The June 2026 Dark Web Threat Actor Trend Report from AhnLab ASEC summarizes broad activity across hacktivist, APT, and cybercrime ecosystems. Key developments include ShinyHunters' migration to dark web infrastructure, North Korean supply chain attacks on npm AI-framework packages via Sapphire Sleet, a RaaS group's EDR-killing toolkit targeting European defense/aerospace, and TA569's Web Inject framework leveraging fake browser updates. Law enforcement achieved notable wins including a Scattered Spider conviction and multiple arrests across Europe.
Dark Web
5 posts
June 2026 Dark Web Threat Actor Trend Report Ransom & Dark Web Issues Week 2, July 2026 This article is a weekly roundup summarizing three data breach and leak incidents reported on cybercrime forums during the second week of July 2026. Affected sectors include Saudi Arabian healthcare, an Irish ICT company, and a US healthcare insurer (LeakNet). No technical IOCs, attack methodologies, or CVE details are provided in the public portion of the article; detailed analysis is available via AhnLab TIP subscription.
Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux QuimaRAT is a cross-platform, Java-based remote access trojan sold as a malware-as-a-service subscription on the dark web. It targets Windows, macOS, and Linux systems by embedding JNA native libraries for multiple architectures within a JAR archive built for Java SE 8. The RAT decrypts an internal configuration file using repeating-key XOR, performs anti-analysis and virtualization checks, establishes persistence via OS-specific mechanisms, and maintains resilient C2 communication through HANDSHAKE and HEARTBEAT protocols. With 23 implemented commands and 212 protocol-only commands, the platform is highly extensible through runtime modules and fileless payloads.
Ransom & Dark Web Issues Week 1, July 2026 AhnLab ASEC's Week 1 July 2026 ransomware and dark web roundup reports three active threat campaigns. Settra claims a data leak at a Korean industrial firm's foreign affiliate. The Gentlemen ransomware group has targeted Spanish defense, aerospace, and IT service firms. DragonForce claims data theft against a South Korean smart factory and digital twin company. Detailed IOCs and analysis are available only to AhnLab TIP subscribers.
Ransom & Dark Web Issues Week 4, June 2026 This weekly roundup from AhnLab's ASEC team highlights three notable dark web and ransomware developments: BreachForums is experiencing internal issues with staff impersonation and unauthorized sales, Lapsus$ claims to have leaked data from a Myanmar bank, and Qilin ransomware targeted a South Korean law firm. No technical IOCs, detection rules, or vulnerability details are provided in the public article; full analysis is available via AhnLab TIP subscription.