Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled
Cyble H1 2026 Threat Actor Landscape (TL-2026-1721), also tracked as Cyble H1 2026 Global Threat Landscape Report, is a high-severity tracked intrusion set, first published 2026-07-27. It is attributed to APT38 (North Korea, China, Palestine, Pakistan) with high confidence, affects Fortinet FortiOS / FortiProxy SSL-VPN, references 4 CVEs (CVE-2023-27997, CVE-2024-39717, CVE-2023-38831), maps to 51 MITRE ATT&CK techniques (T1003.001, T1016, T1020), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-1721
- Threat ID
- TL-2026-1721
- Also known as
- Cyble H1 2026 Global Threat Landscape Report
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-27
- Last reviewed
- 2026-07-27
- Attribution
- APT38
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea, China, Palestine, Pakistan
- Motivation
- ESPIONAGE
- Target sectors
- cryptocurrency, financial services, web3, education, health, government administration, aerospace defense, communications, energy, manufacturing, information technology, police - law enforcement
- Target regions
- North America, Middle East, South Asia, East Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in Cyble H1 2026 Threat Actor Landscape
Malware and tooling: AllaKore RAT, Ares RAT (Linux variant), Crimson RAT, FrozenCell - S0577, INFINITERED, Micropsia - S0339, RustBucket (OS X), VersaMem - S1154, Impacket - S0357, KV Botnet, Mimikatz
Cyble Research tracked 261 distinct threat actor profiles active in H1 2026 (118 nation-state APT groups, 75 ransomware groups, 34 hacktivist collectives, 31 cybercriminal groups, 3 extortion-only groups) and named five of the most active: BlueNoroff/APT38 (North Korea), UNC6508 (China), Volt Typhoon (China), Desert Falcons/APT-C-23 (Palestine), and SideCopy (Pakistan). Cross-referencing each named actor against MITRE ATT&CK, CISA, Google Threat Intelligence Group, and vendor research fills in the malware, infrastructure, exploited CVEs, and ATT&CK techniques the original vendor report did not itemize.
How Cyble H1 2026 Threat Actor Landscape works
Cyble's H1 2026 threat-actor landscape report profiles the composition of 261 tracked adversary groups and calls out five as the most operationally active during the period, each with a distinct nexus, targeting set, and tradecraft.
BlueNoroff (APT38/Lazarus subgroup, North Korea) ran a Web3/cryptocurrency-focused social-engineering campaign beginning January 23, 2026: a manipulated Calendly invite posing as a legal/consulting contact led victims to a typosquatted Zoom or Microsoft Teams meeting link. A fake 'SDK update' prompt triggered a ClickFix-style clipboard-hijack that ran fileless PowerShell, deployed a UAC-bypass DLL, disabled Microsoft Defender, and ultimately harvested browser-stored credentials, Telegram sessions, and cryptocurrency wallet extension data, while covertly capturing webcam video via mediasoup WebRTC for deepfake material. The actor escalated from May 31 to July 14, 2026 with a structured, AI-assisted (GPT-4o-generated headshots) Zoom/Teams phishing kit, compromising 100+ executives (45% CEO/founder) across 20+ countries, persisting up to 66 days per victim before detection.
UNC6508 (PRC-nexus espionage actor) compromised externally facing REDCap (Research Electronic Data Capture) research servers starting in September 2023, deploying custom INFINITERED malware — a three-part implant (upgrade-hijacking dropper, POST-login credential harvester, and a Cookie-triggered web-shell/SQL backdoor) — to persist inside North American academic, medical, and defense-research networks for over a year, through at least November 2025. The actor then abused Google Workspace and Microsoft 365 content-compliance / mail-forwarding rules (one named 'Patroit') to silently BCC-exfiltrate correspondence matching ~150 defense, AI, unmanned-systems, and medical-research keywords, routing access through a hijacked residential ASUS router and other U.S.-based proxies to obscure PRC attribution.
Volt Typhoon (PRC state-sponsored, aka Vanguard Panda/BRONZE SILHOUETTE/Insidious Taurus) continued long-term, living-off-the-land pre-positioning inside U.S. and allied critical-infrastructure IT networks (communications, energy, manufacturing, government, IT), some footholds persisting 5+ years. The group relies on LOLBins (certutil, PsExec, Impacket, WMI, Mimikatz) rather than custom malware, routes C2 through the KV Botnet of compromised SOHO routers, and has exploited edge-device zero-days for initial access, including CVE-2023-27997 (FortiOS/FortiProxy SSL-VPN heap overflow) and, from June through August 2024, CVE-2024-39717 in Versa Director SD-WAN management servers at MSPs/ISPs, deploying the custom VersaMem web shell to harvest downstream client credentials.
Desert Falcons (APT-C-23, aka Arid Viper/Mantis/Bearded Barbie, Palestine-nexus, active since at least 2014) targeted UAE, Israel, Jordan, and other MEA governments, aerospace/defense, and law-enforcement organizations using phishing-delivered Windows backdoors (Micropsia, KasperAgent) and mobile spyware (FrozenCell, Desert Scorpion, GnatSpy, AridSpy), often distributed through trojanized third-party Android app installs impersonating legitimate Palestinian apps.
SideCopy (Pakistan-nexus, active since at least 2019, operationally linked to/overlapping with Transparent Tribe/APT36) targeted Indian and Afghan government and defense entities via spearphishing and honeytrap lures, exploiting the WinRAR path-traversal zero-day CVE-2023-38831 to deploy a Linux variant of the open-source Ares RAT alongside AllaKore RAT, DRat, Action RAT, and Reverse RAT, with C2 infrastructure hosted primarily on Contabo GmbH (Germany) IP space and deliberately mimicking rival group SideWinder's infection chain to confuse attribution.
Cyble's original report provided no CVEs, malware names, or IOCs — this research fills that gap using MITRE ATT&CK group pages (G0082, G1008, G1017, G1028, G0134), CISA advisories, Google Threat Intelligence Group / Mandiant reporting, and vendor research (Arctic Wolf, Seqrite, Kaspersky Securelist, The Hacker News, Fortinet PSIRT).
MITRE ATT&CK techniques used in TL-2026-1721
Credential Access
T1003.001 LSASS Memory; T1110 Brute Force; T1555.003 Credentials from Web Browsers
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
Defense Evasion
T1027.002 Software Packing; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1218.005 Mshta; T1564.001 Hidden Files and Directories
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.005 Visual Basic; T1106 Native API; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File
Collection
T1056.001 Keylogging; T1074.001 Local Data Staging; T1113 Screen Capture; T1115 Clipboard Data
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548.002 Bypass User Account Control
Command and Control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer
Persistence
T1078 Valid Accounts; T1505.003 Web Shell; T1547.001 Registry Run Keys / Startup Folder
Initial Access
T1133 External Remote Services; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact
defense-impairment
T1553.005 Mark-of-the-Web Bypass; T1685 Disable or Modify Tools
stealth
Resource Development
T1583.001 Domains; T1584.001 Domains; T1587.003 Digital Certificates; T1608.001 Upload Malware
Reconnaissance
T1591.004 Identify Roles; T1598.002 Spearphishing Attachment
initial-access
Affected products and versions in Cyble H1 2026 Threat Actor Landscape
- Fortinet — FortiOS / FortiProxy SSL-VPN
Vulnerable versions: Pre-patch FortiOS/FortiProxy branches affected by CVE-2023-27997
Fixed in: FortiOS 7.2.5, 7.0.12, 6.4.13, 6.2.15, 6.0.17 and later - Versa Networks — Versa Director
Vulnerable versions: Versa Director prior to 22.1.4 (CVE-2024-39717)
Fixed in: 22.1.4 and later - RARLAB — WinRAR
Vulnerable versions: Versions prior to the CVE-2023-38831 fix
Fixed in: WinRAR 6.23 and later - Vanderbilt University — REDCap (Research Electronic Data Capture)
Vulnerable versions: Self-hosted, externally facing REDCap deployments with weak perimeter/credential controls
Fixed in: N/A - deployment hardening, not a REDCap software patch
Remediation for Cyble H1 2026 Threat Actor Landscape
Patches
- Fortinet FortiOS/FortiProxy patch for CVE-2023-27997
- Versa Director 22.1.4+ for CVE-2024-39717
- WinRAR 6.23+ for CVE-2023-38831
Immediate actions
- Block published BlueNoroff/APT38 typosquat domains and C2 IPs at DNS/perimeter (uu03webzoom.us, teams.livesmeet.us, check02id.com, thriddata.com, 83.136.208.246, 104.145.210.107)
- Patch Fortinet FortiOS/FortiProxy SSL-VPN beyond CVE-2023-27997 and hunt for post-exploitation web shells
- Upgrade Versa Director to 22.1.4+ and hunt for VersaMem web-shell artifacts tied to CVE-2024-39717
- Update WinRAR past the CVE-2023-38831 fix and block archive attachments exhibiting ADS/path-traversal patterns
- Audit REDCap deployments for unauthorized file modifications matching the INFINITERED GUID marker (b49e334d-9c01-463e-9bc5-00a6920fb66e) and review Google Workspace / Microsoft 365 mail-forwarding and content-compliance rules for unauthorized auto-BCC rules
Workarounds
- Restrict REDCap server exposure to VPN-only access and enforce MFA on REDCap logins
- Disable auto-forwarding and external content-compliance rule creation for standard user accounts pending review
- Require secondary out-of-band verification for any 'update your meeting client' prompt received via a calendar invite
Longer-term hardening
- Deploy EDR/XDR with behavioral detection for LOLBin abuse (certutil, PsExec, Impacket, WMI, Mimikatz) associated with Volt Typhoon
- Enforce phishing-resistant MFA and train executives/finance staff on Calendly/Zoom/Teams typosquat lures targeting crypto-wallet holders
- Segment OT/IT and critical-infrastructure networks to limit living-off-the-land lateral movement
- Implement egress monitoring for residential-proxy and SOHO-router-relayed C2 traffic (KV Botnet pattern)
- Institute routine audits of mail-flow rules (content compliance / auto-forwarding) in Google Workspace and Microsoft 365 tenants handling defense, medical, or research correspondence
CVEs associated with Cyble H1 2026 Threat Actor Landscape
CVE-2023-27997, CVE-2024-39717, CVE-2023-38831, CVE-2022-40684
Weaknesses (CWE) in Cyble H1 2026 Threat Actor Landscape
CWE-122, CWE-434, CWE-22, CWE-288
Timeline of Cyble H1 2026 Threat Actor Landscape
- Desert Falcons (APT-C-23/Arid Viper) emerges as a Palestine-based threat group, later documented by Kaspersky as active since at least 2014 with dedicated Windows and mobile malware targeting the Middle East.
- SideCopy is first identified as a distinct Pakistan-linked APT cluster targeting Indian government and defense entities, deliberately mimicking rival group SideWinder's infection chain.
- Volt Typhoon activity begins; the PRC state-sponsored actor starts establishing long-term, undetected access to U.S. and allied critical-infrastructure IT networks using living-off-the-land techniques.
- SideCopy runs a series of campaigns (April, May, August, October 2023) escalating targeting of Indian defense/government entities, correlating with Israel-Hamas conflict-themed lures.
- Fortinet confirms limited pre-patch in-the-wild exploitation of CVE-2023-27997, a critical FortiOS/FortiProxy SSL-VPN heap-overflow later linked to Volt Typhoon-associated activity.
- SideCopy exploits CVE-2023-38831 (WinRAR path-traversal zero-day) to deploy a Linux variant of the open-source Ares RAT and other payloads against Indian targets.
- UNC6508 (PRC-nexus) compromises the first externally facing REDCap research server, the earliest known intrusion in a campaign that would run undetected for over a year.
- Volt Typhoon begins exploiting the Versa Director zero-day CVE-2024-39717 at MSPs/ISPs, deploying the custom VersaMem web shell to capture downstream client credentials, continuing through August 2024.
- UNC6508's REDCap-intrusion and mail-exfiltration campaign activity is observed continuing through November 2025, per Google Threat Intelligence Group's disclosed observation window.
- BlueNoroff (APT38/Lazarus) initiates a targeted intrusion against a North American Web3 company via a typosquatted Zoom link delivered through a manipulated Calendly invite.
- BlueNoroff delivers a UAC-bypass payload (comBypassUacDLL.x64.dll) to the compromised Web3 victim, escalating privileges on the host.
- BlueNoroff adds a Telegram Bot API exfiltration channel (bot alias 'Aurora') to its intrusion toolkit for the ongoing Web3 campaign.
- BlueNoroff conducts a media-library scrape of the victim host, part of a 66-day persistence window before detection.
- BlueNoroff stands up a structured Zoom/Microsoft Teams phishing kit (five iterative versions through July 14, 2026) that fingerprints browsers for cryptocurrency-wallet extensions before deploying deepfake-assisted ClickFix lures, compromising 100+ executives across 20+ countries.
Sources cited for Cyble H1 2026 Threat Actor Landscape
- Most Active Threat Actors H1 2026 - Cyble
- PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A)
- People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (AA23-144A)
- APT38, BlueNoroff - Group G0082
- Volt Typhoon - Group G1017
- SideCopy - Group G1008
- APT-C-23, Desert Falcon - Group G1028
- Transparent Tribe, APT36 - Group G0134
- Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing AI, Cyber, Medical, and National Defense Research
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
- SideCopy's Multi-platform Onslaught: Leveraging WinRAR Zero-Day and Linux Variant of Ares RAT
- The Desert Falcons Targeted Attacks
- Versa Director zero-day exploited to compromise ISPs, MSPs (CVE-2024-39717)
- Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign
Threats related to Cyble H1 2026 Threat Actor Landscape
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering
- UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military Research
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft
- Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT 1.8.7 Against the Afghanistan Ministry of Finance
Detection coverage for TL-2026-1721
As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1721 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1721
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.