2026 H1 APT Report: How APTs Are Weaponizing Trust in the Age of AI

State-aligned threat actors are folding AI into every stage of the attack chain while hiding their infrastructure inside the services defenders already trust. This report unpacks the geopolitics driving the activity and what defenders should prioritize next.

Download the PDF

By TrendAI™ Research

Advanced persistent threats (APTs) sharpened their tradecraft through the first half of 2026. AI now shows up in more stages of the intrusion lifecycle, from enhancing exploit code to running autonomous reconnaissance and lateral movement. This report compiles six months of research and real-world observations across China-, Russia-, Democratic People’s Republic of Korea (DPRK)-, and Iran-aligned activity to show security leaders how these actors operate today. It also shows how the political backdrop in each region continues to shape their targeting and tradecraft.

Known and zero-day flaws were weaponized quickly, and the software supply chain remained a favored way in. Threat actors increasingly kept command and control (C&C) on services that enterprises already trust, such as major cloud platforms, developer tunnels, public blockchains, and paste sites, letting malicious traffic blend into normal business activity and resist takedown. Critical infrastructure and physical-world targets also came back into focus, from hands-on tampering with internet-exposed fuel-tank gauges to a new dimension of malware-free tracking through advertising intelligence (ADINT).

AI ambitions and constraints across major threat ecosystems

China

“State-aligned scaler”

China-aligned groups leaned on AI at nearly every stage this half. Earth Krahang used generative AI to turn a public exploit into a large-scale scanner, Earth Naga "vibe coded" a backdoor loader, and a separate actor deployed an AI agent that autonomously scanned, harvested credentials, and moved laterally within the target organization’s network. Others hid C&C inside Microsoft 365 drafts and blockchain transactions, while SHADOW-EARTH-067 paired that stealth with a Bring Your Own Vulnerable Driver (BYOVD) rootkit to blind endpoint detection and response (EDR) at the kernel level.

North Korea

“Theft-financed ascendant”

DPRK-aligned cells stayed focused on funding the state. BlueNoroff compromised the Axios maintainer’s account to deploy a remote access trojan (RAT) through a package with over 100 million weekly downloads, while Void Dokkaebi spread malware through fake job-interview repositories. A likely DPRK-aligned threat actor stole US$285 million from Drift Protocol and another actor extracted US$292 million from KelpDAO, adding to steady revenue from IT worker infiltration. Sanctions and a strained power grid keep frontier AI out of reach domestically, pushing these groups toward overseas servers and borrowed AI models to support ambitions such as AI-guided missile tests.

Russia

“Hardware-capped militarizer”

Russia-aligned groups moved fast and stayed hidden. Pawn Storm weaponized a fresh Office zero-day exploit within weeks and hit a wide range of war-related targets, from defense ministries to border police, while Earth Dahu kept exploiting a known WinRAR flaw that not all targets patched. Turla leaned on especially hard-to-kill infrastructure, reworking its Kazuar toolset into a botnet where only one node per network calls out, while Laundry Bear took a different route, posing as wartime charities and running its C&C off disposable paste sites.

Iran and other regions

“Off-the-shelf escalator”

Iran-aligned activity blurred espionage and crime. CyberAv3ngers was tied to IOCONTROL, a reusable malware platform built to target operational technology such as fuel systems. Separately, internet-exposed fuel-tank gauges at U.S. sites were hit in a suspected Iran-linked wave, while Earth Vetala (MuddyWater) mixed its own tooling with a rented backdoor bought from a criminal platform, resolving C&C through public blockchain lookups. Activity from other regions revealed the use of ADINT to track individuals at scale without deploying any malware at all.

What this report covers

This report breaks down how nation-aligned APT activity shifted over the first half of 2026 and what that shift means for defenders going forward. You'll find:

  • Five key takeaways summarizing how AI, trusted-infrastructure abuse, and geopolitical alignment are reshaping the threat landscape
  • Region-by-region political analysis covering China, North Korea, and Russia, and how national priorities influence cyber activity
  • Detailed campaign profiles covering AI-assisted development, abuse of legitimate services as C&C channels, multistage phishing, BYOVD, supply chain poisoning, cryptocurrency theft, attacks on operational technology, and ADINT surveillance
  • A dedicated breakdown of the half's most noteworthy tactics, techniques, and procedures (TTPs)
  • Prioritized mitigation guidance mapped to Security Operations, Governance, and Risk Management owners

Noteworthy TTPs

1. AI-assisted development and agentic lateral movement

The first half of 2026 marked the first time TrendAI™ research teams documented China-aligned threat actors Earth Krahang, Earth Naga (associated with Flax Typhoon), and an unidentified actor actively integrating generative AI (GenAI) into multiple stages of the attack lifecycle. Its uses ranged from enhancing exploit scripts and developing malware through “vibe coding” to deploying AI agents that autonomously conducted internal reconnaissance, credential harvesting, and lateral movement. While these actors are still in an exploratory phase, the trend signals a meaningful lowering of the barrier to entry for sophisticated attack capabilities.

2. Abuse of legitimate services as C&C channels

In the first half of 2026, multiple China-aligned threat actors such as Earth Baxia and SHADOW-EARTH-067 replaced traditional C&C infrastructure with legitimate cloud platforms. These included Microsoft Graph API (OneDrive, OneNote, and draft emails), Microsoft DevTunnel, SoftEther dynamic DNS (DDNS), and even the Stellar blockchain, all used to issue commands and receive results from compromised hosts. By routing malicious traffic through trusted, widely used services, attackers make it extremely difficult for defenders to distinguish malicious activity from normal business traffic.

3. Multistage phishing with decoy documents and social engineering lures

Spear phishing remained a leading initial access vector in the first half of 2026, continuing the trend from the second half of 2025. Threat actors elevated the quality of their lures considerably. Campaigns featured multiturn email conversations to build trust, geopolitically relevant decoy documents, fake software update utilities, and watering-hole attacks with fake browser certificate error pages, all designed to lower victim suspicion and increase click-through rates.

4. BYOVD for EDR and anti-malware evasion

In the first half of 2026, BYOVD was observed being deployed as a dedicated rootkit component, representing a significant escalation in the sophistication of evasion capabilities used by China-aligned actors, notably SHADOW-EARTH-067.

How AI and political shifts are redefining APT campaigns in the first half of 2026

“In one case an AI agent ran its own reconnaissance and lateral movement, jailbroken by an actor falsely claiming the operation was a legitimate penetration test.”

AI is no longer an experimental capability for APT groups; it is an operational component embedded directly into campaigns. China-aligned actors used GenAI to sharpen a public proof-of-concept exploit into a large-scale scanning tool. They also iteratively “vibe coded” a malicious PowerShell-and-C# backdoor loader. In one case tied to a possible Earth Lamia operation, they jailbroke an autonomous AI agent that then conducted its own network scanning, exploitation, credential harvesting, and password spraying against a target in Southeast Asia. Russia- and DPRK-aligned actors have been observed using commercial AI as well, though generally in a more limited, supporting role.

At the same time, the political backdrop behind these campaigns is durable rather than transient. The war in Ukraine has settled into a long attritional fight while Russia tightens information control ahead of its September legislative elections. The DPRK is entrenching itself as a permanent nuclear-armed state funded by cyber theft. China is managing its U.S. rivalry while pushing chip and AI self-reliance. Iran-aligned operations escalated alongside regional tension. None of these trends is expected to reverse by year end. That means the campaigns built around them—such as AI-sharpened exploitation, trusted-infrastructure abuse, and rented or shared tooling—are likely to persist and mature.

Who should read this

This report is built for anyone with a stake in organizational security, though different teams will draw different value from it.

Security leadership such as chief information security officers (CISOs) and security directors can use it to understand how AI adoption, abuse of trusted infrastructure, and geopolitical alignment are changing the long-term risk picture. That view helps when prioritizing budget and briefing executives.

Security operations center (SOC) teams and threat intelligence analysts get to see how China-, Russia-, DPRK-, and Iran-aligned actors operate day to day, from AI-assisted exploit development to C&C hidden inside trusted cloud services and blockchains.

Engineers, meanwhile, can draw on this analysis to sharpen detection logic for BYOVD rootkits, cloud and identity abuse, and supply chain compromise.

Risk, policy, and governance teams get the geopolitical grounding needed to explain why particular regions, sectors, and operational technology are being targeted, which supports risk assessments and planning across teams.

Priority actions for defenders

  • Shift detection toward identity, cloud, and endpoint behavior, since C&C increasingly hides in trusted cloud platforms, developer tunnels, and blockchains. Owner: Security Operations and Identity teams.
  • Treat the software supply chain and the developer as part of the attack surface; pin and verify dependencies and monitor install-time scripts. Owner: Governance and Security Operations.
  • Shrink the patch and exposure window on edge and unmanaged software, especially tools that do not auto-update. Owner: Risk Management.
  • Take operational technology and critical-infrastructure devices off the public internet, and segment and monitor control networks. Owner: Risk Management and Security Operations.
  • Plan for AI-accelerated adversaries, including AI tools already inside the environment such as coding assistants and agent frameworks. Owner: Security Operations and Governance.

Get the full picture

APT Activity Rounup 2026

The preceding sections only scratch the surface. The full 2026 H1 APT Report includes complete campaign write-ups, technical indicators, and region-by-region analysis across China, North Korea, Russia, and Iran. Download it to see the full threat landscape and what it means for your organization heading into the second half of the year.

This report draws on a deeper body of research: the bimonthly APT Research Report, which is available in the TrendAI Vision One™ Threat Intelligence Hub. Everything referenced here, from specific campaigns to individual indicators, is documented at greater length there for teams that need the full picture.

HIDE

Like it? Add this infographic to your site:
1. Click on the box below.   2. Press Ctrl+A to select all.   3. Press Ctrl+C to copy.   4. Paste the code into your page (Ctrl+V).

Image will appear the same size as you see above.