{"id":452850,"date":"2026-06-23T13:56:54","date_gmt":"2026-06-23T10:56:54","guid":{"rendered":"https:\/\/menatech.net\/en\/?p=452850"},"modified":"2026-06-23T18:50:00","modified_gmt":"2026-06-23T15:50:00","slug":"group-ib-ranks-10-cyber-threat-actors-in-2026-report","status":"publish","type":"post","link":"https:\/\/menatech.net\/en\/group-ib-ranks-10-cyber-threat-actors-in-2026-report\/","title":{"rendered":"Group-IB ranks 10 cyber threat actors in 2026 report"},"content":{"rendered":"<p>Group-IB has unveiled its Top 10 Masked Actors for 2026, a ranking of cyber threat actors that the company said reflects changes in cybercrime operations globally. Group-IB said the list is based on its <a href=\"https:\/\/www.group-ib.com\/landing\/high-tech-crime-trends-report-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">High-Tech Crime Trend Report 2026<\/a>, more than 1,550 frontline investigations, and monitoring of the criminal underground.<\/p>\n<p>According to Group-IB, the supply chain was cybercrime\u2019s most exploited attack surface in 2026. The company said threat actors are increasingly embedding themselves into trusted infrastructure and third-party ecosystems instead of targeting victims in isolation, allowing attacks to cascade across multiple organizations and industries.<\/p>\n<p>The ranking uses what Group-IB described as an adversary-centric methodology. The company said each group was scored across six dimensions: financial impact, victims, volume of threats during the operational lifespan, novelty of technical evolution, growth of affiliates, and notoriety.<\/p>\n<h2>The 2026 Top 10 Masked Actors<\/h2>\n<h3>Scattered Spider<\/h3>\n<p>Scattered Spider was named first in the 2026 Top 10 Masked Actors ranking by Group-IB. The company linked the decentralized cybercriminal community to a 2025 operation that compromised more than 130 organizations across the technology sector.<\/p>\n<h3>Lazarus<\/h3>\n<p>Lazarus was named second in the ranking by Group-IB. Group-IB described Lazarus as a state-linked actor combining cyber espionage and large-scale financial crime, and attributed more than $6.5 billion in cryptocurrency theft during its lifespan to the group, including more than $2.02 billion in 2025 alone.<\/p>\n<h3>MuddyWater<\/h3>\n<p>MuddyWater was listed as a state-aligned cyber espionage group targeting government, financial services, and logistics sectors across 113 countries. Group-IB said the group deployed three new malware variants between October 2025 and March 2026.<\/p>\n<h3>Tycoon 2FA<\/h3>\n<p>The list also includes Tycoon 2FA, which Group-IB said controls 89% market share of the adversary-in-the-middle phishing-as-a-service segment. The company said the platform\u2019s SaaS subscription model has enabled credential theft campaigns across cloud environments.<\/p>\n<h3>GoldFactory<\/h3>\n<p>GoldFactory, first identified by Group-IB in 2024, was described as a technically advanced threat cluster that steals biometric data to bypass facial recognition authentication in mobile banking fraud. The company said it is operating 15 infections per day across active campaigns and has shown signs of geographic expansion through Spanish-language code artifacts.<\/p>\n<h3>TX-NFC<\/h3>\n<p>TX-NFC was described as a commercialized ecosystem that emulates contactless payment systems on fraudsters\u2019 devices. Group-IB said access is offered through subscriptions ranging from $45 per day to $1,050 for three months, with expansion into English- and Russian-speaking cybercrime ecosystems.<\/p>\n<h3>Shadow Silk<\/h3>\n<p>According to Group-IB, Shadow Silk was among the most operationally mature actors on this year\u2019s list. The company said the financially motivated group specializes in obfuscation and long-duration evasion, and has remained concealed for more than 12 months in one documented instance involving critical infrastructure and government entities.<\/p>\n<h3>Bloody Wolf<\/h3>\n<p>Bloody Wolf was described as a persistent threat group focused on long-term access and surveillance, primarily in Central Asia and with a focus on government organizations. Group-IB said the group uses geo-fenced delivery infrastructure to maintain targeted, low-profile access.<\/p>\n<h3>Teste PHP<\/h3>\n<p>Teste PHP was listed as a financial crime operation that expanded across five Spanish-speaking countries in under a year. Group-IB said the group uses malicious browser extensions to harvest credentials in real time.<\/p>\n<h3>DarkBlinders<\/h3>\n<p>According to Group-IB, DarkBlinders was the actor with the highest TTP evolution score on this year\u2019s list. The company said the emerging cluster targets aviation and telecommunications sectors in the Middle East and adapts its tactics, techniques, and procedures to invalidate existing detection signatures.<\/p>\n<p>\u201cThe supply chain has become cybercrime\u2019s most powerful multiplier,\u201d Dmitry Volkov, Chief Executive Officer of Group-IB, said. Volkov said defenders need an adversary-centric response that focuses on how specific actors evolve and how AI-driven intelligence can help predict future behavior.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Group-IB has unveiled its Top 10 Masked Actors for 2026, a ranking of cyber threat actors that the company said reflects changes in cybercrime operations globally. Group-IB said the list is based on its High-Tech Crime Trend Report 2026, more than 1,550 frontline investigations, and monitoring of the criminal underground. According to Group-IB, the supply [&hellip;]<\/p>\n","protected":false},"author":257,"featured_media":452854,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":[],"meta":{"_acf_changed":false,"_breakdance_hide_in_design_set":false,"_breakdance_tags":"","footnotes":""},"categories":[29324],"tags":[29380],"audience-intent":[],"content-types":[],"country":[],"entity":[],"persona":[],"class_list":["post-452850","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts\/452850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/users\/257"}],"replies":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/comments?post=452850"}],"version-history":[{"count":0,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/posts\/452850\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/media\/452854"}],"wp:attachment":[{"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/media?parent=452850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/categories?post=452850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/tags?post=452850"},{"taxonomy":"audience-intent","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/audience-intent?post=452850"},{"taxonomy":"content-types","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/content-types?post=452850"},{"taxonomy":"country","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/country?post=452850"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/entity?post=452850"},{"taxonomy":"format","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/format?post=452850"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/menatech.net\/en\/wp-json\/wp\/v2\/persona?post=452850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}