Resources
  • Research
  • Threat Intelligence Reports
State-Sponsored APT Threat Landscape in H1 2026
2026.08.12

✅ Report Title: State-Sponsored APT Threat Landscape in H1 2026

✅ Executive Summary:

  • This report analyzes the activities of North Korean, Chinese, and Russian-backed threat groups based on the APT Threat Trends from January to June 2026.
  • A total of 158 issues were reported as nation-state actor activity in the first half of 2026, marking an increase of 11 cases (7.5%) compared to 147 cases in the second half of 2025.
    • There were 99 cases in North Korea, 33 in China, and 26 in Russia, with the overall increase occurring in the first quarter, which was focused on issues related to North Korea and Russia.

📌 North Korean APT Group Activity Trends

  • Issues linked to North Korea increased by 13.8%, rising from 87 to 99 cases.
    • Fake recruitment, code repositories, npm packages, and activities involving generative AI and deepfakes are repeatedly targeted at the cryptocurrency, IT, and software industries, as well as developers.
  • South Korea was the most targeted by North Korean-backed groups with 19 instances, followed by the United States with 8 instances.

📌 Chinese APT Group Activity Trends

  • Issues linked to China decreased by 17.5%, falling from 40 to 33 cases.
    • While maintaining a focus on the telecommunications sector, the scope has expanded to include energy and military organizations, as well as Southeast Asia and the Middle East, with long-term espionage activities confirmed to have used legitimate cloud APIs, VPNs, tunnels, and BPFDoor.
  • Among the Chinese-backed groups, Southeast Asia was the most frequent target with 8 occurrences, and the Middle East was confirmed 4 times.

📌 Russian APT Group Activity Trends

  • Issues linked to Russia increased by 30.0%, rising from 20 to 26 cases.
    • While maintaining focus on Ukraine, targets have been expanded to include European governments, military organizations, and infrastructure, with activities conducted concurrently for the purposes of intelligence gathering, destruction, and operational disruption.
  • Among the Russian-backed groups, Ukraine was observed the most with 10 instances, followed by Eastern Europe, Poland, and Romania, each observed twice.

📌 Vulnerability Exploitation Trends

  • In the first half of the year, 15 unique CVEs were observed 19 times, and all three countries combined legitimate management tools with cloud and development services in the attack process.
  • North Korea mainly uses social engineering and user execution, China exploits vulnerabilities in servers and boundary equipment, and Russia primarily utilizes vulnerabilities in documents, webmail, and network equipment.

📌 Common Attack Techniques

  • In the activities backed by the three countries, phishing, user execution, exploitation of vulnerabilities in public servers, abuse of legitimate remote management tools, and VPN, proxies, and cloud services were commonly observed.

✅ Threat Detection Recommendations and Mitigation Measures:

  • In the second half of 2026, penetration of the development ecosystem, long-term access to communications and infrastructure, and disruptive activities intertwined with geopolitical conflicts are likely to continue.
    • Iranian-backed and pro-Iran forces can also affect South Korean companies through the Middle East supply chain, so separate monitoring is necessary.
  • The detection scope should be expanded from email and terminals to development environments, code repositories, externally exposed devices, legitimate management tools, cloud, and AI environments.
    • Credential replacement, impact scope investigation, immutable backup, and service recovery capabilities must be strengthened along with intrusion detection.

🧑‍💻 Author: S2W TALON

👉 Contact us: https://s2w.inc/en/contact

*The full report is available upon request or with a subscription to the S2W platform.

S2W Contact

List