Cyble
Read post

APTs Lead The List Of Most Active Threat Actors In H1 2026

Cyble Research and Intelligence Labs tracked 261 distinct threat actor profiles active globally in H1 2026. Nation-state APT groups dominated at 45% (118 profiles), followed by ransomware operators (75), hacktivist collectives (34), cybercriminal groups (31), and extortion-only gangs (3). Key groups flagged for the rest of 2026 include Bluenoroff (North Korea, targeting crypto via Calendly social engineering), Volt Typhoon (China, living-off-the-land pre-positioning in critical infrastructure), UNC6508 (China, compromising REDCap research environments), Desert Falcons (Palestine, targeting MEA governments), and SideCopy (Pakistan, targeting Indian and Afghan government/defense). The near-disappearance of standalone extortion groups confirms double extortion has been absorbed into the standard ransomware model.

    #ransomware
Jul 27•4m read time•From cyble.com
Post cover image
Table of contents
The Worldwide Picture of Most Active Threat Actors: APTs Lead, But Not EverywhereThreat Actors to Watch Out ForTrack These Threat Actors in Real Time
132 Impressions
Cyble's image
Cyble

Cyble's publication is a resource for cybersecurity professionals and businesses seeking to stay ahe...

112 Followers

•

131 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard