A new report has identified the top ten cybersecurity threat actors shaping global digital security in 2026.
The global cybersecurity company Group-IB released this classification based on its latest high-tech crime trends report. Notably, the findings show that supply chains have become the primary target for digital criminals.
Analysts observed a structural shift in attack methodologies through more than 1,550 field investigations. Specifically, threat groups no longer target victims directly but integrate into trusted third-party infrastructures. Consequently, this expands their impact and reduces detection times across entire sectors.
In addition, the classification evaluates each group across six main areas. These include financial impact, victim count, threat volume, technical innovation, partner network growth, and reputation. These threat groups demonstrate how modern digital crime methods are changing.
Analyzing Global Cybersecurity Threat Actors
Understanding these groups helps organizations defend their networks. These cybersecurity threat actors use various methods to infiltrate corporate networks.
1. Scattered Spider
This decentralized group is linked to major digital attacks through social engineering. In 2025, the group compromised more than 130 organizations in the technology sector during a single operation. This attack demonstrated how supply chain compromises can cause cascading effects.
2. Lazarus
Specifically, this state-linked group combines espionage with large-scale financial crime. Notably, the group has stolen more than $6.5 billion in cryptocurrency during its active period. Furthermore, this includes over $2.02 billion stolen in 2025 alone.
3. MuddyWater
This state-sponsored espionage group targets government, financial, and logistics sectors across 113 countries. Between October 2025 and March 2026, the group deployed three new malware strains. This rapid development requires defense teams to prepare in advance.
4. Tycoon 2FA
This group dominates the phishing-as-a-service market, controlling 89% of the adversary-in-the-middle platform market. Its subscription model has made credential theft widely accessible. As a result, this has enabled thousands of attacks against cloud computing environments.
5. GoldFactory
First identified in 2024, this group steals biometric data to bypass facial recognition systems in mobile banking. The group executes approximately 15 infections daily. Moreover, it is expanding beyond the Asia-Pacific region into Spanish-speaking areas.
6. TX-NFC
This commercial criminal platform mimics contactless payment systems on fraud devices. Subscriptions cost from $45 daily to $1,050 for three months. Meanwhile, the group continues to expand within English and Russian-speaking cybercrime circles.
7. Shadow Silk
This financially motivated group specializes in long-term concealment. It has operated undetected inside government organizations and critical infrastructure. In one documented case, the group remained hidden for more than 12 months.
8. Bloody Wolf
This group focuses on long-term access and intelligence gathering rather than immediate financial gain. Meanwhile, it operates mainly in Central Asia, targeting government organizations. Specifically, it uses geographically restricted infrastructure to maintain a low profile.
9. Teste PHP
Notably, in less than a year, this group built a financial crime operation across five Spanish-speaking countries. It uses malicious browser extensions to collect credentials silently. This rapid expansion shows how quickly new operations can scale.
10. DarkBlinders
This emerging group targets the aviation and telecommunications sectors in the Middle East. Furthermore, it recorded the highest rate of tactical evolution over 12 months. The group constantly modifies its methods to evade detection.
Future Outlook and Defense Strategies
“Supply chains are now the strongest multiplier for digital crimes. Attacks no longer target victims individually, but integrate into trusted infrastructures to spread across entire sectors.”
Dmitry Volkov, CEO of Group-IB
Specifically, he noted that attacks integrate into trusted infrastructures to spread across entire sectors. Consequently, defenders must use threat intelligence to predict future adversary movements.
Organizations must monitor these cybersecurity threat actors to protect their digital assets. By analyzing adversary behavior, companies can improve their defenses. In addition, collaboration with international law enforcement remains vital to disrupting these criminal networks.





