Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.
- Reference: TI-2026-0504-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 27 April – 3 May 2026
- Issued: 4 May 2026 · Lead analyst: P. Bassill (SOC Lead) · Reviewed by: SOC Reviewing Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity. Google Threat Intelligence Group reporting in February 2026 attributed coordinated defence-sector cyber operations to Russia (UNC5792 and UNC5976), China (APT5, APT31, UNC3236 / Volt Typhoon), Iran (UNC1549, UNC6446) and North Korea (APT43, UNC2970), with credential harvesting via spoofed login pages the common tradecraft. APT28 has been observed exploiting Microsoft Office vulnerabilities against government and military entities. China continues Typhoon campaigns aimed at IP theft and embarrassing Western governments. The principal material-risk scenario remains long-dwell-time espionage rather than ransomware, although secondary criminal targeting persists.
Key Judgements
1. It is highly likely that long-dwell-time espionage from Russia-, China-, Iran- and DPRK-aligned actors will remain the principal material-risk scenario for R&D and government-contractor entities over the next reporting cycle. (HIGH confidence)
2. It is highly likely that credential harvesting via spoofed login pages targeting current and former contractor employees — the documented Feb 2026 GTIG-attributed pattern — will continue at sustained tempo. (HIGH confidence)
3. It is likely that Volt Typhoon (UNC3236) reconnaissance activity against publicly-hosted login portals of North American military and defence contractors will continue, and there is a realistic possibility of similar UK-targeted activity. (MEDIUM-HIGH confidence)
4. It is likely that APT28 Microsoft Office vulnerability exploitation will continue against government and military entities through the next reporting cycle, with multi-stage stealth-focused post-exploitation chains. (MEDIUM-HIGH confidence)
5. There is a realistic possibility that secondary ransomware targeting of R&D entities will increase as APT-criminal collaboration normalises, but at materially lower operational tempo than against finance / retail / healthcare. (MEDIUM confidence)
2. Sector threat landscape
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity. Google Threat Intelligence Group reporting in February 2026 attributed coordinated defence-sector cyber operations to four state-aligned constellations: Russia (UNC5792 and UNC5976), China (APT5, APT31, UNC3236 / Volt Typhoon), Iran (UNC1549 and UNC6446) and North Korea (APT43 and UNC2970). The common tradecraft across these clusters during the reporting period is credential harvesting via spoofed login pages, with messages sent to both corporate and personal email addresses of current and former contractor employees and personalised lures based on victim role, location and personal interest.
China-nexus APT5 ran two spearphishing campaigns in mid-to-late 2024 and again in May 2025, targeting current and former employees of major aerospace and defence contractors. The continued Typhoon campaign portfolio — Volt Typhoon (UNC3236), Salt Typhoon, Linen Typhoon — has been described in NSA / CISA / NCSC joint advisories as a sustained campaign against Western critical infrastructure with the dual aims of intellectual-property theft and pre-positioning for potential future disruption.
Russian APT28 has been observed exploiting Microsoft Office vulnerabilities against government and military entities during the reporting period, deploying multi-stage attack chains designed to remain stealthy during post-exploitation. Iran-aligned UNC1549 and UNC6446 continue to favour the defence-industrial-base and aerospace sub-sector. North Korean APT43 / UNC2970 maintain the cryptocurrency / IP-theft dual-targeting that has characterised DPRK cyber operations through 2024 and 2025.
Secondary criminal targeting persists. Although the operational tempo of ransomware against R&D entities is materially lower than against finance, retail and healthcare, ransomware leak-site postings during the reporting period continued to surface mid-market defence-supply-chain victims. The principal concern in this lane is APT-criminal collaboration: the partnership patterns observed in 2024 and 2025 (especially between Russian-aligned APT operators and ransomware affiliates with shared tooling) are likely to normalise through 2026.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
| THREAT ACTOR PROFILE — APT28 | |
|---|---|
| Aliases | Fancy Bear, Sofacy, Forest Blizzard |
| Suspected Origin | Russia |
| Suspected Sponsor | GRU Unit 26165 |
| Primary Motivation | Espionage; influence |
| Sector Targeting | Government, military, defence-industrial-base, political organisations |
| Geographic Focus | Global; sustained UK / EU / NATO targeting |
| Signature TTPs | Microsoft Office vulnerability exploitation; credential harvesting via spoofed login pages; multi-stage stealth-focused post-exploitation; OWA / Exchange targeting |
| Tooling / Malware Families | X-Agent / Sednit malware family; Drovorub; OutSteel / SaintBot loaders; living-off-the-land |
| Recent Activity | Sustained Microsoft Office vulnerability exploitation against government / military entities during the reporting period |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — Volt Typhoon | |
|---|---|
| Aliases | UNC3236, BRONZE SILHOUETTE, Vanguard Panda |
| Suspected Origin | China |
| Suspected Sponsor | Chinese state |
| Primary Motivation | Pre-positioning against Western critical infrastructure; intelligence collection |
| Sector Targeting | Critical infrastructure, telecommunications, military / defence contractors |
| Geographic Focus | United States, United Kingdom, allied jurisdictions |
| Signature TTPs | Living-off-the-land; SOHO router-and-edge-appliance abuse for traffic blending; long-dwell-time persistence; reconnaissance against publicly-hosted login portals |
| Tooling / Malware Families | Living-off-the-land — netsh, PowerShell, WMIC, Mimikatz; compromised SOHO router infrastructure |
| Recent Activity | Sustained reconnaissance activity against publicly-hosted login portals of North American military and defence contractors through 2025–2026 |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — APT5 | |
|---|---|
| Aliases | UNC2630, Manganese, MULBERRYMAJESTY |
| Suspected Origin | China |
| Suspected Sponsor | Chinese state |
| Primary Motivation | Espionage — aerospace / defence intellectual property |
| Sector Targeting | Aerospace, defence-industrial-base, telecommunications |
| Geographic Focus | United States, allied jurisdictions |
| Signature TTPs | Spearphishing of current / former contractor employees; personal-and-corporate-mailbox dual targeting; tailored lures based on role and personal interest |
| Tooling / Malware Families | Custom downloaders; living-off-the-land |
| Recent Activity | Two spearphishing campaigns in mid-to-late 2024 and again in May 2025 against current and former employees of major aerospace and defence contractors; pattern continues |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — UNC1549 / UNC6446 (Iran-aligned) | |
|---|---|
| Aliases | Various — Iran-aligned defence-industrial-base targeting |
| Suspected Origin | Iran |
| Suspected Sponsor | IRGC / MOIS-aligned |
| Primary Motivation | Espionage; pre-positioning |
| Sector Targeting | Aerospace, defence-industrial-base, government |
| Geographic Focus | United States, Israel, allied jurisdictions |
| Signature TTPs | Spearphishing; cloud-account abuse; supply-chain targeting |
| Tooling / Malware Families | Custom .NET implants; living-off-the-land |
| Recent Activity | Sustained activity against the defence-industrial-base through 2025 and into 2026; GTIG-attributed in Feb 2026 reporting |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | MEDIUM |
| THREAT ACTOR PROFILE — APT43 / UNC2970 (DPRK) | |
|---|---|
| Aliases | Kimsuky-adjacent; Diamond Sleet-adjacent |
| Suspected Origin | DPRK |
| Suspected Sponsor | DPRK state |
| Primary Motivation | Espionage; cryptocurrency theft |
| Sector Targeting | Government, defence-industrial-base, financial services, cryptocurrency |
| Geographic Focus | Global; sustained US / South Korea / Japan presence |
| Signature TTPs | Spearphishing with personalised lures; LinkedIn-based engagement; trojanised job-offer documents |
| Tooling / Malware Families | Custom .NET / PowerShell implants; living-off-the-land |
| Recent Activity | Sustained engagement-and-spearphishing pattern against defence-contractor employees through the reporting period |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | MEDIUM |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spearphishing Link | Spoofed login pages for credential harvest — common Feb 2026 GTIG-attributed pattern across Russia / China / Iran / DPRK clusters. | H |
| Initial Access | T1190 | Exploit Public-Facing Application | Citrix NetScaler / Microsoft Exchange / Microsoft Office vulnerability exploitation continues to be the principal non-phishing vector. | H |
| Initial Access | T1078 | Valid Accounts | Stolen / phished credentials used for sustained low-and-slow access; long-dwell-time persistence is the espionage hallmark. | H |
| Persistence | T1098 | Account Manipulation | OWA / Exchange mailbox-rule and forwarding-rule manipulation observed in APT28 intrusions during the reporting period. | M |
| Defence Evasion | T1070 | Indicator Removal | Multi-stage stealth-focused post-exploitation chains designed to remain quiet through long-dwell-time campaigns. | H |
| Credential Access | T1003 | OS Credential Dumping | Mimikatz-style and netsh-based credential harvesting consistent with Volt Typhoon living-off-the-land. | M |
| Discovery | T1018 | Remote System Discovery | Sustained reconnaissance against publicly-hosted login portals — Volt Typhoon hallmark. | H |
| Collection | T1119 | Automated Collection | Long-dwell-time IP-theft collection routines across aerospace / defence document repositories. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Feb 2026 | US defence-industrial-base employees (multi-victim) | Russia (UNC5792, UNC5976), China (APT5, APT31), Iran (UNC1549, UNC6446), DPRK (APT43, UNC2970) | Coordinated credential-harvesting via spoofed login pages — GTIG-attributed | Google Threat Intelligence Group / The Hacker News |
| Mid-late 2024 and May 2025 — carry-forward | Aerospace / defence contractor employees (multi-victim) | APT5 (China) | Two spearphishing campaigns against current and former employees | GTIG |
| Reporting period | Government / military entities (multi-victim) | APT28 | Microsoft Office vulnerability exploitation; multi-stage stealth-focused post-exploitation | Public reporting / NSA-CISA-NCSC joint advisories |
| Through 2025–2026 | NA military / defence contractor login portals (reconnaissance) | Volt Typhoon (UNC3236) | Sustained reconnaissance; pre-positioning against Western critical infrastructure | NSA / CISA / NCSC |
| Apr 2026 | Mid-market defence-supply-chain — secondary criminal targeting | Mixed ransomware (Qilin / Akira / DragonForce) | Secondary criminal exposure for defence supply chain | Ransomware leak-site tracking |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; prioritise Internet-facing & multi-tenant hosts |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; review for known-exploit IOCs |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | No | Suspected | Patch; audit panel admin auth events |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager | 8.8 | Yes | Yes | Patch immediately; restrict admin plane to mgmt VLAN |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Rotate SD-WAN passwords; patch |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Patch; review information disclosure logs |
| CVE-2025-2749 | Kentico Xperience | 9.0 | Yes | Yes | Patch; audit upload paths |
| CVE-2025-32975 | Quest KACE SMA | 8.8 | Yes | Suspected | Patch; restrict KACE management UI |
| CVE-2025-48700 | Synacor Zimbra Collaboration | 6.1 | Yes | Yes | Patch; restrict webmail to authenticated users |
| CVE-2024-27199 | JetBrains TeamCity | 7.3 | Yes | Yes | Patch; rotate CI secrets |
7. Indicators of compromise
Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force; IP Insights threat 100/critical; representative of opportunistic source-IP profile |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical, 7 blacklists; relevant to anonymous reconnaissance against public portals |
| ASN | AS200651 | 04 May 2026 | H | FlokiNET — 110/131 known IPs blacklisted; bulletproof-style hosting routinely used in spoofed-login-page operations |
| Pattern | OWA / Exchange mailbox-forwarding-rule create from non-baseline source IP | 27 Apr 2026 | H | APT28 hallmark; hunt against Exchange audit logs |
| Pattern | Spoofed login-page domain pattern: vendor-login-svc[.]com | 27 Apr 2026 | H | Common Feb 2026 GTIG-attributed pattern; encourage URL-defence + domain-takedown loop |
| Pattern | Living-off-the-land: netsh portproxy for SOHO-router pivot | 27 Apr 2026 | H | Volt Typhoon hallmark; hunt against router-and-host telemetry |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Long-dwell-time espionage from state-aligned APT clusters | H | H | CRITICAL |
| Credential harvesting via spoofed login pages targeting current / former employees | H | H | CRITICAL |
| Volt Typhoon-style pre-positioning against critical infrastructure | M | H | HIGH |
| APT28 Microsoft Office vulnerability exploitation against government / military | H | M | HIGH |
| Edge-appliance compromise via Citrix NetScaler / FortiOS / Exchange CVEs | M | H | HIGH |
| Secondary ransomware targeting of defence supply chain | M | M | MEDIUM |
| Insider exfiltration of IP / classified material | L | H | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities are: hunting for OWA / Exchange mailbox-rule and forwarding-rule manipulation against non-baseline source IPs (APT28 hallmark); spoofed-login-page domain hunting (vendor-login-svc patterns) in proxy / DNS telemetry; Volt-Typhoon-pattern living-off-the-land hunting (netsh portproxy, WMIC remote, abnormal scheduled-task creation); long-dwell-time persistence hunting (Run-key / scheduled-task / WMI-event-subscription anomalies); and Citrix NetScaler / FortiOS / Exchange exploitation indicators as soon as Sigma rules are released. Where customers operate publicly-hosted login portals, sustained reconnaissance-pattern hunting (Volt-Typhoon-style) is warranted.
Defend
Patching priorities are dominated by Citrix NetScaler ADC / Gateway, FortiOS, Microsoft Exchange and the Linux kernel CVE-2026-31431. The CISA KEV April additions should be patched on the published federal-deadline schedule. Identity-controls hardening to mitigate spoofed-login-page credential harvest is the highest-impact defensive investment for the vertical: phishing-resistant MFA (FIDO2 hardware tokens), conditional-access rules requiring known-device tokens, and aggressive proxy / URL-defence on personal-and-corporate-mailbox boundaries. ISO/IEC 27001 Annex A controls A.5.13, A.5.16, A.5.17, A.8.10 and A.8.20 are direct levers; for UK customers the NCSC Cyber Essentials Plus and the Defence Cyber Protection Partnership Cyber Risk Profiles (CRP1-5) should be the operating standards, with US customers operating to NIST 800-171 / CMMC.
Disrupt
Disruption priorities are sustained sharing of the IP Insights blocklist into customer perimeter-block lists; coordinated takedown of FlokiNET-hosted spoofed-login-page infrastructure via AS200651 abuse channels and CERT-UK; tabletop exercise against the long-dwell-time-espionage scenario for any customer with material classified or IP exposure; rehearsal of the personal-mailbox-credential-compromise playbook for current and former employees; and engagement with NCSC and the Defence Cyber Protection Partnership where customers are members.
10. Forward outlook
It is highly likely that long-dwell-time espionage from state-aligned APT clusters will remain the principal material-risk scenario for the vertical over the next reporting cycle. (HIGH confidence; 30-day horizon)
It is highly likely that credential-harvesting via spoofed login pages will continue at sustained tempo. (HIGH confidence; 30-day horizon)
It is likely that Volt Typhoon reconnaissance will extend or has already extended to UK military and defence-contractor login portals. (MEDIUM-HIGH confidence; 90-day horizon)
It is likely that APT28 Microsoft Office vulnerability exploitation will continue at sustained tempo against UK and allied government entities. (MEDIUM-HIGH confidence; 60-day horizon)
There is a realistic possibility of secondary ransomware-against-defence-supply-chain incidents at low-to-medium operational tempo. (MEDIUM confidence; 90-day horizon)
Trigger conditions that would prompt revision of this forecast: a UK-attributed Volt Typhoon login-portal reconnaissance disclosure; an in-the-wild APT28 Office zero-day publication; a confirmed APT-criminal-cluster ransomware deployment against a UK defence contractor.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC — Threat reports | NCSC.GOV.UK | A1 |
| 2 | NSA — Press release on countering Chinese state-sponsored actors targeting critical infrastructure | NSA / CISA / NCSC | A1 |
| 3 | CISA — Countering Chinese state-sponsored actors (AA25-239A) | CISA | A1 |
| 4 | Google Threat Intelligence Group — coordinated defence-sector operations attribution (Feb 2026) | Google TIG via The Hacker News | A2 |
| 5 | Industrial Cyber — Google flags sustained cyber pressure on defense industrial base | Industrial Cyber | B2 |
| 6 | CISA KEV — April / May 2026 additions | CISA | A1 |
| 7 | April 2026 Ransomware Report — 772 victims, 70 groups (secondary criminal context) | BreachSense | B2 |
| 8 | IP Insights — IP / ASN / CIDR threat intelligence API | ipinsights.io | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
Defence and government contractors threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by sustained state-sponsored espionage interest in UK and EU defence supply-chain entities, continued Chinese APT operational tempo across the supply-chain pivot model that produced the 2024 MOD payroll-provider breach…
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.