Top 12 Advanced Persistent Threat (APT) Groups in 2026

Top APT groups in 2026 include Salt Typhoon, APT41, Lazarus, and Sandworm, with tactics shaping telecom, cloud, crypto, and infrastructure risk.
Published on
Wednesday, September 2, 2026
Updated on
September 2, 2026

Advanced Persistent Threat (APT) clusters comprise sophisticated cyber operatives engineered for protracted espionage, intellectual property theft, clandestine surveillance, or tactical disruption against premier entities. State sponsorship frequently equips these units with robust infrastructure, bespoke toolsets, intelligence coordination, and the discipline necessary to maintain a stealthy presence within a compromised network significantly longer than conventional criminal factions.

Initial entry may come through phishing, stolen credentials, vulnerable edge appliances, compromised cloud accounts, or exposed supplier systems. Once inside, an operator is able to study internal workflows, deepen its foothold, preserve alternate routes, and collect sensitive information without creating obvious signs of compromise.

Ordinary internet-connected hardware has also become part of this covert ecosystem. In April 2026, CISA and partner agencies reported more than 200,000 devices infected by the Raptor Train network worldwide, including small office routers, IoT systems, firewalls, and NAS devices. Networks built from common hardware give state-linked actors another way to hide command traffic and support longer-running operations.

Our Top Findings About Advanced Persistent Threat (APT) Groups In 2026

APT Group Attribution Main Focus Primary Route Typical Targets
Salt Typhoon China / PRC Telecom espionage Network-device intrusion Telecom, service providers, government communications
Volt Typhoon China / PRC Critical infrastructure access Living-off-the-land Energy, water, transport, aviation, communications
Flax Typhoon China / PRC Covert relay operations Router and IoT botnets Government, enterprise, infrastructure networks
Mustang Panda China / PRC Diplomatic intelligence Spearphishing Government, defense, NGOs, policy targets
APT41 / Wicked Panda China / PRC Espionage and financial gain Web and supply-chain exploitation Software, healthcare, telecom, gaming, technology
APT28 / Fancy Bear Russia / GRU Military intelligence Credential theft Logistics, IT, defense-linked organizations
APT29 / Cozy Bear Russia / SVR Strategic espionage Password spraying and cloud abuse Governments, embassies, think tanks, research
Sandworm / APT44 Russia / GRU Disruption and sabotage Wipers and ICS targeting Energy, transport, logistics, critical services
Turla / Secret Blizzard Russia / FSB Diplomatic espionage Custom backdoors Embassies, diplomats, journalists, government
Lazarus / TraderTraitor North Korea / DPRK Revenue generation Social engineering and crypto compromise Exchanges, fintech, blockchain platforms
Kimsuky / APT43 North Korea / DPRK Policy intelligence QR phishing and account takeover Think tanks, academia, NGOs, government experts
APT42 / Charming Kitten Iran Surveillance Spearphishing and account compromise Journalists, academics, diaspora groups, NGOs

How We Selected These APT Groups?

This list favors APT groups with recent public reporting, credible attribution, and clear relevance to enterprise, government, infrastructure, financial, or policy environments. Government advisories, national CERT alerts, law-enforcement releases, and primary technical reporting carried the most weight.

Operational scale also mattered. Groups associated with telecom networks, critical services, identity platforms, diplomatic systems, crypto assets, and other high-value environments ranked higher because compromise in those areas can affect far more than one organization.

We also considered whether a technique could create downstream exposure. Router abuse, stolen credentials, supply-chain compromise, account takeover, destructive tooling, and targeted phishing can open paths into partners, suppliers, customers, or connected institutions.

What Are the Top 12 Advanced Persistent Threat (APT) Groups in 2026?

The 12 groups below stand out because of their recent campaigns, strategic targets, technical methods, and ability to preserve access across telecom, cloud, critical infrastructure, digital assets, and policy networks.

1. Salt Typhoon

Salt Typhoon is a China-linked espionage cluster focused heavily on telecommunications infrastructure. Tracked since at least 2019, it has targeted carriers, ISPs, provider edge systems, routing paths, and communications metadata with significant intelligence value.

Observed techniques include configuration theft, privileged device control, GRE tunnel creation, and quiet traffic capture inside service-provider environments. Unusual administrative sessions, unexpected configuration exports, new tunnels, or authentication events originating from trusted internal paths deserve close review.

Reuters reported in February 2026 that public comments placed Salt Typhoon across more than 200 U.S. organizations and 80 countries. A campaign with that reach turns telecom compromise into a broader national-security issue rather than a carrier-specific incident.

2. Volt Typhoon

Volt Typhoon has become closely associated with pre-positioning inside critical infrastructure. China-linked campaigns dating back to at least 2021 have affected sectors such as energy, water, transport, aviation, communications, and emergency services.

Much of the tradecraft avoids obvious malware. Common characteristics include:

  • valid credential use
  • command-line execution
  • remote administration tools
  • living-off-the-land behavior
  • compromised routers used as relay nodes

Because this approach generates less endpoint noise, defenders depend more heavily on identity records, administrative baselines, and visibility into unmanaged appliances. New Zealand’s NCSC warned in April 2026 that China-linked operators were using covert networks of compromised devices strategically and at scale, reinforcing the need to monitor SOHO routers and other connected systems.

3. Flax Typhoon

Flax Typhoon relies heavily on compromised routers, cameras, DVRs, firewalls, and NAS devices. First observed around 2021, the China-linked cluster has the potential to turn those systems into relay nodes, making malicious connections appear residential or enterprise-local.

Botnet nodes may support reconnaissance, command routing, and follow-on intrusion work. Many affected appliances lack centralized logging or regular patching, so a compromised device might stay available long after the original takeover.

CISA’s April 2026 advisory linked the Raptor Train botnet to China-based hackers known as Flax Typhoon and reported more than 200,000 infected devices worldwide.

4. Mustang Panda

Public reporting on Mustang Panda reaches back to at least 2012. Its campaigns have concentrated on government bodies, defense organizations, diplomatic targets, NGOs, and regional policy communities.

Common delivery methods include political lures, archive files, legitimate executables, DLL sideloading, and staged payloads. Reported tools include:

  • TONESHELL
  • PlugX
  • SnakeDisk
  • Tonedisk
  • CoolClient-based backdoors

Recent CoolClient variants added browser login theft, clipboard monitoring, endpoint capture, reconnaissance, file management, service management, and remote shell capabilities. ThaiCERT reported those developments in January 2026 and listed public agencies in Myanmar, Mongolia, Malaysia, Russia, and Pakistan among observed victims.

5. APT41 / Wicked Panda

APT41 is unusual because espionage and financially motivated operations can coexist within the same China-linked ecosystem. The group has been tracked since at least 2012 and has targeted telecom, healthcare, software, gaming, travel, education, and technology organizations.

Its methods are broad rather than tied to one preferred entry point. Public-facing server exploitation, phishing, stolen credentials, custom malware, hosted-service abuse, and post-exploitation tooling have all appeared in reporting tied to APT41.

A single foothold may serve several goals, from intelligence collection to platform access or monetization. U.S. Department of Justice records charged APT41-linked operators in connection with intrusion campaigns affecting more than 100 victims globally.

6. APT28 / Fancy Bear

APT28 has been linked to Russian military intelligence operations since at least 2004. Victim selection frequently aligns with strategic interests involving Ukraine, NATO support routes, transport providers, technology companies, public institutions, and defense-linked organizations.

Router-focused campaigns show how the group is able to move beyond conventional credential theft into network-layer interception.

Reported techniques include:

  • DNS hijacking
  • DHCP manipulation
  • adversary-in-the-middle positioning
  • password theft
  • OAuth token theft

The UK NCSC warned in April 2026 that APT28 exploited vulnerable routers to alter DHCP and DNS settings, enabling attackers to harvest passwords, OAuth tokens, and related secrets. Poorly maintained network appliances could expose identity material as well as network traffic.

7. APT29 / Cozy Bear

APT29 is attributed to Russia’s Foreign Intelligence Service, with public reporting stretching back to at least 2008. Embassies, think tanks, research institutions, government agencies, and SaaS-heavy environments make attractive targets because control over mailboxes and identities can support long-term intelligence collection.

Cloud-oriented techniques include password spraying, service account misuse, dormant-account recovery, OAuth abuse, token replay, device registration, and residential proxy use.

Service accounts deserve particular scrutiny. Many carry elevated privileges, receive less frequent review than standard user identities, and have the potential to remain usable long after organizational changes. Official NCSC and partner guidance has described similar hosted-service entry patterns involving token abuse, password attacks, and residential proxies.

8. Sandworm / APT44

Sandworm differs from many espionage-focused groups because disruption and sabotage are central to its mission. Active since at least 2009, the GRU-linked team has targeted energy, transport, satellite, logistics, and industrial environments where cyber operations could produce physical or operational consequences.

Reported methods include wiper malware, OT and ICS manipulation, VPN or firewall exploitation, and stolen credentials.

Defenders in industrial environments should pay close attention to:

  • unexplained protocol behavior
  • engineering workstation changes
  • backup interference
  • lateral movement near OT boundaries
  • abnormal use of already-compromised systems

CERT-EU’s January 2026 cyber brief noted Russia-linked Sandworm targeting renewable energy entities in Poland with a data wiper. National energy supply was not disrupted, but the case illustrates why destructive malware continues to matter for critical infrastructure operators.

9. Turla / Secret Blizzard

Turla’s espionage record dates back to at least 2004 and is associated with Russia’s FSB. Embassies, foreign ministries, defense organizations, journalists, diplomats, and research institutions have all appeared among its targets.

Kazuar shows how Turla has evolved its malware architecture. Newer versions introduced modular components, peer-to-peer communication, leader election, inter-process communication, local staging, and controlled exfiltration rather than relying only on a conventional backdoor model.

Microsoft reported in May 2026 that Kazuar had evolved into a modular peer-to-peer botnet ecosystem designed for persistent, covert control. Looking at one malware sample in isolation may therefore miss the internal routing and staged data movement supporting the broader operation.

10. Lazarus Group / TraderTraitor

Lazarus is central to North Korean cyber operations because digital-asset theft is able to support state revenue objectives. Exchanges, DeFi protocols, fintech firms, blockchain platforms, bridge operators, and signing workflows continue to draw attention from North Korean operators.

Campaigns combine technical compromise with human-led social engineering. Common elements include:

  • fake business relationships
  • signing-process compromise
  • bridge abuse
  • transaction manipulation
  • rapid laundering across chains

Recent cases have also drawn attention to governance mechanics, multisignature workflows, validator design, durable nonce behavior, and cross-chain liquidity.

TRM Labs reported in April 2026 that North Korean hackers stole about $577 million from two crypto attacks, accounting for 76% of crypto hack losses tracked through April. With such a large share tied to two incidents, the issue extends beyond ordinary cybercrime into sanctions enforcement and financial security.

11. Kimsuky / APT43

Kimsuky is closely associated with policy intelligence collection. Public tracking goes back to at least 2012, with think tanks, academic institutions, NGOs, government experts, and foreign-policy communities frequently appearing as targets because inboxes, research drafts, contact lists, briefing notes, and hosted documents can reveal strategic information.

One notable technique is QR-code phishing. A QR lure can shift the interaction from a managed corporate endpoint to a mobile device, where inspection may be weaker.

Redirect chains may then:

  • collect device information
  • display mobile-optimized login pages
  • steal account credentials
  • capture session tokens
  • bypass MFA prompts

The FBI and IC3 warned in January 2026 about Kimsuky QR-code spearphishing campaigns targeting think tanks, academia, and U.S. or foreign official entities. The alert also described session-token theft and MFA bypass using mobile-assisted credential harvesting.

12. APT42 / Charming Kitten

APT42 is an Iran-linked espionage group centered on surveillance of individuals rather than large-scale infrastructure disruption. Since at least 2015, its targets have included journalists, academics, NGOs, diaspora communities, defense officials, government personnel, and policy professionals.

Social engineering often develops over several days or weeks instead of moving immediately to payload delivery. Event invitations, journalist impersonation, meeting requests, messaging apps, and spoofed login pages may all be used to build trust before credentials are requested or malware is introduced.

The objective is frequently account takeover and access to private communications. Harvested credentials, mobile surveillance, and remote collection could expose sensitive discussions taking place outside managed enterprise devices.

MITRE ATT&CK identifies APT42 as an Iranian-sponsored group focused on cyber espionage and surveillance, with operations beginning through spearphishing or Android malware before collection and exfiltration.

Why Are APT Groups Considered One of the Biggest Cybersecurity Threats?

APT groups pose serious cybersecurity risk because they combine patience, specialized resources, and strategic intent. Their operations are designed to preserve access, collect valuable information, or prepare disruptive action without producing the obvious noise associated with many criminal intrusions.

Long-Term Stealth

Extended dwell time gives an operator room to study authentication flows, administrator behavior, mailbox use, file movement, source code, industrial diagrams, and executive communications before defenders recognize the intrusion. Rather than rushing toward an immediate objective, an APT may deepen its foothold gradually and preserve alternate routes. The slower pace also gives the adversary time to observe defensive routines and blend malicious actions into normal administrative behavior.

State-Level Resources

Nation-state support provides malware developers, exploit research, dedicated infrastructure, regional expertise, mission-specific intelligence, and access to stolen or purchased credentials. Those resources make it easier to rotate tools, replace command infrastructure, or change entry methods during a campaign. Even after one part of an attack chain is exposed, other capabilities may keep the operation viable.

High-Value Targeting

APT campaigns concentrate on environments where compromise carries strategic value: telecom providers, defense suppliers, ministries, research institutions, crypto platforms, energy operators, and policy networks. A successful intrusion might expose intellectual property, operational plans, customer records, private communications, or trusted partner connections. Shared systems and supplier relationships have the potential to extend the damage beyond the original victim, giving one foothold value across several connected organizations.

How Do APT Groups Attack Their Targets?

APT intrusions usually progress from initial entry to privilege expansion, persistence, lateral movement, and data collection or removal. The path changes with the victim’s environment, available credentials, exposed systems, and the operator’s objective.

Spearphishing and Social Engineering

Operators may use tailored emails, fake recruiter messages, conference invitations, researcher impersonation, QR codes, or cloud-sharing links to steal credentials or deliver malicious files. Convincing lures often borrow details from real projects, job responsibilities, vendors, or policy topics familiar to the recipient. The closer a message matches normal work, the harder it becomes to dismiss at first glance.

Vulnerability Exploitation

Internet-facing routers, VPNs, firewalls, mail servers, web applications, and administrative portals can provide direct entry if exploitable weaknesses remain unpatched. A compromised system may expose configuration files, session information, service accounts, internal routes, or downstream assets reachable from the original foothold.

Identity Abuse

APT operators do not always need malware after obtaining valid authentication material. They may use:

  • stolen passwords
  • OAuth tokens
  • session cookies
  • API keys
  • privileged accounts
  • dormant or service accounts

Password spraying, token replay, MFA abuse, and account recovery are able to make unauthorized access resemble normal user behavior.

Living-off-the-Land Execution

Native administration tools such as PowerShell, WMI, PsExec, RDP, SSH, scheduled tasks, command shells, and cloud management utilities let attackers execute commands without dropping obvious binaries. Detection depends less on finding unfamiliar software and more on understanding context: unusual parent processes, unexpected arguments, rare source hosts, privilege changes, or execution at times inconsistent with normal administration.

Supply-Chain Entry

A trusted third party could become an indirect route into the intended victim. Vendors, MSPs, software updates, CI/CD pipelines, remote management platforms, and partner integrations may expose shared secrets, support accounts, deployment workflows, signed code, or VPN access. Compromising one relationship is able to create a path into the final target without attacking it directly.

Persistence and Exfiltration

After securing a foothold, an operator may preserve it through backdoors, web shells, hidden accounts, altered startup tasks, device configuration changes, or covert tunnels.

Data has the potential to leave through several channels:

  • staged archives
  • encrypted transfers
  • DNS tunneling
  • cloud storage services
  • relay infrastructure

Multiple persistence and transfer methods make partial cleanup dangerous. Removing one route does not prove the rest of the intrusion has been eliminated.

How Can Organizations Detect and Respond to APT Activity?

Detecting an APT intrusion requires teams to connect identity records, endpoint behavior, SaaS events, edge-device changes, and external threat intelligence instead of treating each signal as an isolated alert. Response then depends on identifying the entry path, containing active access, and checking for alternate footholds.

Behavior Analytics

Normal user actions, administrative sessions, process trees, remote logins, command execution, and file movement create a baseline for comparison. Rare parent-child processes, unusual source hosts, abnormal login hours, impossible travel, or unexpected privilege changes may warrant deeper review. Several weak indicators tied to the same account or device could tell a stronger story than one high-severity alert.

Identity Defense

Privileged accounts, service accounts, API keys, OAuth applications, session tokens, and federation settings need tighter control because attackers are able to reuse them without deploying malware. Phishing-resistant MFA, conditional access policies, shorter token lifetimes, least-privilege permissions, and inactive-account cleanup limit legitimate authentication paths available after credential or token theft.

Threat Hunting

Automated detections might miss weak indicators such as unusual PowerShell arguments, suspicious scheduled tasks, hidden accounts, unsigned scripts, abnormal DNS requests, or unexpected outbound transfers. Focused hunts across telemetry can connect low-confidence events before deeper reconnaissance or collection is complete. Cross-source analysis also helps separate isolated administrative behavior from a coordinated intrusion sequence. Analysts are then able to escalate based on the combined evidence rather than a single event.

Attack Mapping

Observed behavior can be mapped to MITRE ATT&CK tactics covering initial access, execution, persistence, privilege escalation, defense evasion, discovery, lateral movement, command and control, and exfiltration. The framework helps analysts determine whether separate alerts belong to one campaign rather than merely assigning technique labels. It also shows which stages have already occurred and where investigators should look next.

Rapid Containment

Confirmed APT activity may require device isolation, token revocation, password resets, system rebuilds, firewall rule review, and forensic preservation. Containment should remove known attacker routes without destroying evidence needed to find other persistence mechanisms or compromised assets.

Intelligence-Led Response

External intelligence could provide information on known infrastructure, malware families, lure themes, exploited vulnerabilities, leaked secrets, and sector-specific targeting. Correlating those indicators with internal evidence can clarify likely intent and identify assets requiring immediate review. Similarities with previously documented campaigns may also help analysts decide which systems, accounts, or exposure points deserve priority. The response is then based on adversary behavior and observed evidence, not alert severity alone.

Finding Blind Spots: How CloudSEK XVigil Maps APT Attack Surface

CloudSEK XVigil identifies external exposure across leaked credentials, exposed data, phishing infrastructure, brand impersonation, threat mentions, and dark web discussions. These findings could reveal how an APT operator may profile an organization or obtain credentials and other material that has the potential to support initial access.

Monitoring spans dark sites, marketplaces, paste sources, code-sharing spaces, document-sharing platforms, IRC, I2P pages, Telegram channels, breach datasets, and external repositories. Results may include stolen employee accounts, leaked secrets, fake domains, malicious pages, rogue apps, supplier exposure, and threat actor discussions connected to the organization.

BeVigil extends the picture to internet-facing systems by discovering external assets, vulnerabilities, open ports, misconfigurations, and exploitable entry points. Together, those findings can connect leaked credentials, vulnerable remote access, supplier risk, active CVEs, impersonation infrastructure, and other external indicators to possible APT entry paths.

Frequently Asked Questions

What is the difference between an APT group and a cybercriminal group?

APT groups usually pursue long-term intelligence, surveillance, disruption, or state-linked objectives, while cybercriminal gangs are more commonly driven by financial gain. Lazarus and APT41 blur the distinction because espionage and revenue generation may exist within the same operational ecosystem.

Can an organization fully prevent APT attacks?

No organization can guarantee complete prevention. Strong identity controls, patching, phishing-resistant MFA, asset monitoring, and threat-informed hunting reduce available entry paths and make unauthorized movement harder to sustain.

How long are APT groups able to stay hidden inside a network?

Dwell time may range from days to several years depending on the objective, available footholds, logging coverage, and response maturity. Longer persistence is more likely if operators are able to rely on valid accounts, trusted administrative tools, unmanaged devices, or weak monitoring.

Should security teams focus on attribution during an APT incident?

Attribution may provide useful context, but containment should take priority. Teams should first identify compromised assets, exposed credentials, active persistence, lateral movement, and attacker-controlled infrastructure before spending significant effort on naming a specific group.

How often should organizations assess APT exposure?

APT exposure should be reviewed continuously rather than only during scheduled audits. External assets, leaked credentials, new vulnerabilities, remote access paths, supplier risk, and dark web mentions could change frequently.

Related Posts
Creeper Virus: The World’s First Computer Worm
Creeper, written by Bob Thomas in 1971, was the first computer worm. Know how Creeper worked, the Reaper antivirus, and its place in malware history.
What is SCADA? How Supervisory Control Systems Work
Supervisory control and data acquisition (SCADA) is a control system that monitors industrial processes. How SCADA works, its components, types, and security.
Maritime Cybersecurity: Threats, Defenses, and Regulations
Why ships and ports are cyber targets: ransomware, GPS and AIS spoofing, the NotPetya attack on Maersk, IMO and USCG rules, and how the maritime sector defends.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.