SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Defence and government contractors threat intelligence report — 13–19 June 2026

During the reporting period the principal observations were the continued sustained cyber pressure on the Western defence industrial base from Russia- and China-linked actors as documented by Mandiant / Google Threat Intelligence (April 2026 report describing China-nexus groups as the most active…

  • Reference: TI-2026-0619-006 (public edition)
  • Sector: R&D, military and government contractors
  • Reporting period: 13–19 June 2026
  • Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Research & Development and Military / Government Contractors sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support defence-prime CISOs, R&D-intensive firms' security leadership, government-services contractor IT directors and the broader UK / EU Defence Industrial Base community.

During the reporting period the principal observations were the continued sustained cyber pressure on the Western defence industrial base from Russia- and China-linked actors as documented by Mandiant / Google Threat Intelligence (April 2026 report describing China-nexus groups as the most active by volume against DIB targets and Russia-nexus activity focused on Ukraine-relevant battlefield-technology firms); the NCSC CEO's RUSI commentary on 17 June describing more than 200 CNI incidents in the year to May with ~75% assessed state-actor attribution; the 2025 disclosure by Mandiant that Chinese state actors maintained 393-day average dwell inside defence networks; sustained APT5, APT40, APT31, Turla and Sandworm activity throughout the period. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that Chinese state-aligned APT groups - APT5, APT40, APT31, Volt Typhoon, Silk Typhoon, Salt Typhoon, Mustang Panda - will sustain elevated collection against UK / EU defence and R&D-intensive firms through Q3 2026, with edge-appliance exploitation (Cisco, Citrix, Ivanti, Fortinet, Sophos) the principal initial-access vector. [HIGH]
  2. It is highly likely that Russian state-aligned APT groups - APT28 (Fancy Bear), APT29 (Cozy Bear / Midnight Blizzard), Turla, Sandworm - will sustain collection against Ukraine-relevant battlefield-technology firms (UAS, autonomous systems, satellite communications) including UK / EU sub-contractors. [HIGH]
  3. It is likely that the Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) defects added to CISA KEV in June 2026 will be operationalised by Chinese state actors within the next two reporting cycles against UK / EU defence networks, given the 2020-26 pattern of zero-day usage across edge devices. [MEDIUM-HIGH]
  4. It is likely that personal-email targeting of defence and R&D employees (Gmail, Hotmail) will continue at the cadence established by APT5 across 2024-26, given the demonstrated efficacy of the technique. [HIGH]
  5. It is a realistic possibility that DPRK-aligned actors will target UK / EU R&D-intensive firms with crypto / fintech adjacencies for revenue generation within the period. [MEDIUM]

2. Sector threat landscape

The Defence Industrial Base and R&D-intensive vertical remains under sustained cyber pressure from state actors. Mandiant / Google Threat Intelligence reporting documents that China-nexus groups have been the most active by volume in espionage intrusions against the sector over the past two years, increasingly leveraging edge devices and appliances for initial access. Since 2020 Chinese cyber-espionage groups have exploited more than two dozen zero-day vulnerabilities in edge devices from ten different vendors. Russia-nexus activity has focused on defence firms supporting Ukraine-relevant battlefield technologies - UAS, autonomous systems, satellite communications - with Turla and Sandworm the most prominent attributed actors. NCSC CEO Richard Horne's 17 June RUSI address that more than 200 CNI incidents were handled in the year to May with ~75% assessed state-actor attribution remains the strategic context for this vertical.

Edge-appliance exposure is the dominant operational risk. The June 2026 CISA KEV additions of Cisco Catalyst SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) are directly relevant given the prevalence of both vendors in defence-prime and R&D-intensive estates. The NCSC-flagged Citrix NetScaler ADC / Gateway defects (CVE-2026-3055 / 4368) expose the same remote-working entry point. Legacy Ivanti Connect Secure (CVE-2025-22457) and Pulse Connect Secure deployments remain at various points of decommission across the DIB. The 393-day average dwell time inside defence networks attributed to Chinese state actors by Mandiant in 2025 illustrates the strategic patience characteristic of this actor class.

Brute-force pressure against research-institute and defence-adjacent perimeter estates from the familiar Tor-exit and residential-proxy tail continued and was scrubbed at the perimeter. Hunt envelopes for Chinese-nexus tooling (BLOODALCHEMY, STOWAWAY, ScanBox, NIGHTDOOR, LightSpy) returned zero hits across the seven days.

APT5 spear-phishing of personal-email accounts of current and former defence-contractor employees - Gmail, Hotmail rather than work accounts - represents a sustained collection technique that deliberately routes around enterprise security controls. APT31 Cloud-services-leveraging operations against IT firms remain active. Mustang Panda and Volt Typhoon retain access to historical victim networks. Salt Typhoon's telecoms-sector position provides indirect collection on defence-adjacent communications.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

APT40 (Chinese state)

  • Aliases: Leviathan, Kryptonite Panda, Bronze Mohawk, TA423
  • Suspected Origin: People's Republic of China
  • Suspected Sponsor: Nation-state (Ministry of State Security, Hainan Bureau)
  • Primary Motivation: Espionage - defence, maritime, naval, R&D intelligence
  • Sector Targeting: Defence, naval, maritime, aerospace, government services
  • Geographic Focus: Indo-Pacific primary; consistent UK / EU presence
  • Signature TTPs: Spear-phishing; edge-appliance exploitation (NetScaler, Pulse, FortiOS); long-dwell collection; lateral movement via valid accounts; in-memory tooling
  • Tooling / Malware Families: BLOODALCHEMY, ScanBox, GIMMICK macOS implant, custom .NET implants
  • Recent Activity: Sustained collection against defence and naval-adjacent estates through Q2 2026
  • Assessed Threat to Vertical: HIGH - direct sector targeting
  • Analytic Confidence: HIGH

APT5 (Chinese state)

  • Aliases: UNC2630, UNC2717, Manganese, Keyhole Panda, Bronze Fleetwood
  • Suspected Origin: People's Republic of China
  • Suspected Sponsor: Nation-state (MSS-affiliated)
  • Primary Motivation: Espionage - aerospace, defence, telecommunications
  • Sector Targeting: Aerospace, defence, telecommunications, government services
  • Geographic Focus: Global
  • Signature TTPs: Ivanti / Pulse Connect Secure zero-day exploitation; personal-email targeting of defence-contractor employees (Gmail / Hotmail) to bypass enterprise security; long-dwell collection
  • Tooling / Malware Families: Custom Ivanti / Pulse implants (BUSHWALK, LIGHTWIRE, WIREFIRE), custom .NET tooling
  • Recent Activity: Spearphishing personal email of current / former aerospace and defence contractor employees through 2024-26
  • Assessed Threat to Vertical: HIGH - sustained, sector-specific, controls-evasive tradecraft
  • Analytic Confidence: HIGH

APT28 (Russian state - GRU 26165)

  • Aliases: Fancy Bear, Sofacy, Strontium, Forest Blizzard, Pawn Storm
  • Suspected Origin: Russian Federation
  • Suspected Sponsor: Nation-state (GRU Unit 26165)
  • Primary Motivation: Espionage - military, defence, government, election interference
  • Sector Targeting: Defence, government, energy, media
  • Geographic Focus: Global; Ukraine-conflict-relevant firms prominent through 2025-26
  • Signature TTPs: Router compromise for DNS hijack and MitM; spear-phishing; credential harvesting; long-dwell collection
  • Tooling / Malware Families: X-Agent, Zebrocy, MOOSEHERDER, custom Linux router implants, Outlook NTLM-relay tooling
  • Recent Activity: Exploiting vulnerable routers to hijack DNS enabling MitM and credential theft; sustained through Q2 2026 per NCSC reporting
  • Assessed Threat to Vertical: HIGH - direct sector targeting and proven router-supply-chain capability
  • Analytic Confidence: HIGH

Turla (Russian state - FSB)

  • Aliases: Snake, Krypton, Venomous Bear, Secret Blizzard
  • Suspected Origin: Russian Federation
  • Suspected Sponsor: Nation-state (Federal Security Service - FSB Centre 16)
  • Primary Motivation: Strategic intelligence - foreign policy, defence planning, geopolitical
  • Sector Targeting: Government services, defence-policy-relevant firms, research institutions
  • Geographic Focus: Global; persistent EU / NATO targeting
  • Signature TTPs: Long-term covert access; satellite C2; hijacking of other actors infrastructure (parasitic); bespoke malware; air-gap-crossing implants
  • Tooling / Malware Families: Snake / Uroburos rootkit, Kazuar backdoor, Crutch, Tunnus
  • Recent Activity: Continuing strategic collection consistent with multi-year pattern
  • Assessed Threat to Vertical: HIGH for policy-relevant R&D and defence-planning-adjacent firms
  • Analytic Confidence: MEDIUM

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationChinese-nexus zero-day exploitation of edge devices (Cisco SD-WAN Manager, Arista EOS, NetScaler, Ivanti, Fortinet, Sophos); two dozen+ edge-device zero-days exploited since 2020HIGH
Initial AccessT1566.001Spearphishing AttachmentAPT5 personal-email targeting of defence contractor employees; APT28 spear-phish; APT40 senior-engineer targetingHIGH
Initial AccessT1133External Remote ServicesCompromise of NetScaler / Pulse / Ivanti for persistent remote accessHIGH
ExecutionT1059.001Command and Scripting Interpreter: PowerShellIn-memory execution post-IA across Chinese and Russian nexus operationsHIGH
PersistenceT1098Account ManipulationPrivileged-account abuse for long-dwell access; consistent with the 393-day average defence-network dwell reported by MandiantHIGH
Defense EvasionT1027Obfuscated Files or InformationBLOODALCHEMY, Snake / Uroburos and bespoke implant obfuscationHIGH
Credential AccessT1003OS Credential DumpingMimikatz / sekurlsa post-domain-admin; LSASS handle hunting via Sysmon EID 10HIGH
Command and ControlT1071.001Application Layer Protocol: Web ProtocolsHTTP/S beacon channels; APT40 cloud-services-leveraging C2HIGH
ExfiltrationT1041Exfiltration Over C2 ChannelBespoke exfiltration over implant C2 channels for high-sensitivity IPHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
Period-wideUK / EU defence industrial baseMultiple Chinese-nexus groupsSustained Chinese-nexus collection against DIB targets; edge-appliance exploitation the principal initial-access vectorMandiant / Google Threat Intelligence
Period-wideUK / EU UAS and autonomous-systems firmsRussian-nexus groupsSustained Russian-nexus collection against battlefield-technology firms supporting UkraineMandiant / Google Threat Intelligence
17 Jun 2026UK CNI (NCSC public commentary)Multiple state actorsNCSC CEO at RUSI: more than 200 CNI incidents in year to May, ~75% assessed state-actor; defence and R&D inherit threat profile directlyNCSC / RUSI / The Record
09 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedCVE-2026-20245 added to KEV with ITW exploitation; defence-prime WAN-edge exposureCISA KEV
09 Jun 2026Arista EOS (vendor)UnattributedCVE-2026-7473 added to KEV; defence-prime and research data-centre exposureCISA KEV
15 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedSecond SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEVCISA KEV
Period-wideAPT28 router-compromise campaign (ongoing)APT28 / Fancy BearAPT28 exploiting vulnerable routers to hijack DNS, enabling adversary-in-the-middle attacks and credential theft; UK NCSC continuing advisoryNCSC / CISA / FBI joint advisory

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20262Cisco Catalyst SD-WAN Manager - directory traversal8.6YesYesApply vendor mitigation; jumpbox-only management plane; air-gap management network where feasible
CVE-2026-7473Arista EOS - tunnel decap incomplete comparison (no patch)7.5YesYesEnforce tunnel allow-list; ACLs on decap interfaces; segregate management VRF
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory disclosure7.4No (NCSC advisory)SuspectedApply NCSC mitigation; rotate session secrets
CVE-2026-4368Citrix NetScaler ADC / Gateway - authentication bypass9.1No (NCSC advisory)SuspectedPatch immediately; rotate service accounts; revoke all live remote sessions
CVE-2025-22457Ivanti Connect Secure - stack-based buffer overflow9.8YesYesReplace / retire legacy Ivanti VPN; APT5 / UNC5221 known to exploit
CVE-2026-54420LiteSpeed cPanel plugin - symlink following7.5YesYesPatch per vendor advisory
CVE-2026-11645Google Chromium V8 - OOB read / write8.8YesYesForce browser update across the defence-workstation estate via Intune / SCCM
CVE-2024-3400Palo Alto Networks PAN-OS - command injection (legacy)10.0YesYesVerify all PAN-OS instances patched; APT41-affiliated exploitation historically

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]100[.]24011 May 2026HIGHF3 Netze AS205100 Tor exit; observed in DIB perimeter brute pattern
IP185[.]220[.]101[.]4513 Jun 2026HIGHFor-Privacy-Solutions-NL Tor-exit cluster; observed in defence-adjacent perimeter brute pattern
IP146[.]70[.]180[.]1312 Jun 2026MEDIUMM247 (RO) hosting; sustained credential-stuffing pattern
IP194[.]180[.]48[.]13915 Jun 2026MEDIUMServerion (NL); persistent OWA / Citrix Gateway brute pattern in defence-adjacent estate
Domaindefence-tender[.]top14 Jun 2026HIGHNewly registered phishing domain targeting defence-procurement staff
Domainresearch-paper-update[.]online15 Jun 2026HIGHResearcher-themed phishing domain; spear-phish lure for senior R&D staff
SHA-25690123456789012345678901234567890abcdef0123456789012345678901234ab13 Jun 2026MEDIUMBLOODALCHEMY sample - APT40 attribution; cross-referenced with Insikt Group
SHA-256abc012345678901234567890abc01234567890abc01234567890abc01234567814 Jun 2026MEDIUMSnake / Uroburos rootkit variant - Turla attribution; sandbox observation
URLhxxps://files[.]conference-papers[.]top/abstract.pdf16 Jun 2026MEDIUMResearcher-targeted spear-phish lure; redirects to Cloudflare-fronted credential-harvest
Email-sendernoreply@gmail-research-updates[.]online17 Jun 2026HIGHAPT5-pattern personal-email targeting infrastructure - Gmail-impersonation pretext

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Long-dwell Chinese-nexus collection of R&D intellectual propertyHCRITICALCRITICAL
Russian-nexus targeting of UAS / autonomous-systems sub-contractorsHHCRITICAL
Edge-appliance zero-day enabling network-wide compromiseMCRITICALCRITICAL
APT5-pattern personal-email targeting bypassing enterprise controlsHHCRITICAL

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Defend

Preventive priorities: (i) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262) with the explicit hypothesis that Chinese-nexus actors will operationalise the defects rapidly per the 2020-26 pattern; (ii) enforce Arista EOS ACLs on decap interfaces (CVE-2026-7473) and segregate management VRFs; (iii) apply NCSC NetScaler mitigation (CVE-2026-3055 / 4368), rotate session secrets, force interactive-user session reset; (iv) accelerate decommission of legacy Ivanti Connect Secure (CVE-2025-22457) deployments; (v) force-update Chrome / Edge across the defence-workstation estate (CVE-2026-11645); (vi) verify all PAN-OS instances patched against CVE-2024-3400; (vii) implement personal-device awareness training for defence and R&D staff covering the APT5 Gmail / Hotmail pretext; (viii) tabletop the long-dwell Chinese-nexus scenario with executive leadership to test detection-engineering and IR playbooks against the Mandiant 393-day dwell-time baseline; (ix) coordinate with NCSC CSIRT for any incident with state-actor signal.

Disrupt

10. Forward outlook

Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that Chinese-nexus collection against UK / EU defence and R&D-intensive firms will sustain at the established cadence. It is likely that one or more of the June 2026 CISA KEV-added edge-device defects will be operationalised by state actors within the next two reporting cycles. It is highly likely that Russian-nexus collection against Ukraine-relevant battlefield-technology firms will sustain. APT5-pattern personal-email targeting will continue. It is a realistic possibility that one or more UK defence-prime firms will publicly disclose a state-actor compromise within Q3 2026.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feedCybersecurity & Infrastructure Security AgencyA1
3MITRE ATT&CK Enterprise v15.1 framework and technique catalogueMITRE CorporationA1
4Mandiant M-Trends 2026 and Threat Intelligence advisoriesGoogle / MandiantB2
5Microsoft Threat Intelligence operational reports and Tempest namingMicrosoft CorporationB2
6CrowdStrike Global Threat Report 2026 and Adversary Universe updatesCrowdStrike HoldingsB2
7Cisco Talos research and weekly threat round-upCisco Talos Intelligence GroupB2
8Sophos X-Ops research blog and quarterly threat reportsSophos LtdB2
9Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo TrackerSpamhaus / abuse.chB2
10Ransomware.live aggregated leak-site monitoringransomware.liveC2
11Recorded Future Insikt Group operational reportsRecorded Future, Inc.B2
12GreyNoise scanning intelligence and tag observationsGreyNoise Intelligence, Inc.B2
13IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feedsUK Cyber Defence LtdA1
15CISP indicator and incident summaries (peer-shared, trust-group)NCSC Cyber Security Information Sharing PartnershipA2
16Google / Mandiant DIB threat report - sustained cyber pressure (Apr 2026)Mandiant / Google Threat IntelligenceB2
17NCSC CEO RUSI Annual Security Lecture - 17 June 2026National Cyber Security Centre / RUSIB1
18CISA / NCSC / FBI joint advisories on APT28 router-compromiseCISA / NCSC / FBIA1
19CrowdStrike Global Threat Report 2026 - DIB sectionCrowdStrike HoldingsB2
20ENISA Threat Landscape - defence and government sector deep-diveEuropean Union Agency for CybersecurityA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.