ADVERSARY UNMASKED APT QUARTERLY REPORT

Published On : 2026-10-08
Share :
ADVERSARY UNMASKED APT QUARTERLY REPORT

Executive Summary

Mostly long-running campaigns.

48 campaigns linked to the four nexuses were sighted in Q3, against at least 33 in Q2, and 21 were sighted in both. Only 3 were first seen in Q3. 21 were sighted in every month of the quarter.

China remains the largest nexus.

Chinese actors were linked to 27 campaigns (at least 22 in Q2). MISSION2074 (12) and Stone Panda (8) are again the most frequently linked actors, both stable against Q2.

North Korean activity rose late in the quarter.

Lazarus Group was linked to 14 campaigns (at least 9 in Q2), 9 of them attributed to it alone. September sightings (12) exceeded July and August (8 each), and one new campaign appeared in mid-September.

Russian activity is spread thin.

Russian actors were linked to 13 campaigns (at least 8 in Q2). Only Cozy Bear, FIN7 and FIN11 have a Q3 campaign attributed to them alone.

Iranian evidence is the weakest.

Iranian actors were linked to 4 campaigns. None is attributed to an Iranian actor alone, and one carries only North Korean tooling.

Heavy attribution overlap.

21 of 48 campaigns are linked to more than one actor, and 8 span more than one nexus. 7 of the 15 profiled actors have no Q3 campaign attributed to them alone (APT34, Fox Kitten, TA505, Fancy Bear, Gamaredon, Hafnium, Emissary Panda), so their technique, country, and industry lists include other actors’ data. Shared attribution reflects overlapping TTPs, shared tooling or indicator clustering, and is not evidence of collaboration.

Techniques.

Persistent backdoors were recorded in 17 of 48 campaigns, VPN, router, and edge-device exploitation in 9, financial trojans and botnets in 7, and RDP exposure and remote access implants in 6 each.

Geography.

Japan (41 campaigns) and the United States (39) were the most frequently recorded victim countries, followed by the United Kingdom (24), India (23), South Korea (22), and Australia (21).

What to do now.

Patch and integrity-check internet-facing edge devices, remove direct RDP and SSH exposure, enable EDR tamper protection, and deploy the August 2026 Windows update (CVE-2026-68820). The full prioritised list is in the Outlook section.

Overview

During the July–September 2026 reporting period, state-sponsored Advanced Persistent Threat (APT) groups from Iran, Russia, China, and North Korea, alongside Russian-speaking financially motivated cybercrime groups, continued to demonstrate sophisticated and evolving cyber capabilities through cyber espionage, credential theft, infrastructure exploitation, ransomware deployment, supply-chain compromise, and financially motivated operations. These threat actors leveraged internet-facing infrastructure, VPN and router vulnerabilities, persistent backdoors, remote-access trojans (RATs), legitimate administrative tools, and social-engineering techniques to establish long-term access, evade detection, and facilitate intelligence collection or financial gain. Their operations demonstrated a continued emphasis on exploiting enterprise technologies, cloud environments, and critical infrastructure across multiple geographic regions and industries. Assessments in this report draw on the CYFIRMA campaign database and on public reporting; where the database evidence is thin, the actor profile says so, and the confidence is rated accordingly.

Iranian threat actors, particularly APT34 (OilRig) and Fox Kitten, continued targeting government, energy, financial, telecommunications, healthcare, and critical infrastructure organisations through credential theft, vulnerability exploitation, persistent implants, and unauthorised network access.

Russia-linked actors, including the state-aligned Cozy Bear, Fancy Bear, and Gamaredon, and the financially motivated, Russian-speaking cybercrime groups FIN7, FIN11, and TA505, maintained operations against government, defence, financial, technology, and strategically significant organisations, combining cyber espionage, ransomware-enabled intrusions, destructive malware, infrastructure compromise, and intelligence collection.

Chinese threat actors, including MISSION2074, Stone Panda, Leviathan, Hafnium, TICK, and Emissary Panda, sustained espionage campaigns targeting government agencies, telecommunications providers, technology companies, transportation, and critical infrastructure, leveraging backdoors, VPN and router exploitation, web shells, credential theft, and post-exploitation frameworks to maintain persistent access.

Meanwhile, North Korean operators, particularly Lazarus Group, continued combining financially motivated cyberattacks with strategic espionage, targeting cryptocurrency platforms, financial institutions, defence, aerospace, and software development organisations through social engineering, fraudulent employment campaigns, supply-chain compromises, malware deployment, and vulnerability exploitation.

The reporting period showed continued convergence between cyber espionage, financial theft, ransomware operations, vulnerability exploitation, supply-chain compromise, and persistent access through cloud and edge infrastructure. The widespread targeting of interconnected enterprise environments across government, defence, telecommunications, financial services, technology, healthcare, energy, and critical infrastructure highlights the evolving operational capabilities and persistent risks associated with nation-state cyber actors. These developments underscore the importance of maintaining proactive threat intelligence capabilities, continuous vulnerability assessment, robust identity and access management, endpoint and network monitoring, supply-chain security, and comprehensive incident response preparedness to detect emerging threats and strengthen organisational cybersecurity resilience.

CROSS-NEXUS SUMMARY

Nexus Q3 campaigns Q2 campaigns (min) Sighted in both First seen in Q3 Linked to another nexus Attributed to this nexus only
Iran 4 2 2 1 3 1
Russia 13 8 7 0 4 9
China 27 22 14 1 6 21
North Korea 14 9 5 1 5 9
All four (distinct) 48 33 21 3 8 –

PROFILED ACTORS AT A GLANCE

Actor Nexus Score Severity Last IOC activity Q3 campaigns Q2 (min) Sole-attributed
APT34 (OilRig) Iran 9 Critical 26 Sep 2026 3 1 0
Fox Kitten Iran 8 High 13 Sep 2026 * 1 1 0
FIN7 Russia 9 Critical 23 Sep 2026 4 3 1
Cozy Bear Russia 9 Critical 29 Sep 2026 4 1 3
TA505 Russia 10 Critical 29 Sep 2026 3 3 0
Fancy Bear Russia 9 Critical 13 Sep 2026 * 3 1 0
FIN11 Russia 10 Critical 13 Sep 2026 * 2 3 1
Gamaredon Russia 9 Critical 29 Sep 2026 2 2 0
MISSION2074 China 10 Critical 13 Sep 2026 * 12 11 4
Stone Panda China 10 Critical 30 Sep 2026 8 9 3
Leviathan China 10 Critical 21 Sep 2026 3 1 1
Hafnium China 8 High 13 Sep 2026 * 2 2 0
TICK China 10 Critical 25 Sep 2026 2 1 2
Emissary Panda China 10 Critical 25 Sep 2026 3 2 0
Lazarus Group North Korea 10 Critical 29 Sep 2026 14 9 9

IRANIAN ADVERSARY ACTIVITIES

TECHNIQUES OBSERVED

Campaigns are sighted from July to September 2026 per inferred technique: 3 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures. Excludes one campaign recorded under OilRig that carries only North Korean tooling.

TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. All 9 recorded technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Excludes one campaign recorded under OilRig that carries only North Korean tooling.

IRANIAN ADVERSARY ACTIVITIES

TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 23 countries. Also recorded: Turkey, Spain, South Korea, Switzerland, Netherlands, Portugal, Italy, Belgium. Excludes one campaign recorded under OilRig that carries only North Korean tooling.

TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted. Excludes one campaign recorded under OilRig that carries only North Korean tooling.

DATABASE VIEW OF THE IRAN NEXUS, Q3 2026

  • Provenance. All four Iranian-linked campaigns are shared with actors from other nexuses or with MuddyWater. One, recorded under OilRig, carries only North Korean tooling (AppleJeus, NukeSped RAT, RustBucket, HLOADER, SUGARLOADER) and describes Lazarus Group tradecraft. It is excluded from the technique, country, and industry charts above and from the technique table below, which therefore cover three campaigns.
  • Activity. 4 campaigns in Q3 against at least 2 in Q2 (2 sighted in both). Sighted by month: July 3, August 2, September 3. 1 was sighted in every month, and 1 was first seen in Q3. Average campaign risk score: 9.0 out of 10.

Techniques mapped to MITRE ATT&CK

Technique (inferred) MITRE ATT&CK Campaigns Tooling or technology recorded
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services 2 Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, VPN solutions
Cryptomining T1496 Resource Hijacking 1 Cryptominer
Commodity malware staging T1105 Ingress Tool Transfer 1 unnamed commodity malware
Ransomware deployment T1486 Data Encrypted for Impact 1 INC Ransomware

APT34

During the period from July to September 2026, APT34 (OilRig) continued to demonstrate persistent espionage activity aligned with Iranian strategic interests, with targeting spanning government, energy, financial, telecommunications, chemical, technology, and critical infrastructure sectors. Public threat-intelligence reporting continued to associate the group with long-term intelligence collection and information theft, particularly against organisations in the Middle East and other strategically relevant regions. MITRE ATT&CK continued to track APT34 under the OilRig group designation, reflecting the consolidation of overlapping reporting and aliases associated with the actor.

The group continued to rely on credential theft, legitimate system utilities, PowerShell and other native operating-system capabilities, and covert command-and-control mechanisms to maintain access while reducing the visibility of its activities. DNS-based command-and-control and cloud- or internet-facing infrastructure have remained part of the broader APT34 tradecraft documented in threat-intelligence reporting. The group’s continued emphasis on intelligence collection, persistence, and discreet access rather than immediate disruption highlights the importance of monitoring authentication activity, unusual administrative operations, PowerShell execution, and anomalous outbound DNS or network communications.

Profile

Field Detail
Tracked as (CYFIRMA list) APT34
Selected aliases OilRig, Helix Kitten, Hazel Sandstorm (formerly EUROPIUM), Crambus, Chrysene
Alias caveats The CYFIRMA list also files MuddyWater, Seedworm, Lyceum, Scarred Manticore and UNC1860 under APT34. Most vendors track these as separate Iranian clusters, so they are not used as aliases here. The EW database holds APT34 and Oilrig as two names; both are counted under this profile.
Origin Iran (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage
Sponsorship (public attribution) MITRE ATT&CK (G0049) assesses that the group appears to work on behalf of the Iranian government. Agency-level attribution differs between sources.
CYFIRMA exposure score 9 of 10, Critical
Last IOC activity (CYFIRMA) 26 Sep 2026
EW database, Q3 2026 3 campaigns (APT34 2, Oilrig 1); Q2 at least 1. Sighted July 2, August 1, September 2; 1 first seen in Q3.
Attribution basis 0 of 3 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 9.4 (highest 10)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Thin, shared evidence base. All 3 Q3 campaigns are shared with other actors. None is attributed to APT34 or OilRig alone.
  • One new campaign. First seen on 15 July 2026 and co-attributed with MuddyWater. It added INC Ransomware, VPN exploitation, and European victims (Belgium, Italy, Portugal, Spain, Switzerland) that are new to the actor’s record.
  • Fortinet focus via a shared campaign. A long-running campaign shared with Hafnium and US17IRGCorp records Fortinet FortiOS, FortiProxy, and FortiSwitchManager across Gulf, European and North American victims.
  • Weak attribution on the third campaign. The campaign recorded under OilRig is also attributed to APT27 and Lazarus Group, and every tool recorded on it is North Korean (AppleJeus, NukeSped RAT, RustBucket, HLOADER, SUGARLOADER). It is excluded from the technique assessment below as Lazarus Group tradecraft.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, VPN, VPN solutions Shared campaigns only (3)
Commodity malware staging T1105 Ingress Tool Transfer unnamed commodity malware Shared campaigns only (2)
Ransomware deployment T1486 Data Encrypted for Impact INC Ransomware Shared campaign only (1)
PowerShell and native tooling T1059.001 Command and Scripting Interpreter: PowerShell Not recorded in the EW database Public reporting cited above
DNS-based command and control T1071.004 Application Layer Protocol: DNS Not recorded in the EW database Public reporting cited above
Credential theft T1003 OS Credential Dumping (typical procedure, not recorded per campaign) Not recorded in the EW database Public reporting cited above

Excluded as tooling of co-attributed actors: Trojanised cryptocurrency application; Loader / downloader staging; RAT / remote access implant.

What this means for you: APT34

  • Does this affect me? Most relevant to government, telecommunications, energy (oil and gas), and financial organisations in the Gulf states, Israel, Turkey, Western Europe, the UK, and the US.
  • How exposed am I? Exposure is highest where Fortinet FortiOS, FortiProxy, FortiSwitchManager, or other VPN gateways face the internet.
  • What should I do now? Confirm that Fortinet and VPN appliances are on fixed versions, and review their admin accounts and configuration changes since July. Hunt for DNS tunnelling and unusual outbound DNS volume. Treat INC Ransomware precursors (new remote-access tools, mass credential use) as high priority.

Fox Kitten

This profile is based on public reporting; the CYFIRMA campaign database holds only shared, low-confidence campaigns for this actor in Q3 (see below). During the period from July to September 2026, Fox Kitten (Pioneer Kitten/UNC757/Lemon Sandstorm) continued to represent a significant Iranian cyber threat, particularly through operations involving initial access, persistent network penetration, espionage, and access brokering. The group has been associated with targeting government, financial, healthcare, information technology, insurance, energy, telecommunications, manufacturing, defence, and critical infrastructure organisations across the Middle East, Europe, North America, Australia, and other regions.

The actor continued to demonstrate a strong preference for internet-facing infrastructure, particularly VPNs, firewalls, remote-access technologies, and other perimeter devices. Threat reporting also continued to document exploitation of known vulnerabilities in technologies such as Fortinet, Pulse Secure, Citrix, F5 BIG-IP, Ivanti, Check Point, and Palo Alto Networks to obtain or maintain access. Fox Kitten’s activity is notable for the overlap between espionage-oriented operations and the establishment or brokerage of network access that can subsequently be used by ransomware affiliates.

The group’s continued use of legitimate administrative tools, web shells, custom malware, compromised infrastructure, and vulnerability exploitation can make malicious activity difficult to distinguish from normal enterprise administration. Public reporting, including the August 2024 FBI and CISA advisory, characterises Fox Kitten as a hybrid threat actor whose operations can involve both intelligence collection and the monetisation or transfer of compromised access. This makes edge-device hardening, rapid vulnerability remediation, credential protection, network segmentation, and monitoring for unusual remote-access activity particularly important for organisations operating in sectors of strategic interest.

Field Detail
Tracked as (CYFIRMA list) Fox Kitten
Selected aliases Pioneer Kitten, UNC757, Lemon Sandstorm, RUBIDIUM, Parisite
Origin Iran (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Initial access and espionage, with access sold or passed to ransomware affiliates
Sponsorship (public attribution) An FBI and CISA joint advisory (August 2024) describes the actors as Iran-based and associated with the Government of Iran.
CYFIRMA exposure score 8 of 10, High
Last IOC activity (CYFIRMA) 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal)
EW database, Q3 2026 1 campaign; Q2 at least 1. Sighted July 1, August 1, September 1; none first seen in Q3.
Attribution basis 0 of 1 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Cryptomining T1496 Resource Hijacking Cryptominer Shared campaign only (1)
Exploitation of VPNs, firewalls and other perimeter devices T1190 Exploit Public-Facing Application; T1133 External Remote Services Not recorded in the EW database Public reporting cited above
Web shells on compromised servers T1505.003 Server Software Component: Web Shell Not recorded in the EW database Public reporting cited above
Use of legitimate administrative tools T1219 Remote Access Software Not recorded in the EW database Public reporting cited above

What this means for you: Fox Kitten

Does this affect me? Recorded victims are in Germany, Japan, Saudi Arabia, Ukraine, the UAE, the UK, and the US, across telecommunications, IT, government, finance, and defence.

How exposed am I? Database evidence is too thin to rate exposure. Public reporting points to internet-facing Fortinet, Pulse Secure, Citrix, F5, Ivanti, Check Point, and Palo Alto devices.

What should I do now? Prioritise patching and log review on those perimeter products. Treat unexpected crypto mining on servers as a possible sign of wider compromise, not a nuisance.

RUSSIAN ADVERSARY ACTIVITIES

TECHNIQUES OBSERVED

Campaigns sighted from July to September 2026 per inferred technique: 13 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures.

TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. Top 15 of 28 technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Also recorded: PHP, PHPUnit, phpMyAdmin, SMTP, Squid Proxy, ThinkPHP, vBulletin, Voice over IP (VoIP), Weaver E-cology, Web Application Servers, WebDAV, WordPress, Zhiyuan Collaborative Office.

TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 27 countries. Also recorded: Indonesia, Philippines, Ukraine, Brunei, Belgium, Cambodia, Myanmar, Laos, Timor-Leste, United Arab Emirates, Morocco, Hungary

TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted.

DATABASE VIEW OF THE RUSSIA NEXUS, Q3 2026

  • Activity: 13 campaigns in Q3 against at least 8 in Q2 (7 sighted in both). Sighted by month: July 8, August 11, September 11. 7 were sighted in every month, and none were first seen in Q3. Average campaign risk score: 8.0 out of 10.
  • Split by motivation. Financially motivated groups (FIN7, FIN11, TA505) and state-linked groups (Cozy Bear, Fancy Bear, Gamaredon, plus Turla Group and Dragonfly as co-attributed actors) appear in similar numbers. Several campaigns link both kinds of actors; this is consistent with overlapping indicators and is not treated as evidence of cooperation.

Techniques mapped to MITRE ATT&CK

Technique (inferred) MITRE ATT&CK Campaigns Tooling or technology recorded
Persistent backdoor implant T1071 Application Layer Protocol (C2) 5 CivetQ, CosmicDuke, LODEINFO, MiniDuke, flipflop, freshfire
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer 3 Dridex, TrickBot, Zeus (Zbot)
Ransomware deployment T1486 Data Encrypted for Impact 3 Cl0p, Ryuk, Sodinokibi (REvil)
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services 2 RDP
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer 2 FlawedAmmyy RAT
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection 2 Cobalt Strike
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application 1 Apache Tomcat Manager, Drupal, Jira, Jira Server and Data Center, Joomla!, phpMyAdmin and 6 more
Webshell deployment T1505.003 Server Software Component: Web Shell 1 DEWMODE
Cryptomining T1496 Resource Hijacking 1 Cryptominer
EDR / security tool tampering T1562.001 Impair Defenses: Disable or Modify Tools 1 AuKill

FIN7

During the period from July to September 2026, FIN7, a financially motivated, Russian-speaking cybercrime group, continued to demonstrate a broad and adaptable operational profile, conducting financially motivated intrusions against organisations across financial services, government, transportation, aerospace, retail, technology, and industrial sectors. Threat-intelligence reporting for 2026 indicates that the group expanded its geographic reach across Asia, Europe, and North America, while continuing to combine established financially motivated operations with more advanced network intrusion capabilities. Campaigns involved exploitation of internet-facing infrastructure, remote-access services, and enterprise systems to establish persistence and facilitate follow-on activity.

The group continued to leverage a combination of credential theft, ransomware, malware deployment, and lateral movement to increase the impact of compromises. Reported toolsets associated with FIN7 included ransomware families and custom malware, demonstrating continued diversification of its post-compromise operations. FIN7’s presence across multiple sectors during the period highlights its ability to adapt its targeting and operational methods according to available opportunities, making monitoring of exposed remote-access infrastructure, authentication activity, and unusual lateral movement particularly important.

Profile

Field Detail
Tracked as (CYFIRMA list) FIN7
Selected aliases Carbon Spider, Sangria Tempest, ELBRUS, GrayAlpha (Carbanak is sometimes tracked as a separate group)
Origin Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Financial
Sponsorship (public attribution) None established. Financially motivated, Russian-speaking criminal group; several members have been prosecuted in the US since 2018.
CYFIRMA exposure score 9 of 10, Critical
Last IOC activity (CYFIRMA) 23 Sep 2026
EW database, Q3 2026 4 campaigns; Q2 at least 3. Sighted July 3, August 3, September 4; none first seen in Q3.
Attribution basis 1 of 4 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels None identified in the data reviewed; public reporting describes affiliate recruitment and data-leak-site extortion.

Recent activity and shifts

  • Stable activity. 4 campaigns in Q3 against at least 3 in Q2, and 3 of the 4 were sighted in every month.
  • Ransomware through remote access. The one campaign attributed to FIN7 alone records Sodinokibi (REvil) ransomware with RDP and SSH exposure, against victims in Japan, Singapore, South Korea, Thailand, and the US.
  • Overlap with Lazarus Group. Two campaigns are co-attributed to Lazarus Group (AuKill EDR killer, CivetQ, Dridex). This reflects overlapping indicators, not evidence of cooperation.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer Dridex Shared campaign only (1)
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services RDP 1 sole-attributed campaign
Ransomware deployment T1486 Data Encrypted for Impact Sodinokibi (REvil) 1 sole-attributed campaign
EDR / security tool tampering T1562.001 Impair Defenses: Disable or Modify Tools AuKill Shared campaign only (1)
Persistent backdoor implant T1071 Application Layer Protocol (C2) CivetQ Shared campaign only (1)
Credential theft and lateral movement T1078 Valid Accounts; T1021 Remote Services Not recorded in the EW database Public reporting cited above

What this means for you: FIN7

  • Does this affect me? Victims cluster in the US, Japan, South Korea, and the UK, in IT, government, transport, and finance.
  • How exposed am I? Highest for organisations with RDP or SSH reachable from the internet and endpoint protection that can be switched off by a local administrator.
  • What should I do now? Remove direct RDP exposure, enforce MFA on remote access, and enable EDR tamper protection and vulnerable-driver blocking to counter AuKill-style tooling.

COZY BEAR

During the period from July to September 2026, Cozy Bear (APT29/Midnight Blizzard) continued to conduct sophisticated cyber-espionage operations focused primarily on government, diplomatic, defence, technology, healthcare, and strategically important organisations. On 31 July 2026, Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign active since early May 2026 that it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard. Compromised captive-portal gateways at hotels, conference centres, and similar venues were used to manipulate DNS and HTTP traffic and redirect guests to fake update pages, Microsoft 365 credential-harvesting pages, and device-code phishing, with the CornFlake remote-access trojan among the payloads delivered. The activity affected travelers across a broad range of sectors, demonstrating the group’s continued interest in intelligence collection through unconventional access points; the Storm-2945 link is Microsoft’s own assessment and had not been independently corroborated at the time of writing.

The threat actor continued to rely on credential theft, OAuth and identity-focused attacks, compromised infrastructure, DNS manipulation, and persistent access techniques to obtain valuable information while attempting to blend malicious activity with legitimate network operations. Anthropic’s September 2026 threat intelligence report, describing a cluster tracked as GTG-20006 that it assessed as consistent with public reporting on Midnight Blizzard (APT29) and active from roughly December 2025 through August 2026, linked the group to attempts to compromise more than 20 organisations, largely in Europe and Ukraine, including government ministries, defence bodies, embassies, think tanks, and companies in the military drone supply chain. The group’s continued focus on identity, cloud services, and third-party infrastructure demonstrates the importance of monitoring authentication anomalies, captive-portal environments, DNS changes, and unusual access to cloud-based accounts.

Profile

Field Detail
Tracked as (CYFIRMA list) Cozy Bear
Selected aliases APT29, Midnight Blizzard (formerly NOBELIUM), The Dukes, UNC2452, Cloaked Ursa, BlueBravo
Origin Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage
Sponsorship (public attribution) Russian Foreign Intelligence Service (SVR), per US and UK government attribution (April 2021).
CYFIRMA exposure score 9 of 10, Critical
Last IOC activity (CYFIRMA) 29 Sep 2026
EW database, Q3 2026 4 campaigns; Q2 at least 1. Sighted July 3, August 3, September 3; none first seen in Q3.
Attribution basis 3 of 4 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Most self-contained Russian profile. 3 of 4 Q3 campaigns are attributed to Cozy Bear alone, the strongest attribution base among the Russian actors profiled.
  • Rise against a low baseline. 4 campaigns in Q3 against at least 1 in Q2. The Q2 figure is a minimum, so the size of the increase is uncertain.
  • Established tooling. Sole-attributed campaigns record MiniDuke, CosmicDuke, Cobalt Strike, and two families recorded as flipflop and freshfire. No tooling is new to the actor’s record.
  • Odd entry. TrickBot appears on a sole-attributed campaign. It is a criminal botnet rarely linked to SVR operations and may reflect clustering in the source data.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Persistent backdoor implant T1071 Application Layer Protocol (C2) CosmicDuke, MiniDuke, flipflop, freshfire 2 sole-attributed campaigns, 1 shared
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer TrickBot, Zeus (Zbot) 1 sole-attributed campaign, 1 shared
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection Cobalt Strike 2 sole-attributed campaigns
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer FlawedAmmyy RAT Shared campaign only (1)
Device-code phishing and Microsoft 365 credential harvesting T1566 Phishing; T1528 Steal Application Access Token Not recorded in the EW database Public reporting cited above
DNS and HTTP manipulation through compromised captive portals T1557 Adversary-in-the-Middle Not recorded in the EW database Public reporting cited above
Fake update pages delivering the CornFlake RAT T1204.002 User Execution: Malicious File Not recorded in the EW database Public reporting cited above

What this means for you: Cozy Bear

  • Does this affect me? Recorded victims are concentrated in the US, Japan, Germany, and the UK, plus Southeast Asia, with professional services, healthcare, and finance being the most frequent.
  • How exposed am I? Exposure is driven by identity: travelling staff, Microsoft 365 tenants that allow device-code sign-in, and weak monitoring of OAuth consent.
  • What should I do now? Block device-code flow where it is not needed, alert on new OAuth app consents and token use from unfamiliar locations, and brief travelling staff on fake update prompts on hotel and conference networks.

TA505

During the period from July to September 2026, TA505, a financially motivated, Russian-speaking cybercrime group, maintained a consistent operational presence, targeting organisations across financial services, government, telecommunications, technology, and other enterprise sectors in North America, Europe, the Middle East, and Asia-Pacific. Threat-intelligence reporting for 2026 indicates that TA505 continued to operate through financially motivated campaigns involving persistent access, malware delivery, and ransomware-related activity. The group demonstrated continued interest in enterprise applications, operating systems, databases, and internet-facing services as potential entry points into victim environments.

The group continued to employ backdoors, ransomware delivery mechanisms, credential theft, and post-compromise activity to establish and maintain access. Campaign reporting associated TA505 with malware and ransomware operations, including Cl0p and FlawedAmmyy RAT, reflecting its continued ability to adapt its tooling to changing defensive environments. Its sustained targeting across multiple industries and regions demonstrates a persistent financially motivated threat, particularly for organisations with exposed enterprise applications and externally accessible infrastructure.

Profile

Field Detail
Tracked as (CYFIRMA list) TA505
Selected aliases Graceful Spider, Gold Tahoe, Hive0065, SectorJ04, Chimborazo; Microsoft’s Lace Tempest overlaps TA505 and FIN11
Alias caveats The CYFIRMA list files Evil Corp and Silence Group under TA505. Both are tracked as separate groups by most vendors.
Origin Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Financial (ransomware and data-theft extortion)
Sponsorship (public attribution) None established.
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 29 Sep 2026
EW database, Q3 2026 3 campaigns; Q2 at least 3. Sighted July 3, August 2, September 2; none first seen in Q3.
Attribution basis 0 of 3 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels None identified in the data reviewed; public reporting describes affiliate recruitment and data-leak-site extortion.

Recent activity and shifts

  • No sole-attributed campaigns. All 3 Q3 campaigns are shared: one with Cozy Bear and Fancy Bear, one with Stone Panda, one with FIN7, FIN11, and Gamaredon.
  • Mixed tooling. Cl0p and FlawedAmmyy RAT fit TA505’s public profile. CosmicDuke (Dukes) and LODEINFO (APT10) come from the co-attributed actors and should not be read as TA505 tooling.
  • Stable count. 3 campaigns in Q3 and at least 3 in Q2.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer Zeus (Zbot) Shared campaign only (1)
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer FlawedAmmyy RAT Shared campaign only (1)
Ransomware deployment T1486 Data Encrypted for Impact Clop Shared campaign only (1)
Mass exploitation of file-transfer software for data theft T1190 Exploit Public-Facing Application; T1567 Exfiltration Over Web Service Not recorded in the EW database Public reporting cited above

What this means for you: TA505

  • Does this affect me? Finance is the most frequent sector across its campaigns, with victims across Asia-Pacific, North America, and Europe.
  • How exposed am I? Highest for organisations running internet-facing file-transfer or database-backed enterprise applications.
  • What should I do now? Patch and restrict internet-facing file-transfer systems, monitor for large outbound transfers, and keep offline backups tested against Cl0p-style encryption and extortion.

FANCY BEAR

During the period from July to September 2026, Fancy Bear (APT28) continued to conduct intelligence-driven cyber operations against government agencies, defence organisations, political institutions, and other strategically significant targets, particularly in Ukraine and Europe. Reporting published shortly before the period, and still the most recent public account of the group’s tradecraft, includes the group’s GRU-linked router-hijacking operation, detailed in 7 April 2026 advisories from the FBI and NSA with international partners and, separately, the UK NCSC, in which internet-facing SOHO routers (including TP-Link devices via CVE-2023-50224) were compromised to alter DNS settings, redirect traffic, and harvest credentials and OAuth tokens; the FBI announced a court-authorised disruption of the router network on the same day. A long-running campaign against Ukrainian anti-corruption and prosecutorial bodies, reported in April 2026 by Ctrl-Alt-Intel and described by Ukraine’s SSSCIP as consistent with APT28, was also reported in April 2026 and is consistent with the group’s established targeting, demonstrating the group’s continued focus on obtaining politically and strategically valuable information.

The threat actor continued to leverage vulnerability exploitation, compromised network infrastructure, malicious documents, credential theft, and traffic redirection to obtain access and collect intelligence. Earlier exploitation of vulnerabilities in Microsoft Office and other externally exposed technologies illustrates the group’s continued preference for exploiting weaknesses in commonly deployed enterprise technologies. Fancy Bear’s combination of infrastructure compromise and targeted spear-phishing continues to make monitoring of vulnerable edge devices, email infrastructure, authentication events, and suspicious network-routing changes important for organisations operating in strategically sensitive sectors.

Profile

Field Detail
Tracked as (CYFIRMA list) Fancy Bear
Selected aliases APT28, Forest Blizzard (formerly STRONTIUM), Sofacy, Sednit, Pawn Storm, BlueDelta, Fighting Ursa, Unit 26165
Alias caveats The CYFIRMA list includes Unit 74455, which is the GRU unit linked to Sandworm, not APT28. UAC-0063 and TAG-110 are tracked as separate clusters that some vendors associate with APT28.
Origin Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage and influence operations
Sponsorship (public attribution) Russian military intelligence (GRU) Unit 26165, per US DOJ indictment (July 2018) and the April 2026 FBI and NSA advisory.
CYFIRMA exposure score 9 of 10, Critical
Last IOC activity (CYFIRMA) 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal)
EW database, Q3 2026 3 campaigns; Q2 at least 1. Sighted July 1, August 2, September 1; none first seen in Q3.
Attribution basis 0 of 3 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • All shared. 3 Q3 campaigns, co-attributed with Dragonfly, Turla Group, and Cozy Bear, with TA505, respectively.
  • Opportunistic exploitation set. One shared campaign lists ThinkPHP, Drupal, Jira, Joomla, PHPUnit, vBulletin, Apache Tomcat Manager, and Chinese office suites. That pattern matches broad scanning more than APT28’s targeted operations.
  • Sectors. Energy and utilities, and materials, are the most frequent sectors across its Q3 campaigns.
  • Timing of external events. The router-hijacking advisory and the Ukrainian prosecutor targeting cited above were both reported in April 2026, before the reporting period.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application Apache Tomcat Manager, Drupal, Jira, Jira Server and Data Center, Joomla!, phpMyAdmin and 6 more Shared campaign only (1)
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services RDP Shared campaign only (1)
SOHO router compromise (TP-Link, CVE-2023-50224) and Roundcube exploitation T1190 Exploit Public-Facing Application Not recorded in the EW database Public reporting cited above
DNS redirection to harvest passwords and tokens T1557 Adversary-in-the-Middle Not recorded in the EW database Public reporting cited above
Malicious documents T1566.001 Phishing: Spearphishing Attachment Not recorded in the EW database Public reporting cited above

Excluded as tooling of co-attributed actors: Persistent backdoor implant; Financial trojan / botnet distribution; RAT / remote access implant.

What this means for you: Fancy Bear

  • Does this affect me? Recorded victims are in South Korea, the US, Australia, Japan, and Canada. Public reporting centres on Ukraine and Europe.
  • How exposed am I? Highest where staff use unmanaged home or small-office routers, and where webmail such as Roundcube is internet-facing.
  • What should I do now? Replace end-of-life SOHO routers used by remote staff, monitor for DNS resolver changes, and patch internet-facing webmail.

FIN11

During the period from July to September 2026, FIN11, a financially motivated, Russian-speaking cybercrime group, continued to demonstrate a persistent, financially motivated intrusion capability, targeting financial institutions, government organisations, industrial enterprises, telecommunications providers, technology companies, and critical infrastructure. Reporting for 2026 indicates that the group maintained a strong focus on ransomware-enabled compromises while also conducting intelligence gathering and network reconnaissance to maximise the value of compromised environments. The actor was observed across multiple geographic regions, reflecting a broad enterprise-targeting strategy rather than concentration on a single country or sector.

The group continued to employ VPN exploitation, credential theft, remote-access tools, network reconnaissance, lateral movement, and ransomware during post-compromise operations. Reported malware families and capabilities included Clop, FlawedAmmyy RAT, and DEWMODE, demonstrating a focused but adaptable operational toolkit. FIN11’s continued combination of access acquisition, persistence, data theft, and ransomware deployment indicates that organisations should closely monitor externally exposed remote-access technologies and unusual authentication, administrative, and lateral-movement activity.

Profile

Field Detail
Tracked as (CYFIRMA list) FIN11
Selected aliases TEMP.Warlock; Lace Tempest (Microsoft, overlaps TA505)
Origin Global (CYFIRMA list); Russia, ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Financial (ransomware and data-theft extortion)
Sponsorship (public attribution) None established.
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal)
EW database, Q3 2026 2 campaigns; Q2 at least 3. Sighted July 1, August 2, September 2; none first seen in Q3.
Attribution basis 1 of 2 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels None identified in the data reviewed; public reporting describes affiliate recruitment and data-leak-site extortion.

Recent activity and shifts

  • Clear financial-sector focus. The campaign attributed to FIN11 alone records Clop, Ryuk, DEWMODE web shells, and FlawedAmmyy RAT against banks and financial services in India, Japan, South Korea, the UK, and the US.
  • Lower count. 2 campaigns in Q3 against at least 3 in Q2. With the Q2 undercount, this is best read as flat.
  • Ryuk is unusual. Ryuk is more often linked to Wizard Spider; its presence may reflect shared affiliates or clustering in the source.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer FlawedAmmyy RAT 1 sole-attributed campaign
Webshell deployment T1505.003 Server Software Component: Web Shell DEWMODE 1 sole-attributed campaign
Ransomware deployment T1486 Data Encrypted for Impact Clop, Ryuk 1 sole-attributed campaign
VPN exploitation and lateral movement T1133 External Remote Services; T1021 Remote Services Not recorded in the EW database Public reporting cited above

What this means for you: FIN11

  • Does this affect me? Banks and diversified financial services, mainly in the US, UK, Japan, South Korea, and India.
  • How exposed am I? Highest for organisations with internet-facing file-transfer or web applications where DEWMODE-style web shells can be planted.
  • What should I do now? Hunt for unexpected web-shell files and new server-side scripts on file-transfer hosts, and confirm ransomware recovery plans cover data-theft extortion as well as encryption.

GAMAREDON

This profile is based on public reporting; the CYFIRMA campaign database holds only shared, low-confidence campaigns for this actor in Q3 (see below). During the period from July to September 2026, Gamaredon continued to conduct persistent cyber-espionage activity primarily against government and military organisations in Ukraine, while maintaining a strong focus on information collection and long-term access. In June 2026, Sekoia documented Gamaredon, an FSB-linked group, delivering the GammaWorm and GammaSteel tools through booby-trapped RAR archives that abused a WinRAR flaw (CVE-2025-8088), and ESET’s 25 June 2026 report on the group’s 2025 activity described new PowerShell tooling, a growing reliance on legitimate third-party services to hide command-and-control and stolen data, and a continued focus solely on Ukraine. Spear-phishing lures themed on military and legal communications, such as troop-movement and court-summons themes, illustrate the group’s continued use of highly contextualised social-engineering lures.

Profile

Field Detail
Tracked as (CYFIRMA list) Gamaredon
Selected aliases Primitive Bear, Shuckworm, Armageddon, Trident Ursa, Actinium, UAC-0010, Iron Tilden
Origin Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage
Sponsorship (public attribution) Russian Federal Security Service (FSB), per Security Service of Ukraine attribution (November 2021).
CYFIRMA exposure score 9 of 10, Critical
Last IOC activity (CYFIRMA) 29 Sep 2026
EW database, Q3 2026 2 campaigns; Q2 at least 2. Sighted July 2, August 2, September 2; none first seen in Q3.
Attribution basis 0 of 2 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Database profile conflicts with public reporting. Both Q3 campaigns are shared (with Fox Kitten, Emissary Panda and Transparent Tribe, and with FIN7, FIN11 and TA505). The only tool recorded is a cryptominer, and victims include Japan, the US, and Singapore. ESET reports the group targeted only Ukraine in 2025.
  • Low confidence. The Gamaredon attribution on these campaigns is weak. The narrative above relies on external reporting and should be presented that way.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Spear phishing with RAR archives exploiting WinRAR CVE-2025-8088 T1566.001 Spear phishing Attachment; T1203 Exploitation for Client Execution Not recorded in the EW database Public reporting cited above
PowerShell tooling T1059.001 Command and Scripting Interpreter: PowerShell Not recorded in the EW database Public reporting cited above
Legitimate web services for command and control and exfiltration T1102 Web Service; T1567 Exfiltration Over Web Service Not recorded in the EW database Public reporting cited above

What this means for you: Gamaredon

  • Does this affect me? Mainly organisations with operations, staff, or suppliers in Ukraine, particularly government, defence, and legal bodies.
  • How exposed am I? Highest where WinRAR is unpatched, and mail filtering allows archives inside HTML or XHTML attachments.
  • What should I do now? Update WinRAR beyond the CVE-2025-8088 fix, block archive-in-HTML attachments, and alert on PowerShell launched from archive extraction paths.

CHINESE ADVERSARY ACTIVITIES

TECHNIQUES OBSERVED

Campaigns sighted July to September 2026 per inferred technique: 27 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures.

TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. Top 15 of 48 technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Also recorded: Remote desktop software, Routers, Atlassian Confluence, Citrix NetScaler ADC, Citrix NetScaler Gateway, Cloud Migration Services, Content Delivery Networks, Content Management System, Dropbox, File Hosting System, Firewall management software, Firewall software, Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, Go, GitHub, Internet-facing Web Applications, Ivanti Connect Secure, Ivanti Policy Secure, Java, Microsoft .NET Framework, Microsoft Exchange Server, Network Monitoring Tools, Perl, PowerShell, Server Message Block (SMB), SQL Server Performance Monitoring Tools, TOR, Transportation & Logistics Software, USAHerds, VMware vCenter Server, Windows Management Instrumentation (WMI).

TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 47 countries. Also recorded: Italy, Malaysia, Netherlands, Vietnam, Spain, Cambodia, Oman, Israel, Turkey, Qatar, China, Norway, Indonesia, New Zealand, Brazil, Ukraine, Cyprus, Kuwait, Iraq, Syria, Yemen, Iran, Lebanon, Bahrain, Jordan, Egypt, Austria, South Africa, Argentina, Macao, Switzerland, Belgium.

TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted.

DATABASE VIEW OF THE CHINA NEXUS, Q3 2026

  • Activity. 27 campaigns in Q3 against at least 22 in Q2 (14 sighted in both). Sighted by month: July 18, August 21, September 23. 13 were sighted in every month, and 1 was first seen in Q3. Average campaign risk score: 8.4 out of 10.
  • Edge devices. VPN, router, and edge-device exploitation is recorded in 8 of 27 Chinese-linked campaigns, with Ivanti Connect Secure and Policy Secure, Citrix NetScaler ADC and Gateway, Fortinet FortiOS, FortiProxy and FortiSwitchManager, VMware vCenter, and firewall management software named. Named products entered the data with the September 2026 export enrichment, so they cannot be compared with earlier quarters.

Techniques mapped to MITRE ATT&CK

Technique (inferred) MITRE ATT&CK Campaigns Tooling or technology recorded
Persistent backdoor implant T1071 Application Layer Protocol (C2) 13 BLACKCOFFEE, LODEINFO, PlugX, ShadowPad, Volt (as recorded), Winnti and 3 more
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services 8 Citrix NetScaler ADC, Citrix NetScaler Gateway, firewall management software, firewall software, Fortinet FortiOS, Fortinet FortiProxy and 7 more
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services 4 RDP, remote desktop software
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection 3 Cobalt Strike
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer 3 NukeSped RAT, gh0st RAT
Loader / downloader staging T1105 Ingress Tool Transfer 3 HLOADER, MultiPlug, PubLoad, RustBucket, SUGARLOADER
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application 3 Apache Log4j, Atlassian Confluence, Microsoft Exchange Server, USAHerds, VMware vCenter Server
IoT botnet exploitation (Mirai) T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service 2 Mirai
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer 2 Emotet, TrickBot
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie 2 Azorult, FormBook, RedLine Stealer
Commodity malware staging T1105 Ingress Tool Transfer 2 unnamed commodity malware, FlyStudio
Firmware-level implant T1542.001 Pre-OS Boot: System Firmware 1 MoonBounce
Privilege escalation tooling T1134.001 Access Token Manipulation: Token Impersonation/Theft 1 Bad Potato
Webshell deployment T1505.003 Server Software Component: Web Shell 1 ASPXSpy
Cryptomining T1496 Resource Hijacking 1 Cryptominer
Ransomware deployment T1486 Data Encrypted for Impact 1 Clop
Trojanised cryptocurrency application T1204.002 User Execution: Malicious File 1 AppleJeus

MISSION2074

During the period from July to September 2026, MISSION2074 continued to demonstrate sustained cyber-espionage activity targeting government, telecommunications, transportation, energy, technology, healthcare, and critical infrastructure organisations across Europe, North America, the Middle East, and Asia-Pacific. The group leveraged persistent backdoors, remote-access trojans, VPN and router exploitation, and post-exploitation frameworks to establish and maintain access within targeted environments. MISSION2074 was the most frequently linked China-nexus actor in the CYFIRMA campaign database this quarter (12 campaigns), with IT, government, and professional services the most frequently recorded sectors.

The threat actor continued to employ credential theft, reconnaissance, lateral movement, remote desktop abuse, and data exfiltration while using legitimate network infrastructure and commonly deployed enterprise technologies to reduce detection. Malware families observed across campaigns tracked under this CYFIRMA-designated cluster included PlugX, Sidewalk, Winnti, and Zingdoor, alongside families more commonly associated with other actors or with commodity botnets, such as NukeSped (Lazarus), LODEINFO (APT10/MirrorFace), and Mirai; these overlaps point to shared or aggregated tooling rather than exclusive attribution, and supported persistence and intelligence collection. MISSION2074’s sustained targeting of organisations involved in communications, technology, transportation, and critical infrastructure indicates a continued emphasis on obtaining strategic intelligence and maintaining long-term access rather than conducting immediately disruptive operations.

Profile

Field Detail
Tracked as (CYFIRMA list) MISSION2025 (CYFIRMA list); MISSION2074 (EW database, used in this report)
Selected aliases APT41, Brass Typhoon (formerly BARIUM), Wicked Panda, Earth Baku, Double Dragon
Alias caveats The CYFIRMA list names this actor MISSION2025 and merges several APT41 sub-clusters under it (Earth Longzhi, Grayfly, Blackfly, RedGolf, SparklingGoblin). “Winnti” is used both as a group name and as a malware family shared by many China-nexus actors.
Origin China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage, with financially motivated activity
Sponsorship (public attribution) US DOJ indictments (September 2020) charged individuals linked to the activity, some associated with Chengdu 404 Network Technology.
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal)
EW database, Q3 2026 12 campaigns; Q2 at least 11. Sighted July 7, August 10, September 9; 1 first seen in Q3.
Attribution basis 4 of 12 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.5 (highest 10)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Most active China-nexus actor. 12 Q3 campaigns against at least 11 in Q2, so activity is stable at a high level. 4 are attributed to MISSION2074 alone.
  • One new campaign. First seen on 4 July 2026, recording Winnti, ShadowPad and Mirai against firewall, CDN and logistics software in India, Japan and the Philippines.
  • Backdoors dominate. Persistent backdoors (Winnti, ShadowPad, PlugX) appear in 8 of 12 campaigns.
  • Named edge products. Ivanti Connect Secure and Policy Secure, VMware vCenter and Apache Log4j appear for the first time in the actor’s record. These named products arrived with the September 2026 export enrichment, so this is a change in data detail, not necessarily in behaviour.
  • Wide overlap. 8 campaigns are shared, including two with Lazarus Group and one recorded against six actors.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Persistent backdoor implant T1071 Application Layer Protocol (C2) PlugX, ShadowPad, Volt (as recorded), Winnti, Winnti for Linux, Winnti for Windows and 1 more 3 sole-attributed campaigns, 5 shared
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services firewall management software, firewall software, Ivanti Connect Secure, Ivanti Policy Secure, routers, VPN solutions 1 sole-attributed campaign, 2 shared
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services RDP 2 sole-attributed campaigns
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application Apache Log4j, USAHerds, VMware vCenter Server 1 sole-attributed campaign, 1 shared
IoT botnet exploitation (Mirai) T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service Mirai 1 sole-attributed campaign, 1 shared
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection Cobalt Strike 1 sole-attributed campaign, 1 shared
Firmware-level implant T1542.001 Pre-OS Boot: System Firmware MoonBounce Shared campaign only (1)
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie Azorult, RedLine Stealer Shared campaign only (1)
Commodity malware staging T1105 Ingress Tool Transfer FlyStudio Shared campaign only (1)
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer TrickBot Shared campaign only (1)
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer NukeSped RAT Shared campaign only (1)
Privilege escalation tooling T1134.001 Access Token Manipulation: Token Impersonation/Theft Bad Potato 1 sole-attributed campaign

What this means for you: MISSION2074

  • Does this affect me? Japan, the US, the UK, India, Germany, Taiwan, and Australia lead. Professional services, telecommunications, IT and finance are the most frequent sectors.
  • How exposed am I? Highest for organisations running Ivanti Connect Secure or Policy Secure, VMware vCenter, Log4j-dependent applications, or internet-facing RDP.
  • What should I do now? Patch and integrity-check Ivanti and vCenter, hunt for DLL side-loading consistent with ShadowPad and PlugX, and look for Cobalt Strike beacons and token-impersonation tools (Bad Potato) on servers.

STONE PANDA

STONE PANDA

During the period from July to September 2026, Stone Panda (APT10/menuPass) continued to demonstrate persistent cyber-espionage activity against government agencies, financial institutions, telecommunications providers, technology organisations, and critical infrastructure across North America, Europe, and the Asia-Pacific region. The group leveraged VPN and router exploitation, web shells, persistent backdoors, remote-access trojans, and post-exploitation frameworks to establish footholds and maintain long-term access. Stone Panda was the second most frequently linked China-nexus actor in the CYFIRMA campaign database this quarter (8 campaigns), with professional services, manufacturing, telecommunications, and IT the most frequently recorded sectors.

The threat actor continued to target web applications, database management systems, email services, network monitoring platforms, and internet-facing infrastructure, while employing credential theft and lateral movement to expand access. Reported toolsets included LODEINFO, gh0st RAT, ASPXSpy, and Zingdoor, alongside families more commonly associated with other actors, such as Winnti (APT41) and BLACKCOFFEE (APT17), which likely reflect shared tooling or aggregated reporting; together they supported persistence, surveillance, and intelligence collection. The group’s continued interest in sensitive technologies and strategically important organisations indicates a sustained focus on long-term intelligence gathering, technology acquisition, and access development.

Profile

Field Detail
Tracked as (CYFIRMA list) Stone Panda
Selected aliases APT10, menuPass, Cicada, Red Apollo, POTASSIUM, Cloud Hopper
Alias caveats The CYFIRMA list includes MirrorFace and Earth Kasha (often assessed as an APT10 sub-group), and Bronze Starlight and UAT-7290, which are tracked separately by most vendors.
Origin China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage
Sponsorship (public attribution) US DOJ indictment (December 2018) linked members to the Ministry of State Security (MSS) Tianjin State Security Bureau.
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 30 Sep 2026
EW database, Q3 2026 8 campaigns; Q2 at least 9. Sighted July 6, August 6, September 7; none first seen in Q3.
Attribution basis 3 of 8 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.4 (highest 10)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Stable. 8 Q3 campaigns against at least 9 in Q2. Half were sighted in every month.
  • Sole-attributed tooling. gh0st RAT, ASPXSpy web shells, BLACKCOFFEE, and Emotet appear on campaigns attributed to Stone Panda alone.
  • Edge products on shared campaigns. Ivanti Connect Secure and Policy Secure, VMware vCenter, and routers appear only on campaigns shared with MISSION2074 and others.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Persistent backdoor implant T1071 Application Layer Protocol (C2) BLACKCOFFEE, LODEINFO, Volt (as recorded), Winnti, Zingdoor 1 sole-attributed campaign, 3 shared
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services Ivanti Connect Secure, Ivanti Policy Secure, routers, VPN solutions Shared campaigns only (2)
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer Emotet 1 sole-attributed campaign
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer gh0st RAT 1 sole-attributed campaign
Webshell deployment T1505.003 Server Software Component: Web Shell ASPXSpy 1 sole-attributed campaign
Ransomware deployment T1486 Data Encrypted for Impact Clop Shared campaign only (1)
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application VMware vCenter Server Shared campaign only (1)
IoT botnet exploitation (Mirai) T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service Mirai Shared campaign only (1)
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection Cobalt Strike Shared campaign only (1)

What this means for you: Stone Panda

  • Does this affect me? The US and Japan lead, followed by Taiwan, the UK, South Korea, India, and Australia. Professional services, manufacturing, telecommunications, and IT are most frequent.
  • How exposed am I? Highest for managed service providers and their clients, and for organisations with internet-facing IIS or Exchange where ASPXSpy can be planted.
  • What should I do now? Review MSP access paths and shared credentials, scan IIS and Exchange web roots for unexpected .aspx files, and patch Ivanti and vCenter.

LEVIATHAN

During the period from July to September 2026, Leviathan (APT40) continued to conduct cyber-espionage operations against government, defence, maritime, aerospace, healthcare, manufacturing, transportation, and academic organisations across the Asia-Pacific region, Europe, North America, and other strategically important locations. The group maintained an emphasis on organisations possessing sensitive governmental, technological, maritime, and defence-related information. The CYFIRMA campaign database links Leviathan to three Q3 campaigns, with manufacturing, professional services, transport, and materials the most frequently recorded sectors.

The threat actor continued to rely on spear-phishing, exploitation of internet-facing systems, credential theft, web-based intrusion techniques, and malware-enabled persistence to gain and maintain access. Its operational approach emphasizes reconnaissance and intelligence collection, with compromised environments potentially providing access to sensitive organisational and strategic information. Leviathan’s continued presence across technology, government, maritime, and critical infrastructure-related targets highlights the importance of monitoring exposed applications, authentication activity, suspicious email traffic, and abnormal outbound communications.

Profile

Field Detail
Tracked as (CYFIRMA list) Leviathan
Selected aliases APT40, Gadolinium, TEMP.Periscope, Kryptonite Panda, BRONZE MOHAWK, ISLANDDREAMS, MUDCARP
Origin China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage
Sponsorship (public attribution) US DOJ indictment (July 2021) linked members to the MSS Hainan State Security Department; Australian-led joint advisory (July 2024).
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 21 Sep 2026
EW database, Q3 2026 3 campaigns; Q2 at least 1. Sighted July 2, August 3, September 3; none first seen in Q3.
Attribution basis 1 of 3 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.0 (highest 8)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Up from a low base. 3 Q3 campaigns against at least 1 in Q2. 1 is attributed to Leviathan alone.
  • Exploitation-led. The sole-attributed campaign records no malware but lists Apache Log4j, Atlassian Confluence, Microsoft Exchange, VPN, RDP, SMB, WMI, and PowerShell, consistent with public-facing exploitation and living-off-the-land.
  • New geography. Belgium, Indonesia, Norway and Switzerland are new to the actor’s record. A Middle East victim set (Kuwait, Bahrain, Iraq, Jordan, and others) comes from a campaign shared with MISSION2074.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services RDP, remote desktop software 1 sole-attributed campaign
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services VPN 1 sole-attributed campaign
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application Apache Log4j, Atlassian Confluence, Microsoft Exchange Server 1 sole-attributed campaign
Spear phishing T1566 Phishing Not recorded in the EW database Public reporting cited above

What this means for you: Leviathan

  • Does this affect me? Manufacturing, professional services, transport and materials, across the US, Japan, Germany, the UK, Saudi Arabia, and Europe.
  • How exposed am I? Highest for organisations running unpatched Log4j, Confluence, or Exchange on the internet.
  • What should I do now? Patch those products, hunt for WMI and PowerShell remote execution from web servers, and review outbound traffic to Dropbox, GitHub, and Tor.

HAFNIUM

During the period from July to September 2026, Hafnium (Silk Typhoon) continued to demonstrate a persistent cyber-espionage capability targeting government, technology, telecommunications, transportation, and critical infrastructure organisations across Europe, North America, Asia-Pacific, and the Middle East. The CYFIRMA campaign database links Hafnium to two Q3 campaigns, both shared with other China-nexus actors, with government, IT, finance, and telecommunications as the recorded sectors.

The group continued to employ internet-facing infrastructure exploitation, VPN and router compromise, persistent backdoors, downloader frameworks, and post-exploitation tools to establish long-term access. Its activity demonstrated continued interest in enterprise applications, operating systems, databases, network monitoring platforms, and remote-access technologies. The group’s persistent targeting of organisations holding sensitive governmental and technological information indicates an ongoing emphasis on stealthy access, intelligence collection, credential compromise, and long-term persistence rather than overt disruption.

Profile

Field Detail
Tracked as (CYFIRMA list) HAFNIUM
Selected aliases Silk Typhoon, Murky Panda
Alias caveats The CYFIRMA list includes UNC5221, which Mandiant tracks as a separate cluster.
Origin China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage
Sponsorship (public attribution) US DOJ charges in 2025 linked individuals involved in this activity to China’s Ministry of State Security.
CYFIRMA exposure score 8 of 10, High
Last IOC activity (CYFIRMA) 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal)
EW database, Q3 2026 2 campaigns; Q2 at least 2. Sighted July 0, August 2, September 2; none first seen in Q3.
Attribution basis 0 of 2 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 9.3 (highest 10)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • All shared, no July sightings. 2 Q3 campaigns, both shared, first sighted in the quarter in August. One is recorded against six actors (MISSION2074, Salt Typhoon, Stone Panda, Volt Typhoon, Earth Estries, and Hafnium), the clearest example of indicator clustering in the dataset.
  • Edge devices. Fortinet FortiOS, FortiProxy, and FortiSwitchManager, routers, and VPN solutions are the recorded technologies.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, routers, VPN solutions Shared campaigns only (2)
Persistent backdoor implant T1071 Application Layer Protocol (C2) Volt (as recorded), Winnti, Zingdoor Shared campaign only (1)
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection Cobalt Strike Shared campaign only (1)
Exploitation of internet-facing servers T1190 Exploit Public-Facing Application Not recorded in the EW database Public reporting cited above
Web shells T1505.003 Server Software Component: Web Shell Not recorded in the EW database Public reporting cited above

Excluded as tooling of co-attributed actors: IoT botnet exploitation (Mirai).

Recent activity and shifts

  • Self-contained. Both Q3 campaigns are attributed to TICK alone and were sighted every month.
  • Commodity tooling. FormBook and MultiPlug are recorded as commodity families rather than the custom tooling public reporting associates with the group.
  • Geography differs from the narrative. Recorded victims are in the US, Japan, India, Australia, Taiwan, and Spain. South Korea does not appear in Q3.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie FormBook 1 sole-attributed campaign
Loader / downloader staging T1105 Ingress Tool Transfer MultiPlug 1 sole-attributed campaign

What this means for you: TICK

  • Does this affect me? Manufacturing and IT in Japan and the US, with India, Australia, Taiwan, and Spain also recorded.
  • How exposed am I? Highest for organisations where infostealer infections on Windows endpoints go uninvestigated, and where Linux servers allow SSH password authentication.
  • What should I do now? Treat FormBook detections as possible targeted activity, rotate credentials from affected hosts, and enforce key-based SSH.

EMISSARY PANDA

During the period from July to September 2026, Emissary Panda (APT27/LuckyMouse) continued to conduct long-term cyber-espionage operations against government, defence, aerospace, technology, telecommunications, and other strategic organisations. The CYFIRMA campaign database links Emissary Panda to three Q3 campaigns, all shared with other actors, with government, IT, professional services, finance, and manufacturing as the recorded sectors. The group continued to demonstrate an access-focused operational model, seeking persistent footholds that can support extended intelligence collection.

The threat actor continued to leverage internet-facing applications, credential theft, web-based intrusion techniques, malware, and legitimate administrative functionality to establish and maintain access. Its operations typically emphasize stealth and persistence, allowing compromised environments to be used for reconnaissance, lateral movement, and information theft over extended periods. Emissary Panda’s continued activity against government and strategic technology organisations highlights the importance of monitoring exposed web applications, authentication events, privileged accounts, unusual administrative behaviour, and anomalous outbound traffic.

Profile

Field Detail
Tracked as (CYFIRMA list) Emissary Panda
Selected aliases APT27, LuckyMouse, Iron Tiger, BRONZE UNION, TG-3390, Budworm, Linen Typhoon
Alias caveats The CYFIRMA list includes “EternalBlue”, which is an exploit, not an actor. A second CYFIRMA entry, Goblin Panda, carries APT27 aliases, but Goblin Panda (Cycldek) is a different actor. The EW database holds Emissary Panda, APT27 and Iron Tiger as separate names; all are counted here.
Origin China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Espionage, with for-profit intrusion activity
Sponsorship (public attribution) US DOJ indictment (March 2025) charged two APT27 members and described for-profit hacking with ties to the MSS.
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 25 Sep 2026
EW database, Q3 2026 3 campaigns (Emissary Panda 2, APT27 1); Q2 at least 2. Sighted July 2, August 2, September 3; none first seen in Q3.
Attribution basis 0 of 3 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.5 (highest 10)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • No sole-attributed campaigns. All 3 Q3 campaigns are shared: one with Volt Typhoon, one with Fox Kitten, Gamaredon, and Transparent Tribe, and one with OilRig and Lazarus Group.
  • Most technique data is borrowed. Cryptomining and the North Korean toolset (AppleJeus, NukeSped RAT, RustBucket, HLOADER, SUGARLOADER) come from the co-attributed campaigns and are excluded below.
  • Edge devices. The campaign shared with Volt Typhoon records VPN appliances and routers in Australia, India, Japan, Taiwan, Thailand, the UK, and the US.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services routers, VPN, VPN appliances, VPN solutions Shared campaigns only (2)
Persistent backdoor implant T1071 Application Layer Protocol (C2) Volt (as recorded) Shared campaign only (1)
Exploitation of internet-facing applications T1190 Exploit Public-Facing Application Not recorded in the EW database Public reporting cited above
Credential theft T1003 OS Credential Dumping (typical procedure, not recorded per campaign) Not recorded in the EW database Public reporting cited above

Excluded as tooling of co-attributed actors: Cryptomining; Trojanised cryptocurrency application; Loader / downloader staging; RAT / remote access implant; Commodity malware staging.

What this means for you: Emissary Panda

  • Does this affect me? Government, IT, professional services, finance, and manufacturing across Asia-Pacific, the Gulf, Europe, and North America.
  • How exposed am I? Highest for organisations with internet-facing VPN appliances and routers.
  • What should I do now? Patch and monitor VPN appliances and routers, and review privileged account use on systems reachable from them.

NORTH KOREAN ADVERSARY ACTIVITIES

TECHNIQUES OBSERVED

Campaigns sighted July to September 2026 per inferred technique: 14 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures.

TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. Top 15 of 20 technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Also recorded: Server Message Block (SMB), Software Components, VPN gateways and appliances, VMware, Web Portal Software

TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 27 countries. Also recorded: Denmark, Morocco, Norway, Argentina, China, Macao, the Netherlands, Malaysia, Indonesia, Canada, Italy, France.

TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted.

DATABASE VIEW OF THE NORTH KOREA NEXUS, Q3 2026

  • Activity. 14 campaigns in Q3 against at least 9 in Q2 (5 sighted in both). Sighted by month: July 8, August 8, September 12. 5 were sighted every month, and 1 was first sighted in Q3. Average campaign risk score 8.4 of 10.

Techniques mapped to MITRE ATT&CK

Technique (inferred) MITRE ATT&CK Campaigns Tooling or technology recorded
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer 3 Dridex, Emotet, Glupteba, Tofsee, TrickBot
Trojanised cryptocurrency application T1204.002 User Execution: Malicious File 3 AppleJeus
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer 3 NukeSped RAT
Persistent backdoor implant T1071 Application Layer Protocol (C2) 3 CivetQ, Winnti
Loader / downloader staging T1105 Ingress Tool Transfer 2 HLOADER, RustBucket, SUGARLOADER
Commodity malware staging T1105 Ingress Tool Transfer 2 unnamed commodity malware, FlyStudio
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application 1 Microsoft Exchange Server
Cryptomining T1496 Resource Hijacking 1 Cryptominer
Ransomware deployment T1486 Data Encrypted for Impact 1 Sodinokibi (REvil)
EDR / security tool tampering T1562.001 Impair Defenses: Disable or Modify Tools 1 AuKill
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie 1 Azorult, RedLine Stealer
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services 1 VPN, VPN solutions

LAZARUS GROUP

During the period from July to September 2026, Lazarus Group continued to demonstrate a highly adaptable operational capability through a combination of cyber-espionage, financial theft, supply-chain compromise, and social-engineering campaigns targeting cryptocurrency, financial, technology, defence, aerospace, and software organisations worldwide. The group maintained a strong focus on cryptocurrency and digital-asset environments while also expanding its espionage activity against defence and aerospace organisations. Lazarus Group was the most frequently linked actor in the CYFIRMA campaign database this quarter (14 campaigns, nine attributed to it alone), and public reporting highlighted continued Operation Dream Job activity targeting professionals through fraudulent employment opportunities. In August 2026, Check Point Research detailed a new Dream Job wave that used fake recruiter offers and trojanised PDF viewers against defence and aerospace staff, exploited the Windows AFD.sys zero-day CVE-2026-68820 (patched on 11 August 2026) to deploy an updated FudModule rootkit, and delivered the new Troy backdoor, with confirmed victims in France, Germany, Brazil, and India.

The threat actor continued to employ social engineering, malicious documents and applications, supply-chain compromises, credential theft, and exploitation of vulnerabilities to establish initial access and maintain persistence. Lazarus Group’s continued combination of financially motivated operations, sophisticated social engineering, zero-day exploitation, and supply-chain activity demonstrates an evolving threat profile that can make detection increasingly difficult, particularly for organisations operating in the cryptocurrency, technology, defence, aerospace, and financial sectors.

Profile

Field Detail
Tracked as (CYFIRMA list) Lazarus Group
Selected aliases HIDDEN COBRA, Diamond Sleet (formerly ZINC), Labyrinth Chollima
Alias caveats The CYFIRMA list treats Lazarus as an umbrella covering APT38 (Bluenoroff), Andariel, TraderTraitor (Jade Sleet), Famous Chollima, Moonstone Sleet and others. Many vendors track these as distinct clusters under the Reconnaissance General Bureau.
Origin North Korea (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified)
Motivation Financial theft (notably cryptocurrency) and espionage
Sponsorship (public attribution) North Korea’s Reconnaissance General Bureau, per US Treasury sanctions (September 2019).
CYFIRMA exposure score 10 of 10, Critical
Last IOC activity (CYFIRMA) 29 Sep 2026
EW database, Q3 2026 14 campaigns; Q2 at least 9. Sighted July 8, August 8, September 12; 1 first seen in Q3.
Attribution basis 9 of 14 Q3 campaigns attributed to this actor alone
Average campaign risk score, Q3 8.3 (highest 10)
Handlers and channels Not applicable (state-directed actor); none identified in the data reviewed.

Recent activity and shifts

  • Up, with a September rise. 14 Q3 campaigns against at least 9 in Q2. September sightings (12) rose from 8 in each of July and August.
  • Strong attribution base. 9 of 14 campaigns are attributed to Lazarus Group alone.
  • New campaign, new loader set. First seen on 16 September 2026 against Denmark, the UAE and the US, recording AppleJeus, NukeSped RAT, RustBucket, HLOADER and SUGARLOADER. These loaders first appear in the actor’s record this quarter; RustBucket is macOS malware in public reporting.
  • Finance and IT. IT and finance are the most frequent sectors, with Japan, the US, and India the most frequent victim countries.
  • Overlap. 5 campaigns are shared, two each with FIN7 and MISSION2074 and one with OilRig and APT27.

TTPs mapped to MITRE ATT&CK

Technique MITRE ATT&CK Tooling or technology recorded Basis
Trojanised cryptocurrency application T1204.002 User Execution: Malicious File AppleJeus 2 sole-attributed campaigns, 1 shared
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer NukeSped RAT 1 sole-attributed campaign, 2 shared
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer Dridex, Emotet, Glupteba, Tofsee, TrickBot 2 sole-attributed campaigns, 1 shared
Persistent backdoor implant T1071 Application Layer Protocol (C2) CivetQ, Winnti Shared campaigns only (3)
Loader / downloader staging T1105 Ingress Tool Transfer HLOADER, RustBucket, SUGARLOADER 1 sole-attributed campaign, 1 shared
Commodity malware staging T1105 Ingress Tool Transfer unnamed commodity malware, FlyStudio Shared campaigns only (2)
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services VPN, VPN solutions Shared campaign only (1)
Cryptomining T1496 Resource Hijacking Cryptominer 1 sole-attributed campaign
Ransomware deployment T1486 Data Encrypted for Impact Sodinokibi (REvil) 1 sole-attributed campaign
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie Azorult, RedLine Stealer Shared campaign only (1)
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application Microsoft Exchange Server 1 sole-attributed campaign
EDR / security tool tampering T1562.001 Impair Defenses: Disable or Modify Tools AuKill Shared campaign only (1)
Fake recruiter lures and trojanised PDF viewers T1566 Phishing; T1204.002 User Execution: Malicious File Not recorded in the EW database Public reporting cited above
Windows AFD.sys zero-day (CVE-2026-68820) for privilege escalation T1068 Exploitation for Privilege Escalation Not recorded in the EW database Public reporting cited above
FudModule rootkit tampering with security tooling T1014 Rootkit; T1562.001 Impair Defenses Not recorded in the EW database Public reporting cited above

What this means for you: Lazarus Group

  • Does this affect me? Financial services, cryptocurrency and fintech firms, IT and software developers, and defence and aerospace staff, most often in Japan, the US, and India.-
  • How exposed am I? Highest where developers and finance staff use macOS with limited monitoring, install tools from outside managed channels, or respond to unsolicited job offers.
  • What should I do now? Confirm the August 2026 Windows update (CVE-2026-68820) is deployed, extend EDR coverage to macOS, restrict unsigned software installation, and brief staff on recruiter-themed lures.

OUTLOOK: NEXT 90 DAYS

  • China (moderate confidence). 13 of 27 Chinese-linked campaigns were sighted every month, and the two most active actors held steady across Q2 and Q3. Continued sightings are likely, with backdoor families (Winnti, ShadowPad, PlugX) and edge devices (Ivanti, Fortinet, Citrix, VMware vCenter, VPN gateways, routers) remaining the main recorded tradecraft.
  • North Korea (moderate confidence). The September rise and a new campaign with a fresh loader set point to continued Lazarus Group activity against finance, cryptocurrency and IT targets. Public reporting of a Windows zero-day used against defence and aerospace staff adds a second, espionage-focused line of activity.
  • Russia (low to moderate confidence). Financially motivated groups show stable counts and are likely to keep using ransomware and data-theft extortion. Database evidence for the state-linked groups is thin outside Cozy Bear, so expectations for them rest mainly on public reporting of identity-focused and router-based operations.
  • Iran (low confidence). Database evidence is too thin and too entangled with other actors to project from. Monitoring should rely on public reporting of perimeter-device exploitation and the new ransomware-linked campaign.

PRIORITISED MITIGATIONS

Priority Action Addresses Actors most relevant
1 Inventory, patch and integrity-check internet-facing Fortinet, Ivanti, Citrix NetScaler, VMware vCenter, VPN gateways and routers; review admin accounts and configuration changes since July 2026 T1190, T1133 MISSION2074, Stone Panda, Hafnium, Emissary Panda, APT34, Fox Kitten
2 Remove direct RDP and SSH exposure; enforce MFA on all remote access T1021.001, T1133 FIN7, MISSION2074, Leviathan, TICK
3 Enable EDR tamper protection and vulnerable-driver blocking; deploy the August 2026 Windows update (CVE-2026-68820) T1562.001, T1068 FIN7, Lazarus Group
4 Hunt for DLL side-loading, Winnti, ShadowPad, PlugX and Cobalt Strike beacons on servers T1071, T1055 MISSION2074, Stone Panda, Cozy Bear
5 Restrict device-code sign-in and monitor OAuth consents and token use T1528, T1566 Cozy Bear
6 Scan web roots on IIS, Exchange and file-transfer servers for web shells; patch Log4j, Confluence and Exchange T1505.003, T1190 Stone Panda, FIN11, Leviathan
7 Test ransomware recovery against encryption and data-theft extortion (Clop, INC, Sodinokibi) T1486, T1567 FIN11, TA505, FIN7, APT34
8 Extend EDR to macOS, restrict unsigned software, brief staff on recruiter and fake-update lures T1204.002 Lazarus Group, Cozy Bear

IOCs and platform-specific hunting queries are not included: neither source dataset carries indicators.

CONCLUSION

During July to September 2026, 48 campaigns linked to Iranian, Russian, Chinese, and North Korean actors were sighted in the CYFIRMA campaign database, compared to at least 33 in Q2. Most were long-running: only three were first seen in the quarter, and 21 were sighted in every month.

China remains the largest nexus (27 campaigns), with MISSION2074 and Stone Panda stable at a high level and persistent backdoors (Winnti, ShadowPad, PlugX) and edge-device exploitation the dominant recorded tradecraft. North Korean activity rose late in the quarter: Lazarus Group was linked to 14 campaigns, nine attributed to it alone, with a new loader set first seen in September and, in public reporting, a Windows zero-day used against defence and aerospace staff. Russian activity is spread across financially motivated and state-linked groups with a thin database base outside Cozy Bear. Iranian evidence is the weakest and rests mainly on public reporting.

Shared attribution is common: 21 of 48 campaigns are linked to more than one actor. This is consistent with overlapping tooling and indicator clustering and is not treated as evidence of collaboration. Where the database is thin, this report has relied on public reporting and says so.

The prioritised mitigations in the Outlook section address the techniques most frequently recorded this quarter: internet-facing edge devices, exposed RDP and SSH, EDR tamper protection, backdoor and beacon hunting, identity controls and ransomware recovery. They are based on the intelligence available at the time of writing and should be read alongside the customer’s own controls and monitoring.

APPENDIX A: CHART DATA

A1. Campaigns by nexus, Q3 against Q2

Nexus Q3 campaigns Q2 campaigns (min)
Iran 4 2
Russia 13 8
China 27 22
North Korea 14 9

A2. Campaigns sighted per month by nexus

Month Iran Russia China North Korea All four (distinct)
July 2026 3 8 18 8 30
August 2026 2 11 21 8 35
September 2026 3 11 23 12 40

A3. Profiled actors

Actor Nexus Q3 campaigns Q2 campaigns (min) Attributed alone (Q3) CYFIRMA exposure score
APT34 (OilRig) Iran 3 1 0 9
Fox Kitten Iran 1 1 0 8
FIN7 Russia 4 3 1 9
Cozy Bear Russia 4 1 3 9
TA505 Russia 3 3 0 10
Fancy Bear Russia 3 1 0 9
FIN11 Russia 2 3 1 10
Gamaredon Russia 2 2 0 9
MISSION2074 China 12 11 4 10
Stone Panda China 8 9 3 10
Leviathan China 3 1 1 10
Hafnium China 2 2 0 8
TICK China 2 1 2 10
Emissary Panda China 3 2 0 10
Lazarus Group North Korea 14 9 9 10

A4. Victim countries by nexus, Q3 (campaigns), as charted

Country Iran Russia China North Korea
Japan 2 13 24 10
United States 3 13 23 9
United Kingdom 3 9 15 5
India 1 5 16 6
Australia 0 6 15 5
South Korea 1 9 10 5
Germany 3 4 11 4
Taiwan 0 3 13 4
Saudi Arabia 3 3 8 2
Thailand 0 4 8 3
Philippines 0 2 8 2
United Arab Emirates 3 1 5 2
France 2 3 5 1
Canada 1 3 5 1
Singapore 0 3 5 2
Malaysia 0 2 3 1
Vietnam 0 2 3 0
Ukraine 1 2 1 0
Qatar 1 0 2 0
Oman 1 0 2 0
Israel 1 0 2 0
Austria 1 0 1 0
South Africa 1 0 1 0
Russia 0 0 0 1
Mongolia 0 0 0 1

Every country that appears in any nexus chart (top 15 per nexus). Iran excludes the campaign carrying North Korean tooling. Regional labels (Europe, Africa, Worldwide, ALL) excluded.

A5. Sectors by nexus, Q3 (campaigns), as charted

Sector Iran Russia China North Korea
Information Technology 2 7 17 9
Professional Goods & Services 2 7 20 5
Manufacturing 3 5 19 6
Finance 2 6 14 6
Telecommunications & Media 3 4 14 3
Government & Civic 3 4 12 4
Transportation & Logistics 0 5 10 5
Energy & Utilities 1 3 7 4
Consumer Goods & Services 1 2 8 4
Healthcare 0 3 6 3
Materials 0 3 6 2
Automotive 0 3 5 1
Real Estate & Construction 1 2 3 0

Uses the database’s 14 broad sector categories, which cover most but not all Q3 campaign records. Iran excludes the campaign carrying North Korean tooling.

A6. Techniques, Q3 against Q2 (all four nexuses, distinct campaigns)

Technique (inferred) MITRE ATT&CK Q3 Q2 (min)
Persistent backdoor implant T1071 Application Layer Protocol (C2) 17 10
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services 9 1
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer 7 5
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services 6 3
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer 6 5
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application 5 0
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection 5 1
Ransomware deployment T1486 Data Encrypted for Impact 5 3
Loader / downloader staging T1105 Ingress Tool Transfer 4 2
Trojanised cryptocurrency application T1204.002 User Execution: Malicious File 3 0
Commodity malware staging T1105 Ingress Tool Transfer 3 2
IoT botnet exploitation (Mirai) T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service 2 1
Cryptomining T1496 Resource Hijacking 2 1
Webshell deployment T1505.003 Server Software Component: Web Shell 2 2
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie 2 1
Firmware-level implant T1542.001 Pre-OS Boot: System Firmware 1 0
Privilege escalation tooling T1134.001 Access Token Manipulation: Token Impersonation/Theft 1 0
EDR / security tool tampering T1562.001 Impair Defenses: Disable or Modify Tools 1 0

Technology-based techniques (edge devices, named products, RDP) are not comparable across Q2 and Q3 because named products were added to the source data in September 2026.

A7. Techniques by nexus, Q3 (campaigns), as charted

Technique (inferred) MITRE ATT&CK Iran Russia China North Korea
Persistent backdoor implant T1071 Application Layer Protocol (C2) 0 5 13 3
VPN / router / edge device exploitation T1190 Exploit Public-Facing Application; T1133 External Remote Services 2 0 8 1
Financial trojan / botnet distribution T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer 0 3 2 3
RAT / remote access implant T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer 0 2 3 3
Ransomware deployment T1486 Data Encrypted for Impact 1 3 1 1
Remote desktop exploitation T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services 0 2 4 0
Loader / downloader staging T1105 Ingress Tool Transfer 0 0 3 2
Commodity malware staging T1105 Ingress Tool Transfer 1 0 2 2
Post-exploitation framework (Cobalt Strike) T1071.001 Web Protocols; T1055 Process Injection 0 2 3 0
Public-facing application exploitation (named products) T1190 Exploit Public-Facing Application 0 1 3 1
Trojanised cryptocurrency application T1204.002 User Execution: Malicious File 0 0 1 3
Cryptomining T1496 Resource Hijacking 1 1 1 1
Infostealer deployment T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie 0 0 2 1
IoT botnet exploitation (Mirai) T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service 0 0 2 0
Webshell deployment T1505.003 Server Software Component: Web Shell 0 1 1 0
EDR / security tool tampering T1562.001 Impair Defenses: Disable or Modify Tools 0 1 0 1
Privilege escalation tooling T1134.001 Access Token Manipulation: Token Impersonation/Theft 0 0 1 0
Firmware-level implant T1542.001 Pre-OS Boot: System Firmware 0 0 1 0

APPENDIX B: CAMPAIGN REFERENCE, Q3 2026

Campaign Attributed actors Nexus First seen Sighted in Q3 Also in Q2 Risk
bite MISSION2074 China 2021-05-08 Jul, Aug, Sep Yes 8
Bush TICK China 2020-01-09 Jul, Aug, Sep No 8
Citrix NSCN2301 China 2023-07-18 Jul, Aug, Sep No 8
Dominion MISSION2074, Salt Typhoon China 2026-01-23 Aug, Sep No 9
Double Blow CCCN2101 China 2021-01-31 Sep Yes 8
Fast pace MISSION2074 China 2020-01-12 Jul, Aug, Sep No 8
harts Lazarus Group, MISSION2074 China, North Korea 2023-08-09 Aug No 8
Hegemon MISSION2074, Salt Typhoon, Stone Panda, Volt Typhoon, Earth Estries, Hafnium China 2024-12-05 Aug, Sep Yes 10
hwasong APT27, Lazarus Group, Oilrig China, Iran, North Korea 2024-06-15 Jul, Sep Yes 10
ivanti MISSION2074, Stone Panda China 2024-01-15 Jul, Aug, Sep Yes 9
meteor Lazarus Group, MISSION2074 China, North Korea 2023-02-04 Jul, Aug, Sep Yes 10
Oblivion Stone Panda China 2020-11-12 Jul, Sep Yes 10
Panther@4& Leviathan, Stone Panda China 2021-02-12 Jul, Aug, Sep No 8
reliable Leviathan China 2021-01-21 Jul, Aug, Sep Yes 8
Sail Emissary Panda, Fox Kitten, Gamaredon, Transparent Tribe China, Iran, Russia 2024-03-08 Jul, Aug, Sep Yes 8
Scissors Leviathan, MISSION2074 China 2021-05-11 Aug, Sep No 8
Sound effect Stone Panda China 2020-01-07 Jul, Aug No 8
Speed Up TICK China 2021-04-04 Jul, Aug, Sep Yes 8
Stealth Attack MISSION2074 China 2024-08-30 Aug No 8
Tailgate Hafnium, US17IRGCorp, APT34 China, Iran 2022-09-15 Aug, Sep No 8
territorial integrity Mustang Panda China 2023-04-06 Jul, Aug, Sep Yes 8
Thunderstorm Emissary Panda, Volt Typhoon China 2024-09-28 Aug, Sep No 8
Victory Stone Panda, TA505 China, Russia 2025-01-06 Jul, Aug, Sep Yes 8
VINUM MISSION2074 China 2026-07-04 Jul No 10
Vision2025 MISSION2074, Tropic Trooper China 2017-10-31 Jul, Sep No 8
Wakeup Gothic Panda, MISSION2074, Stone Panda China 2019-01-12 Jul, Aug, Sep Yes 8
WipeOut Stone Panda China 2021-02-22 Sep Yes 8
Victory Against Traitors APT34, MuddyWater Iran 2026-07-15 Jul No 10
Cactus Lazarus Group North Korea 2020-02-15 Jul, Sep Yes 8
field trip Lazarus Group North Korea 2020-01-05 Aug, Sep No 8
Horn Lazarus Group North Korea 2021-06-14 Jul, Aug, Sep No 8
illusion FIN7, Lazarus Group North Korea, Russia 2021-01-28 Jul, Aug, Sep Yes 8
Jmp Lazarus Group North Korea 2020-01-09 Jul, Aug, Sep No 8
Mankind Wisdom Lazarus Group North Korea 2019-10-30 Aug, Sep No 8
Muance Lazarus Group North Korea 2026-09-16 Sep No 10
Sandpaper Lazarus Group North Korea 2019-10-30 Jul No 8
Tumen FIN7, Lazarus Group North Korea, Russia 2024-08-31 Sep No 8
verdict Lazarus Group North Korea 2020-01-09 Jul, Aug, Sep Yes 8
Virtuality Lazarus Group North Korea 2021-01-04 Sep No 8
20 Yard Dragonfly, Fancy Bear Russia 2020-04-08 Aug No 8
crop up Cozy Bear Russia 2021-05-11 Aug, Sep No 8
Enlightenment Fancy Bear, Turla Group Russia 2019-01-01 Aug, Sep No 8
Evian Cozy Bear, Fancy Bear, TA505 Russia 2022-09-21 Jul Yes 8
hurricane Cozy Bear Russia 2020-01-11 Jul, Aug, Sep No 8
Mountain Range FIN11 Russia 2021-02-19 Aug, Sep Yes 8
natural disaster Cozy Bear Russia 2022-03-17 Jul, Aug, Sep No 8
Raw Material FIN7 Russia 2020-04-17 Jul, Aug, Sep Yes 8
Void FIN11, FIN7, Gamaredon, TA505 Russia 2023-02-08 Jul, Aug, Sep Yes 8