Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled — Threadlinqs Intelligence
As of 2026-07-27, Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled is a high-severity threat intel threat attributed to APT38 (North Korea (DPRK), China, Palestine, Pakistan), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1721 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: APT38 · North Korea (DPRK), China, Palestine, Pakistan · ESPIONAGE
Cyble Research tracked 261 distinct threat actor profiles active in H1 2026 (118 nation-state APT groups, 75 ransomware groups, 34 hacktivist collectives, 31 cybercriminal groups, 3 extortion-only
Cyble's H1 2026 threat-actor landscape report profiles the composition of 261 tracked adversary groups and calls out five as the most operationally active during the period, each with a distinct nexus, targeting set, and tradecraft.
BlueNoroff (APT38/Lazarus subgroup, North Korea) ran a Web3/cryptocurrency-focused social-engineering campaign beginning January 23, 2026: a manipulated Calendly invite posing as a legal/consulting contact led victims to a typosquatted Zoom or Microsoft Teams meeting link. A fake 'SDK update' prompt triggered a ClickFix-style clipboard-hijack that ran fileless PowerShell, deployed a UAC-bypass DLL, disabled Microsoft Defender, and ultimately harvested browser-stored credentials, Telegram sessions, and cryptocurrency wallet extension data, while covertly capturing webcam video via mediasoup WebRTC for deepfake material. The actor escalated from May 31 to July 14, 2026 with a structured, AI-assisted (GPT-4o-generated headshots) Zoom/Teams phishing kit, compromising 100+ executives (45% CEO/founder) across 20+ countries, persisting up to 66 days per victim before detection.
UNC6508 (PRC-nexus espionage actor) compromised externally facing REDCap (Research Electronic Data Capture) research servers starting in September 2023, deploying custom INFINITERED malware — a three-part implant (upgrade-hijacking dropper, POST-login credential harvester, and a Cookie-triggered web-shell/SQL backdoor) — to persist inside North American academic, medical, and defense-research networks for over a year, through at least November 2025. The actor then abused Google Workspace and Microsoft 365 content-compliance / mail-forwarding rules (one named 'Patroit') to silently BCC-exfiltrate correspondence matching ~150 defense, AI, unmanned-systems, and medical-research keywords, routing access through a hijacked residential ASUS router and other U.S.-based proxies to obscure PRC attribution.
Volt Typhoon (PRC state-sponsored, aka Vanguard Panda/BRONZE SILHOUETTE/Insidious Taurus) continued long-term, living-off-the-land pre-positioning inside U.S. and allied critical-infrastructure IT networks (communications, energy, manufacturing, government, IT), some footholds persisting 5+ years. The group relies on LOLBins (certutil, PsExec, Impacket, WMI, Mimikatz) rather than custom malware, routes C2 through the KV Botnet of compromised SOHO routers, and has exploited edge-device zero-days for initial access, including CVE-2023-27997 (FortiOS/FortiProxy SSL-VPN heap overflow) and, from June through August 2024, CVE-2024-39717 in Versa Director SD-WAN management servers at MSPs/ISPs, deploying the custom VersaMem web shell to harvest downstream client credentials.
Desert Falcons (APT-C-23, aka Arid Viper/Mantis/Bearded Barbie, Palestine-nexus, active since at least 2014) targeted UAE, Israel, Jordan, and other MEA governments, aerospace/defense, and law-enforcement organizations using phishing-delivered Windows backdoors (Micropsia, KasperAgent) and mobile spyware (FrozenCell, Desert Scorpion, GnatSpy, AridSpy), often distributed through trojanized third-party Android app installs impersonating legitimate Palestinian apps.
SideCopy (Pakistan-nexus, active since at least 2019, operationally linked to/overlapping with Transparent Tribe/APT36) targeted Indian and Afghan government and defense entities via spearphishing and honeytrap lures, exploiting the WinRAR path-traversal zero-day CVE-2023-38831 to deploy a Linux variant of the open-source Ares RAT alongside AllaKore RAT, DRat, Action RAT, and Reverse RAT, with C2 infrastructure hosted primarily on Contabo GmbH (Germany) IP space and deliberately mimicking rival group SideWinder's infection chain to confuse attribution.
Cyble's original report provided no CVEs, malware names, or IOCs — this research fills that gap using MITRE ATT&CK group pages (G0082, G1008, G1017, G1028, G0134), CISA advisories, Google Threat Intelligence Group / Mandiant reporting, and vendor research (Arcti
Weaknesses (CWE)
CWE-122, CWE-434, CWE-22, CWE-288
Target sectors: cryptocurrency, financial services, web3, education, health, government administration, aerospace defense, communications, energy, manufacturing, information technology, police - law enforcement
Target regions: North America, Middle East, South Asia, East Asia, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, CVE-2023-27997, CVE-2024-39717, CVE-2023-38831, CVE-2022-40684, T1591.004, T1598.002, T1583.001, T1584.001, T1587.003, T1608.001, T1189, T1190, T1133, T1566.001