惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
A
About on SuperTechFans
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
博客园 - Franky
D
Docker
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
U
Unit 42
F
Fortinet All Blogs
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
P
Proofpoint News Feed
月光博客
月光博客
G
Google Developers Blog

Cyble

Cyble's Executive Monitoring Module Gets An Upgrade Boost Infostealer Malware To Marketplace: The Credential Pipeline Qatar's Digital Boom Has A Blind Spot: What The Data Says AI-Powered Threat Intelligence For GCC Cyber Compliance Supply Chain Attacks In 2026: Risks And Defenses Financial Exposure: From Cyber Risk To Business Impact Ransomware Attack Vectors: 5 Endpoint Blind Spots Brand Impersonation: Detect & Take Down Threats At AI Speed Brand Impersonation Takedown: Why Manual Response Fails Ransomware Threats In The Americas H1 2026: Deep Dive Ransomware Incident Response Plan: 2025-2026 Threat Guide Ransomware Threats In Europe H1 2026: A Deep Dive Decoding The 72-hour Timeline Of A Credential-Based Attack Attack Surface Discovery: Why Asset Visibility Matters Most Dark Web Trends 2026: Ransomware, AI And Cyber Threats 2026 Threat Intelligence Trends, Cyber And Ransomware Report Glitch SPY RAT Distributed Via Fake Polish Rental App Operation FanTrap: FIFA 2026 Fraud Ecosystem Exposed Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO Attack FIFA World Cup 2026 Scams Surge As Fake Sites Target Fans CEO Fraud And Executive Impersonation Threats In The Gulf How AI-Powered Brand Impersonation Works — And Why Traditional Security Misses It Entirely OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign - Cyble Cyble: Challenger In 2026 Gartner® Magic Quadrant™ For CTI GCC Digital Banking Attack Surface Risks In 2026 Australian Dark Web Data Breaches Surge In 2025-2026 Gartner® Magic Quadrant™ 2026 | Cyberthreat Intelligence Operation HumanitarianBait: An Infostealer Campaign Weekly Vulnerability Report: Azure AI, Spring AI, Fortinet Bugs
APTs Lead The List Of Most Active Threat Actors In H1 2026
Ashish Khaitan · 2026-07-27 · via Cyble

You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? 

We do. 

Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis of the Global Threat Landscape spanning ransomware, initial access brokers, data breaches and leaks, nation-state espionage, and hacktivism, among others.  

One of the most striking analyses that puts the threat landscape severity in perspective was the number of distinct threat actor profiles active worldwide between January and June. 261 — that’s how many identifiable groups and individuals, each with its own tradecraft, targeting logic, and operational rhythm, running campaigns simultaneously across nation-state espionage, ransomware, hacktivism, and cybercrime.

What makes this data set valuable isn’t just the headline count. It’s what the composition reveals. A threat landscape dominated by nation-state APT groups tells a very different story than one dominated by ransomware crews — and as Cyble’s regional breakdown shows, that composition shifts dramatically depending on where you’re standing. 

The Worldwide Picture of Most Active Threat Actors: APTs Lead, But Not Everywhere 

Across all 261 profiles tracked globally, nation-state Advanced Persistent Threat (APT) groups were the single largest category — accounting for 118 profiles, or just over 45% of the total. Ransomware operators came second at 75 profiles (29%), followed by hacktivist collectives (34), cybercriminal groups (31), and dedicated extortion-only gangs, which remained a niche category at just 3. 

Threat Actor Category Profiles Tracked Share of Total 
Nation-State APT Groups 118 45.2% 
Ransomware Groups 75 28.7% 
Hacktivist Collectives 34 13.0% 
Cybercriminal Groups 31 11.9% 
Extortion-Only Groups 1.1% 
Total 261 100% 

That APT dominance reflects the sheer number of state-sponsored programs China, North Korea, Iran, and Russia field simultaneously across espionage, intellectual property theft, and pre-positioning operations.

The extortion-only category being almost statistically irrelevant is telling too — it confirms that pure extortion has essentially been absorbed into the ransomware business model rather than surviving as an independent specialty. Double extortion is now just how ransomware works. 

Worried your business is not immune to the tactics of these APT and ransomware groups? Book a demo to validate and fortify your defenses today! 

Threat Actors to Watch Out For 

CRIL flagged five groups worldwide as carrying the highest confidence and activity levels for security teams to track through the rest of 2026: 

Actor Origin Primary Targets Sectors Targeted 
Bluenoroff North Korea (Lazarus subgroup) Global — cryptocurrency sector Cryptocurrency, Financial Services 
UNC6508 China (PRC-nexus espionage) US, Canada Education, Healthcare, Government, Aerospace & Defense 
Volt Typhoon China (state-sponsored) US (incl. Guam) and allies Communications, Energy, Manufacturing, Government, IT 
Desert Falcons Palestine UAE, Israel, Jordan, and 12+ other MEA nations Aerospace & Defense, Government, Law Enforcement, Media 
SideCopy Pakistan India, Afghanistan Government, Defense/military 

Two of these deserve particular attention for how they operate.  

Bluenoroff, a financially motivated Lazarus Group subgroup, funds North Korean state operations by impersonating established crypto investors and planting malicious links inside victims’ Calendly scheduling accounts. This fraud vector blends social engineering with a tool most professionals trust implicitly.  

Volt Typhoon continues to favor “living off the land” techniques that blend into normal network activity, prioritizing long-term undetected access over rapid data theft — a profile consistent with pre-positioning for a future disruption event rather than opportunistic espionage. 

UNC6508 is worth flagging separately: the group compromises externally accessible REDCap research environments and has been observed creating malicious mail-forwarding rules to silently exfiltrate correspondence — all routed through US-based residential proxies and compromised routers specifically to obscure attribution. 

For a regional breakdown of which actors were the most active and which sectors they target, download Cyble Research and Intelligence Labs’ H1 2026 Global Threat Landscape Report. 
 
Download now! 

Track These Threat Actors in Real Time

The threat actor profiles, targeting patterns, and regional breakdowns in this analysis are drawn from Cyble’s H1 2026 Global Threat Landscape Report, built on continuous monitoring across dark web forums, ransomware leak sites, and threat actor communications worldwide.  

Cyble Vision provides ongoing tracking of these groups — including new actor emergence, TTP shifts, and targeting changes — as they develop.  

Request a demo to see how continuous threat actor intelligence can sharpen your regional security priorities.