H1 2026 threat activity was dominated by abuse of legitimate tools, trusted platforms, and routine workflows, while AI mainly augmented existing intrusion tradecraft rather than replacing it. The report also highlights widespread exploitation of exposed CVEs, persistent RAT and stealware activity, evolving supply-chain compromises, NFC-based mobile fraud, and Magecart campaigns that leveraged trusted third-party services. #AsyncRAT #CobaltStrike #XWorm #Stealc #REMCOSRAT #PromptSpy #NGate #NFCShare #Magecart #ShaiHulud #TeamPCP
Keypoints
- Insikt Group identified 215 actively exploited CVEs in H1 2026, a 34% increase from H1 2025.
- Most exploited vulnerabilities were network-accessible, and many required no prior authentication, with 60 unauthenticated RCE flaws also exposed to the network.
- RATs remained highly prominent, with AsyncRAT leading malware submissions by unique hashes and C2 diversity.
- AI-enabled malware activity mostly stayed within AIM3 Levels 1 to 3, supporting specific tasks like persistence, UI interaction, malware development, and delivery.
- Ransomware operators continued using established access and evasion methods such as ClickFix lures, public-facing application exploitation, and legitimate admin tools like AnyDesk, PsExec, and s5cmd.
- Android NFC malware became a major mobile threat trend, with NFCShare and NGate enabling payment-card theft, contactless fraud, and ATM cash-outs.
- Supply-chain attacks, including Shai-Hulud-like and TeamPCP-related activity, targeted npm, GitHub, CI/CD, and AI-enabled developer tools to steal credentials and propagate malicious code.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â Used to gain initial access by exploiting exposed applications and management interfaces (âthreat actors repeatedly relied on familiar executionâŚâ; âExploitation of public-facing applicationsâ).
- [T1082 ] System Information Discovery â Used to profile infected systems after execution (âused System Information Discovery to profile infected systems after executionâ).
- [T1005 ] Data from Local System â Used to collect data from compromised hosts (âData from Local Systemâ).
- [T1105 ] Ingress Tool Transfer â Used to stage and transfer payloads into victim environments (âIngress Tool Transferâ; âused Ingress Tool Transfer to stage payload deliveryâ).
- [T1059.001 ] PowerShell â Used for command execution and malicious automation (âmalicious PowerShell commandâ; âPowerShell (T1059.001)â).
- [T1059.003 ] Windows Command Shell â Used for script and command execution on Windows (âWindows Command Shell (T1059.003)â).
- [T1059.004 ] Unix Shell â Used for shell-based execution in Unix environments (âUnix Shell (T1059.004)â).
- [T1041 ] Exfiltration Over C2 Channel â Used to send stolen data out through command-and-control channels (âExfiltration Over C2 Channel (T1041)â).
- [T1071.001 ] Web Protocols â Used for command-and-control communication over web-based protocols (âWeb Protocols (T1071.001)â).
- [T1505.003 ] Web Shell â Used to maintain persistent access after exploitation (âWeb Shell (T1505.003)â).
- [T1027 ] Obfuscated Files or Information â Used to hide malicious behavior and complicate analysis (âObfuscated Files or Informationâ; âLLM-generated decoy logicâ).
- [T1204 ] User Execution â Used when victims were tricked into running malicious files or installers (âUser Executionâ; âdevelopers to install trojanized Open Visual Studio Extensionsâ).
Indicators of Compromise
- [Malware families ] observed in reporting â AsyncRAT, Cobalt Strike, XWorm, Stealc, REMCOS RAT, Gh0st RAT, PromptSpy, NGate, NFCShare, PlugX, DOGCALL (RokRAT), Vidar, Amatera, GlassWorm
- [Threat actor / group names ] linked to campaigns â StrikeShark, Storm-1175, Kimsuky, TAG-176, TeamPCP, SHADOW-EARTH-053, VerdantBamboo, APT37, Camaro Dragon
- [CVE identifiers ] exploited or referenced â CVE-2026-20131, CVE-2025-68947, CVE-2023-27532, CVE-2024-4345, and 2 more items
- [Domains / platforms ] used for delivery or infrastructure â GitHub, Dropbox, claude.ai, Medium, and Google Tag Manager
- [File names / package names ] used in delivery or staging â SyncAppvPublishingServer.vbs, colorcpl.exe, mbt, @cap-js/*, and OpenClaw
- [Tools / software names ] seen in campaigns â AnyDesk, PsExec, s5cmd, Rclone, Mimikatz, Impacket, Atera, DWAgent, and MeshAgent
- [C2 / network indicators ] mentioned as infrastructure types â WebSocket endpoint, hard-coded C2 infrastructure, Cloudflare tunnels, and Internet Computer Protocol (ICP) canisters
- [Operating system / application targets ] referenced in attacks â Microsoft Exchange Server, SharePoint, Windows Server, Next.js, Red Hat Enterprise Linux, Android, WooCommerce, Magento, and Adobe Commerce
Read more: https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends