
THREAT ENVIRONMENT
India’s Government & Defence ecosystem remained a primary target for intelligence-driven cyber operations, with nation-state actors prioritising persistent access over disruptive attacks.
KEY ADVERSARY OBJECTIVE
Intelligence collection, strategic surveillance and long-term access remained the dominant objectives throughout the reporting period.
OPERATIONAL SHIFT
Identity compromise, trusted relationships and AI-enabled tradecraft increasingly replaced traditional malware-centric intrusion models.
FORWARD OUTLOOK
CYFIRMA assesses that nation-state activity is likely to intensify, with increased emphasis on identity infrastructure, supply chains and critical government systems.
| Primary Threat Actor Profile | Nation-State Espionage Groups
China-aligned (APT41, Mustang Panda) Pakistan-aligned (APT36) |
| Threat Activity Assessment | HIGH
(Sustained & Evolving) |
| Primary Target Environment | Government & Defence Ecosystem |
| Dominant Initial Access Vector | Identity & Credential Compromise |
| Operational Trend | AI-Enabled Multi-Stage Intrusions |
| 12-Month Outlook | Escalating
(Persistent & Long-Term) |
“India’s Government & Defence cyber threat landscape is increasingly characterised by persistent, intelligence-driven campaigns designed to establish long-term strategic access rather than achieve immediate operational disruption. Nation-state actors continue to exploit trusted identities, interconnected supply chains and internet-facing services to support sustained espionage, intelligence collection and broader geopolitical objectives.”
Executive Intelligence Dashboard | Reporting Period Jan – Aug 2026
THREAT ACTORS
Multiple Active Threat Actors
Nation-state | Hacktivist | Cyber Criminals
MAJOR CAMPAIGNS
Numerous Major Campaigns
Espionage | Credential Theft | DDOS | Data Theft
RANSOMWARE ACTIVITY HIGH
Active
Espionage | Credential Theft | DDOS | Data Theft
DARK WEB EXPOSURE ELEVATED
Exposure
Data Leaks | Access Sales | Breach Claims | Credentials
THREAT CHATTERS INCREASING
Volume
Telegram | Forums | Leak Sites | Social Media
AI THREAT TRENDS RAPID GROWTH
Observed
AI-Assisted Phishing | Deepfake | Recon Automation | AI-Assisted Malware
INITIAL ACCESS TRENDS
TOP TARGETED SECTORS
CRITICAL CVEs IN FOCUS
KEY RISKS
ESPIONAGE
Nation-state actors targeting sensitive government & defence information
IDENTITY COMPROMISE
Credential theft and misuse enabling unauthorised access
SUPPLY CHAIN RISK
Third-party & vendor compromises leading to lateral impact
AI–Enabled ATTACKS
AI-assisted phishing, deepfakes and automated reconnaissance continue to evolve.
PUBLIC SERVICE DISRUPTION
Potential impact on critical government services and operational continuity
India’s Government and Defence sector continues to face sustained cyber pressure from nation-state actors, hacktivists and financially motivated adversaries. While nation-state espionage remains the dominant strategic threat, ransomware continues to present a significant operational risk, alongside AI-assisted phishing and increasing underground coordination.
Strategic Drivers Behind Persistent Cyber Targeting

KEY ADVERSE OBJECTIVES

STRATEGIC IMPERATIVE
India’s digital expansion, defence advancements and geopolitical positioning collectively make its Government & Defence ecosystem a persistent target for diverse threat actors.
Diverse Adversaries Targeting India’s Government & Defence Sector
India’s Government & Defence ecosystem faces a wide spectrum of threat actors motivated by espionage, disruption, financial gain and ideological objectives.

TOP ACTOR PROFILES

How Adversaries Target India’s Government & Defence Ecosystem
Analysis of the recent campaigns indicates a consistent and evolving attack lifecycle leveraging identity, access and automation to achieve strategic advantages.

TOP TRADECRAFT TRENDS

Threat actors are increasingly exploring AI-assisted capabilities, particularly for reconnaissance, phishing and social engineering. Broader operational use remains an emerging trend.
From Manual Operations to Intelligent, Automated and Scalable Attacks
Threat actors are increasingly exploring AI-assisted capabilities across the attack lifecycle, particularly in reconnaissance, phishing and social engineering.
RECONNAISSANCE
Manual OSINT collection and target profiling.
WEAPONIZATION
Generic phishing templates and manual crafting.
DELIVERY
Mass targeting with limited personalization.
EXPLOITATION
Exploitation attempts with known techniques.
OPERATIONS
Manual execution and limited automation.
IMPACT
Slower execution and higher detection risk.
AI-ASSISTED RECON
AI-driven OSINT, social graph analysis, deep profiling and pattern discovery.
INTELLIGENT WEAPONIZATION
AI-generated lures, deepfake content and content-aware payloads.
AUTOMATED DELIVERY
AI-optimized targeting, send-time optimization and multi-channel delivery.
AI-ASSISTED EXPLOITATION
AI may assist exploit research and code development.
AUTONOMOUS OPERATIONS
AI-assisted operational automation remains an emerging capability.
INTELLIGENT IMPACT
AI may assist data analysis and operational efficiency following compromise.
Current intelligence indicates that AI-assisted capabilities are primarily enhancing reconnaissance, phishing and content generation, while autonomous operations remain an emerging capability.
Primary Entry Vectors Targeting India’s Government & Defence Networks
Adversaries continue to exploit human trust, exposed services and identity weaknesses to gain initial foothold in targeted environments.

KEY OBSERVATIONS
Threat actors increasingly favour identity compromise over malware-based intrusion, combining phishing, credential abuse and trusted third-party access to achieve stealthier and more persistent initial access.
Evolution, Activity Trends & Targeting Patterns Across India’s Government Ecosystem
Ransomware operations targeting India’s Government ecosystem have evolved into high-impact, multi-extortion campaigns driven by data theft, operational disruption and public pressure.
RANSOMWARE ACTIVITY TRENDS IN INDIA (JAN-AUG 2026)

OBSERVED RANSOMWARE GROUPS TARGETING INDIAN ENTITIES

EXECUTIVE OBSERVATION
Ransomware activity increased sharply during the second half of the reporting period, rising from 9 observed incidents in April to 29 in August. The sustained increase from June onward indicates elevated ransomware activity and persistent operational pressure against Indian entities.
KEY TAKEAWAYS
Thegentlemen
Highest observed targeting activity, followed by krybit, sinobi and dragonforce.
Threat Ecosystem
A combination of established and emerging ransomware groups indicates a fragmented but highly active threat landscape.
Multi-Extortion
Data theft, leak sites and public pressure continue to amplify operational and reputational impact.
Figures represent ransomware activity observed by CYFIRMA during the January–August 2026 reporting period.
Ransomware is no longer limited to encryption. Modern operators increasingly combine credential theft, data exfiltration, multi-extortion and public exposure to maximise operational, financial and reputational pressure against government organisations.
What Adversaries Are Trying to Compromise in India’s Government Ecosystem
Adversaries focus on high-value assets that provide strategic advantage, operational leverage or indirect access to defence and government networks.

THREAT PRIORITY TIERING

KEY TAKEAWAY
Protecting high-value assets, identity infrastructure and the third-party ecosystem is essential to reducing exposure, operational disruption and strategic cyber risk across India’s Government & Defence sector.
Malware Enabling Initial Access, Persistence, Credential Theft and Data Exfiltration
Threat actors use a combination of commodity and custom malware to gain access, maintain persistence, steal credentials and exfiltrate sensitive government data.
MALWARE CAPABILITY FRAMEWORK

REPRESENTATIVE MALWARE & CAPABILITIES
| CAPABILITIES | MALWARE EXAMPLE | PRIMARY USE |
| Initial Access | DarkGate,LokiBot,
SmokeLoader,QokBot |
Deliver payloads and establish initial compromise |
| Persistence | PlugX, XWorm, Web Shell | Maintain long-term access and evade detection |
| Remote Access | Remcos RAT, AsyncRAT, Quasar RAT, Cobalt Strike | Remote control, lateral movement and command execution |
| Credential Theft | Lumma Stealer, RedLine Stealer | Steal credentials, browser data and session tokens |
| Data Exfiltration | Rclone, WinSCP, SFTP Tools | Transfer sensitive data to remote infrastructure |
KEY OBSERVATION
Rather than relying on a single malware family, adversaries employ modular toolsets tailored to campaign objectives, enabling stealthier, longer-duration and intelligence-driven operations.
Technologies Most Frequently Targeted to Gain Access and Maintain Control
Threat actors prioritise technology environments that deliver broad access, high privilege and persistent reach across government networks and critical systems.
| INTERNET EDGE
VPN Gateways, Firewalls, Secure Remote Access |
Commonly targeted by threat actors through the exploitation of vulnerabilities and configuration weaknesses. |
| IDENTITY INFRASTRUCTURE
Active Directory, Identity Federation, MFA Infrastructure |
Compromise of identity systems enables privilege escalation and access to critical resources. |
| COLLABORATION PLATFORMS
Email Systems, Microsoft 365, SharePoint, Teams |
Commonly targeted through phishing, credential theft and abuse of trusted user identities.. |
| PUBLIC-FACING APPLICATIONS
Citizen Portals, Government Services, Applications & APIs |
Internet-facing applications are continuously scanned and exploited to gain foothold in target environments. |
| ENTERPRISE INFRASTRUCTURE
Windows Servers, VMware, Hypervisors, Databases |
Commonly targeted through exploitation of vulnerabilities, identity compromise and configuration weaknesses. |
| CLOUD ENVIRONMENTS
Azure, AWS, Government Cloud, SaaS |
Threat actors commonly target cloud environments through identity compromise, exposed credentials and cloud misconfigurations. |
WHY THREAT ACTORS TARGET THESE TECHNOLOGIES
| ACCESS | These technologies provide the most direct paths into government networks. |
| PRIVILEGE | Compromising core platforms enables privilege escalation and domain-wide access. |
| PERSISTENCE | These environments offer multiple opportunities for long-term persistence. |
| DATA ACCESS | Access to sensitive data repositories and information systems is the ultimate objective. |
| OPERATIONAL IMPACT | Compromise can disrupt critical services and government operations. |
| STEALTH | These platforms are trusted, widely used and often poorly monitored. |
Strategic Cyber Incident Highlights Targeting India’s Government & Defence Ecosystem (Jan – Aug 2026)
The selected incidents demonstrate that nation-state espionage continued to shape the strategic threat environment, while ransomware operations and third-party compromises reinforced the evolving operational risk landscape.
KEY DATA EXPOSURE INCIDENT & CAMPAIGNS
PAKISTAN-ALIGNED ESPIONAGE CAMPAIGN (APT36 – TRANSPARENT TRIBE)
Targeting Indian Government & Strategic Institutions

Future Threat Outlook: What Adversaries Are Likely to Prioritize (H2 2026 – 2027)
Forward-looking intelligence assessment of key threat trends likely to shape the cyber risk landscape for India’s Government, Defence and critical infrastructure ecosystem.
01 . GOVERNMENT IDENTITY INFRASTRUCTURE
Likelihood: Very High
CYFIRMA assesses that identity platforms and privileged accounts are likely to remain primary targets for establishing persistent access across government environments.
02 . CRITICAL INFRASTRUCTURE
Likelihood: High
Current intelligence indicates that critical infrastructure and supporting supply chains are likely to remain attractive targets for sustained intelligence collection and strategic targeting.
03 . AI-ENABLED OPERATIONS
Likelihood: High
CYFIRMA assesses that AI-assisted capabilities are likely to increasingly support reconnaissance, phishing, malware development and large-scale social engineering campaigns.
04 . SUPPLY CHAIN TARGETING
Likelihood: High
Government contractors and trusted technology partners are likely to remain preferred pathways into protected government networks.
05. NATION-STATE ESPIONAGE
Likelihood: Very High
CYFIRMA assesses that state-aligned actors are likely to sustain long-term espionage campaigns targeting defence, government and strategic sectors.
06. SENSITIVE DATA THEFT
Likelihood: Medium to High
Current intelligence indicates that technical documentation, procurement data and internal communications are likely to remain priority intelligence collection objectives.
INTELLIGENCE INDICATORS TO WATCH

Executive Assessment of the Evolving Threat Environment
Synthesis of key observations from the threat landscape (Jan – Aug 2026) and their strategic implications for India’s Government & Defence Ecosystem.

EXECUTIVE INTELLIGENCE JUDGEMENT
The observed threat landscape reflects a structural evolution from isolated cyber incidents to persistent intelligence-driven campaigns. CYFIRMA assesses that future operations are likely to prioritise strategic access, information superiority and influence rather than immediate disruption, requiring government organisations to adopt an intelligence-led and resilience-focused security posture.
CYFIRMA further assesses that nation-state espionage is likely to remain the principal strategic cyber threat, while ransomware will continue to represent a significant but primarily operational risk.

Priority Focus Areas for Strengthening National Cyber Resilience
Strategic focus areas to build a secure, resilient and future-ready government and defence ecosystem.
01 . IDENTITY-CENTRIC SECURITY
Shift security investments towards protecting identities, privileged access and authentication infrastructure.
02. INTELLIGENCE-LED DEFENCE
Integrate cyber threat intelligence into strategic planning, risk management and operational decision-making.
03. SUPPLY CHAIN ASSURANCE
Strengthen security governance across contractors, technology providers and third-party ecosystems supporting government operations.
04. CRITICAL INFRASTRUCTURE PROTECTION
Enhance resilience of nationally significant infrastructure through continuous monitoring and risk-based security investments.
05. AI SECURITY READINESS
Develop governance, detection and response capabilities to address AI-enabled cyber operations.
06. STRATEGIC CYBER RESILIENCE
Build long-term organisational resilience through continuous assessment, coordinated response planning and executive oversight.
EXECUTIVE RECOMMENDATION
India’s evolving threat landscape requires a transition from reactive cybersecurity towards intelligence-led, resilience-driven cyber defence that integrates strategic risk management, supply chain assurance and continuous threat visibility across the government ecosystem.
Strategic Actions to Strengthen Government & Defence Cyber Resilience
A phased, actionable roadmap to enhance resilience, reduce risk and build long-term cyber strength across India’s Government & Defence ecosystem.

Observed Underground Activity Targeting India’s Government & Defence Ecosystem

EXECUTIVE INTELLIGENCE ASSESSMENT
Underground activity observed during the reporting period reinforces that government digital infrastructure and defence-related information remain attractive targets within cybercriminal and intelligence-focused communities. Dark web advertisements and forum posts should be treated as indicators of adversary interest or intent and do not independently confirm compromise, victim impact or the authenticity of the claimed material. They should be corroborated with additional intelligence before drawing operational conclusions.
Critical Intelligence Conclusions for Government & Defence Leadership

Final Intelligence Assessment
CYFIRMA assesses that India’s Government & Defence cyber threat landscape will remain dominated by persistent nation-state espionage, identity-focused intrusions and strategic targeting of critical infrastructure. While ransomware is likely to persist, it represents a significant operational risk, whereas state-aligned espionage remains the primary strategic threat. Organisations adopting intelligence-led security and stronger cyber resilience will be better positioned to counter evolving threats.