-39717
  • WinRAR 6.23+ for CVE-2023-38831

Immediate actions

  • Block published BlueNoroff/APT38 typosquat domains and C2 IPs at DNS/perimeter (uu03webzoom.us, teams.livesmeet.us, check02id.com, thriddata.com, 83.136.208.246, 104.145.210.107)
  • Patch Fortinet FortiOS/FortiProxy SSL-VPN beyond CVE-2023-27997 and hunt for post-exploitation web shells
  • Upgrade Versa Director to 22.1.4+ and hunt for VersaMem web-shell artifacts tied to CVE-2024-39717
  • Update WinRAR past the CVE-2023-38831 fix and block archive attachments exhibiting ADS/path-traversal patterns
  • Audit REDCap deployments for unauthorized file modifications matching the INFINITERED GUID marker (b49e334d-9c01-463e-9bc5-00a6920fb66e) and review Google Workspace / Microsoft 365 mail-forwarding and content-compliance rules for unauthorized auto-BCC rules

Workarounds

  • Restrict REDCap server exposure to VPN-only access and enforce MFA on REDCap logins
  • Disable auto-forwarding and external content-compliance rule creation for standard user accounts pending review
  • Require secondary out-of-band verification for any 'update your meeting client' prompt received via a calendar invite

Longer-term hardening

  • Deploy EDR/XDR with behavioral detection for LOLBin abuse (certutil, PsExec, Impacket, WMI, Mimikatz) associated with Volt Typhoon
  • Enforce phishing-resistant MFA and train executives/finance staff on Calendly/Zoom/Teams typosquat lures targeting crypto-wallet holders
  • Segment OT/IT and critical-infrastructure networks to limit living-off-the-land lateral movement
  • Implement egress monitoring for residential-proxy and SOHO-router-relayed C2 traffic (KV Botnet pattern)
  • Institute routine audits of mail-flow rules (content compliance / auto-forwarding) in Google Workspace and Microsoft 365 tenants handling defense, medical, or research correspondence

CVEs associated with Cyble H1 2026 Threat Actor Landscape

CVE-2023-27997, CVE-2024-39717, CVE-2023-38831, CVE-2022-40684

Weaknesses (CWE) in Cyble H1 2026 Threat Actor Landscape

CWE-122, CWE-434, CWE-22, CWE-288

Timeline of Cyble H1 2026 Threat Actor Landscape

  • Desert Falcons (APT-C-23/Arid Viper) emerges as a Palestine-based threat group, later documented by Kaspersky as active since at least 2014 with dedicated Windows and mobile malware targeting the Middle East.
  • SideCopy is first identified as a distinct Pakistan-linked APT cluster targeting Indian government and defense entities, deliberately mimicking rival group SideWinder's infection chain.
  • Volt Typhoon activity begins; the PRC state-sponsored actor starts establishing long-term, undetected access to U.S. and allied critical-infrastructure IT networks using living-off-the-land techniques.
  • SideCopy runs a series of campaigns (April, May, August, October 2023) escalating targeting of Indian defense/government entities, correlating with Israel-Hamas conflict-themed lures.
  • Fortinet confirms limited pre-patch in-the-wild exploitation of CVE-2023-27997, a critical FortiOS/FortiProxy SSL-VPN heap-overflow later linked to Volt Typhoon-associated activity.
  • SideCopy exploits CVE-2023-38831 (WinRAR path-traversal zero-day) to deploy a Linux variant of the open-source Ares RAT and other payloads against Indian targets.
  • UNC6508 (PRC-nexus) compromises the first externally facing REDCap research server, the earliest known intrusion in a campaign that would run undetected for over a year.
  • Volt Typhoon begins exploiting the Versa Director zero-day CVE-2024-39717 at MSPs/ISPs, deploying the custom VersaMem web shell to capture downstream client credentials, continuing through August 2024.
  • UNC6508's REDCap-intrusion and mail-exfiltration campaign activity is observed continuing through November 2025, per Google Threat Intelligence Group's disclosed observation window.
  • BlueNoroff (APT38/Lazarus) initiates a targeted intrusion against a North American Web3 company via a typosquatted Zoom link delivered through a manipulated Calendly invite.
  • BlueNoroff delivers a UAC-bypass payload (comBypassUacDLL.x64.dll) to the compromised Web3 victim, escalating privileges on the host.
  • BlueNoroff adds a Telegram Bot API exfiltration channel (bot alias 'Aurora') to its intrusion toolkit for the ongoing Web3 campaign.
  • BlueNoroff conducts a media-library scrape of the victim host, part of a 66-day persistence window before detection.
  • BlueNoroff stands up a structured Zoom/Microsoft Teams phishing kit (five iterative versions through July 14, 2026) that fingerprints browsers for cryptocurrency-wallet extensions before deploying deepfake-assisted ClickFix lures, compromising 100+ executives across 20+ countries.

Sources cited for Cyble H1 2026 Threat Actor Landscape

Threats related to Cyble H1 2026 Threat Actor Landscape

Detection coverage for TL-2026-1721

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1721 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1721

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats