NSFOCUS Monthly APT Insights – July 2026

Regional APT Threat Situation

In July 2026, the global threat hunting system of the FUYING Lab detected a total of 21 APT attack activities. These activities were primarily concentrated in regions including East Asia, Eastern Europe, Middle East, South Asia, Southeast Asia, and South America as shown in the figure below.

Regarding the activity levels of different groups, the most active APT groups were Lazarus from East Asia. Other notably active groups included Kimsuky from East Asia. All other groups were observed engaging in activity only once.

The most prevalent intrusion method in this month’s incidents was spear-phishing email attacks, accounting for 76% of all attack events. A minority of threat actors also employed watering hole attacks, vulnerability exploitation, and supply chain attacks, representing 10%, 9%, and 5% of incidents, respectively.

In July 2026, the primary industry targeted by APT groups was the government agencies, accounting for 29% of attacks. This was followed by organizations/individuals at 24%. Other targets included military institutions, financial institutions, and research institutions.

East Asia

This month, APT activities in the East Asian region were primarily launched by known APT groups, with victims mainly located in South Korea, including South Korean organizations or individuals, military institutions, financial institutions, and scientific research institutions.

In terms of attack tactics, the majority of APT operations in East Asia this month were initiated via spear-phishing emails, with a smaller number employing watering hole attacks and supply chain attacks. Regarding spear-phishing, a typical decoy was an official academic affairs announcement from the Office of Academic Affairs at Korea National University of Transportation, titled “Comprehensive Summary of the Full-Year Core Academic Affairs Schedule for the 2026 Academic Year.”

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Middle East

This month, APT activities in the Middle East region were primarily launched by known APT groups, with victims including government agencies and military institutions in NATO member states and various countries across the Middle East.

In terms of attack tactics, the majority of APT operations in the Middle East this month were initiated via spear-phishing emails, with a smaller number exploiting vulnerabilities to conduct attacks. Regarding vulnerability exploitation, threat actors sent phishing emails containing malicious JS code to gain initial access.

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

South Asia

This month, APT activities in the South Asian region were primarily launched by known APT groups, with victims including government departments in Pakistan and India. In terms of attack tactics, APT operations in South Asia this month were dominated by spear-phishing email attacks. A typical decoy was an official inquiry letter from the Air Marshal Unit of the Pakistan Airport Security Force.

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Global Key APT Events

Event NameRelated Groups
The state-sponsored APT group LAUNDRY BEAR launched an attack campaign exploiting a Zimbra zero-day vulnerability.LAUNDRY BEAR
The APT group Mirage Kitten initiated cyber-attack operations targeting multiple sectors across various countries in the Middle East and Africa.Mirage Kitten

Interpretation of Key APT Events

The state-sponsored APT group LAUNDRY BEAR launched an attack campaign exploiting a Zimbra zero-day vulnerability

The Russian state-sponsored APT group LAUNDRY BEAR (also known as Void Blizzard, CL-STA-1114, and TA488) has been conducting a continuous zero-day vulnerability attack campaign from July 2025 to the present.

LAUNDRY BEAR exploited CVE-2025-66376, a vulnerability in the Zimbra Collaboration Suite email system, to target Ukrainian defense, government, law enforcement, technology, energy, education, and media institutions utilizing this platform.

In this campaign, victims only need to preview or view malicious email within the ZCS Webmail client to automatically trigger multiple layers of obfuscated malicious scripts; no clicking of links or downloading of attachments is required. LAUNDRY BEAR deploys a data theft framework named “Ulej” on compromised hosts. This framework comprises a script-based Trojan called “ZimReaper” and a data collection server named “Flowerbed.” It automatically exfiltrates emails from the past 90 days, address books, and two-factor authentication (2FA) codes, while establishing long-term persistent access via IMAP. The specific attack workflow of LAUNDRY BEAR is illustrated in the figure below:

Group NameLAUNDRY BEAR, Void Blizzard, CL-STA-1114, TA488
Appear Time2024
Attack TargetUkraine, NATO.
Attack Strategy……
Attack Technique……
Attack Weapon……

CVE-2025-66376 is a Cross-Site Scripting (XSS) vulnerability affecting the Zimbra Web client within the Zimbra Collaboration Suite (ZCS). The root cause lies in the insufficient sanitization of CSS @import directives and related tags when the Zimbra Web client parses HTML-formatted emails. By embedding specific stylesheet import directives in the email body, threat actors can bypass the security filtering mechanisms of the web-based email rendering engine, force the retrieval of external resources or directly parsing and executing inline JavaScript attack scripts.

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

The APT group Mirage Kitten initiated cyber-attack operations targeting multiple sectors across various countries in the Middle East and Africa

The Iran-linked APT group Mirage Kitten has launched cyber-attack operations targeting multiple sectors across various countries in the Middle East and Africa using spear-phishing emails. The primary targets include the aerospace, aviation, defense, telecommunications, government, and financial sectors, with victims being internal staff within these institutions. Compromised hosts are implanted with the “NightLedger” backdoor to achieve persistent residence, enabling threat actors to remotely execute commands, capture screenshots, and exfiltrate files and system logs. Additionally, tunneling tools such as “BridgeHead” or “ArcBridge” are used to transform compromised hosts into internal network SOCKS5 relay jumpers, facilitating lateral movement and the theft of sensitive data. These activities demonstrate the group’s advanced persistent threat characteristics, including a complete self-developed toolchain, highly targeted social engineering capabilities, a focus on internal network tunnel relaying, customized anti-sandboxing techniques for samples, and continuous iteration of C2 infrastructure to evade attribution. The attack begins with spear-phishing emails disguised as job recruitment notices or video conference pages, inducing victims to download malicious compressed archives from third-party file hosting services.

Group NameMirage Kitten
Attack Time2022
Attack TargetEgypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso, Israel, United States, UAE
Attack Strategy……
Attack Technique……
Attack Weapon……

Mirage Kitten has been continuously iterating its tunneling tools, evolving from early versions like LIGHTRAIL and POLLBLEND to the recently deployed BridgeHead and ArcBridge. Compared to older versions, BridgeHead introduces two primary enhancements: anti-analysis mechanisms and enterprise proxy penetration capabilities.

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Leave a Reply

Your email address will not be published. Required fields are marked *

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.