NSFOCUS Monthly APT Insights – April 2026

Regional APT Threat Situation

In April 2026, the global threat hunting system of Fuying Lab detected a total of 29 APT attack activities. These activities were primarily concentrated in regions including East Asia, South Asia, Eastern Europe, North America, and the Middle East, as shown in the figure below.

Regarding the activity levels of different groups, the most active APT groups this month were Kimsuky, Lazarus, and Transparent Tribe, operating out of East Asia, while other relatively active groups included Bitter and Sidewinder, which are focused on South Asia.

The most prevalent intrusion method in this month’s incidents was spear-phishing email attacks, accounting for 48% of all attack events. A small number of threat actors also employed watering hole attacks, supply chain attacks, and vulnerability exploitation, representing 10%, 7%, and 4% of incidents, respectively.

In April 2026, the primary target industries for APT groups were the government agencies, accounting for 24% of attacks. This was followed by financial institutions and organizations or individuals, each representing 17%. Other targets included research institutions and military institutions.

East Asia

This month, APT activities in East Asia were primarily initiated by known APT groups, with victims mainly targeting South Korean entities, including South Korean organizations and individuals, financial institutions, and research institutions. In terms of attack tactics, most APT operations in East Asia this month utilized spear-phishing emails, while some groups employed supply chain attacks and vulnerability exploitation. In terms of spear-phishing, a typical decoy was a spreadsheet titled “Server Configuration List.” The document contained detailed server configuration and deployment information.

South Asia

This month, APT activities in South Asia were also driven by known APT groups, targeting government agencies and military institutions in Pakistan, as well as government agencies in Saudi Arabia. In terms of tactics, spear-phishing emails remained the primary method for APT activities in South Asia. A notable decoy targeted the Ministry of Finance of the Kingdom of Saudi Arabia. The threat actor employed its customary spear-phishing approach, using a PowerPoint file as bait.

Eastern Europe

This month, APT activities in Eastern Europe were initiated by known APT groups, targeting Canadian government departments and Russian military institutions. Tactically, APT operations in Eastern Europe this month relied mainly on spear-phishing emails and watering hole attacks. Regarding spear-phishing, a typical decoy involved a government document issued by the Ministry of Defense of the Russian Federation. The content was a personnel submission report from Unit 71289 of the Russian Ministry of Defense, stationed in Ussuriysk, addressed to the Director of the Personnel Administration of the Moscow Airborne Forces.

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Global Key APT Events

Event NameRelated Groups
APT28’s zero-day attack campaign targeting Ukrainian defense objectives continues to expandAPT28
Transparent Tribe has launched the “TrustTrap” operation targeting IndiaTransparent Tribe

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Interpretation of Key APT Events

APT28’s Zero-Day Attack Campaign Targeting Ukrainian Defense Objectives Continues to Expand

In January 2026, APT28 conducted a cyber campaign named “Operation Neusploit,” targeting defense institutions in Ukraine and its allied nations.

Certain aspects of “Operation Neusploit” were previously disclosed in January by Ukraine’s CERT-UA, including APT28’s use of a zero-day vulnerability (CVE-2026-21509) and geofencing techniques. These technical details were analyzed extensively in the January 2026 monthly report of this series; readers are referred to that issue for further information. Due to the large scale and intricate details of this campaign, security research continued through March 2026. This ongoing analysis led to the discovery of another zero-day vulnerability utilized in the operation (CVE-2026-21513), a suite of Trojans, and a unique steganography approach. Currently, the complete attack workflow employed by APT28 in this campaign has been largely reconstructed.

Group NameAPT28, Sofacy, Fancy Bear
Appear Time2004
Attack TargetAfghanistan, Armenia, Australia, Azerbaijan……
Attack Strategy / Technique / WeaponSubscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

CVE-2026-21513 is another vulnerability within the Microsoft MSHTML framework, specifically located in the _AttemptShellExecuteForHlinkNavigate function of ieframe.dll, the core library of the Internet Explorer browser. The _AttemptShellExecuteForHlinkNavigate function is an internal routine designed to handle hyperlinks. It fails to perform strict validation on URLs passed via parameters. A shortcut file containing CVE-2026-21513 embeds a complete HTML file at its end. Consequently, when the .lnk file is opened, the MSHTML engine processes this embedded HTML content…

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Transparent Tribe has Launched the “TrustTrap” Operation Targeting India

In early 2026, the APT group Transparent Tribe initiated a large-scale domain spoofing campaign codenamed “Operation TrustTrap,” focusing on domain spoofing. This operation primarily targeted state government agencies in the United States, Indian government entities, and citizen digital service systems such as the UK’s NHS. By employing visual decoys to deceive victims, the group conducted massive credential theft and bank card information interception. The threat actor pre-registered over 16,800 malicious domains for this campaign, with the primary objective of gaining victim trust by impersonating legitimate government portals. In typical attack scenarios, Transparent Tribe operators deliver phishing SMS messages or emails containing decoy links to targets. These messages induce victims to click the links and access high-fidelity spoofed government service portals. These phishing pages meticulously replicate real interfaces for fine payments or bill settlements. Furthermore, they utilize specific URL structures and extremely short lifespans to evade browser malicious domain markers and sandbox detection.

Group NameAPT36, Transparent Tribe
Appear Time2013
Attack TargetAfghanistan, Australia, Austria, Azerbaijan……
Attack Strategy / Technique / WeaponSubscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

In the current “Operation TrustTrap,” the Transparent Tribe organization has executed a significant strategic pivot compared to its historical operations. The NSFOCUS Fuying Lab has observed this same shift across multiple APT campaigns since the beginning of 2026, making it a development worthy of close attention. In past activities, Transparent Tribe’s technical characteristics were primarily defined by a reliance on specific types of customized payloads and the maintenance of long-term persistent control. The organization frequently employed specialized Trojans such as Crimson RAT, or infiltrated victim devices using specific Office document decoys to deploy these Trojans and sustain long-term Command and Control (C2) connections….

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.