July 2026 Threat Trend Report on APT Groups
Purpose and Scope
The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and remote access systems, mobile devices, and credentials stored in browsers.
Key Attack Trends
Threat actors are increasingly focusing on exploiting legitimate accounts and services rather than relying solely on malware. After achieving the Initial Breach through phishing, social engineering, and supply chain attacks, they attempted long-term concealment and lateral movement by employing tactics such as Credential Access, Initial Access, Persistence, and Defense Evasion. Script-based execution (such as PowerShell, VBScript, CMD, and JavaScript), obfuscation, ingress tool transfer, HTTP/HTTPS-based C2 communication, local system data collection, and data exfiltration via C2 paths were repeatedly observed.
Status of Major APT Groups by Region
North Korea
North Korean-linked groups combined social engineering, supply chain attacks, and cloud service exploitation. APT38 (BlueNoroff) lured victims into fake Zoom and Microsoft Teams meetings using compromised Telegram accounts and executed Windows and macOS malware via ClickFix to steal cryptocurrency wallets and credentials. In cases linked to Famous Chollima, the group compromised GitHub maintainer accounts and legitimate repositories to inject obfuscated JavaScript loaders into npm, Packagist, Go modules, and Chrome extensions, thereby committing credential theft, browser data theft, and cryptocurrency wallet information theft. Kimsuky used Gomir, BirdTroy, and DriveTroy to spread the infection across groupware developers and their clients.
China
China-linked groups focused on long-term persistence and securing attack infrastructure. Daxin and Stupig executed commands with SYSTEM privileges and engaged in credential theft within the environments of Taiwanese high-tech manufacturing companies. UNK_MassTraction repeatedly exploited Roundcube vulnerabilities to infiltrate university networks and used IceCube, SquareShell, and VShell. UAT-7810 targeted unpatched Ruckus wireless routers and ASUS AiCloud routers to deploy LONGLEASH, DOGLEASH, and JARLEASH, thereby establishing an ORB network.
Russia
Russia-linked groups utilized webmail as a key entry point. APT28 executed a remote access Trojan using Filen.Io as a C2 channel via document- and file-based techniques. APT28-like activity involved compromising Wi-Fi gateways at hotels and conference facilities to exploit DNS poisoning and the Microsoft device-code authentication flow, thereby conducting credential theft for Microsoft 365 and stealing OAuth tokens. TA458 and Void Blizzard exploited the “Half-click” vulnerability in Zimbra, Outlook Web Access, Roundcube, and SOGo to use ZimReaper and OWAReaper to collect credentials, contacts, and emails, and establish long-term persistence.
Iran
Iran-linked threat actors have intensified their use of AI-powered phishing and cloud- and messenger-based C2. APT42 used TAMECAT to collect Windows search-ms, WebDAV, browser credentials, and cookies. Cavern Manticore exploited SysAid and RMM access to deploy the Cavern modular .NET C2. TAG-182 used fake VPNs and media players to induce MarkiRAT infections.
India and Others
Viceroy Tiger (Donot) targeted Bangladeshi military and defense officials using remote template injection and a multi-stage shellcode loader. Armored Likho deployed the BusySnake stealer to harvest browser credentials, cookies, documents, screen information, and reverse SSH tunnels. Awaken Likho used an AutoIt backdoor targeting Russia and Belarus. CloudAtlas employed remote template injection and maintained a Google Sheets-based C2, while GOFFEE utilized legitimate utilities and the Mythic agent to conduct reconnaissance, access credentials, and carry out follow-up activities in container environments. Larva-25001 deployed SpyGlace through Proton Drive, malicious RAR and LNK files, and a chain involving mshta.Exe and git.Exe. OceanLotus utilized IMG images, LNK files, DLL sideloading, and registry hive-based persistence. Rare Werewolf deployed AnyDesk using an unattended approach and exfiltrated configuration data.
Conclusion
This month’s trends highlight a multi-vector penetration strategy that simultaneously targets accounts, cloud services, webmail, the developer ecosystem, and network equipment. Organizations must prioritize MFA, separation of administrator accounts, integrated log monitoring, integrity verification of open-source and third-party software, EDR/XDR-based behavior detection, and supply chain audits that include business partners. As long-term, stealthy attacks exploiting legitimate services and tools have increased, controls centered on accounts, cloud environments, and development environments are proposed as key response measures.