The Q3 2026 Threat Landscape Report: 8.3 Million IOCs, 1,160 Adversaries, and the Industrialisation of Attack Infrastructure
In ninety-two days — from 01 July through 30 September 2026 — the HackForLab intelligence platform ingested 15,973,683 raw observations and resolved them into 8,314,037 unique high-confidence indicators of compromise. Behind that corpus sits one of the largest publicly-published quarterly adversary datasets of 2026: 1,160 named adversaries, 11 threat categories, 90 contributing feeds, 192,049 CIDR clusters analysed, 711,000+ cloud-attributed indicators, and 480,863 newly-registered domains scored against our DGA detection model.
This report translates that scale into what a CISO, CIO or board walks out with: a clear picture of who is operating against your sector, how their infrastructure is evolving, and the specific control changes the next ninety days demand. It is built to be read by a board on Monday morning and acted on by a SOC director by Wednesday afternoon.
Executive Essentials
The 90-second brief, the 3am read, and the eight statistics your board update can quote directly.
Executive Summary · What Q3 2026 Means for Your Program
The threat environment did not stand still through Q3. Three structural shifts changed what effective detection posture looks like going into Q4. First, the C2 ecosystem industrialised — 74 named command-and-control operators produced over 7.1 million distinct indicators, a scale that no individual-IP block-listing architecture can keep up with. Second, ransomware operator diversity exploded — we tracked 386 distinct ransomware operators across the quarter, more than any prior quarterly reading. Third, the attack surface moved into the cloud — over 711,000 attributed indicators correlated to legitimate public-cloud provider ranges, meaning adversaries now run their operations alongside your production workloads inside the same hyperscalers.
Three actions every CISO should take this quarter:
- Transition from IP-list to CIDR-density enforcement. Programs still blocking at individual-IP granularity are structurally under-covered against the Q3 C2 scale. CIDR-density enforcement — refreshed weekly or better — is now the minimum viable control for this environment.
- Add cloud-provider-aware trust scoring. With 711,000+ attributed indicators living inside legitimate cloud ranges, blanket cloud trust is not safe. The right posture is per-provider, per-service risk scoring that correlates with actor-attribution feeds.
- Deploy DGA and homoglyph detection at the DNS resolver. Q3 surfaced 67,670 high-confidence DGA domains, 1,719 leet-substitution brand lookalikes, 281 punycode IDN attacks and 3,000 dictionary-DGA domains. DNS-resolver detection catches these before endpoints ever query the domain.
The anchoring numbers for a boardroom briefing: 8.3 million distinct IOCs tracked, 1,160 named adversaries, 386 ransomware operators, 192,049 CIDR clusters, 480,863 newly-registered domains scored. These are not back-of-envelope figures; they are the direct output of a production threat-intelligence pipeline running continuously for ninety-two days.
Why Q3 2026 should change your Q4 budget conversation
This is the quarter the threat environment stopped resembling the models most enterprise security programs were built against. The 2016-2020 playbook assumed a few hundred named adversaries, discrete campaign cycles, and clear boundaries between legitimate and malicious hosting. Every one of those assumptions broke in Q3 2026. We tracked 1,160 named adversaries — more than most CISOs could name if asked. We saw 386 ransomware operators, which means the ransomware market is now a diversified affiliate economy, not a few headline brands. We saw adversary operations running on fifteen different hyperscalers and CDNs — the same providers hosting your production.
If your detection content was tuned in 2024 or earlier against a smaller operator population, it is structurally under-sized for the Q3 2026 reality. The techniques your SOC watches for are the right ones — the top-10 MITRE ATT&CK techniques of Q3 are the same classics that have dominated the matrix for years. What changed is the population deploying those techniques.
Three realities a CISO must accept and plan around. One: individual-indicator blocking cannot scale. If your perimeter still works from static IP lists refreshed weekly, you have a documented coverage gap against a specific operator population at scale. Two: the cloud is now where adversaries live, not just where you deploy. Treating public cloud as a trusted zone and the open internet as untrusted is a 2018 assumption that no longer survives contact with 2026 data. Three: brand-impersonation attacks are no longer a niche phishing sub-problem — one single banking brand attracted 2,012 lookalikes this quarter alone.
The budget conversation that follows this report is about architecture, not tooling. Weekly-refreshed CIDR enforcement. DNS-resolver domain intelligence. Actor-fingerprint analytics. Provider-aware trust scoring. These are the Q4 investments the Q3 data forces. Programs that ship the architecture pivot in Q4 2026 will enter 2027 ahead of the curve. Programs that don’t will spend 2027 explaining incidents to their boards that were foreseeable from this document.
Eight statistics your board update can quote directly
- “The HackForLab platform observed 8.3 million distinct high-confidence indicators of compromise this quarter, resolved from 15.97 million raw observations.” This is the scale of the environment your controls operate against.
- “We tracked 1,160 named adversary identifiers across 11 threat categories.” The adversary population is wider than the 2024 playbook assumed.
- “386 distinct ransomware operators were active across Q3 — more operators than any prior quarterly reading.” The ransomware market has diversified into an affiliate economy.
- “Just 74 named command-and-control operators produced 7.1 million distinct indicators.” The C2 tier is industrialising; individual-IP enforcement no longer scales.
- “259 malware families and 158 named campaigns were observed during Q3.” The payload-and-campaign surface is correspondingly diverse.
- “Over 711,000 attributed indicators correlated to legitimate public-cloud provider ranges.” Adversaries are co-located with production workloads inside the same hyperscalers.
- “480,863 newly-registered domains were scored against our DGA model; 28,601 scored HIGH (≥70) and were elevated to the suspicion watchlist.” Domain-registration abuse operates at industrial scale.
- “We tracked lookalike attacks against 15+ consumer and financial brands — one single banking brand attracted 2,012 lookalikes in Q3 alone.” Brand-impersonation is now a board-level fraud exposure.
This report is a Q3 snapshot. HuntIntel is where you watch Q4 unfold.
Everything in this document — the 8.3M IOCs, the 1,160 adversary fingerprints, the 192K CIDR clusters, the 480K scored newly-registered domains, the full cloud-provider attribution lattice, the brand-lookalike watchlists, the DGA model output — is a snapshot extract from a live corpus that updates continuously. HuntIntel is the operator console where that corpus lives.
Per-cluster live fingerprints. Actor migration timelines. Live CIDR-density feed. The Cloud Battleground attribution lattice interactively. The NRD Watch dashboard. The Domain Intelligence engine. Sector heatmaps. Country attribution atlas. MITRE × technique drill-down. Export as STIX, MISP, CSV.
What this document covers · seven parts · twenty-three sections
- Executive Summary · the CISO 90-second brief
- CISO Nightmare Reading · the 3am read
- Board Talking Points · eight quotable statistics
- Methodology & Scope · how this report was built
- The Numbers at a Glance · twelve anchoring statistics
- Growth Trajectory · July → August → September
- IOC Taxonomy · domains, IPs, URLs, hashes
- Named Adversaries at Scale · 1,160 operators across 11 types
- Five Q3 Observations · the headline shifts of the quarter
- C2 Industrialisation · 74 operators, 7.1M indicators
- Shared-Infrastructure Clustering · 192,049 /24 CIDRs
- Where Adversaries Live · the anonymised provider lattice
- Industry Sectors Under Fire
- Country-Level Targeting
- Top 10 MITRE ATT&CK Techniques
- CVE Exploitation Landscape
- NRD Watch · the newly-registered-domain problem
- TLD Abuse Divergence
- Brand-Lookalike Hunter
- DGA Detection · entropy & dictionary families
- Homoglyph & Punycode Attacks
- Risk Register · four ready-to-paste ERM entries
- What Changes in Q4 · forecast · executive takeaways · close
Scale & Methodology · The Q3 2026 Environment
How this report was built, the twelve numbers that anchor it, the month-by-month growth shape, and the taxonomy of 8.3 million distinct indicators.
Methodology & Scope
Window: 01 July 2026 00:00 UTC through 30 September 2026 23:59 UTC. Ninety-two calendar days.
Data source: HackForLab’s production threat-intelligence platform, aggregating 90 distinct feed sources (open-source, commercial, custom-sourced and research-partner contributions). The master IOC table carried approximately 7.46 million rows at the start of the quarter and 8.95 million rows at the end.
Scope filter: every statistic derives from indicators where detection date falls inside the Q3 window. Aggregates are over distinct indicator values where quoted as “distinct IOCs”, and over raw observations where quoted as “events”.
Attribution filter: named-adversary counts (1,160 figure, 386 ransomware operators, 74 C2 operators, 239 named threat actors) include only indicators where our platform resolved a specific operator identity — not generic classifications. Rows with Unknown, N/A, blank or placeholder adversary names are excluded from attribution counts.
Anonymisation: this report does not disclose specific adversary names, specific target organisations, or specific real-victim data. Cloud providers are referred to as Hyperscaler-A, CDN-B, Anonymiser-A in Part IV, with the key preserved operationally in the HuntIntel console. Published IOCs are defanged per standard CTI practice.
The intent of this report is to translate production threat-intelligence output into decisions a CISO, CIO, SOC director and board can act on. We publish the numbers at the scale we see them, with analytical commentary informed by both the data and the operational experience of running the intelligence pipeline for ninety-two consecutive days.
The Numbers at a Glance
Q3 2026 at twelve numbers. Each number drives at least one section of this report.
Two framing observations before we dive in. First: the ratio of distinct IOCs to raw observations is approximately 1 : 1.92 — meaning the deduplication layer is removing roughly half of ingested rows as duplicates across sources, which is a healthy sign of multi-source corroboration. Second: the quarter is heavily back-loaded. September alone contributed 7.19 million distinct IOCs — more than July and August combined. The chart below shows the monthly shape.
Growth Trajectory · July → August → September
Q3 did not distribute evenly across its three months. The chart shows month-by-month distinct-IOC volume. The surge in September is almost entirely attributable to a single persistent command-and-control operator that produced approximately 45,000 fresh indicators per week across three consecutive weeks (31 August – 20 September).
Monthly distinct-IOC volume · July 1.23M → August 1.27M → September 7.19M
| Month | Distinct IOCs | Raw Rows | Named Adversaries | What Happened |
|---|---|---|---|---|
| July 2026 | 1,234,736 | 3,340,610 | 444 | Baseline operations · steady diverse surface |
| August 2026 | 1,267,637 | 3,427,332 | 463 | Slight expansion · summer campaign-cycle entry |
| September 2026 | 7,185,771 | 9,205,741 | 333 | Persistent C2 operator surge · sustained 3 consecutive weeks at ~45K IOCs/week |
The September surge is real — those indicators were observed, confirmed, deduplicated and attributed — but the operator shape is one dominant producer plus a materially narrower long tail than July or August showed. Named-adversary count actually fell in September (333 vs August’s 463) despite the IOC surge because the surge was concentrated in one operator while the broader adversary population consolidated.
IOC Taxonomy & Distribution
Seven IOC types were observed in Q3. Domains dominate the corpus (74% of all distinct IOCs), reflecting both the reality that adversaries register domain infrastructure far more frequently than they rotate IP infrastructure, and our platform’s broad domain-coverage pipeline (NRD Watch + Domain Intelligence).
IOC type distribution · Q3 2026 · 8.3M distinct indicators across 7 types
| IOC Type | Distinct IOCs | Raw Observations | Distinct Adversaries | Role in Q3 Picture |
|---|---|---|---|---|
| DOMAIN | 6,139,620 | 7,880,952 | 417 | Dominant tier · 480K+ NRDs scored for DGA risk · delivery infrastructure |
| IP | 1,645,561 | 5,646,123 | 414 | C2 + scanner + direct exploitation · 711K+ cloud-attributed |
| URL | 282,548 | 1,445,512 | 638 | Highest operator diversity · staging + payload-delivery URLs |
| HASH | 223,712 | 768,503 | 455 | Payload signatures · loader / RAT / trojan / ransomware families |
| OTHERS | 22,199 | 232,130 | 173 | Process names, registry keys, mutex IDs, behavioural artefacts |
| 392 | 455 | 137 | Spearphishing recipient indicators · high operator diversity | |
| PROCESS | 8 | 8 | 5 | Rare but high-signal behavioural indicators |
The Adversary Landscape · 1,160 Named Operators
Who was operating against your environment during Q3 — the shape of the ransomware market, the C2 industrialisation tier, and the shared-infrastructure clustering of /24 blocks.
Named Adversaries at Scale · 1,160 Operators Across 11 Types
Eleven adversary types were observed in Q3. The table below shows each type with its distinct named-operator count and total distinct IOC volume. The “Named operators” column answers the question CISOs most often ask: “How many distinct ransomware groups are we tracking right now?”
Named-operator diversity · top 6 adversary types by distinct operator count
| # | Adversary Type | Named Operators | Distinct IOCs | Interpretation |
|---|---|---|---|---|
| 1 | C2 (command-and-control) | 74 | 71,49,454 | Industrial-scale infrastructure provisioning · persistent operators + rotating fleets |
| 2 | Malware families | 259 | 5,50,284 | Loader / RAT / backdoor / spyware ecosystem |
| 3 | Threat Actor (named APT) | 239 | 14,108 | Nation-state and advanced persistent groups |
| 4 | Malware campaign | 158 | 11,294 | Discrete named campaigns across operators |
| 5 | Ransomware operators | 386 | 3,434 | Highest actor diversity · affiliate-market shape |
| 6 | Phishing Campaign | 46 | 2,057 | Spearphishing + bulk credential harvesting |
| 7 | Scanner (automated) | — | 9,91,723 | Mass scanning · precursor to targeted exploitation |
| 8 | TOR traffic | — | 16,277 | Exit-node activity · anonymised C2 fallback |
| 9 | SCAN (attributed) | 14 | 117 | Attributed reconnaissance groups |
| 10 | Phishing Kit | 10 | 3,967 | Kit infrastructure used across campaigns |
| 11 | DDoS | 2 | 24 | Attributed DDoS operators |
Four observations from this table:
- The C2 tier dominates by IOC volume but is operator-light. 74 operators produced 7.1M IOCs — a 96,000:1 ratio. This is infrastructure-provisioning operations, not endpoint-compromise operations.
- The ransomware tier is operator-rich but IOC-light. 386 operators produced 3,434 IOCs — a 9:1 ratio. This is the affiliate-economy signature: many small operators each running tight, focused campaigns.
- The Threat Actor and Malware tiers sit in between. 239 named APT groups + 259 malware families + 158 campaigns represent the mid-density population — meaningfully diverse operators each producing meaningful volume.
- Scanner activity is attribution-free but massive in volume. 991,723 distinct scanner IOCs with zero named operators means almost all of this activity is attributed only at the behavioural level — the precursor-reconnaissance tier.
Five Q3 Observations · The Headline Shifts of the Quarter
Five structural observations about the Q3 2026 landscape, each tied to specific control recommendations.
Named-adversary tracking crossed the 1,000-operator threshold
Our platform resolved 1,160 distinct named adversaries across the quarter. For context: this is more individual actor identities than most enterprise programs explicitly track. The distribution is heavily skewed — the top 50 adversaries by IOC volume account for roughly 80% of total attributed observations, while the long tail of 1,110+ smaller operators each contributes modest individual volume.
The ransomware market diversified to 386 concurrent operators
The Ransomware adversary type produced 3,434 distinct indicators from 386 operators. By volume this is modest. By operator diversity it is unprecedented in the trailing six-quarter corpus. Quarter-average per-operator volume is roughly 9 — most ransomware operators are small, discrete affiliates running focused campaigns.
C2 operations industrialised — 74 operators produced 7.1 million indicators
The Command-and-Control adversary type dominated Q3: 7,149,454 distinct IOCs from 74 operators. Average per-operator volume is ~96,000 distinct indicators — four orders of magnitude higher than the ransomware tier. This is infrastructure-as-a-service C2 at industrial scale, with a small handful of operators serving the broader adversary ecosystem.
Over 711,000 attributed indicators ran on legitimate public-cloud infrastructure
Our Cloud Battleground attribution layer correlated 711,000+ Q3 indicators to legitimate hyperscaler, CDN, VPN and SaaS provider ranges. Roughly 43% of IP-tier attributed IOCs this quarter lived inside providers most enterprises implicitly trust at the perimeter.
Newly-registered-domain abuse operates at half-a-million per quarter
Our NRD Watch pipeline scored 480,863 newly-registered domains against our six-feature DGA detection model this quarter. Of those: 28,601 scored HIGH (≥70), 130,981 scored LIKELY (55-69), and 321,281 scored POSSIBLE (45-54). Separately, Domain Intelligence surfaced 67,670 high-confidence DGA domains across the quarter.
C2 Industrialisation · 74 Operators & 7.1 Million Indicators
Section 06 Observation 03 opens the story on C2 industrialisation. This section goes deeper on what that means operationally — because the industrial-scale C2 pattern is the single most important structural shift of Q3 2026.
The scale: 74 named C2 operators produced 7,149,454 distinct network-address IOCs across 92 days — an average of 96,614 IOCs per operator per quarter, or roughly 1,050 IOCs per operator per day. One specific operator sustained ~45,000 fresh indicators per week across three consecutive weeks in September; that single operator alone deposited approximately 144,000 unique network addresses into the Q3 corpus.
Provisioning velocity: averaged across the C2 tier, the per-operator provisioning rate is roughly 44 fresh network addresses per hour sustained. The highest-velocity individual operator provisioned closer to 267 addresses per hour during peak weeks. These rates exceed the ingest and distribution speed of any enterprise individual-IP block-list architecture by two to three orders of magnitude.
What the market looks like: the 74 named C2 operators split into roughly four tiers. A small handful of industrial operators (fewer than 10) provision at tens of thousands of IOCs per week. A mid-tier group of 15-20 operators provision at single-digit thousands per week. A long tail of 40-50 smaller operators provision at hundreds per week. The industrial operators function as infrastructure suppliers to downstream campaign operators including many of the 386 ransomware affiliates.
Shared-Infrastructure Clustering · 192,049 CIDR /24 Analysis
Our platform maintains a continuous CIDR-cluster analytics layer (90-day rolling window) that groups activity by /24 network block. Each /24 is characterised by its unique IP count, unique adversary count, feed overlap and other signals. Across Q3’s rolling-90-day window we tracked 192,049 distinct /24 clusters, carrying 4,243,556 total observations and 1,266,134 distinct IPs.
The signal that matters for defenders is the distinct-adversary count per /24. A /24 with one adversary is probably one operator’s rental pool. A /24 with multiple adversaries is almost certainly a shared-infrastructure block.
| Distinct Adversaries per /24 | CIDR Count | Total Observations | Interpretation |
|---|---|---|---|
| 2 operators | 904 | 36,698 | Modest shared-infra signal |
| 3 operators | 105 | 15,247 | Strong shared-infra · likely IaaS C2 or bulletproof hosting |
| 4 operators | 17 | 1,730 | Very strong shared-infra · known rental pool |
| 5 operators | 5 | 1,854 | Confirmed multi-tenant adversary infrastructure |
| 6 operators | 3 | 1,186 | Industrial infrastructure-as-a-service provider |
| 7 operators | 1 | 271 | One block carrying 7 operators — rare and high-signal |
| 8 operators | 1 | 427 | The ultimate shared-infra block of Q3 2026 |
1,036 /24 blocks hosted multiple distinct adversaries during Q3. 10 of those blocks hosted 5 or more adversaries. One single /24 block hosted eight different named adversaries — the strongest shared-infrastructure signal in the Q3 dataset. These multi-actor /24s are the correct CIDR-density enforcement targets: blocking any one of them removes multiple operators simultaneously.
Live CIDR Clusters feed → The full 192,049 /24 cluster lattice with per-block distinct-adversary count, feed overlap, severity mix and provisioning velocity. Export as CIDR block list for direct firewall ingestion.
Cloud Battleground · Where Adversaries Live
711,000 attributed indicators correlated to legitimate public-cloud ranges across 20 anonymised providers. The attack surface moved into the cloud and the data proves it.
Cloud Battleground · Where Adversaries Live (Anonymised)
Our Cloud Battleground attribution layer correlates every IP-tier IOC in the corpus against a catalog of hyperscaler, CDN, VPN, SaaS and bulletproof-hosting provider CIDRs. The resulting fact table pre-joins IOC × provider so provider-level analytics are millisecond-fast.
Q3 picture: 711,000+ attributed indicators correlated to legitimate public-cloud ranges, spanning twenty top providers with meaningful attributed-adversary activity. The chart and table below show each provider’s Q3 activity, anonymised with class + rank labels. The real-identity key is preserved in the HuntIntel operator console.
Anonymisation key: Hyperscaler-A through Hyperscaler-M are the thirteen largest cloud providers by Q3 attributed-indicator volume. CDN-A and CDN-B are the two primary content-delivery networks. Anonymiser-A is a Tor-exit-node class provider. SaaS-A and SaaS-B are developer-platform and anonymised-browsing SaaS respectively. AI-Bot-A is an AI-crawler bot network. Search-A is a major search / portal provider’s attributable IP range.
Top 10 cloud providers · attributed indicator rows · Q3 2026 (anonymised)
| # | Provider | Class | Rows | Distinct IPs | Actors | Adv Types |
|---|---|---|---|---|---|---|
| 1 | Hyperscaler-A | Cloud · IaaS | 1,06,669 | 24,851 | 34 | 8 |
| 2 | Hyperscaler-B | Cloud · IaaS | 98,293 | 39,361 | 48 | 7 |
| 3 | Hyperscaler-C | Cloud · IaaS | 76,970 | 25,728 | 14 | 7 |
| 4 | Hyperscaler-D | Cloud · IaaS | 63,579 | 13,296 | 31 | 8 |
| 5 | Anonymiser-A | VPN · Tor | 61,858 | 1,914 | 3 | 5 |
| 6 | Hyperscaler-E | Cloud · IaaS | 54,641 | 16,157 | 29 | 8 |
| 7 | SaaS-A | SaaS · Dev | 45,423 | 8,448 | 10 | 6 |
| 8 | Hyperscaler-F | Cloud · IaaS | 44,881 | 4,218 | 15 | 6 |
| 9 | Hyperscaler-G | Cloud · IaaS | 39,676 | 13,854 | 19 | 7 |
| 10 | Hyperscaler-H | Cloud · IaaS | 30,558 | 6,196 | 12 | 6 |
| 11 | Hyperscaler-I | Cloud · IaaS | 25,598 | 3,934 | 28 | 8 |
| 12 | Hyperscaler-J | Cloud · IaaS | 12,721 | 4,078 | 34 | 8 |
| 13 | Hyperscaler-K | Cloud · IaaS | 11,919 | 2,025 | 10 | 5 |
| 14 | Hyperscaler-L | Cloud · IaaS | 10,166 | 3,177 | 11 | 5 |
| 15 | CDN-A | CDN | 9,170 | 1,946 | 12 | 5 |
| 16 | Search-A | Search/Portal | 8,908 | 971 | 7 | 4 |
| 17 | SaaS-B | SaaS · Privacy | 6,987 | 1,042 | — | 2 |
| 18 | Hyperscaler-M | Cloud · IaaS | 6,917 | 937 | 9 | 7 |
| 19 | AI-Bot-A | AI Crawler | 5,104 | 1,199 | — | 3 |
| 20 | CDN-B | CDN | 4,427 | 652 | 3 | 4 |
Four observations from the Cloud Battleground data:
- Thirteen hyperscalers carry attributed activity. This is not a “one bad cloud” picture — adversary operations distribute across every major public-cloud provider.
- Hyperscaler-A, B and C carry the most attributed activity (106K, 98K, 77K rows). Together they host ~40% of all cloud-attributed Q3 indicators.
- Anonymiser-A has the lowest IP diversity — 1,914 distinct IPs carrying 61,858 attributed observations means a small number of exit nodes see very high repeat-attribution activity.
- Hyperscaler-B has the highest named-actor diversity: 48 distinct operators. This provider hosts the broadest cross-section of the Q3 adversary population — a strong candidate for provider-aware trust-scoring.
The full cloud-attribution lattice → HuntIntel resolves each anonymised label to its real identity, with per-service and per-region drill-down. See Hyperscaler-A’s adversary profile with name, operator classes and IP sample.
Targeting Patterns · Sectors, Countries, Techniques, CVEs
Which sectors and countries faced the broadest attack surface, which MITRE techniques dominated the quarter, and which CVEs were actively exploited against named adversaries.
Industry Sectors Under Fire
Where adversaries directed their operations in Q3. The chart and table show targeting events (not successful breaches — observed-targeting indicators extracted from feed-source attribution). The “Adv Types” column shows how many distinct adversary types (out of 11) targeted each sector.
Top 10 targeted industry sectors · Q3 2026 · ranked by targeting event volume
| # | Sector | Targeting Events | Adv Types |
|---|---|---|---|
| 1 | Technology | 21,443 | 8 |
| 2 | Government | 20,779 | 8 |
| 3 | Healthcare | 18,512 | 7 |
| 4 | Manufacturing | 15,967 | 7 |
| 5 | Telecommunications | 15,841 | 7 |
| 6 | Financial Services | 15,786 | 7 |
| 7 | Education | 14,389 | 7 |
| 8 | Retail | 13,254 | 7 |
| 9 | Individual Users | 9,565 | 5 |
| 10 | Finance (banking) | 3,336 | 7 |
| 11 | Professional Services | 3,002 | 6 |
| 12 | Critical Infrastructure | 2,306 | 4 |
| 13 | Energy | 1,940 | 5 |
| 14 | Military / Defence | 1,728 | 3 |
| 15 | Research | 1,652 | 1 |
Three observations about this landscape:
- Technology (21,443) and Government (20,779) lead by raw volume — both at 8 distinct adversary types, meaning the broadest attack-surface diversity. These sectors face every major adversary class.
- Healthcare, Financial Services and Manufacturing cluster closely (18.5K / 15.8K / 16.0K events). Attack-type diversity is 7 — one notch below Technology/Government but still substantially broader than the long tail.
- Critical Infrastructure and Military have lower raw volumes but narrower diversity (2,306 and 1,728 events, 4 and 3 adversary types). Consistent with these sectors being primarily targeted by APT and C2-class operators.
Country-Level Targeting
Geographic attribution of adversary targeting across Q3. “Targeting events” are instances where an indicator carried a geographic-targeting label.
Top 7 targeted countries · Q3 2026 · all above 8,000 targeting events
| # | Country | Targeting Events | Adv Types |
|---|---|---|---|
| 1 | United States | 13,032 | 6 |
| 2 | Germany | 11,601 | 7 |
| 3 | United Kingdom | 11,261 | 6 |
| 4 | Canada | 11,015 | 7 |
| 5 | France | 11,012 | 7 |
| 6 | Australia | 10,542 | 7 |
| 7 | India | 8,789 | 6 |
| 8 | Italy | 2,647 | 5 |
| 9 | Spain | 2,031 | 5 |
| 10 | Brazil | 1,360 | 4 |
| 11 | Japan | 951 | 5 |
| 12 | Netherlands | 586 | 4 |
| 13 | Switzerland | 506 | 3 |
| 14 | Ukraine | 361 | 5 |
| 15 | South Korea | 377 | 3 |
The seven most-targeted countries all exceed 8,000 events: United States (13,032), Germany (11,601), United Kingdom (11,261), Canada (11,015), France (11,012), Australia (10,542) and India (8,789). These are the long-tail-stable top-targeted nations — large economies with digital-first critical infrastructure. The 6-7 adversary-type diversity confirms enterprise defenders in these jurisdictions face every major adversary class.
India at 8,789 events / 6 adversary types is a meaningful standout for an Asian-Pacific nation ranking directly behind the Five Eyes economies — reflecting both India’s rising digital-economy profile and the specific targeting of its banking sector observed in the brand-lookalike data.
Top 10 MITRE ATT&CK Techniques of Q3 2026
Our platform resolves adversary-reported technique annotations against the MITRE ATT&CK framework. The heatmap and table show the top 15 techniques by observation count. The cell intensity in the heatmap scales with event count.
Top 15 MITRE ATT&CK techniques · Q3 2026 · heatmap intensity scales with event count
| # | Technique | Name | Events | Tactic |
|---|---|---|---|---|
| 1 | T1105 | Ingress Tool Transfer | 25,253 | Command & Control |
| 2 | T1027 | Obfuscated Files or Information | 12,163 | Defense Evasion |
| 3 | T1189 | Drive-by Compromise | 11,556 | Initial Access |
| 4 | T1041 | Exfiltration Over C2 Channel | 8,764 | Exfiltration |
| 5 | T1036 | Masquerading | 7,869 | Defense Evasion |
| 6 | T1059 | Command & Scripting Interpreter | 5,682 | Execution |
| 7 | T1005 | Data from Local System | 4,171 | Collection |
| 8 | T1082 | System Information Discovery | 3,735 | Discovery |
| 9 | T1190 | Exploit Public-Facing Application | 3,475 | Initial Access |
| 10 | T1539 | Steal Web Session Cookie | 3,373 | Credential Access |
| 11 | T1083 | File and Directory Discovery | 3,159 | Discovery |
| 12 | T1486 | Data Encrypted for Impact | 3,149 | Impact |
| 13 | T1078 | Valid Accounts | 2,672 | Defense Evasion |
| 14 | T1490 | Inhibit System Recovery | 2,404 | Impact |
| 15 | T1021 | Remote Services | 2,252 | Lateral Movement |
Four observations about Q3’s technique landscape:
- The top three techniques are classics. T1105 Ingress Tool Transfer, T1027 Obfuscation, T1189 Drive-by Compromise. These dominate every modern threat landscape and are the techniques most detection content should prioritise.
- T1041 at 8,764 events reflects the C2-dominated nature of the corpus. With 7.1M C2-tier IOCs, exfiltration-over-C2 is the volumetric baseline of adversary data-theft operations.
- T1190 Exploit Public-Facing Application at 3,475 events reflects the initial-access-via-exploitation surface — paired with the CVE table in Section 13.
- T1486 Data Encrypted for Impact at 3,149 events confirms the ransomware operator-diversity story. 386 operators each contributing to this technique produces a mid-tier volume that any precursor-cascade rule will catch at scale.
CVE Exploitation Landscape
Vulnerabilities actively exploited by named adversaries during Q3, ranked by observation count.
| # | CVE | Name | Events |
|---|---|---|---|
| 1 | CVE-2023-1389 | TP-Link Archer AX21 command injection | 1,324 |
| 2 | CVE-2022-22965 | Spring Framework RCE (Spring4Shell) | 1,235 |
| 3 | CVE-2020-29557 | D-Link DIR-825 auth bypass | 1,235 |
| 4 | CVE-2022-29303 | SolarView Compact command injection | 1,235 |
| 5 | CVE-2021-1497 | Cisco HyperFlex command injection | 1,235 |
| 6 | CVE-2020-25506 | D-Link DNS-320 RCE | 1,235 |
| 7 | CVE-2021-31207 | Microsoft Exchange SSRF (ProxyShell) | 423 |
| 8 | CVE-2021-34523 | Microsoft Exchange elevation (ProxyShell) | 420 |
| 9 | CVE-2021-26855 | Microsoft Exchange SSRF (ProxyLogon) | 402 |
| 10 | CVE-2023-27532 | Veeam Backup credential disclosure | 366 |
| 11 | CVE-2017-17215 | Huawei HG532 RCE | 323 |
| 12 | CVE-2014-8361 | Realtek SDK RCE | 323 |
| 13 | CVE-2024-1709 | ConnectWise ScreenConnect auth bypass | 299 |
| 14 | CVE-2024-1708 | ConnectWise ScreenConnect path traversal | 299 |
| 15 | CVE-2020-3259 | Cisco ASA/FTD info disclosure | 292 |
The composition tells three stories:
- Edge-device vulnerabilities dominate the top of the list. TP-Link, D-Link, SolarView, Huawei, Realtek SDK. This is the botnet-recruitment attack surface — low-security consumer and small-business routers compromised at scale to form distributed infrastructure.
- Enterprise identity-and-messaging vulnerabilities form the second cluster. ProxyShell (CVE-2021-31207, CVE-2021-34523) and ProxyLogon (CVE-2021-26855) remain actively exploited at 400+ events each despite being 2021 vulnerabilities with widely-available patches.
- Modern enterprise tooling vulnerabilities round out the list. ScreenConnect (CVE-2024-1709, 1708), Veeam (CVE-2023-27532), Spring4Shell (CVE-2022-22965), Cisco ASA (CVE-2020-3259). These enable lateral movement, backup-destruction, and widespread enterprise compromise.
Live CVE-exploitation feed → HuntIntel surfaces top actively-exploited CVEs with 90-day trending, vendor product mapping, and adversary attribution per CVE. Patch-management teams prioritise directly from live exploitation data.
Domain Threat Intelligence · The NRD / DGA / Brand Problem
Half a million newly-registered domains per quarter. 67,670 high-confidence DGA domains. 2,012 lookalikes against a single banking brand. The domain-tier intelligence picture of Q3.
NRD Watch · The Newly-Registered-Domain Problem
Our NRD Watch pipeline monitors the global stream of newly-registered domains, applying a six-feature DGA detection model to every candidate. Q3’s output:
Why NRDs matter: newly-registered domains are the single highest-leverage early-warning signal in the modern threat environment. Adversaries buy new domains for every phishing campaign, every DGA-generated C2 infrastructure, every brand-impersonation attack. The gap between registration and first weaponisation is typically 24-72 hours — the window during which proactive NRD scoring can block the domain before any endpoint ever queries it.
The DGA scoring model: each domain’s name (TLD stripped) is scored 0-100 as a weighted sum of six features, each normalised to 0-1 before weighting. Character diversity (weight 30): rewards random-looking names that use most of the alphabet. Consonant-run length (20): penalises unpronounceable consonant streaks. Vowel scarcity (15): one-sided penalty for low vowel ratio. Length band (15): full points for 8-16 characters (common DGA family range). Digit density (10): penalises heavy digit mixing. Dictionary-word absence (10): penalises domains that contain any common English or brand substring.
Thresholds: ≥70 HIGH (hard-block recommended), 55-69 LIKELY (daily review), 45-54 POSSIBLE (watchlist).
TLD Abuse Divergence
Not all top-level domains carry equal threat weight. Our NRD Watch rollup tracks which TLDs produce the highest newly-registered-domain volumes across Q3.
| # | TLD | Q3 NRD Count |
|---|---|---|
| 1 | .com | 18,02,951 |
| 2 | .xyz | 5,05,672 |
| 3 | .top | 2,19,092 |
| 4 | .cn | 1,58,521 |
| 5 | .shop | 1,43,611 |
| 6 | .net | 1,13,352 |
| 7 | .org | 1,08,141 |
| 8 | .online | 1,06,734 |
| 9 | .site | 70,997 |
| 10 | .ru | 66,802 |
| 11 | .info | 61,513 |
| 12 | .vip | 56,044 |
| 13 | .store | 55,919 |
| 14 | .cc | 52,670 |
| 15 | .app | 50,590 |
The TLD distribution tells a three-tier story:
- Legacy generics (.com, .net, .org) still dominate. .com alone produced 1.80 million NRDs in Q3 — the largest TLD by registration volume and the TLD most adversaries default to for lookalike domains.
- Cheap generics are the real abuse surface. .xyz (506K), .top (219K), .shop (144K), .online (107K), .site (71K), .vip (56K), .store (56K), .click (41K). These TLDs offer registration prices sometimes under one US dollar — the economic choice for mass-DGA and phishing infrastructure.
- Country-code TLDs with permissive registration carry notable volume. .cn (159K), .ru (67K), .uk (48K), .br (38K).
Brand-Lookalike Hunter
Our Domain Intelligence engine maintains a persistent brand-lookalike watchlist, continuously matching new domain registrations against high-value brand names (banks, major tech companies, cryptocurrency exchanges, consumer services). Q3’s top-15 brand-lookalike targets:
| # | Brand | Q3 Lookalikes | Industry |
|---|---|---|---|
| 1 | Axis | 2,012 | Banking (India) |
| 2 | Apple | 1,322 | Consumer tech |
| 3 | Chase | 743 | US banking |
| 4 | Wells | 683 | US banking (Wells Fargo) |
| 5 | Amazon | 520 | E-commerce / cloud |
| 6 | 432 | Consumer / enterprise tech | |
| 7 | 365 | Messaging | |
| 8 | Binance | 151 | Crypto exchange |
| 9 | Coinbase | 144 | Crypto exchange |
| 10 | Netflix | 127 | Streaming |
| 11 | Adobe | 126 | Enterprise software |
| 12 | Microsoft | 122 | Enterprise software |
| 13 | 110 | Social | |
| 14 | 73 | Social | |
| 15 | PayPal | 64 | Payments |
Axis at 2,012 lookalike domains in Q3 alone is the single-largest brand-lookalike event in the dataset — reflecting concentrated attacker focus on India’s banking sector. At that volume, the brand faces approximately 22 new lookalike domains registered against it every day on average — a continuous intake rate no manual review process can keep up with.
- Banking brands dominate. Axis, Chase, Wells, Binance, Coinbase, PayPal — six of the top-15 are financial-services. The motivation is obvious: successful phishing against banking brands converts directly to monetised fraud.
- Consumer-tech brands follow. Apple, Amazon, Google, WhatsApp, Netflix, Microsoft, Facebook, Instagram. Targeted both for credential-harvesting and ecosystem-abuse.
- Cryptocurrency exchanges are a growing surface. Comparatively small by lookalike-count but very high by per-lookalike monetisation potential.
DGA Detection · Entropy & Dictionary-Based Families
Our Domain Intelligence engine runs two complementary DGA detectors over the full attributed-domain corpus. The entropy-based detector catches classical character-random DGAs. A separate dictionary-based detector catches DGAs that concatenate real English words (Suppobox, Matsnu, Rovnix family) and evade the entropy detector by producing pronounceable strings.
Why dictionary-DGA detection matters: the classical entropy-based DGA detector catches malware families like Necurs or Mirai whose generated domains look obviously-random (xkqwqpsjlk[.]com). But a newer generation of DGA families — Suppobox, Matsnu, Rovnix — generate domains by concatenating real English words (brightmoment[.]com, sweeterwater[.]com). Our dictionary-DGA detector flags pure-alpha, hyphen-free, pronounceable domains that contain ≥2 distinct common dictionary words.
The 200 named adversary domain-fleet entries represent operators whose domain-registration infrastructure has been fingerprinted sufficiently to be tracked as a fleet: a persistent domain-generation pipeline tied to a specific operator identity, with domain count, TLD distribution, severity mix and attack-type profile.
Structural clustering of DGA families: beyond scoring individual domains, our engine clusters DGA candidates into structural families based on their generation algorithm’s statistical fingerprint. Two domains generated by the same DGA function will have highly similar feature profiles — length, character set, vowel ratio, digit density — even if they share no visible textual similarity. The analytical leverage is one-to-many: identify one representative sample, block the whole family.
Homoglyph & Punycode Attacks
Our Domain Intelligence engine’s homoglyph detector catches two distinct attack patterns: IDN punycode domains (xn---prefixed internationalised domains that render as near-indistinguishable Unicode variants of real brand names) and leet-substitution brand lookalikes (g00gle, paypa1, microsоft).
IDN punycode attacks are among the most insidious phishing techniques in the modern landscape. A domain like xn--pple-43d[.]com renders in most browsers as a visual variant of apple.com using a Unicode character substitution visually indistinguishable to most users. Browsers have added mitigations (Punycode display for mixed-script domains, Latin-only policy for enforcing TLDs) but the attack surface remains meaningful.
Leet-substitution brand lookalikes are the volumetric majority (1,719 vs 281). These are the g00gle.com, paypa1.com, micr0soft.com, amaz0n.com pattern — simple character substitutions (zero for O, one for L, three for E) that human readers often miss at a glance.
Live Domain Intelligence console → Explore the 798K DGA corpus, 2,000 homoglyph entries, 3,000 dictionary-DGA domains and 200 adversary domain-fleet fingerprints interactively. Export filtered lists in STIX, MISP, CSV.
The Forward View · Risk Register, Forecast, Takeaways
Four ready-to-paste ERM entries. Q4 forecast base cases. The Monday-morning action list for CISOs, CIOs and boards.
Risk Register Language for Enterprise ERM
Four Ready-to-Paste ERM Register Entries
Each entry is drafted to survive a board-level risk committee review. Adapt the risk IDs to your organisation’s taxonomy.
Q3 2026 threat intelligence documents 74 named command-and-control operators producing 7.1 million distinct network-infrastructure indicators across the quarter, including one operator sustaining approximately 45,000 fresh indicators per week across three consecutive weeks. Operators of this scale provision infrastructure at a rate that exceeds the ingest capacity of individual-IP block-listing architectures by multiple orders of magnitude. Enterprise programs still operating individual-IP enforcement are structurally under-covered against documented, named, publicly-attributed adversary infrastructure. Risk owner: Head of Security Architecture. Review cadence: quarterly through 2027. Treatment plan: transition from individual-IP enforcement to CIDR-density enforcement; adopt weekly-or-better refresh cadence for CIDR block list.
Q3 2026 threat intelligence correlated over 711,000 attributed adversary indicators to legitimate public-cloud provider IP ranges across 13 hyperscalers, 2 content-delivery networks, and multiple SaaS and VPN providers. Adversaries have strategically chosen public-cloud infrastructure for operational hosting because enterprise security postures still treat major cloud provider IP space as implicitly trusted. Enterprise programs operating blanket cloud-provider trust rules are exposed to adversary traffic originating from the same IP ranges hosting legitimate business services. Risk owner: CISO / Head of Cloud Security joint. Treatment plan: implement provider-aware, service-aware trust-scoring at perimeter and SIEM-correlation layer; adopt dynamic trust-level adjustment based on real-time threat-intelligence attribution per provider / service / region.
Q3 2026 threat intelligence tracked 386 distinct named ransomware operators active across the quarter — the highest operator-diversity count in HackForLab’s publishing history. The ransomware ecosystem has fully transitioned from a few headline-brand operations to a diversified affiliate economy of hundreds of operators running focused campaigns against enterprise targets. Family-specific detection content ages faster than operator entry rate, meaning programs relying on named-family detection content are structurally under-covered against the new-affiliate cohort within 60-90 days of each quarterly refresh. Risk owner: Head of Detection Engineering / SOC Director. Treatment plan: prioritise technique-based ransomware detection (T1486 Data Encrypted for Impact, T1490 Inhibit System Recovery, T1562.001 Impair Defenses) over family-specific content; verify production-tier deployment across all endpoints quarterly.
Q3 2026 threat intelligence documented concentrated brand-lookalike attack volumes against major consumer, financial and crypto brands, including one single banking brand attracting 2,012 new lookalike domains in Q3 alone. Brand-impersonation attacks drive both direct customer fraud and indirect brand damage through observed-but-not-interrupted impersonation activity. Enterprise brand-protection operations relying on manual review or quarterly-cadence takedown vendor cycles are structurally under-sized for the current attack volume. Risk owner: CISO / Head of Fraud / Head of Brand Protection joint. Treatment plan: implement real-time brand-lookalike-domain monitoring with automated takedown-vendor integration; add homoglyph and IDN-punycode detection at DNS-resolver and email-security layers.
What Changes in Q4 2026 · Forecast
Base case for the next ninety days (October – December 2026)
Confidence high · The C2 industrialisation trend continues. The infrastructure-as-a-service C2 model that produced September’s single-operator mega-surge is structural, not one-off. Base case: at least one similar-scale operator (10,000+ IOCs/week sustained for 2+ weeks) will emerge in Q4. Programs that have not transitioned to CIDR-density enforcement by end of October will have another documented coverage gap by end of November.
Confidence high · Ransomware operator count continues growing. The 386 operator count in Q3 was itself a 20-30% increase over Q2. The affiliate-economy market structure means barriers to entry are low. Base case for Q4: 400-500 distinct ransomware operators active.
Confidence medium-high · Cloud-attribution surface grows. Q4 base case is 800,000-1,000,000 cloud-attributed IOCs as adversaries continue migrating infrastructure to public cloud. Provider mix should remain stable but service-level granularity will become increasingly important.
Confidence medium · NRD / DGA volume stays high. Half-a-million suspicious NRDs per quarter is likely sustained baseline. Q4 base case: 450,000-550,000 NRDs DGA-scored, 25,000-35,000 scoring HIGH.
Confidence lower · Brand-lookalike volume on the targeted-banking brand may escalate further in Q4 (end-of-year financial transaction volumes are a known spearphishing driver).
Three specific things to watch for in Q4
- A new C2 operator surfacing at >10,000 IOCs/week. If observed, treat as the Q3 persistent operator’s successor and apply the same CIDR-density enforcement response.
- Ransomware operator identifier turnover. If the Q4 top-20 ransomware operators show less than 50% overlap with Q3’s top-20, treat as evidence of continued new-cohort entry.
- Cloud provider attribution shifts. If any top-13 Hyperscaler meaningfully changes rank, that signals operator migration.
Executive Takeaways · Monday-Morning Action List
For the CISO
- Communicate the architecture pivot to the board this quarter. The Q3 data makes the case concrete: CIDR-density enforcement, cloud-aware trust scoring, DNS-resolver domain intelligence. Use the data in this report in the board presentation.
- Audit coverage against the top-10 MITRE techniques (Section 12). One-week engagement with SOC and detection-engineering. Produce a coverage matrix for each technique and verify production-tier Sigma / Elastic / Splunk rule deployment.
- Verify quarterly patch cadence against the top-15 exploited CVEs (Section 13). Every CVE has a patch available. Any unpatched instance is a documented, defensible-in-after-action coverage gap.
- Review brand-lookalike exposure (Section 16). If your brand is on the list, your fraud and brand-protection teams need operational visibility into the lookalike stream.
For the CIO
- Fund the cloud-aware trust-scoring project. The 711,000 cloud-attributed IOCs are a budget-justification case for provider-aware risk scoring at perimeter and SIEM layers.
- Prioritise DNS-infrastructure modernisation. DGA detection and homoglyph detection at the DNS-resolver layer require modern DNS infrastructure.
- Review cloud-security contracts. Every major hyperscaler carries attributed adversary activity — enterprise cloud contracts should include provisions for abuse-reporting and infrastructure-takedown response times.
For the Board
- Treat threat-intelligence program maturity as a board-level governance question. The 1,160-adversary environment is beyond the scope of any individual CISO’s manual tracking.
- Risk-register the four entries from Section 19 verbatim. They give the audit function concrete language to track against.
- Ask the CISO: “What is our coverage against the top-10 MITRE techniques, and how was that measured?” The answer should reference specific detection content and production-tier deployment status.
Close
Q3 2026 is the quarter the threat landscape stopped being covered by assumptions and started being covered — or not — by architecture. The 8.3 million IOCs, the 1,160 named adversaries, the 386 ransomware operators, the industrial C2 tier, the cloud-colocated adversary infrastructure, the half-million suspicious new domains: these are not alarm bells. They are the shape of the environment your controls operate against today, documented at scale.
What good looks like in Q4: a CISO who can walk a board through the four risk-register entries in Section 19 and point to specific control changes shipped during Q4 against each. A SOC director who can show a coverage matrix against the top-10 MITRE techniques with production-tier Sigma rules for each. A detection-engineering team that has deployed DGA scoring at the DNS-resolver layer, cloud-aware trust scoring at the perimeter, and CIDR-density enforcement at the egress firewall.
What getting it wrong looks like: entering 2027 with 2024-era architecture, 2024-era detection content, and 2024-era assumptions about where the adversary lives. The programs that ship the architecture pivot in Q4 will enter 2027 with meaningfully reduced incident probability. The programs that don’t will spend 2027 explaining incidents to boards that could have been foreseen from this document, published in October 2026.
The quarterly report is a snapshot. HuntIntel is the operating surface for continuous Q4 intelligence.
Everything documented in this report lives inside the HuntIntel operator console, updated continuously as Q4 unfolds. The 1,160 named adversaries with per-cluster drill-down. The 192,049 /24 CIDR clusters with distinct-adversary count. The Cloud Battleground attribution lattice resolving each anonymised provider to real identity. The 798,000 DGA corpus with structural-family clustering. The brand-lookalike watchlist streaming in real time. The MITRE × technique coverage matrix with trailing 90-day frequency trending.
For CISOs: strategic dashboards render cycle-level metrics directly as boardroom slides. For SOC directors: operational feeds — live CIDR-density, cloud-provider attribution, actor migration timelines, ransomware operator-diversity — feed detection engineering pipelines. For hunt leads: TaHiTI-aligned artefact templates, backlog-scoring math, hypothesis abstract library.
Cite this document as: HackForLab CTI Research. “Q3 2026 Threat Landscape Report: 8.3 Million IOCs, 1,160 Adversaries, and the Industrialisation of Attack Infrastructure.” October 2026. hackforlab.com/q3-2026-threat-landscape-report/.










