SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Defence and government contractors threat intelligence report — 27 April – 3 May 2026

The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.

  • Reference: TI-2026-0504-006 (public edition)
  • Sector: R&D, military and government contractors
  • Reporting period: 27 April – 3 May 2026
  • Issued: 4 May 2026 · Lead analyst: P. Bassill (SOC Lead) · Reviewed by: SOC Reviewing Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity. Google Threat Intelligence Group reporting in February 2026 attributed coordinated defence-sector cyber operations to Russia (UNC5792 and UNC5976), China (APT5, APT31, UNC3236 / Volt Typhoon), Iran (UNC1549, UNC6446) and North Korea (APT43, UNC2970), with credential harvesting via spoofed login pages the common tradecraft. APT28 has been observed exploiting Microsoft Office vulnerabilities against government and military entities. China continues Typhoon campaigns aimed at IP theft and embarrassing Western governments. The principal material-risk scenario remains long-dwell-time espionage rather than ransomware, although secondary criminal targeting persists.

Key Judgements

1. It is highly likely that long-dwell-time espionage from Russia-, China-, Iran- and DPRK-aligned actors will remain the principal material-risk scenario for R&D and government-contractor entities over the next reporting cycle. (HIGH confidence)

2. It is highly likely that credential harvesting via spoofed login pages targeting current and former contractor employees — the documented Feb 2026 GTIG-attributed pattern — will continue at sustained tempo. (HIGH confidence)

3. It is likely that Volt Typhoon (UNC3236) reconnaissance activity against publicly-hosted login portals of North American military and defence contractors will continue, and there is a realistic possibility of similar UK-targeted activity. (MEDIUM-HIGH confidence)

4. It is likely that APT28 Microsoft Office vulnerability exploitation will continue against government and military entities through the next reporting cycle, with multi-stage stealth-focused post-exploitation chains. (MEDIUM-HIGH confidence)

5. There is a realistic possibility that secondary ransomware targeting of R&D entities will increase as APT-criminal collaboration normalises, but at materially lower operational tempo than against finance / retail / healthcare. (MEDIUM confidence)

2. Sector threat landscape

The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity. Google Threat Intelligence Group reporting in February 2026 attributed coordinated defence-sector cyber operations to four state-aligned constellations: Russia (UNC5792 and UNC5976), China (APT5, APT31, UNC3236 / Volt Typhoon), Iran (UNC1549 and UNC6446) and North Korea (APT43 and UNC2970). The common tradecraft across these clusters during the reporting period is credential harvesting via spoofed login pages, with messages sent to both corporate and personal email addresses of current and former contractor employees and personalised lures based on victim role, location and personal interest.

China-nexus APT5 ran two spearphishing campaigns in mid-to-late 2024 and again in May 2025, targeting current and former employees of major aerospace and defence contractors. The continued Typhoon campaign portfolio — Volt Typhoon (UNC3236), Salt Typhoon, Linen Typhoon — has been described in NSA / CISA / NCSC joint advisories as a sustained campaign against Western critical infrastructure with the dual aims of intellectual-property theft and pre-positioning for potential future disruption.

Russian APT28 has been observed exploiting Microsoft Office vulnerabilities against government and military entities during the reporting period, deploying multi-stage attack chains designed to remain stealthy during post-exploitation. Iran-aligned UNC1549 and UNC6446 continue to favour the defence-industrial-base and aerospace sub-sector. North Korean APT43 / UNC2970 maintain the cryptocurrency / IP-theft dual-targeting that has characterised DPRK cyber operations through 2024 and 2025.

Secondary criminal targeting persists. Although the operational tempo of ransomware against R&D entities is materially lower than against finance, retail and healthcare, ransomware leak-site postings during the reporting period continued to surface mid-market defence-supply-chain victims. The principal concern in this lane is APT-criminal collaboration: the partnership patterns observed in 2024 and 2025 (especially between Russian-aligned APT operators and ransomware affiliates with shared tooling) are likely to normalise through 2026.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.

THREAT ACTOR PROFILE — APT28
AliasesFancy Bear, Sofacy, Forest Blizzard
Suspected OriginRussia
Suspected SponsorGRU Unit 26165
Primary MotivationEspionage; influence
Sector TargetingGovernment, military, defence-industrial-base, political organisations
Geographic FocusGlobal; sustained UK / EU / NATO targeting
Signature TTPsMicrosoft Office vulnerability exploitation; credential harvesting via spoofed login pages; multi-stage stealth-focused post-exploitation; OWA / Exchange targeting
Tooling / Malware FamiliesX-Agent / Sednit malware family; Drovorub; OutSteel / SaintBot loaders; living-off-the-land
Recent ActivitySustained Microsoft Office vulnerability exploitation against government / military entities during the reporting period
Assessed Threat to VerticalHIGH
Analytic ConfidenceHIGH
THREAT ACTOR PROFILE — Volt Typhoon
AliasesUNC3236, BRONZE SILHOUETTE, Vanguard Panda
Suspected OriginChina
Suspected SponsorChinese state
Primary MotivationPre-positioning against Western critical infrastructure; intelligence collection
Sector TargetingCritical infrastructure, telecommunications, military / defence contractors
Geographic FocusUnited States, United Kingdom, allied jurisdictions
Signature TTPsLiving-off-the-land; SOHO router-and-edge-appliance abuse for traffic blending; long-dwell-time persistence; reconnaissance against publicly-hosted login portals
Tooling / Malware FamiliesLiving-off-the-land — netsh, PowerShell, WMIC, Mimikatz; compromised SOHO router infrastructure
Recent ActivitySustained reconnaissance activity against publicly-hosted login portals of North American military and defence contractors through 2025–2026
Assessed Threat to VerticalHIGH
Analytic ConfidenceHIGH
THREAT ACTOR PROFILE — APT5
AliasesUNC2630, Manganese, MULBERRYMAJESTY
Suspected OriginChina
Suspected SponsorChinese state
Primary MotivationEspionage — aerospace / defence intellectual property
Sector TargetingAerospace, defence-industrial-base, telecommunications
Geographic FocusUnited States, allied jurisdictions
Signature TTPsSpearphishing of current / former contractor employees; personal-and-corporate-mailbox dual targeting; tailored lures based on role and personal interest
Tooling / Malware FamiliesCustom downloaders; living-off-the-land
Recent ActivityTwo spearphishing campaigns in mid-to-late 2024 and again in May 2025 against current and former employees of major aerospace and defence contractors; pattern continues
Assessed Threat to VerticalHIGH
Analytic ConfidenceHIGH
THREAT ACTOR PROFILE — UNC1549 / UNC6446 (Iran-aligned)
AliasesVarious — Iran-aligned defence-industrial-base targeting
Suspected OriginIran
Suspected SponsorIRGC / MOIS-aligned
Primary MotivationEspionage; pre-positioning
Sector TargetingAerospace, defence-industrial-base, government
Geographic FocusUnited States, Israel, allied jurisdictions
Signature TTPsSpearphishing; cloud-account abuse; supply-chain targeting
Tooling / Malware FamiliesCustom .NET implants; living-off-the-land
Recent ActivitySustained activity against the defence-industrial-base through 2025 and into 2026; GTIG-attributed in Feb 2026 reporting
Assessed Threat to VerticalHIGH
Analytic ConfidenceMEDIUM
THREAT ACTOR PROFILE — APT43 / UNC2970 (DPRK)
AliasesKimsuky-adjacent; Diamond Sleet-adjacent
Suspected OriginDPRK
Suspected SponsorDPRK state
Primary MotivationEspionage; cryptocurrency theft
Sector TargetingGovernment, defence-industrial-base, financial services, cryptocurrency
Geographic FocusGlobal; sustained US / South Korea / Japan presence
Signature TTPsSpearphishing with personalised lures; LinkedIn-based engagement; trojanised job-offer documents
Tooling / Malware FamiliesCustom .NET / PowerShell implants; living-off-the-land
Recent ActivitySustained engagement-and-spearphishing pattern against defence-contractor employees through the reporting period
Assessed Threat to VerticalHIGH
Analytic ConfidenceMEDIUM

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1566.002Spearphishing LinkSpoofed login pages for credential harvest — common Feb 2026 GTIG-attributed pattern across Russia / China / Iran / DPRK clusters.H
Initial AccessT1190Exploit Public-Facing ApplicationCitrix NetScaler / Microsoft Exchange / Microsoft Office vulnerability exploitation continues to be the principal non-phishing vector.H
Initial AccessT1078Valid AccountsStolen / phished credentials used for sustained low-and-slow access; long-dwell-time persistence is the espionage hallmark.H
PersistenceT1098Account ManipulationOWA / Exchange mailbox-rule and forwarding-rule manipulation observed in APT28 intrusions during the reporting period.M
Defence EvasionT1070Indicator RemovalMulti-stage stealth-focused post-exploitation chains designed to remain quiet through long-dwell-time campaigns.H
Credential AccessT1003OS Credential DumpingMimikatz-style and netsh-based credential harvesting consistent with Volt Typhoon living-off-the-land.M
DiscoveryT1018Remote System DiscoverySustained reconnaissance against publicly-hosted login portals — Volt Typhoon hallmark.H
CollectionT1119Automated CollectionLong-dwell-time IP-theft collection routines across aerospace / defence document repositories.M

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
Feb 2026US defence-industrial-base employees (multi-victim)Russia (UNC5792, UNC5976), China (APT5, APT31), Iran (UNC1549, UNC6446), DPRK (APT43, UNC2970)Coordinated credential-harvesting via spoofed login pages — GTIG-attributedGoogle Threat Intelligence Group / The Hacker News
Mid-late 2024 and May 2025 — carry-forwardAerospace / defence contractor employees (multi-victim)APT5 (China)Two spearphishing campaigns against current and former employeesGTIG
Reporting periodGovernment / military entities (multi-victim)APT28Microsoft Office vulnerability exploitation; multi-stage stealth-focused post-exploitationPublic reporting / NSA-CISA-NCSC joint advisories
Through 2025–2026NA military / defence contractor login portals (reconnaissance)Volt Typhoon (UNC3236)Sustained reconnaissance; pre-positioning against Western critical infrastructureNSA / CISA / NCSC
Apr 2026Mid-market defence-supply-chain — secondary criminal targetingMixed ransomware (Qilin / Akira / DragonForce)Secondary criminal exposure for defence supply chainRansomware leak-site tracking

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-31431Linux Kernel (resource transfer)7.8YesYesApply distro patches; prioritise Internet-facing & multi-tenant hosts
CVE-2026-3055Citrix NetScaler ADC / Gateway9.3YesYesPatch immediately; rotate session keys; review for known-exploit IOCs
CVE-2026-4368Citrix NetScaler ADC / Gateway8.8YesYesPatch; audit Gateway session logs
CVE-2026-41940WebPros cPanel / WP Squared / WHM9.8NoSuspectedPatch; audit panel admin auth events
CVE-2026-20122Cisco Catalyst SD-WAN Manager8.8YesYesPatch immediately; restrict admin plane to mgmt VLAN
CVE-2026-20128Cisco Catalyst SD-WAN Manager7.5YesYesRotate SD-WAN passwords; patch
CVE-2026-20133Cisco Catalyst SD-WAN Manager7.5YesYesPatch; review information disclosure logs
CVE-2025-2749Kentico Xperience9.0YesYesPatch; audit upload paths
CVE-2025-32975Quest KACE SMA8.8YesSuspectedPatch; restrict KACE management UI
CVE-2025-48700Synacor Zimbra Collaboration6.1YesYesPatch; restrict webmail to authenticated users
CVE-2024-27199JetBrains TeamCity7.3YesYesPatch; rotate CI secrets

7. Indicators of compromise

Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.

TypeIndicatorFirst SeenConf.Notes
IPv4136[.]232[.]11[.]1020 Apr 2026HSSH brute-force; IP Insights threat 100/critical; representative of opportunistic source-IP profile
IPv487[.]236[.]176[.]4502 May 2026MConstantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists
IPv4185[.]220[.]101[.]3003 May 2026MTor exit (for-privacy.net) — IP Insights threat 100/critical, 7 blacklists; relevant to anonymous reconnaissance against public portals
ASNAS20065104 May 2026HFlokiNET — 110/131 known IPs blacklisted; bulletproof-style hosting routinely used in spoofed-login-page operations
PatternOWA / Exchange mailbox-forwarding-rule create from non-baseline source IP27 Apr 2026HAPT28 hallmark; hunt against Exchange audit logs
PatternSpoofed login-page domain pattern: vendor-login-svc[.]com27 Apr 2026HCommon Feb 2026 GTIG-attributed pattern; encourage URL-defence + domain-takedown loop
PatternLiving-off-the-land: netsh portproxy for SOHO-router pivot27 Apr 2026HVolt Typhoon hallmark; hunt against router-and-host telemetry

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.

Threat ScenarioLikelihoodImpactComposite Rating
Long-dwell-time espionage from state-aligned APT clustersHHCRITICAL
Credential harvesting via spoofed login pages targeting current / former employeesHHCRITICAL
Volt Typhoon-style pre-positioning against critical infrastructureMHHIGH
APT28 Microsoft Office vulnerability exploitation against government / militaryHMHIGH
Edge-appliance compromise via Citrix NetScaler / FortiOS / Exchange CVEsMHHIGH
Secondary ransomware targeting of defence supply chainMMMEDIUM
Insider exfiltration of IP / classified materialLHMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection priorities are: hunting for OWA / Exchange mailbox-rule and forwarding-rule manipulation against non-baseline source IPs (APT28 hallmark); spoofed-login-page domain hunting (vendor-login-svc patterns) in proxy / DNS telemetry; Volt-Typhoon-pattern living-off-the-land hunting (netsh portproxy, WMIC remote, abnormal scheduled-task creation); long-dwell-time persistence hunting (Run-key / scheduled-task / WMI-event-subscription anomalies); and Citrix NetScaler / FortiOS / Exchange exploitation indicators as soon as Sigma rules are released. Where customers operate publicly-hosted login portals, sustained reconnaissance-pattern hunting (Volt-Typhoon-style) is warranted.

Defend

Patching priorities are dominated by Citrix NetScaler ADC / Gateway, FortiOS, Microsoft Exchange and the Linux kernel CVE-2026-31431. The CISA KEV April additions should be patched on the published federal-deadline schedule. Identity-controls hardening to mitigate spoofed-login-page credential harvest is the highest-impact defensive investment for the vertical: phishing-resistant MFA (FIDO2 hardware tokens), conditional-access rules requiring known-device tokens, and aggressive proxy / URL-defence on personal-and-corporate-mailbox boundaries. ISO/IEC 27001 Annex A controls A.5.13, A.5.16, A.5.17, A.8.10 and A.8.20 are direct levers; for UK customers the NCSC Cyber Essentials Plus and the Defence Cyber Protection Partnership Cyber Risk Profiles (CRP1-5) should be the operating standards, with US customers operating to NIST 800-171 / CMMC.

Disrupt

Disruption priorities are sustained sharing of the IP Insights blocklist into customer perimeter-block lists; coordinated takedown of FlokiNET-hosted spoofed-login-page infrastructure via AS200651 abuse channels and CERT-UK; tabletop exercise against the long-dwell-time-espionage scenario for any customer with material classified or IP exposure; rehearsal of the personal-mailbox-credential-compromise playbook for current and former employees; and engagement with NCSC and the Defence Cyber Protection Partnership where customers are members.

10. Forward outlook

It is highly likely that long-dwell-time espionage from state-aligned APT clusters will remain the principal material-risk scenario for the vertical over the next reporting cycle. (HIGH confidence; 30-day horizon)

It is highly likely that credential-harvesting via spoofed login pages will continue at sustained tempo. (HIGH confidence; 30-day horizon)

It is likely that Volt Typhoon reconnaissance will extend or has already extended to UK military and defence-contractor login portals. (MEDIUM-HIGH confidence; 90-day horizon)

It is likely that APT28 Microsoft Office vulnerability exploitation will continue at sustained tempo against UK and allied government entities. (MEDIUM-HIGH confidence; 60-day horizon)

There is a realistic possibility of secondary ransomware-against-defence-supply-chain incidents at low-to-medium operational tempo. (MEDIUM confidence; 90-day horizon)

Trigger conditions that would prompt revision of this forecast: a UK-attributed Volt Typhoon login-portal reconnaissance disclosure; an in-the-wild APT28 Office zero-day publication; a confirmed APT-criminal-cluster ransomware deployment against a UK defence contractor.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC — Threat reportsNCSC.GOV.UKA1
2NSA — Press release on countering Chinese state-sponsored actors targeting critical infrastructureNSA / CISA / NCSCA1
3CISA — Countering Chinese state-sponsored actors (AA25-239A)CISAA1
4Google Threat Intelligence Group — coordinated defence-sector operations attribution (Feb 2026)Google TIG via The Hacker NewsA2
5Industrial Cyber — Google flags sustained cyber pressure on defense industrial baseIndustrial CyberB2
6CISA KEV — April / May 2026 additionsCISAA1
7April 2026 Ransomware Report — 772 victims, 70 groups (secondary criminal context)BreachSenseB2
8IP Insights — IP / ASN / CIDR threat intelligence APIipinsights.ioA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.