NSFOCUS Monthly APT Insights – June 2026

Regional APT Threat Situation

In June 2026, the global threat hunting system of Fuying Lab detected a total of 28 APT attack activities. These activities were primarily concentrated in regions including East Asia, South Asia, Eastern Europe, South America, and Central Asia as shown in the figure below.

Regarding the activity levels of different groups, the most active APT groups were Lazarus from East Asia, and Sidewinder from South Asia. Other notably active groups included Konni from East Asia and Gamaredon from Eastern Europe.

The most prevalent intrusion method in this month’s incidents was spear-phishing email attacks, accounting for 75% of all attack events. A minority of threat actors also employed supply chain attacks, vulnerability exploitation, and watering hole attacks, representing 11%, 11%, and 3% of incidents, respectively.

In June 2026, the primary industry targeted by APT groups was the organizations or individuals, accounting for 29% of attacks. This was followed by military institutions at 25%. Other attack targets included government agencies, financial sectors, and research institutions.

East Asia

This month, APT activities in East Asia were primarily initiated by known APT groups, with victims mainly located in South Korea, including Korean organizations or individuals, military institutions, financial sectors, and research institutes.

In terms of attack tactics, most APT operations in East Asia this month employed spear-phishing emails, while a smaller number utilized Watering hole attacks and supply chain attacks.

Regarding spear-phishing, a typical decoy involved a file named “Notification of May Tax Filing and Payment Deadline.” Upon clicking, victims were presented with a ……

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

South Asia

This month, APT activities in South Asia were primarily initiated by known APT groups. Victims included government agencies in Pakistan, India, and Cambodia, as well as military institutions in Sri Lanka.

In terms of attack tactics, spear-phishing emails dominated APT operations in South Asia this month. A typical decoy targeting Indian government agencies was observed. The threat actor employed its commonly used spear-phishing approach. The decoy was a PowerPoint file named “PPT_for_Breifing_at_HQ_Norther_Command.pptx”. The file featured the logo of India’s Ministry of Road Transport and Highways (MoRT&H) and primarily contained information about……

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Eastern Europe

This month, APT activities in Eastern Europe were primarily conducted by known APT groups. Victims included Ukrainian government agencies and military institutions, as well as Polish organizations or individuals.

In terms of attack tactics, spear-phishing emails remained the predominant method for APT operations in Eastern Europe this month.

Regarding spear-phishing, a typical decoy targeted Ukrainian government agencies. The threat actor, Gamaredon, utilized its characteristic spear-phishing technique. The decoy was a PDF document purporting to be an official notice issued on June 4, 2026, by Military Unit 3018 of the Ukrainian National Guard. The notice reported that a private first class from the unit’s maintenance workshop failed to return to duty following the end of his leave on May 23, 2026. The unit had received no orders regarding his deployment or transfer, and all search efforts proved unsuccessful; furthermore, his phone remained unreachable, leaving his current whereabouts unknown. The notice also included contact telephone numbers and a work email address for inquiries. Based on this evidence, the primary target of this attack is a……

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Global Key APT Events

Event NameRelated Groups
APT group SideCopy launched “Operation Xenofiscal” targeting the Afghan governmentSideCopy
Russian APT group Gamaredon: Operations and Evolution in 2025Gamaredon

Interpretation of Key APT Events

APT Group SideCopy Launched “Operation Xenofiscal” Targeting the Afghan Government

In May 2026, the Pakistani APT group SideCopy launched “Operation Xenofiscal,” a cyber campaign targeting the Afghan government. The primary objectives were the Ministry of Finance of the Islamic Emirate of Afghanistan and its tax and finance bureaus across all 34 provinces. Operation Xenofiscal specifically focused on provincial-level fiscal officials, tax supervisors, and financial management personnel rather than central ministry institutions, demonstrating SideCopy’s in-depth understanding of Afghanistan’s local financial infrastructure.

The main attack workflow of Operation Xenofiscal is illustrated in the figure below:

Group NameSideCopy
Appear Time2019
Attack TargetIndia, Afghanistan
Attack Strategy……
Attack Technique……
Attack Weapon……

Operation Xenofiscal marks the first known cyber-attack campaign launched by Pakistan against Afghanistan, and it also represents the first time the SideCopy group has targeted objectives outside of India. This indicates that Pakistan now views the current Taliban government as a national-level threat comparable to India.

Following the Taliban’s return to power in Afghanistan, bilateral relations have continued to deteriorate due to intensified international conflicts, including border security controls, cross-border attacks by the Tehrik-i-Taliban Pakistan (TTP), and disputes over border demarcation. The Ministry of Finance of the Taliban government and its branches across all 34 provinces (Mustoufiats) serve as the critical lifeline for maintaining regime operations, controlling local taxation, and disbursing military and administrative salaries. By stealing authentic rosters containing the names and direct contact information of fiscal officials and tax supervisors across all 34 provinces, the SideCopy group enables Pakistani intelligence agencies to monitor……

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Russian APT Group Gamaredon: Operations and Evolution in 2025

In 2025, Gamaredon’s attack campaigns maintained a high degree of targeting and frequency. Primary targets included Ukrainian government agencies, military units, law enforcement departments, security institutions, and enterprises related to critical infrastructure. The group’s objectives have shifted entirely to matters concerning the Russia-Ukraine war, focusing on gathering tactical intelligence, acquiring sensitive military information, and monitoring target networks.

Gamaredon continued its strategy of automated, large-scale delivery in 2025. This new attack model, adopted by the group in 2025, is relatively mature and stable, with minimal variations observed between different campaigns.

Compared to previous operations, the primary changes in this new model involve the deployment of new payloads and an enhanced capability to infect removable media. Specific details regarding these new tactics, techniques, and procedures (TTPs) and changes are discussed in the insights section of this subsection.

  • Initial: ……
  • Execution: ……
  • Persistence:……
  • C2 Communication:……
  • Data Exfiltration and Lateral Movement:……
Group NameGamaredon
Appear Time2013
Attack TargetAlbania, Austria, Australia, Bangladesh, Brazil, Canada, Chile, China, Colombia, Croatia, Denmark, Georgia, Germany, Guatemala, Honduras, India, Indonesia, Iran, Israel, Italy, Japan, Kazakhstan, Latvia, Malaysia, Netherlands, Nigeria, Norway, Pakistan, Papua New Guinea, Poland, Portugal, Romania, Russia, South Africa, South Korea, Spain, Sweden, Turkey, UK, Ukraine, USA, Vietnam.
Attack Strategy……
Attack Technique……
Attack Weapon……

In recent years of cyber confrontation, the Gamaredon group has continuously strengthened its capabilities for lateral penetration and crossing isolated networks via removable storage media. In 2025, the group’s newly deployed USB propagation module demonstrated highly automated and dynamic characteristics.

Gamaredon’s USB propagation module real-time monitors removable drive letters on target hosts. By combining file hiding techniques with malicious shortcut disguise, it achieves low-cost, high-efficiency secondary infection and spread. This propagation method is particularly effective during the lateral movement phase and can even penetrate network boundaries to target physically isolated environments.

Regarding specific implementation details, the module monitors interface status in real-time by polling in a loop or listening to system WMI events. Once a newly inserted USB storage device is identified, the module automatically traverses the file structure in the root directory of the drive. Instead of directly destroying original files, the module calls system attribute interfaces to modify existing user files and directories to have “Hidden” and “System” attributes. Simultaneously, it generates LNK shortcuts with names identical to the original files. These shortcuts point to embedded obfuscated scripts or built-in legitimate command-line tools. When a user clicks on what appears to be a normal file, malicious code execution logic is silently triggered in the background, after which the real file is opened to mask the anomaly.

To evade signature-based detection by endpoint security software, Gamaredon has introduced a dynamic payload generation mechanism within its USB propagation component. Each time a payload is written to a USB device, the malicious module performs real-time obfuscation on the core VBScript or PowerShell code. Techniques include randomizing variable names, inserting useless control flows, and……

Subscribe NSFOCUS Threat Intelligence for full details of APT incident insights.

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.