August 2026 Threat Trend Report on APT Groups

2026-09-18 Ahnlab

https://asec.ahnlab.com/en/95478

Thumbnail for August 2026 Threat Trend Report on APT Groups

North Korea-linked actors focused on developers, software supply chains, remote hiring, and defense targets during August 2026. Famous Chollima continued PolinRider supply-chain activity and used Ethereum for covert command and control, while Jasper Sleet sought internal access through AI-generated identities and remote-job scams. Kimsuky employed AI-generated decoys and Git-based command and control. Lazarus used a malicious PDF viewer and the then-undisclosed CVE-2026-68820 zero-day against defense-sector targets in Operation Dream Job.

Related Actors

Related Reports

« Back