Cyble Research and Intelligence Labs tracked 261 distinct threat actor profiles active globally in H1 2026. Nation-state APT groups dominated at 45% (118 profiles), followed by ransomware operators (75), hacktivist collectives (34), cybercriminal groups (31), and extortion-only gangs (3). Key groups flagged for the rest of 2026 include Bluenoroff (North Korea, targeting crypto via Calendly social engineering), Volt Typhoon (China, living-off-the-land pre-positioning in critical infrastructure), UNC6508 (China, compromising REDCap research environments), Desert Falcons (Palestine, targeting MEA governments), and SideCopy (Pakistan, targeting Indian and Afghan government/defense). The near-disappearance of standalone extortion groups confirms double extortion has been absorbed into the standard ransomware model.