Read AhnLab's August round-up of state-sponsored activity looking for a common thread and one turns up quickly. It is not a technique or a target. It is the infrastructure. Across North Korean, Chinese and Russian operations logged that month, the security company's ASEC team found GitHub, GitLab, OneDrive, Telegram, Discord, Google Sheets and blockchain networks doing the work that attacker-owned servers used to do: carrying commands, delivering payloads and taking stolen data back out.
That is an awkward finding for anyone who defends a network by deciding which destinations are allowed. All of those services are allowed, everywhere, by almost everyone.
The same services keep showing up
The report is a summary rather than a technical deep dive, and the detail sits with the cases it names. North Korea-linked groups concentrated on developers and software supply chains: AhnLab says Famous Chollima continued its PolinRider supply chain attacks, with command and control routed over the Ethereum blockchain, while Lazarus went after defence industry targets in the long-running Operation Dream Job using a malicious PDF viewer and a zero-day, CVE-2026-68820, that we reported on last month.
China-linked activity ran to long-term access rather than smash and grab. AhnLab records Fire Ant compromising trusted infrastructure, including Cisco IOS XR routers, TACACS authentication servers and Linux management hosts, to harvest credentials and traffic, and Mustang Panda pairing hydropower-themed lures with the Claimloader, ToneShell and Havencode backdoors.
Russia-linked groups went after mail and the networks people join without thinking. APT28 used a tool AhnLab calls HOOKEDGE together with a public webhook service for spear phishing and data exfiltration. Storm-2945 manipulated captive portal networks, the sign-in pages at hotels, conferences and airports, to steal Microsoft 365 accounts and tokens and push two loaders.
AI has moved into the setup work
The other pattern worth noting is where generative AI shows up in these cases, which is earlier in the chain than the alarming version of this story usually suggests. AhnLab describes Jasper Sleet attempting to gain internal access with AI-generated fake identities and remote job scams, and Kimsuky using generative-AI-built decoy documents alongside Git-based command and control, with indications of local language model use. That is AI doing the preparation, the paperwork and the pretext, rather than writing novel malware.
Allow lists cannot see this
AhnLab's own conclusion is that indicator-based detection alone has clear limits against this, which follows directly from the finding: there is no bad domain to block when the domain is github.com. It recommends supply chain verification, multi-factor authentication, cloud log monitoring, and behaviour-based detection through EDR or XDR tooling.
The practical version for most defenders is narrower. If developer platforms, consumer chat apps and cloud storage are permitted everywhere on the network by default, the question worth asking is not whether they are reachable but whether anyone would notice a workstation talking to them in a pattern no developer would produce. Attacker infrastructure used to be something you could put on a list. Increasingly it is a service you already pay for, and the only thing that distinguishes malicious use is behaviour.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.