August 2026 Threat Trend Report on APT Groups

August 2026 Threat Trend Report on APT Groups

Purpose and Scope The August 2026 APT Threat Trends report summarizes attack cases in which state-sponsored threat actors combined attacks involving open-source supply chain compromises, the use of generative AI, the exploitation of legitimate cloud services, job scams, and the exploitation of zero-day vulnerabilities. A key finding is the use

July 2026 Threat Trend Report on APT Groups

July 2026 Threat Trend Report on APT Groups

Purpose and Scope The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub

June 2026 Threat Trend Report on APT Groups

June 2026 Threat Trend Report on APT Groups

Purpose and Scope The June 2026 Threat Trend Report on APT Groups summarizes the trend of state-sponsored threat groups actively incorporating generative AI, cloud services, OAuth tokens, and commercial MaaS (Malware-as-a-Service) platforms into their attack operations. A key finding is that the scope of attacks has expanded beyond traditional Malware

February 2026 APT Group Trends Report

February 2026 APT Group Trends Report

Purpose and Scope. this report summarizes major APT group activity in February 2026. the analysis covers supply chain compromises, zero-day exploits, network segregation bypass, and backup and network infrastructure compromises. the major groups included in the report are APT28, Lotus Blossom, TA-RedAnt (APT37), UAT-8616, UNC3886, and UNC6201. Major APT groups

January 2026 APT Group Trends Report

January 2026 APT Group Trends Report

  Key APT Groups   Sandworm attempted to destroy OT and IT equipment using DynoWiper after exploiting a vulnerable configuration of FortiGate, targeting at least 30 energy facilities, including wind and solar power plants in Poland, by the end of December 2025. They directly damaged RTUs, IEDs, and serial devices

December 2025 APT Group Trends

December 2025 APT Group Trends

  Key APT Group Trends by Region   1) North Korea   North Korean state‑sponsored threat groups have increasingly relied on fake IT employment schemes, actively exploiting legitimate hiring platforms and fabricated identities to infiltrate corporate environments. These actors frequently take advantage of remote‑work infrastructures to obtain elevated access and

September 2025 APT Group Trends

September 2025 APT Group Trends

Trends of Key APT Groups by Region   1)   North Korea   North Korea-linked APT groups have been intensively carrying out advanced spear-phishing and remote access attacks against the defense, military, and cryptocurrency sectors in South Korea. They have also introduced a new psychological deception technique using generative AI and

July 2025 Major APT Group Trends

July 2025 Major APT Group Trends

Purpose and Scope This report covers nation-led threat groups, presumed to conduct cyber espionage or sabotage supported by certain governments. These groups are referred to as advanced persistent threat (APT) groups for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming to gain financial

Threat Trend Report on APT Groups – June 2025 Major APT Group Trends

Threat Trend Report on APT Groups – June 2025 Major APT Group Trends

Purpose and Scope This report covers nation-led threat groups, presumed to conduct cyber espionage or sabotage supported by certain governments. These groups are referred to as advanced persistent threat (APT) groups for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming to gain financial

APT Group Trends in October 2024

APT Group Trends in October 2024

  The following are the main APT groups and their cases based on the analysis reports released by security companies and organizations in October 2024.   1.   Andariel   Symantec’s Threat Hunter Team has found evidence that the Andariel group is launching financially motivated attacks against companies in the United