
Mostly long-running campaigns.
48 campaigns linked to the four nexuses were sighted in Q3, against at least 33 in Q2, and 21 were sighted in both. Only 3 were first seen in Q3. 21 were sighted in every month of the quarter.
China remains the largest nexus.
Chinese actors were linked to 27 campaigns (at least 22 in Q2). MISSION2074 (12) and Stone Panda (8) are again the most frequently linked actors, both stable against Q2.
North Korean activity rose late in the quarter.
Lazarus Group was linked to 14 campaigns (at least 9 in Q2), 9 of them attributed to it alone. September sightings (12) exceeded July and August (8 each), and one new campaign appeared in mid-September.
Russian activity is spread thin.
Russian actors were linked to 13 campaigns (at least 8 in Q2). Only Cozy Bear, FIN7 and FIN11 have a Q3 campaign attributed to them alone.
Iranian evidence is the weakest.
Iranian actors were linked to 4 campaigns. None is attributed to an Iranian actor alone, and one carries only North Korean tooling.
Heavy attribution overlap.
21 of 48 campaigns are linked to more than one actor, and 8 span more than one nexus. 7 of the 15 profiled actors have no Q3 campaign attributed to them alone (APT34, Fox Kitten, TA505, Fancy Bear, Gamaredon, Hafnium, Emissary Panda), so their technique, country, and industry lists include other actors’ data. Shared attribution reflects overlapping TTPs, shared tooling or indicator clustering, and is not evidence of collaboration.
Techniques.
Persistent backdoors were recorded in 17 of 48 campaigns, VPN, router, and edge-device exploitation in 9, financial trojans and botnets in 7, and RDP exposure and remote access implants in 6 each.
Geography.
Japan (41 campaigns) and the United States (39) were the most frequently recorded victim countries, followed by the United Kingdom (24), India (23), South Korea (22), and Australia (21).
What to do now.
Patch and integrity-check internet-facing edge devices, remove direct RDP and SSH exposure, enable EDR tamper protection, and deploy the August 2026 Windows update (CVE-2026-68820). The full prioritised list is in the Outlook section.
During the July–September 2026 reporting period, state-sponsored Advanced Persistent Threat (APT) groups from Iran, Russia, China, and North Korea, alongside Russian-speaking financially motivated cybercrime groups, continued to demonstrate sophisticated and evolving cyber capabilities through cyber espionage, credential theft, infrastructure exploitation, ransomware deployment, supply-chain compromise, and financially motivated operations. These threat actors leveraged internet-facing infrastructure, VPN and router vulnerabilities, persistent backdoors, remote-access trojans (RATs), legitimate administrative tools, and social-engineering techniques to establish long-term access, evade detection, and facilitate intelligence collection or financial gain. Their operations demonstrated a continued emphasis on exploiting enterprise technologies, cloud environments, and critical infrastructure across multiple geographic regions and industries. Assessments in this report draw on the CYFIRMA campaign database and on public reporting; where the database evidence is thin, the actor profile says so, and the confidence is rated accordingly.
Iranian threat actors, particularly APT34 (OilRig) and Fox Kitten, continued targeting government, energy, financial, telecommunications, healthcare, and critical infrastructure organisations through credential theft, vulnerability exploitation, persistent implants, and unauthorised network access.
Russia-linked actors, including the state-aligned Cozy Bear, Fancy Bear, and Gamaredon, and the financially motivated, Russian-speaking cybercrime groups FIN7, FIN11, and TA505, maintained operations against government, defence, financial, technology, and strategically significant organisations, combining cyber espionage, ransomware-enabled intrusions, destructive malware, infrastructure compromise, and intelligence collection.
Chinese threat actors, including MISSION2074, Stone Panda, Leviathan, Hafnium, TICK, and Emissary Panda, sustained espionage campaigns targeting government agencies, telecommunications providers, technology companies, transportation, and critical infrastructure, leveraging backdoors, VPN and router exploitation, web shells, credential theft, and post-exploitation frameworks to maintain persistent access.
Meanwhile, North Korean operators, particularly Lazarus Group, continued combining financially motivated cyberattacks with strategic espionage, targeting cryptocurrency platforms, financial institutions, defence, aerospace, and software development organisations through social engineering, fraudulent employment campaigns, supply-chain compromises, malware deployment, and vulnerability exploitation.
The reporting period showed continued convergence between cyber espionage, financial theft, ransomware operations, vulnerability exploitation, supply-chain compromise, and persistent access through cloud and edge infrastructure. The widespread targeting of interconnected enterprise environments across government, defence, telecommunications, financial services, technology, healthcare, energy, and critical infrastructure highlights the evolving operational capabilities and persistent risks associated with nation-state cyber actors. These developments underscore the importance of maintaining proactive threat intelligence capabilities, continuous vulnerability assessment, robust identity and access management, endpoint and network monitoring, supply-chain security, and comprehensive incident response preparedness to detect emerging threats and strengthen organisational cybersecurity resilience.
| Nexus | Q3 campaigns | Q2 campaigns (min) | Sighted in both | First seen in Q3 | Linked to another nexus | Attributed to this nexus only |
| Iran | 4 | 2 | 2 | 1 | 3 | 1 |
| Russia | 13 | 8 | 7 | 0 | 4 | 9 |
| China | 27 | 22 | 14 | 1 | 6 | 21 |
| North Korea | 14 | 9 | 5 | 1 | 5 | 9 |
| All four (distinct) | 48 | 33 | 21 | 3 | 8 | – |
| Actor | Nexus | Score | Severity | Last IOC activity | Q3 campaigns | Q2 (min) | Sole-attributed | |
| APT34 (OilRig) | Iran | 9 | Critical | 26 Sep 2026 | 3 | 1 | 0 | |
| Fox Kitten | Iran | 8 | High | 13 Sep 2026 * | 1 | 1 | 0 | |
| FIN7 | Russia | 9 | Critical | 23 Sep 2026 | 4 | 3 | 1 | |
| Cozy Bear | Russia | 9 | Critical | 29 Sep 2026 | 4 | 1 | 3 | |
| TA505 | Russia | 10 | Critical | 29 Sep 2026 | 3 | 3 | 0 | |
| Fancy Bear | Russia | 9 | Critical | 13 Sep 2026 * | 3 | 1 | 0 | |
| FIN11 | Russia | 10 | Critical | 13 Sep 2026 * | 2 | 3 | 1 | |
| Gamaredon | Russia | 9 | Critical | 29 Sep 2026 | 2 | 2 | 0 | |
| MISSION2074 | China | 10 | Critical | 13 Sep 2026 * | 12 | 11 | 4 | |
| Stone Panda | China | 10 | Critical | 30 Sep 2026 | 8 | 9 | 3 | |
| Leviathan | China | 10 | Critical | 21 Sep 2026 | 3 | 1 | 1 | |
| Hafnium | China | 8 | High | 13 Sep 2026 * | 2 | 2 | 0 | |
| TICK | China | 10 | Critical | 25 Sep 2026 | 2 | 1 | 2 | |
| Emissary Panda | China | 10 | Critical | 25 Sep 2026 | 3 | 2 | 0 | |
| Lazarus Group | North Korea | 10 | Critical | 29 Sep 2026 | 14 | 9 | 9 |
TECHNIQUES OBSERVED

Campaigns are sighted from July to September 2026 per inferred technique: 3 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures. Excludes one campaign recorded under OilRig that carries only North Korean tooling.
TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. All 9 recorded technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Excludes one campaign recorded under OilRig that carries only North Korean tooling.
TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 23 countries. Also recorded: Turkey, Spain, South Korea, Switzerland, Netherlands, Portugal, Italy, Belgium. Excludes one campaign recorded under OilRig that carries only North Korean tooling.
TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted. Excludes one campaign recorded under OilRig that carries only North Korean tooling.
Techniques mapped to MITRE ATT&CK
| Technique (inferred) | MITRE ATT&CK | Campaigns | Tooling or technology recorded |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | 2 | Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, VPN solutions |
| Cryptomining | T1496 Resource Hijacking | 1 | Cryptominer |
| Commodity malware staging | T1105 Ingress Tool Transfer | 1 | unnamed commodity malware |
| Ransomware deployment | T1486 Data Encrypted for Impact | 1 | INC Ransomware |
APT34
During the period from July to September 2026, APT34 (OilRig) continued to demonstrate persistent espionage activity aligned with Iranian strategic interests, with targeting spanning government, energy, financial, telecommunications, chemical, technology, and critical infrastructure sectors. Public threat-intelligence reporting continued to associate the group with long-term intelligence collection and information theft, particularly against organisations in the Middle East and other strategically relevant regions. MITRE ATT&CK continued to track APT34 under the OilRig group designation, reflecting the consolidation of overlapping reporting and aliases associated with the actor.
The group continued to rely on credential theft, legitimate system utilities, PowerShell and other native operating-system capabilities, and covert command-and-control mechanisms to maintain access while reducing the visibility of its activities. DNS-based command-and-control and cloud- or internet-facing infrastructure have remained part of the broader APT34 tradecraft documented in threat-intelligence reporting. The group’s continued emphasis on intelligence collection, persistence, and discreet access rather than immediate disruption highlights the importance of monitoring authentication activity, unusual administrative operations, PowerShell execution, and anomalous outbound DNS or network communications.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | APT34 |
| Selected aliases | OilRig, Helix Kitten, Hazel Sandstorm (formerly EUROPIUM), Crambus, Chrysene |
| Alias caveats | The CYFIRMA list also files MuddyWater, Seedworm, Lyceum, Scarred Manticore and UNC1860 under APT34. Most vendors track these as separate Iranian clusters, so they are not used as aliases here. The EW database holds APT34 and Oilrig as two names; both are counted under this profile. |
| Origin | Iran (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage |
| Sponsorship (public attribution) | MITRE ATT&CK (G0049) assesses that the group appears to work on behalf of the Iranian government. Agency-level attribution differs between sources. |
| CYFIRMA exposure score | 9 of 10, Critical |
| Last IOC activity (CYFIRMA) | 26 Sep 2026 |
| EW database, Q3 2026 | 3 campaigns (APT34 2, Oilrig 1); Q2 at least 1. Sighted July 2, August 1, September 2; 1 first seen in Q3. |
| Attribution basis | 0 of 3 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 9.4 (highest 10) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, VPN, VPN solutions | Shared campaigns only (3) |
| Commodity malware staging | T1105 Ingress Tool Transfer | unnamed commodity malware | Shared campaigns only (2) |
| Ransomware deployment | T1486 Data Encrypted for Impact | INC Ransomware | Shared campaign only (1) |
| PowerShell and native tooling | T1059.001 Command and Scripting Interpreter: PowerShell | Not recorded in the EW database | Public reporting cited above |
| DNS-based command and control | T1071.004 Application Layer Protocol: DNS | Not recorded in the EW database | Public reporting cited above |
| Credential theft | T1003 OS Credential Dumping (typical procedure, not recorded per campaign) | Not recorded in the EW database | Public reporting cited above |
Excluded as tooling of co-attributed actors: Trojanised cryptocurrency application; Loader / downloader staging; RAT / remote access implant.
What this means for you: APT34
Fox Kitten
This profile is based on public reporting; the CYFIRMA campaign database holds only shared, low-confidence campaigns for this actor in Q3 (see below). During the period from July to September 2026, Fox Kitten (Pioneer Kitten/UNC757/Lemon Sandstorm) continued to represent a significant Iranian cyber threat, particularly through operations involving initial access, persistent network penetration, espionage, and access brokering. The group has been associated with targeting government, financial, healthcare, information technology, insurance, energy, telecommunications, manufacturing, defence, and critical infrastructure organisations across the Middle East, Europe, North America, Australia, and other regions.
The actor continued to demonstrate a strong preference for internet-facing infrastructure, particularly VPNs, firewalls, remote-access technologies, and other perimeter devices. Threat reporting also continued to document exploitation of known vulnerabilities in technologies such as Fortinet, Pulse Secure, Citrix, F5 BIG-IP, Ivanti, Check Point, and Palo Alto Networks to obtain or maintain access. Fox Kitten’s activity is notable for the overlap between espionage-oriented operations and the establishment or brokerage of network access that can subsequently be used by ransomware affiliates.
The group’s continued use of legitimate administrative tools, web shells, custom malware, compromised infrastructure, and vulnerability exploitation can make malicious activity difficult to distinguish from normal enterprise administration. Public reporting, including the August 2024 FBI and CISA advisory, characterises Fox Kitten as a hybrid threat actor whose operations can involve both intelligence collection and the monetisation or transfer of compromised access. This makes edge-device hardening, rapid vulnerability remediation, credential protection, network segmentation, and monitoring for unusual remote-access activity particularly important for organisations operating in sectors of strategic interest.
| Field | Detail |
| Tracked as (CYFIRMA list) | Fox Kitten |
| Selected aliases | Pioneer Kitten, UNC757, Lemon Sandstorm, RUBIDIUM, Parisite |
| Origin | Iran (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Initial access and espionage, with access sold or passed to ransomware affiliates |
| Sponsorship (public attribution) | An FBI and CISA joint advisory (August 2024) describes the actors as Iran-based and associated with the Government of Iran. |
| CYFIRMA exposure score | 8 of 10, High |
| Last IOC activity (CYFIRMA) | 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal) |
| EW database, Q3 2026 | 1 campaign; Q2 at least 1. Sighted July 1, August 1, September 1; none first seen in Q3. |
| Attribution basis | 0 of 1 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Cryptomining | T1496 Resource Hijacking | Cryptominer | Shared campaign only (1) |
| Exploitation of VPNs, firewalls and other perimeter devices | T1190 Exploit Public-Facing Application; T1133 External Remote Services | Not recorded in the EW database | Public reporting cited above |
| Web shells on compromised servers | T1505.003 Server Software Component: Web Shell | Not recorded in the EW database | Public reporting cited above |
| Use of legitimate administrative tools | T1219 Remote Access Software | Not recorded in the EW database | Public reporting cited above |
What this means for you: Fox Kitten
Does this affect me? Recorded victims are in Germany, Japan, Saudi Arabia, Ukraine, the UAE, the UK, and the US, across telecommunications, IT, government, finance, and defence.
How exposed am I? Database evidence is too thin to rate exposure. Public reporting points to internet-facing Fortinet, Pulse Secure, Citrix, F5, Ivanti, Check Point, and Palo Alto devices.
What should I do now? Prioritise patching and log review on those perimeter products. Treat unexpected crypto mining on servers as a possible sign of wider compromise, not a nuisance.
TECHNIQUES OBSERVED

Campaigns sighted from July to September 2026 per inferred technique: 13 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures.
TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. Top 15 of 28 technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Also recorded: PHP, PHPUnit, phpMyAdmin, SMTP, Squid Proxy, ThinkPHP, vBulletin, Voice over IP (VoIP), Weaver E-cology, Web Application Servers, WebDAV, WordPress, Zhiyuan Collaborative Office.
TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 27 countries. Also recorded: Indonesia, Philippines, Ukraine, Brunei, Belgium, Cambodia, Myanmar, Laos, Timor-Leste, United Arab Emirates, Morocco, Hungary
TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted.
DATABASE VIEW OF THE RUSSIA NEXUS, Q3 2026
Techniques mapped to MITRE ATT&CK
| Technique (inferred) | MITRE ATT&CK | Campaigns | Tooling or technology recorded |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | 5 | CivetQ, CosmicDuke, LODEINFO, MiniDuke, flipflop, freshfire |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | 3 | Dridex, TrickBot, Zeus (Zbot) |
| Ransomware deployment | T1486 Data Encrypted for Impact | 3 | Cl0p, Ryuk, Sodinokibi (REvil) |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | 2 | RDP |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | 2 | FlawedAmmyy RAT |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | 2 | Cobalt Strike |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | 1 | Apache Tomcat Manager, Drupal, Jira, Jira Server and Data Center, Joomla!, phpMyAdmin and 6 more |
| Webshell deployment | T1505.003 Server Software Component: Web Shell | 1 | DEWMODE |
| Cryptomining | T1496 Resource Hijacking | 1 | Cryptominer |
| EDR / security tool tampering | T1562.001 Impair Defenses: Disable or Modify Tools | 1 | AuKill |
FIN7
During the period from July to September 2026, FIN7, a financially motivated, Russian-speaking cybercrime group, continued to demonstrate a broad and adaptable operational profile, conducting financially motivated intrusions against organisations across financial services, government, transportation, aerospace, retail, technology, and industrial sectors. Threat-intelligence reporting for 2026 indicates that the group expanded its geographic reach across Asia, Europe, and North America, while continuing to combine established financially motivated operations with more advanced network intrusion capabilities. Campaigns involved exploitation of internet-facing infrastructure, remote-access services, and enterprise systems to establish persistence and facilitate follow-on activity.
The group continued to leverage a combination of credential theft, ransomware, malware deployment, and lateral movement to increase the impact of compromises. Reported toolsets associated with FIN7 included ransomware families and custom malware, demonstrating continued diversification of its post-compromise operations. FIN7’s presence across multiple sectors during the period highlights its ability to adapt its targeting and operational methods according to available opportunities, making monitoring of exposed remote-access infrastructure, authentication activity, and unusual lateral movement particularly important.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | FIN7 |
| Selected aliases | Carbon Spider, Sangria Tempest, ELBRUS, GrayAlpha (Carbanak is sometimes tracked as a separate group) |
| Origin | Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Financial |
| Sponsorship (public attribution) | None established. Financially motivated, Russian-speaking criminal group; several members have been prosecuted in the US since 2018. |
| CYFIRMA exposure score | 9 of 10, Critical |
| Last IOC activity (CYFIRMA) | 23 Sep 2026 |
| EW database, Q3 2026 | 4 campaigns; Q2 at least 3. Sighted July 3, August 3, September 4; none first seen in Q3. |
| Attribution basis | 1 of 4 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | None identified in the data reviewed; public reporting describes affiliate recruitment and data-leak-site extortion. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | Dridex | Shared campaign only (1) |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | RDP | 1 sole-attributed campaign |
| Ransomware deployment | T1486 Data Encrypted for Impact | Sodinokibi (REvil) | 1 sole-attributed campaign |
| EDR / security tool tampering | T1562.001 Impair Defenses: Disable or Modify Tools | AuKill | Shared campaign only (1) |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | CivetQ | Shared campaign only (1) |
| Credential theft and lateral movement | T1078 Valid Accounts; T1021 Remote Services | Not recorded in the EW database | Public reporting cited above |
What this means for you: FIN7
COZY BEAR
During the period from July to September 2026, Cozy Bear (APT29/Midnight Blizzard) continued to conduct sophisticated cyber-espionage operations focused primarily on government, diplomatic, defence, technology, healthcare, and strategically important organisations. On 31 July 2026, Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign active since early May 2026 that it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard. Compromised captive-portal gateways at hotels, conference centres, and similar venues were used to manipulate DNS and HTTP traffic and redirect guests to fake update pages, Microsoft 365 credential-harvesting pages, and device-code phishing, with the CornFlake remote-access trojan among the payloads delivered. The activity affected travelers across a broad range of sectors, demonstrating the group’s continued interest in intelligence collection through unconventional access points; the Storm-2945 link is Microsoft’s own assessment and had not been independently corroborated at the time of writing.
The threat actor continued to rely on credential theft, OAuth and identity-focused attacks, compromised infrastructure, DNS manipulation, and persistent access techniques to obtain valuable information while attempting to blend malicious activity with legitimate network operations. Anthropic’s September 2026 threat intelligence report, describing a cluster tracked as GTG-20006 that it assessed as consistent with public reporting on Midnight Blizzard (APT29) and active from roughly December 2025 through August 2026, linked the group to attempts to compromise more than 20 organisations, largely in Europe and Ukraine, including government ministries, defence bodies, embassies, think tanks, and companies in the military drone supply chain. The group’s continued focus on identity, cloud services, and third-party infrastructure demonstrates the importance of monitoring authentication anomalies, captive-portal environments, DNS changes, and unusual access to cloud-based accounts.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Cozy Bear |
| Selected aliases | APT29, Midnight Blizzard (formerly NOBELIUM), The Dukes, UNC2452, Cloaked Ursa, BlueBravo |
| Origin | Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage |
| Sponsorship (public attribution) | Russian Foreign Intelligence Service (SVR), per US and UK government attribution (April 2021). |
| CYFIRMA exposure score | 9 of 10, Critical |
| Last IOC activity (CYFIRMA) | 29 Sep 2026 |
| EW database, Q3 2026 | 4 campaigns; Q2 at least 1. Sighted July 3, August 3, September 3; none first seen in Q3. |
| Attribution basis | 3 of 4 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | CosmicDuke, MiniDuke, flipflop, freshfire | 2 sole-attributed campaigns, 1 shared |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | TrickBot, Zeus (Zbot) | 1 sole-attributed campaign, 1 shared |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | Cobalt Strike | 2 sole-attributed campaigns |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | FlawedAmmyy RAT | Shared campaign only (1) |
| Device-code phishing and Microsoft 365 credential harvesting | T1566 Phishing; T1528 Steal Application Access Token | Not recorded in the EW database | Public reporting cited above |
| DNS and HTTP manipulation through compromised captive portals | T1557 Adversary-in-the-Middle | Not recorded in the EW database | Public reporting cited above |
| Fake update pages delivering the CornFlake RAT | T1204.002 User Execution: Malicious File | Not recorded in the EW database | Public reporting cited above |
What this means for you: Cozy Bear
TA505
During the period from July to September 2026, TA505, a financially motivated, Russian-speaking cybercrime group, maintained a consistent operational presence, targeting organisations across financial services, government, telecommunications, technology, and other enterprise sectors in North America, Europe, the Middle East, and Asia-Pacific. Threat-intelligence reporting for 2026 indicates that TA505 continued to operate through financially motivated campaigns involving persistent access, malware delivery, and ransomware-related activity. The group demonstrated continued interest in enterprise applications, operating systems, databases, and internet-facing services as potential entry points into victim environments.
The group continued to employ backdoors, ransomware delivery mechanisms, credential theft, and post-compromise activity to establish and maintain access. Campaign reporting associated TA505 with malware and ransomware operations, including Cl0p and FlawedAmmyy RAT, reflecting its continued ability to adapt its tooling to changing defensive environments. Its sustained targeting across multiple industries and regions demonstrates a persistent financially motivated threat, particularly for organisations with exposed enterprise applications and externally accessible infrastructure.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | TA505 |
| Selected aliases | Graceful Spider, Gold Tahoe, Hive0065, SectorJ04, Chimborazo; Microsoft’s Lace Tempest overlaps TA505 and FIN11 |
| Alias caveats | The CYFIRMA list files Evil Corp and Silence Group under TA505. Both are tracked as separate groups by most vendors. |
| Origin | Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Financial (ransomware and data-theft extortion) |
| Sponsorship (public attribution) | None established. |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 29 Sep 2026 |
| EW database, Q3 2026 | 3 campaigns; Q2 at least 3. Sighted July 3, August 2, September 2; none first seen in Q3. |
| Attribution basis | 0 of 3 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | None identified in the data reviewed; public reporting describes affiliate recruitment and data-leak-site extortion. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | Zeus (Zbot) | Shared campaign only (1) |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | FlawedAmmyy RAT | Shared campaign only (1) |
| Ransomware deployment | T1486 Data Encrypted for Impact | Clop | Shared campaign only (1) |
| Mass exploitation of file-transfer software for data theft | T1190 Exploit Public-Facing Application; T1567 Exfiltration Over Web Service | Not recorded in the EW database | Public reporting cited above |
What this means for you: TA505
FANCY BEAR
During the period from July to September 2026, Fancy Bear (APT28) continued to conduct intelligence-driven cyber operations against government agencies, defence organisations, political institutions, and other strategically significant targets, particularly in Ukraine and Europe. Reporting published shortly before the period, and still the most recent public account of the group’s tradecraft, includes the group’s GRU-linked router-hijacking operation, detailed in 7 April 2026 advisories from the FBI and NSA with international partners and, separately, the UK NCSC, in which internet-facing SOHO routers (including TP-Link devices via CVE-2023-50224) were compromised to alter DNS settings, redirect traffic, and harvest credentials and OAuth tokens; the FBI announced a court-authorised disruption of the router network on the same day. A long-running campaign against Ukrainian anti-corruption and prosecutorial bodies, reported in April 2026 by Ctrl-Alt-Intel and described by Ukraine’s SSSCIP as consistent with APT28, was also reported in April 2026 and is consistent with the group’s established targeting, demonstrating the group’s continued focus on obtaining politically and strategically valuable information.
The threat actor continued to leverage vulnerability exploitation, compromised network infrastructure, malicious documents, credential theft, and traffic redirection to obtain access and collect intelligence. Earlier exploitation of vulnerabilities in Microsoft Office and other externally exposed technologies illustrates the group’s continued preference for exploiting weaknesses in commonly deployed enterprise technologies. Fancy Bear’s combination of infrastructure compromise and targeted spear-phishing continues to make monitoring of vulnerable edge devices, email infrastructure, authentication events, and suspicious network-routing changes important for organisations operating in strategically sensitive sectors.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Fancy Bear |
| Selected aliases | APT28, Forest Blizzard (formerly STRONTIUM), Sofacy, Sednit, Pawn Storm, BlueDelta, Fighting Ursa, Unit 26165 |
| Alias caveats | The CYFIRMA list includes Unit 74455, which is the GRU unit linked to Sandworm, not APT28. UAC-0063 and TAG-110 are tracked as separate clusters that some vendors associate with APT28. |
| Origin | Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage and influence operations |
| Sponsorship (public attribution) | Russian military intelligence (GRU) Unit 26165, per US DOJ indictment (July 2018) and the April 2026 FBI and NSA advisory. |
| CYFIRMA exposure score | 9 of 10, Critical |
| Last IOC activity (CYFIRMA) | 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal) |
| EW database, Q3 2026 | 3 campaigns; Q2 at least 1. Sighted July 1, August 2, September 1; none first seen in Q3. |
| Attribution basis | 0 of 3 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | Apache Tomcat Manager, Drupal, Jira, Jira Server and Data Center, Joomla!, phpMyAdmin and 6 more | Shared campaign only (1) |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | RDP | Shared campaign only (1) |
| SOHO router compromise (TP-Link, CVE-2023-50224) and Roundcube exploitation | T1190 Exploit Public-Facing Application | Not recorded in the EW database | Public reporting cited above |
| DNS redirection to harvest passwords and tokens | T1557 Adversary-in-the-Middle | Not recorded in the EW database | Public reporting cited above |
| Malicious documents | T1566.001 Phishing: Spearphishing Attachment | Not recorded in the EW database | Public reporting cited above |
Excluded as tooling of co-attributed actors: Persistent backdoor implant; Financial trojan / botnet distribution; RAT / remote access implant.
What this means for you: Fancy Bear
During the period from July to September 2026, FIN11, a financially motivated, Russian-speaking cybercrime group, continued to demonstrate a persistent, financially motivated intrusion capability, targeting financial institutions, government organisations, industrial enterprises, telecommunications providers, technology companies, and critical infrastructure. Reporting for 2026 indicates that the group maintained a strong focus on ransomware-enabled compromises while also conducting intelligence gathering and network reconnaissance to maximise the value of compromised environments. The actor was observed across multiple geographic regions, reflecting a broad enterprise-targeting strategy rather than concentration on a single country or sector.
The group continued to employ VPN exploitation, credential theft, remote-access tools, network reconnaissance, lateral movement, and ransomware during post-compromise operations. Reported malware families and capabilities included Clop, FlawedAmmyy RAT, and DEWMODE, demonstrating a focused but adaptable operational toolkit. FIN11’s continued combination of access acquisition, persistence, data theft, and ransomware deployment indicates that organisations should closely monitor externally exposed remote-access technologies and unusual authentication, administrative, and lateral-movement activity.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | FIN11 |
| Selected aliases | TEMP.Warlock; Lace Tempest (Microsoft, overlaps TA505) |
| Origin | Global (CYFIRMA list); Russia, ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Financial (ransomware and data-theft extortion) |
| Sponsorship (public attribution) | None established. |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal) |
| EW database, Q3 2026 | 2 campaigns; Q2 at least 3. Sighted July 1, August 2, September 2; none first seen in Q3. |
| Attribution basis | 1 of 2 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | None identified in the data reviewed; public reporting describes affiliate recruitment and data-leak-site extortion. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | FlawedAmmyy RAT | 1 sole-attributed campaign |
| Webshell deployment | T1505.003 Server Software Component: Web Shell | DEWMODE | 1 sole-attributed campaign |
| Ransomware deployment | T1486 Data Encrypted for Impact | Clop, Ryuk | 1 sole-attributed campaign |
| VPN exploitation and lateral movement | T1133 External Remote Services; T1021 Remote Services | Not recorded in the EW database | Public reporting cited above |
What this means for you: FIN11
GAMAREDON
This profile is based on public reporting; the CYFIRMA campaign database holds only shared, low-confidence campaigns for this actor in Q3 (see below). During the period from July to September 2026, Gamaredon continued to conduct persistent cyber-espionage activity primarily against government and military organisations in Ukraine, while maintaining a strong focus on information collection and long-term access. In June 2026, Sekoia documented Gamaredon, an FSB-linked group, delivering the GammaWorm and GammaSteel tools through booby-trapped RAR archives that abused a WinRAR flaw (CVE-2025-8088), and ESET’s 25 June 2026 report on the group’s 2025 activity described new PowerShell tooling, a growing reliance on legitimate third-party services to hide command-and-control and stolen data, and a continued focus solely on Ukraine. Spear-phishing lures themed on military and legal communications, such as troop-movement and court-summons themes, illustrate the group’s continued use of highly contextualised social-engineering lures.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Gamaredon |
| Selected aliases | Primitive Bear, Shuckworm, Armageddon, Trident Ursa, Actinium, UAC-0010, Iron Tilden |
| Origin | Russia (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage |
| Sponsorship (public attribution) | Russian Federal Security Service (FSB), per Security Service of Ukraine attribution (November 2021). |
| CYFIRMA exposure score | 9 of 10, Critical |
| Last IOC activity (CYFIRMA) | 29 Sep 2026 |
| EW database, Q3 2026 | 2 campaigns; Q2 at least 2. Sighted July 2, August 2, September 2; none first seen in Q3. |
| Attribution basis | 0 of 2 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Spear phishing with RAR archives exploiting WinRAR CVE-2025-8088 | T1566.001 Spear phishing Attachment; T1203 Exploitation for Client Execution | Not recorded in the EW database | Public reporting cited above |
| PowerShell tooling | T1059.001 Command and Scripting Interpreter: PowerShell | Not recorded in the EW database | Public reporting cited above |
| Legitimate web services for command and control and exfiltration | T1102 Web Service; T1567 Exfiltration Over Web Service | Not recorded in the EW database | Public reporting cited above |
What this means for you: Gamaredon
TECHNIQUES OBSERVED

Campaigns sighted July to September 2026 per inferred technique: 27 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures.
TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. Top 15 of 48 technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Also recorded: Remote desktop software, Routers, Atlassian Confluence, Citrix NetScaler ADC, Citrix NetScaler Gateway, Cloud Migration Services, Content Delivery Networks, Content Management System, Dropbox, File Hosting System, Firewall management software, Firewall software, Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, Go, GitHub, Internet-facing Web Applications, Ivanti Connect Secure, Ivanti Policy Secure, Java, Microsoft .NET Framework, Microsoft Exchange Server, Network Monitoring Tools, Perl, PowerShell, Server Message Block (SMB), SQL Server Performance Monitoring Tools, TOR, Transportation & Logistics Software, USAHerds, VMware vCenter Server, Windows Management Instrumentation (WMI).
TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 47 countries. Also recorded: Italy, Malaysia, Netherlands, Vietnam, Spain, Cambodia, Oman, Israel, Turkey, Qatar, China, Norway, Indonesia, New Zealand, Brazil, Ukraine, Cyprus, Kuwait, Iraq, Syria, Yemen, Iran, Lebanon, Bahrain, Jordan, Egypt, Austria, South Africa, Argentina, Macao, Switzerland, Belgium.
TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted.
DATABASE VIEW OF THE CHINA NEXUS, Q3 2026
Techniques mapped to MITRE ATT&CK
| Technique (inferred) | MITRE ATT&CK | Campaigns | Tooling or technology recorded |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | 13 | BLACKCOFFEE, LODEINFO, PlugX, ShadowPad, Volt (as recorded), Winnti and 3 more |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | 8 | Citrix NetScaler ADC, Citrix NetScaler Gateway, firewall management software, firewall software, Fortinet FortiOS, Fortinet FortiProxy and 7 more |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | 4 | RDP, remote desktop software |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | 3 | Cobalt Strike |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | 3 | NukeSped RAT, gh0st RAT |
| Loader / downloader staging | T1105 Ingress Tool Transfer | 3 | HLOADER, MultiPlug, PubLoad, RustBucket, SUGARLOADER |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | 3 | Apache Log4j, Atlassian Confluence, Microsoft Exchange Server, USAHerds, VMware vCenter Server |
| IoT botnet exploitation (Mirai) | T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service | 2 | Mirai |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | 2 | Emotet, TrickBot |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | 2 | Azorult, FormBook, RedLine Stealer |
| Commodity malware staging | T1105 Ingress Tool Transfer | 2 | unnamed commodity malware, FlyStudio |
| Firmware-level implant | T1542.001 Pre-OS Boot: System Firmware | 1 | MoonBounce |
| Privilege escalation tooling | T1134.001 Access Token Manipulation: Token Impersonation/Theft | 1 | Bad Potato |
| Webshell deployment | T1505.003 Server Software Component: Web Shell | 1 | ASPXSpy |
| Cryptomining | T1496 Resource Hijacking | 1 | Cryptominer |
| Ransomware deployment | T1486 Data Encrypted for Impact | 1 | Clop |
| Trojanised cryptocurrency application | T1204.002 User Execution: Malicious File | 1 | AppleJeus |
MISSION2074
During the period from July to September 2026, MISSION2074 continued to demonstrate sustained cyber-espionage activity targeting government, telecommunications, transportation, energy, technology, healthcare, and critical infrastructure organisations across Europe, North America, the Middle East, and Asia-Pacific. The group leveraged persistent backdoors, remote-access trojans, VPN and router exploitation, and post-exploitation frameworks to establish and maintain access within targeted environments. MISSION2074 was the most frequently linked China-nexus actor in the CYFIRMA campaign database this quarter (12 campaigns), with IT, government, and professional services the most frequently recorded sectors.
The threat actor continued to employ credential theft, reconnaissance, lateral movement, remote desktop abuse, and data exfiltration while using legitimate network infrastructure and commonly deployed enterprise technologies to reduce detection. Malware families observed across campaigns tracked under this CYFIRMA-designated cluster included PlugX, Sidewalk, Winnti, and Zingdoor, alongside families more commonly associated with other actors or with commodity botnets, such as NukeSped (Lazarus), LODEINFO (APT10/MirrorFace), and Mirai; these overlaps point to shared or aggregated tooling rather than exclusive attribution, and supported persistence and intelligence collection. MISSION2074’s sustained targeting of organisations involved in communications, technology, transportation, and critical infrastructure indicates a continued emphasis on obtaining strategic intelligence and maintaining long-term access rather than conducting immediately disruptive operations.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | MISSION2025 (CYFIRMA list); MISSION2074 (EW database, used in this report) |
| Selected aliases | APT41, Brass Typhoon (formerly BARIUM), Wicked Panda, Earth Baku, Double Dragon |
| Alias caveats | The CYFIRMA list names this actor MISSION2025 and merges several APT41 sub-clusters under it (Earth Longzhi, Grayfly, Blackfly, RedGolf, SparklingGoblin). “Winnti” is used both as a group name and as a malware family shared by many China-nexus actors. |
| Origin | China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage, with financially motivated activity |
| Sponsorship (public attribution) | US DOJ indictments (September 2020) charged individuals linked to the activity, some associated with Chengdu 404 Network Technology. |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal) |
| EW database, Q3 2026 | 12 campaigns; Q2 at least 11. Sighted July 7, August 10, September 9; 1 first seen in Q3. |
| Attribution basis | 4 of 12 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.5 (highest 10) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | PlugX, ShadowPad, Volt (as recorded), Winnti, Winnti for Linux, Winnti for Windows and 1 more | 3 sole-attributed campaigns, 5 shared |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | firewall management software, firewall software, Ivanti Connect Secure, Ivanti Policy Secure, routers, VPN solutions | 1 sole-attributed campaign, 2 shared |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | RDP | 2 sole-attributed campaigns |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | Apache Log4j, USAHerds, VMware vCenter Server | 1 sole-attributed campaign, 1 shared |
| IoT botnet exploitation (Mirai) | T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service | Mirai | 1 sole-attributed campaign, 1 shared |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | Cobalt Strike | 1 sole-attributed campaign, 1 shared |
| Firmware-level implant | T1542.001 Pre-OS Boot: System Firmware | MoonBounce | Shared campaign only (1) |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | Azorult, RedLine Stealer | Shared campaign only (1) |
| Commodity malware staging | T1105 Ingress Tool Transfer | FlyStudio | Shared campaign only (1) |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | TrickBot | Shared campaign only (1) |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | NukeSped RAT | Shared campaign only (1) |
| Privilege escalation tooling | T1134.001 Access Token Manipulation: Token Impersonation/Theft | Bad Potato | 1 sole-attributed campaign |
What this means for you: MISSION2074
STONE PANDA
STONE PANDA
During the period from July to September 2026, Stone Panda (APT10/menuPass) continued to demonstrate persistent cyber-espionage activity against government agencies, financial institutions, telecommunications providers, technology organisations, and critical infrastructure across North America, Europe, and the Asia-Pacific region. The group leveraged VPN and router exploitation, web shells, persistent backdoors, remote-access trojans, and post-exploitation frameworks to establish footholds and maintain long-term access. Stone Panda was the second most frequently linked China-nexus actor in the CYFIRMA campaign database this quarter (8 campaigns), with professional services, manufacturing, telecommunications, and IT the most frequently recorded sectors.
The threat actor continued to target web applications, database management systems, email services, network monitoring platforms, and internet-facing infrastructure, while employing credential theft and lateral movement to expand access. Reported toolsets included LODEINFO, gh0st RAT, ASPXSpy, and Zingdoor, alongside families more commonly associated with other actors, such as Winnti (APT41) and BLACKCOFFEE (APT17), which likely reflect shared tooling or aggregated reporting; together they supported persistence, surveillance, and intelligence collection. The group’s continued interest in sensitive technologies and strategically important organisations indicates a sustained focus on long-term intelligence gathering, technology acquisition, and access development.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Stone Panda |
| Selected aliases | APT10, menuPass, Cicada, Red Apollo, POTASSIUM, Cloud Hopper |
| Alias caveats | The CYFIRMA list includes MirrorFace and Earth Kasha (often assessed as an APT10 sub-group), and Bronze Starlight and UAT-7290, which are tracked separately by most vendors. |
| Origin | China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage |
| Sponsorship (public attribution) | US DOJ indictment (December 2018) linked members to the Ministry of State Security (MSS) Tianjin State Security Bureau. |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 30 Sep 2026 |
| EW database, Q3 2026 | 8 campaigns; Q2 at least 9. Sighted July 6, August 6, September 7; none first seen in Q3. |
| Attribution basis | 3 of 8 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.4 (highest 10) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | BLACKCOFFEE, LODEINFO, Volt (as recorded), Winnti, Zingdoor | 1 sole-attributed campaign, 3 shared |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | Ivanti Connect Secure, Ivanti Policy Secure, routers, VPN solutions | Shared campaigns only (2) |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | Emotet | 1 sole-attributed campaign |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | gh0st RAT | 1 sole-attributed campaign |
| Webshell deployment | T1505.003 Server Software Component: Web Shell | ASPXSpy | 1 sole-attributed campaign |
| Ransomware deployment | T1486 Data Encrypted for Impact | Clop | Shared campaign only (1) |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | VMware vCenter Server | Shared campaign only (1) |
| IoT botnet exploitation (Mirai) | T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service | Mirai | Shared campaign only (1) |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | Cobalt Strike | Shared campaign only (1) |
What this means for you: Stone Panda
LEVIATHAN
During the period from July to September 2026, Leviathan (APT40) continued to conduct cyber-espionage operations against government, defence, maritime, aerospace, healthcare, manufacturing, transportation, and academic organisations across the Asia-Pacific region, Europe, North America, and other strategically important locations. The group maintained an emphasis on organisations possessing sensitive governmental, technological, maritime, and defence-related information. The CYFIRMA campaign database links Leviathan to three Q3 campaigns, with manufacturing, professional services, transport, and materials the most frequently recorded sectors.
The threat actor continued to rely on spear-phishing, exploitation of internet-facing systems, credential theft, web-based intrusion techniques, and malware-enabled persistence to gain and maintain access. Its operational approach emphasizes reconnaissance and intelligence collection, with compromised environments potentially providing access to sensitive organisational and strategic information. Leviathan’s continued presence across technology, government, maritime, and critical infrastructure-related targets highlights the importance of monitoring exposed applications, authentication activity, suspicious email traffic, and abnormal outbound communications.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Leviathan |
| Selected aliases | APT40, Gadolinium, TEMP.Periscope, Kryptonite Panda, BRONZE MOHAWK, ISLANDDREAMS, MUDCARP |
| Origin | China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage |
| Sponsorship (public attribution) | US DOJ indictment (July 2021) linked members to the MSS Hainan State Security Department; Australian-led joint advisory (July 2024). |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 21 Sep 2026 |
| EW database, Q3 2026 | 3 campaigns; Q2 at least 1. Sighted July 2, August 3, September 3; none first seen in Q3. |
| Attribution basis | 1 of 3 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.0 (highest 8) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | RDP, remote desktop software | 1 sole-attributed campaign |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | VPN | 1 sole-attributed campaign |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | Apache Log4j, Atlassian Confluence, Microsoft Exchange Server | 1 sole-attributed campaign |
| Spear phishing | T1566 Phishing | Not recorded in the EW database | Public reporting cited above |
What this means for you: Leviathan
HAFNIUM
During the period from July to September 2026, Hafnium (Silk Typhoon) continued to demonstrate a persistent cyber-espionage capability targeting government, technology, telecommunications, transportation, and critical infrastructure organisations across Europe, North America, Asia-Pacific, and the Middle East. The CYFIRMA campaign database links Hafnium to two Q3 campaigns, both shared with other China-nexus actors, with government, IT, finance, and telecommunications as the recorded sectors.
The group continued to employ internet-facing infrastructure exploitation, VPN and router compromise, persistent backdoors, downloader frameworks, and post-exploitation tools to establish long-term access. Its activity demonstrated continued interest in enterprise applications, operating systems, databases, network monitoring platforms, and remote-access technologies. The group’s persistent targeting of organisations holding sensitive governmental and technological information indicates an ongoing emphasis on stealthy access, intelligence collection, credential compromise, and long-term persistence rather than overt disruption.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | HAFNIUM |
| Selected aliases | Silk Typhoon, Murky Panda |
| Alias caveats | The CYFIRMA list includes UNC5221, which Mandiant tracks as a separate cluster. |
| Origin | China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage |
| Sponsorship (public attribution) | US DOJ charges in 2025 linked individuals involved in this activity to China’s Ministry of State Security. |
| CYFIRMA exposure score | 8 of 10, High |
| Last IOC activity (CYFIRMA) | 13 Sep 2026 (bulk timestamp shared by many actors, not an activity signal) |
| EW database, Q3 2026 | 2 campaigns; Q2 at least 2. Sighted July 0, August 2, September 2; none first seen in Q3. |
| Attribution basis | 0 of 2 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 9.3 (highest 10) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitchManager, routers, VPN solutions | Shared campaigns only (2) |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | Volt (as recorded), Winnti, Zingdoor | Shared campaign only (1) |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | Cobalt Strike | Shared campaign only (1) |
| Exploitation of internet-facing servers | T1190 Exploit Public-Facing Application | Not recorded in the EW database | Public reporting cited above |
| Web shells | T1505.003 Server Software Component: Web Shell | Not recorded in the EW database | Public reporting cited above |
Excluded as tooling of co-attributed actors: IoT botnet exploitation (Mirai).
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | FormBook | 1 sole-attributed campaign |
| Loader / downloader staging | T1105 Ingress Tool Transfer | MultiPlug | 1 sole-attributed campaign |
What this means for you: TICK
EMISSARY PANDA
During the period from July to September 2026, Emissary Panda (APT27/LuckyMouse) continued to conduct long-term cyber-espionage operations against government, defence, aerospace, technology, telecommunications, and other strategic organisations. The CYFIRMA campaign database links Emissary Panda to three Q3 campaigns, all shared with other actors, with government, IT, professional services, finance, and manufacturing as the recorded sectors. The group continued to demonstrate an access-focused operational model, seeking persistent footholds that can support extended intelligence collection.
The threat actor continued to leverage internet-facing applications, credential theft, web-based intrusion techniques, malware, and legitimate administrative functionality to establish and maintain access. Its operations typically emphasize stealth and persistence, allowing compromised environments to be used for reconnaissance, lateral movement, and information theft over extended periods. Emissary Panda’s continued activity against government and strategic technology organisations highlights the importance of monitoring exposed web applications, authentication events, privileged accounts, unusual administrative behaviour, and anomalous outbound traffic.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Emissary Panda |
| Selected aliases | APT27, LuckyMouse, Iron Tiger, BRONZE UNION, TG-3390, Budworm, Linen Typhoon |
| Alias caveats | The CYFIRMA list includes “EternalBlue”, which is an exploit, not an actor. A second CYFIRMA entry, Goblin Panda, carries APT27 aliases, but Goblin Panda (Cycldek) is a different actor. The EW database holds Emissary Panda, APT27 and Iron Tiger as separate names; all are counted here. |
| Origin | China (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Espionage, with for-profit intrusion activity |
| Sponsorship (public attribution) | US DOJ indictment (March 2025) charged two APT27 members and described for-profit hacking with ties to the MSS. |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 25 Sep 2026 |
| EW database, Q3 2026 | 3 campaigns (Emissary Panda 2, APT27 1); Q2 at least 2. Sighted July 2, August 2, September 3; none first seen in Q3. |
| Attribution basis | 0 of 3 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.5 (highest 10) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | routers, VPN, VPN appliances, VPN solutions | Shared campaigns only (2) |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | Volt (as recorded) | Shared campaign only (1) |
| Exploitation of internet-facing applications | T1190 Exploit Public-Facing Application | Not recorded in the EW database | Public reporting cited above |
| Credential theft | T1003 OS Credential Dumping (typical procedure, not recorded per campaign) | Not recorded in the EW database | Public reporting cited above |
Excluded as tooling of co-attributed actors: Cryptomining; Trojanised cryptocurrency application; Loader / downloader staging; RAT / remote access implant; Commodity malware staging.
What this means for you: Emissary Panda
TECHNIQUES OBSERVED

Campaigns sighted July to September 2026 per inferred technique: 14 campaigns. MITRE ATT&CK IDs in brackets; mapping is inferred from recorded malware and technology, not observed procedures.
TARGETED TECHNOLOGIES

Campaigns per recorded technology, July to September 2026. Top 15 of 20 technologies; VPN variants merged. Generic entries (unspecified operating system or web application) are kept as recorded. Also recorded: Server Message Block (SMB), Software Components, VPN gateways and appliances, VMware, Web Portal Software
TARGETED COUNTRIES

Campaigns per victim country, July to September 2026. Top 15 of 27 countries. Also recorded: Denmark, Morocco, Norway, Argentina, China, Macao, the Netherlands, Malaysia, Indonesia, Canada, Italy, France.
TARGETED INDUSTRIES

Campaigns per broad sector, July to September 2026, using the database’s 14 sector categories. The finer industry labels mixed three taxonomies and are not charted.
DATABASE VIEW OF THE NORTH KOREA NEXUS, Q3 2026
Techniques mapped to MITRE ATT&CK
| Technique (inferred) | MITRE ATT&CK | Campaigns | Tooling or technology recorded |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | 3 | Dridex, Emotet, Glupteba, Tofsee, TrickBot |
| Trojanised cryptocurrency application | T1204.002 User Execution: Malicious File | 3 | AppleJeus |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | 3 | NukeSped RAT |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | 3 | CivetQ, Winnti |
| Loader / downloader staging | T1105 Ingress Tool Transfer | 2 | HLOADER, RustBucket, SUGARLOADER |
| Commodity malware staging | T1105 Ingress Tool Transfer | 2 | unnamed commodity malware, FlyStudio |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | 1 | Microsoft Exchange Server |
| Cryptomining | T1496 Resource Hijacking | 1 | Cryptominer |
| Ransomware deployment | T1486 Data Encrypted for Impact | 1 | Sodinokibi (REvil) |
| EDR / security tool tampering | T1562.001 Impair Defenses: Disable or Modify Tools | 1 | AuKill |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | 1 | Azorult, RedLine Stealer |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | 1 | VPN, VPN solutions |
LAZARUS GROUP
During the period from July to September 2026, Lazarus Group continued to demonstrate a highly adaptable operational capability through a combination of cyber-espionage, financial theft, supply-chain compromise, and social-engineering campaigns targeting cryptocurrency, financial, technology, defence, aerospace, and software organisations worldwide. The group maintained a strong focus on cryptocurrency and digital-asset environments while also expanding its espionage activity against defence and aerospace organisations. Lazarus Group was the most frequently linked actor in the CYFIRMA campaign database this quarter (14 campaigns, nine attributed to it alone), and public reporting highlighted continued Operation Dream Job activity targeting professionals through fraudulent employment opportunities. In August 2026, Check Point Research detailed a new Dream Job wave that used fake recruiter offers and trojanised PDF viewers against defence and aerospace staff, exploited the Windows AFD.sys zero-day CVE-2026-68820 (patched on 11 August 2026) to deploy an updated FudModule rootkit, and delivered the new Troy backdoor, with confirmed victims in France, Germany, Brazil, and India.
The threat actor continued to employ social engineering, malicious documents and applications, supply-chain compromises, credential theft, and exploitation of vulnerabilities to establish initial access and maintain persistence. Lazarus Group’s continued combination of financially motivated operations, sophisticated social engineering, zero-day exploitation, and supply-chain activity demonstrates an evolving threat profile that can make detection increasingly difficult, particularly for organisations operating in the cryptocurrency, technology, defence, aerospace, and financial sectors.
Profile
| Field | Detail |
| Tracked as (CYFIRMA list) | Lazarus Group |
| Selected aliases | HIDDEN COBRA, Diamond Sleet (formerly ZINC), Labyrinth Chollima |
| Alias caveats | The CYFIRMA list treats Lazarus as an umbrella covering APT38 (Bluenoroff), Andariel, TraderTraitor (Jade Sleet), Famous Chollima, Moonstone Sleet and others. Many vendors track these as distinct clusters under the Reconnaissance General Bureau. |
| Origin | North Korea (CYFIRMA list); ‘Confirmed’ per EW database (source label, not independently verified) |
| Motivation | Financial theft (notably cryptocurrency) and espionage |
| Sponsorship (public attribution) | North Korea’s Reconnaissance General Bureau, per US Treasury sanctions (September 2019). |
| CYFIRMA exposure score | 10 of 10, Critical |
| Last IOC activity (CYFIRMA) | 29 Sep 2026 |
| EW database, Q3 2026 | 14 campaigns; Q2 at least 9. Sighted July 8, August 8, September 12; 1 first seen in Q3. |
| Attribution basis | 9 of 14 Q3 campaigns attributed to this actor alone |
| Average campaign risk score, Q3 | 8.3 (highest 10) |
| Handlers and channels | Not applicable (state-directed actor); none identified in the data reviewed. |
Recent activity and shifts
TTPs mapped to MITRE ATT&CK
| Technique | MITRE ATT&CK | Tooling or technology recorded | Basis |
| Trojanised cryptocurrency application | T1204.002 User Execution: Malicious File | AppleJeus | 2 sole-attributed campaigns, 1 shared |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | NukeSped RAT | 1 sole-attributed campaign, 2 shared |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | Dridex, Emotet, Glupteba, Tofsee, TrickBot | 2 sole-attributed campaigns, 1 shared |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | CivetQ, Winnti | Shared campaigns only (3) |
| Loader / downloader staging | T1105 Ingress Tool Transfer | HLOADER, RustBucket, SUGARLOADER | 1 sole-attributed campaign, 1 shared |
| Commodity malware staging | T1105 Ingress Tool Transfer | unnamed commodity malware, FlyStudio | Shared campaigns only (2) |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | VPN, VPN solutions | Shared campaign only (1) |
| Cryptomining | T1496 Resource Hijacking | Cryptominer | 1 sole-attributed campaign |
| Ransomware deployment | T1486 Data Encrypted for Impact | Sodinokibi (REvil) | 1 sole-attributed campaign |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | Azorult, RedLine Stealer | Shared campaign only (1) |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | Microsoft Exchange Server | 1 sole-attributed campaign |
| EDR / security tool tampering | T1562.001 Impair Defenses: Disable or Modify Tools | AuKill | Shared campaign only (1) |
| Fake recruiter lures and trojanised PDF viewers | T1566 Phishing; T1204.002 User Execution: Malicious File | Not recorded in the EW database | Public reporting cited above |
| Windows AFD.sys zero-day (CVE-2026-68820) for privilege escalation | T1068 Exploitation for Privilege Escalation | Not recorded in the EW database | Public reporting cited above |
| FudModule rootkit tampering with security tooling | T1014 Rootkit; T1562.001 Impair Defenses | Not recorded in the EW database | Public reporting cited above |
What this means for you: Lazarus Group
OUTLOOK: NEXT 90 DAYS
PRIORITISED MITIGATIONS
| Priority | Action | Addresses | Actors most relevant |
| 1 | Inventory, patch and integrity-check internet-facing Fortinet, Ivanti, Citrix NetScaler, VMware vCenter, VPN gateways and routers; review admin accounts and configuration changes since July 2026 | T1190, T1133 | MISSION2074, Stone Panda, Hafnium, Emissary Panda, APT34, Fox Kitten |
| 2 | Remove direct RDP and SSH exposure; enforce MFA on all remote access | T1021.001, T1133 | FIN7, MISSION2074, Leviathan, TICK |
| 3 | Enable EDR tamper protection and vulnerable-driver blocking; deploy the August 2026 Windows update (CVE-2026-68820) | T1562.001, T1068 | FIN7, Lazarus Group |
| 4 | Hunt for DLL side-loading, Winnti, ShadowPad, PlugX and Cobalt Strike beacons on servers | T1071, T1055 | MISSION2074, Stone Panda, Cozy Bear |
| 5 | Restrict device-code sign-in and monitor OAuth consents and token use | T1528, T1566 | Cozy Bear |
| 6 | Scan web roots on IIS, Exchange and file-transfer servers for web shells; patch Log4j, Confluence and Exchange | T1505.003, T1190 | Stone Panda, FIN11, Leviathan |
| 7 | Test ransomware recovery against encryption and data-theft extortion (Clop, INC, Sodinokibi) | T1486, T1567 | FIN11, TA505, FIN7, APT34 |
| 8 | Extend EDR to macOS, restrict unsigned software, brief staff on recruiter and fake-update lures | T1204.002 | Lazarus Group, Cozy Bear |
IOCs and platform-specific hunting queries are not included: neither source dataset carries indicators.
CONCLUSION
During July to September 2026, 48 campaigns linked to Iranian, Russian, Chinese, and North Korean actors were sighted in the CYFIRMA campaign database, compared to at least 33 in Q2. Most were long-running: only three were first seen in the quarter, and 21 were sighted in every month.
China remains the largest nexus (27 campaigns), with MISSION2074 and Stone Panda stable at a high level and persistent backdoors (Winnti, ShadowPad, PlugX) and edge-device exploitation the dominant recorded tradecraft. North Korean activity rose late in the quarter: Lazarus Group was linked to 14 campaigns, nine attributed to it alone, with a new loader set first seen in September and, in public reporting, a Windows zero-day used against defence and aerospace staff. Russian activity is spread across financially motivated and state-linked groups with a thin database base outside Cozy Bear. Iranian evidence is the weakest and rests mainly on public reporting.
Shared attribution is common: 21 of 48 campaigns are linked to more than one actor. This is consistent with overlapping tooling and indicator clustering and is not treated as evidence of collaboration. Where the database is thin, this report has relied on public reporting and says so.
The prioritised mitigations in the Outlook section address the techniques most frequently recorded this quarter: internet-facing edge devices, exposed RDP and SSH, EDR tamper protection, backdoor and beacon hunting, identity controls and ransomware recovery. They are based on the intelligence available at the time of writing and should be read alongside the customer’s own controls and monitoring.
APPENDIX A: CHART DATA
A1. Campaigns by nexus, Q3 against Q2
| Nexus | Q3 campaigns | Q2 campaigns (min) |
| Iran | 4 | 2 |
| Russia | 13 | 8 |
| China | 27 | 22 |
| North Korea | 14 | 9 |
A2. Campaigns sighted per month by nexus
| Month | Iran | Russia | China | North Korea | All four (distinct) |
| July 2026 | 3 | 8 | 18 | 8 | 30 |
| August 2026 | 2 | 11 | 21 | 8 | 35 |
| September 2026 | 3 | 11 | 23 | 12 | 40 |
A3. Profiled actors
| Actor | Nexus | Q3 campaigns | Q2 campaigns (min) | Attributed alone (Q3) | CYFIRMA exposure score |
| APT34 (OilRig) | Iran | 3 | 1 | 0 | 9 |
| Fox Kitten | Iran | 1 | 1 | 0 | 8 |
| FIN7 | Russia | 4 | 3 | 1 | 9 |
| Cozy Bear | Russia | 4 | 1 | 3 | 9 |
| TA505 | Russia | 3 | 3 | 0 | 10 |
| Fancy Bear | Russia | 3 | 1 | 0 | 9 |
| FIN11 | Russia | 2 | 3 | 1 | 10 |
| Gamaredon | Russia | 2 | 2 | 0 | 9 |
| MISSION2074 | China | 12 | 11 | 4 | 10 |
| Stone Panda | China | 8 | 9 | 3 | 10 |
| Leviathan | China | 3 | 1 | 1 | 10 |
| Hafnium | China | 2 | 2 | 0 | 8 |
| TICK | China | 2 | 1 | 2 | 10 |
| Emissary Panda | China | 3 | 2 | 0 | 10 |
| Lazarus Group | North Korea | 14 | 9 | 9 | 10 |
A4. Victim countries by nexus, Q3 (campaigns), as charted
| Country | Iran | Russia | China | North Korea |
| Japan | 2 | 13 | 24 | 10 |
| United States | 3 | 13 | 23 | 9 |
| United Kingdom | 3 | 9 | 15 | 5 |
| India | 1 | 5 | 16 | 6 |
| Australia | 0 | 6 | 15 | 5 |
| South Korea | 1 | 9 | 10 | 5 |
| Germany | 3 | 4 | 11 | 4 |
| Taiwan | 0 | 3 | 13 | 4 |
| Saudi Arabia | 3 | 3 | 8 | 2 |
| Thailand | 0 | 4 | 8 | 3 |
| Philippines | 0 | 2 | 8 | 2 |
| United Arab Emirates | 3 | 1 | 5 | 2 |
| France | 2 | 3 | 5 | 1 |
| Canada | 1 | 3 | 5 | 1 |
| Singapore | 0 | 3 | 5 | 2 |
| Malaysia | 0 | 2 | 3 | 1 |
| Vietnam | 0 | 2 | 3 | 0 |
| Ukraine | 1 | 2 | 1 | 0 |
| Qatar | 1 | 0 | 2 | 0 |
| Oman | 1 | 0 | 2 | 0 |
| Israel | 1 | 0 | 2 | 0 |
| Austria | 1 | 0 | 1 | 0 |
| South Africa | 1 | 0 | 1 | 0 |
| Russia | 0 | 0 | 0 | 1 |
| Mongolia | 0 | 0 | 0 | 1 |
Every country that appears in any nexus chart (top 15 per nexus). Iran excludes the campaign carrying North Korean tooling. Regional labels (Europe, Africa, Worldwide, ALL) excluded.
A5. Sectors by nexus, Q3 (campaigns), as charted
| Sector | Iran | Russia | China | North Korea |
| Information Technology | 2 | 7 | 17 | 9 |
| Professional Goods & Services | 2 | 7 | 20 | 5 |
| Manufacturing | 3 | 5 | 19 | 6 |
| Finance | 2 | 6 | 14 | 6 |
| Telecommunications & Media | 3 | 4 | 14 | 3 |
| Government & Civic | 3 | 4 | 12 | 4 |
| Transportation & Logistics | 0 | 5 | 10 | 5 |
| Energy & Utilities | 1 | 3 | 7 | 4 |
| Consumer Goods & Services | 1 | 2 | 8 | 4 |
| Healthcare | 0 | 3 | 6 | 3 |
| Materials | 0 | 3 | 6 | 2 |
| Automotive | 0 | 3 | 5 | 1 |
| Real Estate & Construction | 1 | 2 | 3 | 0 |
Uses the database’s 14 broad sector categories, which cover most but not all Q3 campaign records. Iran excludes the campaign carrying North Korean tooling.
A6. Techniques, Q3 against Q2 (all four nexuses, distinct campaigns)
| Technique (inferred) | MITRE ATT&CK | Q3 | Q2 (min) |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | 17 | 10 |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | 9 | 1 |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | 7 | 5 |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | 6 | 3 |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | 6 | 5 |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | 5 | 0 |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | 5 | 1 |
| Ransomware deployment | T1486 Data Encrypted for Impact | 5 | 3 |
| Loader / downloader staging | T1105 Ingress Tool Transfer | 4 | 2 |
| Trojanised cryptocurrency application | T1204.002 User Execution: Malicious File | 3 | 0 |
| Commodity malware staging | T1105 Ingress Tool Transfer | 3 | 2 |
| IoT botnet exploitation (Mirai) | T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service | 2 | 1 |
| Cryptomining | T1496 Resource Hijacking | 2 | 1 |
| Webshell deployment | T1505.003 Server Software Component: Web Shell | 2 | 2 |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | 2 | 1 |
| Firmware-level implant | T1542.001 Pre-OS Boot: System Firmware | 1 | 0 |
| Privilege escalation tooling | T1134.001 Access Token Manipulation: Token Impersonation/Theft | 1 | 0 |
| EDR / security tool tampering | T1562.001 Impair Defenses: Disable or Modify Tools | 1 | 0 |
Technology-based techniques (edge devices, named products, RDP) are not comparable across Q2 and Q3 because named products were added to the source data in September 2026.
A7. Techniques by nexus, Q3 (campaigns), as charted
| Technique (inferred) | MITRE ATT&CK | Iran | Russia | China | North Korea |
| Persistent backdoor implant | T1071 Application Layer Protocol (C2) | 0 | 5 | 13 | 3 |
| VPN / router / edge device exploitation | T1190 Exploit Public-Facing Application; T1133 External Remote Services | 2 | 0 | 8 | 1 |
| Financial trojan / botnet distribution | T1566 Phishing (typical delivery); T1105 Ingress Tool Transfer | 0 | 3 | 2 | 3 |
| RAT / remote access implant | T1071 Application Layer Protocol (C2); T1105 Ingress Tool Transfer | 0 | 2 | 3 | 3 |
| Ransomware deployment | T1486 Data Encrypted for Impact | 1 | 3 | 1 | 1 |
| Remote desktop exploitation | T1021.001 Remote Services: Remote Desktop Protocol; T1133 External Remote Services | 0 | 2 | 4 | 0 |
| Loader / downloader staging | T1105 Ingress Tool Transfer | 0 | 0 | 3 | 2 |
| Commodity malware staging | T1105 Ingress Tool Transfer | 1 | 0 | 2 | 2 |
| Post-exploitation framework (Cobalt Strike) | T1071.001 Web Protocols; T1055 Process Injection | 0 | 2 | 3 | 0 |
| Public-facing application exploitation (named products) | T1190 Exploit Public-Facing Application | 0 | 1 | 3 | 1 |
| Trojanised cryptocurrency application | T1204.002 User Execution: Malicious File | 0 | 0 | 1 | 3 |
| Cryptomining | T1496 Resource Hijacking | 1 | 1 | 1 | 1 |
| Infostealer deployment | T1555 Credentials from Password Stores; T1539 Steal Web Session Cookie | 0 | 0 | 2 | 1 |
| IoT botnet exploitation (Mirai) | T1110.001 Brute Force: Password Guessing; T1498 Network Denial of Service | 0 | 0 | 2 | 0 |
| Webshell deployment | T1505.003 Server Software Component: Web Shell | 0 | 1 | 1 | 0 |
| EDR / security tool tampering | T1562.001 Impair Defenses: Disable or Modify Tools | 0 | 1 | 0 | 1 |
| Privilege escalation tooling | T1134.001 Access Token Manipulation: Token Impersonation/Theft | 0 | 0 | 1 | 0 |
| Firmware-level implant | T1542.001 Pre-OS Boot: System Firmware | 0 | 0 | 1 | 0 |
APPENDIX B: CAMPAIGN REFERENCE, Q3 2026
| Campaign | Attributed actors | Nexus | First seen | Sighted in Q3 | Also in Q2 | Risk |
| bite | MISSION2074 | China | 2021-05-08 | Jul, Aug, Sep | Yes | 8 |
| Bush | TICK | China | 2020-01-09 | Jul, Aug, Sep | No | 8 |
| Citrix | NSCN2301 | China | 2023-07-18 | Jul, Aug, Sep | No | 8 |
| Dominion | MISSION2074, Salt Typhoon | China | 2026-01-23 | Aug, Sep | No | 9 |
| Double Blow | CCCN2101 | China | 2021-01-31 | Sep | Yes | 8 |
| Fast pace | MISSION2074 | China | 2020-01-12 | Jul, Aug, Sep | No | 8 |
| harts | Lazarus Group, MISSION2074 | China, North Korea | 2023-08-09 | Aug | No | 8 |
| Hegemon | MISSION2074, Salt Typhoon, Stone Panda, Volt Typhoon, Earth Estries, Hafnium | China | 2024-12-05 | Aug, Sep | Yes | 10 |
| hwasong | APT27, Lazarus Group, Oilrig | China, Iran, North Korea | 2024-06-15 | Jul, Sep | Yes | 10 |
| ivanti | MISSION2074, Stone Panda | China | 2024-01-15 | Jul, Aug, Sep | Yes | 9 |
| meteor | Lazarus Group, MISSION2074 | China, North Korea | 2023-02-04 | Jul, Aug, Sep | Yes | 10 |
| Oblivion | Stone Panda | China | 2020-11-12 | Jul, Sep | Yes | 10 |
| Panther@4& | Leviathan, Stone Panda | China | 2021-02-12 | Jul, Aug, Sep | No | 8 |
| reliable | Leviathan | China | 2021-01-21 | Jul, Aug, Sep | Yes | 8 |
| Sail | Emissary Panda, Fox Kitten, Gamaredon, Transparent Tribe | China, Iran, Russia | 2024-03-08 | Jul, Aug, Sep | Yes | 8 |
| Scissors | Leviathan, MISSION2074 | China | 2021-05-11 | Aug, Sep | No | 8 |
| Sound effect | Stone Panda | China | 2020-01-07 | Jul, Aug | No | 8 |
| Speed Up | TICK | China | 2021-04-04 | Jul, Aug, Sep | Yes | 8 |
| Stealth Attack | MISSION2074 | China | 2024-08-30 | Aug | No | 8 |
| Tailgate | Hafnium, US17IRGCorp, APT34 | China, Iran | 2022-09-15 | Aug, Sep | No | 8 |
| territorial integrity | Mustang Panda | China | 2023-04-06 | Jul, Aug, Sep | Yes | 8 |
| Thunderstorm | Emissary Panda, Volt Typhoon | China | 2024-09-28 | Aug, Sep | No | 8 |
| Victory | Stone Panda, TA505 | China, Russia | 2025-01-06 | Jul, Aug, Sep | Yes | 8 |
| VINUM | MISSION2074 | China | 2026-07-04 | Jul | No | 10 |
| Vision2025 | MISSION2074, Tropic Trooper | China | 2017-10-31 | Jul, Sep | No | 8 |
| Wakeup | Gothic Panda, MISSION2074, Stone Panda | China | 2019-01-12 | Jul, Aug, Sep | Yes | 8 |
| WipeOut | Stone Panda | China | 2021-02-22 | Sep | Yes | 8 |
| Victory Against Traitors | APT34, MuddyWater | Iran | 2026-07-15 | Jul | No | 10 |
| Cactus | Lazarus Group | North Korea | 2020-02-15 | Jul, Sep | Yes | 8 |
| field trip | Lazarus Group | North Korea | 2020-01-05 | Aug, Sep | No | 8 |
| Horn | Lazarus Group | North Korea | 2021-06-14 | Jul, Aug, Sep | No | 8 |
| illusion | FIN7, Lazarus Group | North Korea, Russia | 2021-01-28 | Jul, Aug, Sep | Yes | 8 |
| Jmp | Lazarus Group | North Korea | 2020-01-09 | Jul, Aug, Sep | No | 8 |
| Mankind Wisdom | Lazarus Group | North Korea | 2019-10-30 | Aug, Sep | No | 8 |
| Muance | Lazarus Group | North Korea | 2026-09-16 | Sep | No | 10 |
| Sandpaper | Lazarus Group | North Korea | 2019-10-30 | Jul | No | 8 |
| Tumen | FIN7, Lazarus Group | North Korea, Russia | 2024-08-31 | Sep | No | 8 |
| verdict | Lazarus Group | North Korea | 2020-01-09 | Jul, Aug, Sep | Yes | 8 |
| Virtuality | Lazarus Group | North Korea | 2021-01-04 | Sep | No | 8 |
| 20 Yard | Dragonfly, Fancy Bear | Russia | 2020-04-08 | Aug | No | 8 |
| crop up | Cozy Bear | Russia | 2021-05-11 | Aug, Sep | No | 8 |
| Enlightenment | Fancy Bear, Turla Group | Russia | 2019-01-01 | Aug, Sep | No | 8 |
| Evian | Cozy Bear, Fancy Bear, TA505 | Russia | 2022-09-21 | Jul | Yes | 8 |
| hurricane | Cozy Bear | Russia | 2020-01-11 | Jul, Aug, Sep | No | 8 |
| Mountain Range | FIN11 | Russia | 2021-02-19 | Aug, Sep | Yes | 8 |
| natural disaster | Cozy Bear | Russia | 2022-03-17 | Jul, Aug, Sep | No | 8 |
| Raw Material | FIN7 | Russia | 2020-04-17 | Jul, Aug, Sep | Yes | 8 |
| Void | FIN11, FIN7, Gamaredon, TA505 | Russia | 2023-02-08 | Jul, Aug, Sep | Yes | 8 |