August 2026 Threat Trend Report on APT Groups
2026-09-18 • Ahnlab •
North Korea-linked actors focused on developers, software supply chains, remote hiring, and defense targets during August 2026. Famous Chollima continued PolinRider supply-chain activity and used Ethereum for covert command and control, while Jasper Sleet sought internal access through AI-generated identities and remote-job scams. Kimsuky employed AI-generated decoys and Git-based command and control. Lazarus used a malicious PDF viewer and the then-undisclosed CVE-2026-68820 zero-day against defense-sector targets in Operation Dream Job.
Related Actors
Related Reports
2026-09-07 •
55% Match
#APT38
#Andariel
#Kimsuky
#CryptoCore
#TEMP.Hermit
#JadeSleet
#CitrineSleet
#ITWorker
#MoonstoneSleet
#Lazarus
#FamousChollima
Shares tags: Kimsuky, Lazarus, FamousChollima • Published within a month
2026-09-02 •
55% Match
#Kimsuky
#Phishing
#LNK
#T1082
#T1070.004
#T1057
#T1566.001
#T1053.005
#T1059.001
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
2026-09-02 •
55% Match
#Kimsuky
#Phishing
#LNK
#T1082
#T1070.004
#T1057
#T1566.001
#T1053.005
#T1059.001
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tags: Trend, Kimsuky, Lazarus • Same author: Ahnlab
Shares tags: Trend, Kimsuky, Lazarus • Same author: Ahnlab
Shares tags: Trend, Kimsuky • Same author: Ahnlab