H1 2026 Malware Vulnerability Trends
H1 2026 threat activity was dominated by abuse of legitimate tools, trusted platforms, and routine workflows, while AI mainly augmented existing intrusion tradecraft rather than replacing it. The report also highlights widespread exploitation of exposed CVEs, persistent RAT and stealware activity, evolving supply-chain compromises, NFC-based mobile fraud, and Magecart campaigns that leveraged trusted third-party services. #AsyncRAT #CobaltStrike #XWorm #Stealc #REMCOSRAT #PromptSpy #NGate #NFCShare #Magecart #ShaiHulud #TeamPCP

Keypoints

  • Insikt Group identified 215 actively exploited CVEs in H1 2026, a 34% increase from H1 2025.
  • Most exploited vulnerabilities were network-accessible, and many required no prior authentication, with 60 unauthenticated RCE flaws also exposed to the network.
  • RATs remained highly prominent, with AsyncRAT leading malware submissions by unique hashes and C2 diversity.
  • AI-enabled malware activity mostly stayed within AIM3 Levels 1 to 3, supporting specific tasks like persistence, UI interaction, malware development, and delivery.
  • Ransomware operators continued using established access and evasion methods such as ClickFix lures, public-facing application exploitation, and legitimate admin tools like AnyDesk, PsExec, and s5cmd.
  • Android NFC malware became a major mobile threat trend, with NFCShare and NGate enabling payment-card theft, contactless fraud, and ATM cash-outs.
  • Supply-chain attacks, including Shai-Hulud-like and TeamPCP-related activity, targeted npm, GitHub, CI/CD, and AI-enabled developer tools to steal credentials and propagate malicious code.

MITRE Techniques

  • [T1190 ] Exploit Public-Facing Application – Used to gain initial access by exploiting exposed applications and management interfaces (‘threat actors repeatedly relied on familiar execution…’; ‘Exploitation of public-facing applications’).
  • [T1082 ] System Information Discovery – Used to profile infected systems after execution (‘used System Information Discovery to profile infected systems after execution’).
  • [T1005 ] Data from Local System – Used to collect data from compromised hosts (‘Data from Local System’).
  • [T1105 ] Ingress Tool Transfer – Used to stage and transfer payloads into victim environments (‘Ingress Tool Transfer’; ‘used Ingress Tool Transfer to stage payload delivery’).
  • [T1059.001 ] PowerShell – Used for command execution and malicious automation (‘malicious PowerShell command’; ‘PowerShell (T1059.001)’).
  • [T1059.003 ] Windows Command Shell – Used for script and command execution on Windows (‘Windows Command Shell (T1059.003)’).
  • [T1059.004 ] Unix Shell – Used for shell-based execution in Unix environments (‘Unix Shell (T1059.004)’).
  • [T1041 ] Exfiltration Over C2 Channel – Used to send stolen data out through command-and-control channels (‘Exfiltration Over C2 Channel (T1041)’).
  • [T1071.001 ] Web Protocols – Used for command-and-control communication over web-based protocols (‘Web Protocols (T1071.001)’).
  • [T1505.003 ] Web Shell – Used to maintain persistent access after exploitation (‘Web Shell (T1505.003)’).
  • [T1027 ] Obfuscated Files or Information – Used to hide malicious behavior and complicate analysis (‘Obfuscated Files or Information’; ‘LLM-generated decoy logic’).
  • [T1204 ] User Execution – Used when victims were tricked into running malicious files or installers (‘User Execution’; ‘developers to install trojanized Open Visual Studio Extensions’).

Indicators of Compromise

  • [Malware families ] observed in reporting – AsyncRAT, Cobalt Strike, XWorm, Stealc, REMCOS RAT, Gh0st RAT, PromptSpy, NGate, NFCShare, PlugX, DOGCALL (RokRAT), Vidar, Amatera, GlassWorm
  • [Threat actor / group names ] linked to campaigns – StrikeShark, Storm-1175, Kimsuky, TAG-176, TeamPCP, SHADOW-EARTH-053, VerdantBamboo, APT37, Camaro Dragon
  • [CVE identifiers ] exploited or referenced – CVE-2026-20131, CVE-2025-68947, CVE-2023-27532, CVE-2024-4345, and 2 more items
  • [Domains / platforms ] used for delivery or infrastructure – GitHub, Dropbox, claude.ai, Medium, and Google Tag Manager
  • [File names / package names ] used in delivery or staging – SyncAppvPublishingServer.vbs, colorcpl.exe, mbt, @cap-js/*, and OpenClaw
  • [Tools / software names ] seen in campaigns – AnyDesk, PsExec, s5cmd, Rclone, Mimikatz, Impacket, Atera, DWAgent, and MeshAgent
  • [C2 / network indicators ] mentioned as infrastructure types – WebSocket endpoint, hard-coded C2 infrastructure, Cloudflare tunnels, and Internet Computer Protocol (ICP) canisters
  • [Operating system / application targets ] referenced in attacks – Microsoft Exchange Server, SharePoint, Windows Server, Next.js, Red Hat Enterprise Linux, Android, WooCommerce, Magento, and Adobe Commerce


Read more: https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends