Most Active Threat Actors_H1

You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? 

We do. 

Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis of the Global Threat Landscape spanning ransomware, initial access brokers, data breaches and leaks, nation-state espionage, and hacktivism, among others.  

One of the most striking analyses that puts the threat landscape severity in perspective was the number of distinct threat actor profiles active worldwide between January and June. 261 — that’s how many identifiable groups and individuals, each with its own tradecraft, targeting logic, and operational rhythm, running campaigns simultaneously across nation-state espionage, ransomware, hacktivism, and cybercrime.

What makes this data set valuable isn’t just the headline count. It’s what the composition reveals. A threat landscape dominated by nation-state APT groups tells a very different story than one dominated by ransomware crews — and as Cyble’s regional breakdown shows, that composition shifts dramatically depending on where you’re standing. 

The Worldwide Picture of Most Active Threat Actors: APTs Lead, But Not Everywhere 

Across all 261 profiles tracked globally, nation-state Advanced Persistent Threat (APT) groups were the single largest category — accounting for 118 profiles, or just over 45% of the total. Ransomware operators came second at 75 profiles (29%), followed by hacktivist collectives (34), cybercriminal groups (31), and dedicated extortion-only gangs, which remained a niche category at just 3. 

Threat Actor Category  Profiles Tracked  Share of Total 
Nation-State APT Groups  118  45.2% 
Ransomware Groups  75  28.7% 
Hacktivist Collectives  34  13.0% 
Cybercriminal Groups  31  11.9% 
Extortion-Only Groups  1.1% 
Total  261  100% 

That APT dominance reflects the sheer number of state-sponsored programs China, North Korea, Iran, and Russia field simultaneously across espionage, intellectual property theft, and pre-positioning operations.

The extortion-only category being almost statistically irrelevant is telling too — it confirms that pure extortion has essentially been absorbed into the ransomware business model rather than surviving as an independent specialty. Double extortion is now just how ransomware works. 

Worried your business is not immune to the tactics of these APT and ransomware groups? Book a demo to validate and fortify your defenses today! 

Threat Actors to Watch Out For 

CRIL flagged five groups worldwide as carrying the highest confidence and activity levels for security teams to track through the rest of 2026: 

Actor  Origin  Primary Targets  Sectors Targeted 
Bluenoroff  North Korea (Lazarus subgroup)  Global — cryptocurrency sector  Cryptocurrency, Financial Services 
UNC6508  China (PRC-nexus espionage)  US, Canada  Education, Healthcare, Government, Aerospace & Defense 
Volt Typhoon  China (state-sponsored)  US (incl. Guam) and allies  Communications, Energy, Manufacturing, Government, IT 
Desert Falcons  Palestine  UAE, Israel, Jordan, and 12+ other MEA nations  Aerospace & Defense, Government, Law Enforcement, Media 
SideCopy  Pakistan  India, Afghanistan  Government, Defense/military 

Two of these deserve particular attention for how they operate.  

Bluenoroff, a financially motivated Lazarus Group subgroup, funds North Korean state operations by impersonating established crypto investors and planting malicious links inside victims’ Calendly scheduling accounts. This fraud vector blends social engineering with a tool most professionals trust implicitly.  

Volt Typhoon continues to favor “living off the land” techniques that blend into normal network activity, prioritizing long-term undetected access over rapid data theft — a profile consistent with pre-positioning for a future disruption event rather than opportunistic espionage. 

UNC6508 is worth flagging separately: the group compromises externally accessible REDCap research environments and has been observed creating malicious mail-forwarding rules to silently exfiltrate correspondence — all routed through US-based residential proxies and compromised routers specifically to obscure attribution. 

For a regional breakdown of which actors were the most active and which sectors they target, download Cyble Research and Intelligence Labs’ H1 2026 Global Threat Landscape Report. 
 
Download now! 

Track These Threat Actors in Real Time

The threat actor profiles, targeting patterns, and regional breakdowns in this analysis are drawn from Cyble’s H1 2026 Global Threat Landscape Report, built on continuous monitoring across dark web forums, ransomware leak sites, and threat actor communications worldwide.  

Cyble Vision provides ongoing tracking of these groups — including new actor emergence, TTP shifts, and targeting changes — as they develop.  

Request a demo to see how continuous threat actor intelligence can sharpen your regional security priorities. 

The post APTs Top the List of Most Active Threat Actors in H1 2026 appeared first on Cyble.