August 2026 Threat Trend Report on APT Groups

August 2026 Threat Trend Report on APT Groups

Purpose and Scope


The August 2026 APT Threat Trends report summarizes attack cases in which state-sponsored threat actors combined attacks involving open-source supply chain compromises, the use of generative AI, the exploitation of legitimate cloud services, job scams, and the exploitation of zero-day vulnerabilities. A key finding is the use of GitHub, GitLab, OneDrive, Telegram, Discord, Google Sheets, and blockchain networks as C2 (Command and Control) channels, payload delivery mechanisms, and information exfiltration channels.

Status of Major APT Groups by Region


North Korea


Groups linked to North Korea primarily targeted developers and software supply chains. Famous Chollima continued its PolinRider supply chain attacks, and stealthy C2 techniques utilizing the Ethereum blockchain were identified. Jasper Sleet (PurpleDelta) attempted to gain internal access using AI-generated fake identities and remote job scams. Kimsuky used generative AI-based decoy documents and Git-based C2, and there were also indications of the use of local LLM and AI technologies. Lazarus attacked defense industry targets in “Operation Dream Job” using a malicious PDF viewer and the CVE-2026-68820 zero-day vulnerability (a vulnerability exploited before it was publicly disclosed).

China


China-linked actors continued long-term infiltration and intelligence gathering targeting the government, defense, and telecommunications sectors. Fire Ant compromised trusted infrastructure—including Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts—to collect authentication credentials and traffic. Mustang Panda used hydropower-themed lures along with the Claimloader, ToneShell v10, and Havencode backdoors, while Earth Alux (Jewelbug) utilized XG-Web, Antino, PDF Viewer, and ClientKing for both espionage activity and cryptocurrency scams.

Russia


Russia-linked actors expanded their information gathering by exploiting webmail, network infrastructure, and Wi-Fi networks at hotels and airports. APT28 (BlueDelta) used HOOKEDGE and webhook.Site to carry out spear phishing and data exfiltration. Storm-2945 manipulated captive portal networks at hotels, conferences, and airports to steal Microsoft 365 accounts and tokens and distribute CornFlake and ChocoShell.

Others


Transparent Tribe (APT36) targeted Afghan telecommunications companies and Indian government, defense, and energy organizations using PATCHCORD, SHEETCORD, and the HACKERAI C2 Agent. Armored Likho, Awaken Likho, Core Werewolf, Dark Caracal, Darkhotel, Head Mare, and OceanLotus (APT32) also carried out attacks exploiting legitimate services and software such as Telegram, GitLab, GitHub, OneDrive, TrueConf, and Sogou Input Method, respectively.

Conclusion


Attacks this month showed a strong tendency to repurpose legitimate services, accounts, and collaboration tools as attack infrastructure. Developer accounts, open-source supply chains, Microsoft 365 and cloud environments, remote work infrastructure, and the defense industry and research institutions were identified as key risk areas. Since IOC-based detection alone has its limitations, supply chain verification, MFA, cloud log monitoring, and EDR/XDR-based behavior detection are critical.