State hackers now log in instead of dropping malware

The North Korean operation that opens AhnLab's July threat report did not start with an exploit. It started with a meeting invite. The group AhnLab tracks as APT38, better known as BlueNoroff, used compromised Telegram accounts to pull targets into fake Zoom and Teams meetings, then walked them through a ClickFix-style prompt that ran malware on Windows and macOS to steal cryptocurrency wallets and credentials.

Nothing in that chain is a hacked server. The way in was a real account belonging to somebody the victim already trusted.

That is the thread running through the whole report. AhnLab's ASEC says state-sponsored and financially motivated crews alike are leaning on legitimate accounts and services rather than malware alone: in through phishing, social engineering and supply chain compromise, then quiet, using script-based execution, obfuscation and HTTP-based command and control. The targets it lists are simply the places credentials live: Microsoft 365, webmail, cloud infrastructure, GitHub, VPN and remote access, and passwords saved in browsers.

Pyongyang went after the people who build software

Alongside the fake meetings, AhnLab describes Famous Chollima compromising GitHub maintainer accounts, then injecting obfuscated JavaScript loaders into npm, Packagist, Go modules and Chrome extensions to steal credentials, browser data and wallet information. That is a supply chain position bought with a stolen login, not an exploit. Kimsuky is separately reported using Gomir, BirdTroy and DriveTroy to spread from groupware developers into their customers.

Russia's crews went through the mail server

The Russian section is almost all webmail and identity. APT28 is reported running a remote access trojan that used the file-sharing service Filen.io as its command channel. AhnLab also describes APT28-like activity compromising Wi-Fi gateways at hotels and conference venues, then using DNS poisoning and Microsoft's device-code sign-in flow to collect Microsoft 365 credentials and OAuth tokens. TA458 and Void Blizzard are described exploiting a flaw the report calls "Half-click" in Zimbra, Outlook Web Access, Roundcube and SOGo, using ZimReaper and OWAReaper to take credentials, contacts and mail. The report names that flaw but does not explain it.

China built infrastructure, Iran built phishing

The China-linked activity is about staying rather than getting in: Daxin and Stupig executing commands with SYSTEM privileges and stealing credentials inside Taiwanese high-tech manufacturers, UNK_MassTraction repeatedly exploiting Roundcube to reach university networks, and UAT-7810 planting LONGLEASH, DOGLEASH and JARLEASH on unpatched Ruckus and ASUS AiCloud routers to build an ORB network, a relay layer of compromised devices that masks an operator's true origin. Iran-linked groups intensified AI-assisted phishing and moved command and control onto cloud and messenger services, with APT42 taking browser credentials and cookies via TAMECAT and TAG-182 pushing MarkiRAT through fake VPN installers.

The controls AhnLab puts first

Its recommendations follow the pattern rather than any one campaign: multi-factor authentication, separating administrator accounts from everyday ones, log monitoring, integrity checks on open-source and third-party software, behaviour-based EDR and XDR detection, and supply chain audits that reach business partners, with accounts, cloud and development environments named as the places to concentrate.

What a monthly roll-up cannot tell you

This is a trend summary, not an incident report: it names groups, tools and sectors but publishes no indicators of compromise and no victim names, so it cannot tell you whether a particular organization was hit. What it is good for is direction, and it holds across four countries' worth of activity with little else in common: initial access is increasingly a valid credential rather than a broken door. That is harder to catch than a malicious file, because at the moment it happens nothing has occurred that a signature could see.

AhnLab's ASEC published the July 2026 Threat Trend Report on APT Groups, credited to its ATCP team. It is the same account-first pattern IntelFusions covered this week when North Korean fake hires used AI to get through job interviews.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions