All Posts
Anomali Cyber Watch
Public Sector
1
min read

Salt Typhoon Resurfaces, Fortinet Credentials Remain Exposed, and a 3-Million-Record Vendor Breach Hits Texas: What State IT Leaders Must Do Today

Published on
June 23, 2026
Table of Contents
<p> <strong> Threat Assessment Level: ELEVATED </strong> </p> <p> <em> Unchanged from the prior cycle. The convergence of actively exploited Fortinet vulnerabilities, confirmed Chinese state-sponsored targeting of U.S. government networks, and a massive third-party vendor breach affecting state citizen data sustains this posture. Escalation to HIGH is possible within 72 hours if Fortinet credential exploitation against state agencies is confirmed. </em> </p> <h2> <strong> Introduction </strong> </h2> <p> State government IT leaders face a threat environment where three distinct attack vectors are converging simultaneously: nation-state espionage actors are actively targeting government networks with fresh malware, a critical mass of stolen Fortinet credentials remains available to adversaries, and third-party vendors handling millions of citizen records are being breached at scale. </p> <p> This is not a theoretical risk briefing. CISA updated its Fortinet hardening directive on June 22. A Chinese state-sponsored group refreshed its malware infrastructure targeting U.S. government on June 23. And Texas just disclosed that 3 million citizens had their driver's license and passport data exposed through a state licensing vendor. </p> <p> If your agency operates Fortinet perimeter devices, relies on third-party vendors for citizen services, or has not validated its endpoint detection resilience against kernel-level attacks &mdash; this report requires your immediate attention. </p> <h2> <strong> What Changed </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Development </strong> </p> </th> <th> <p> <strong> Date </strong> </p> </th> <th> <p> <strong> Why It Matters </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> CISA updates Fortinet credential exposure guidance </strong> </p> </td> <td> <p> Jun 22 </p> </td> <td> <p> Government explicitly named as targeted sector; credential rotation now mandatory, not advisory </p> </td> </tr> <tr> <td> <p> <strong> Salt Typhoon (China) deploys fresh SNAPPYBEE loader targeting U.S. government </strong> </p> </td> <td> <p> Jun 23 </p> </td> <td> <p> Active espionage campaign with IOC updated today &mdash; this group previously compromised major U.S. telecoms </p> </td> </tr> <tr> <td> <p> <strong> Texas Parks &amp; Wildlife vendor breach exposes 3M citizen records </strong> </p> </td> <td> <p> Jun 23 </p> </td> <td> <p> Driver's licenses, passports, addresses exposed via unnamed third-party licensing vendor </p> </td> </tr> <tr> <td> <p> <strong> Dual-RMM phishing campaigns deliver ConnectWise + MSP360 </strong> </p> </td> <td> <p> Jun 23 </p> </td> <td> <p> Legitimate remote management tools weaponized &mdash; blends with normal state IT operations </p> </td> </tr> <tr> <td> <p> <strong> "Gentlemen" ransomware group reveals GentleKiller EDR-killing framework </strong> </p> </td> <td> <p> Jun 23 </p> </td> <td> <p> Operator-maintained EDR defeat capability with rapid BYOVD weaponization; top-5 most active RaaS in Q1 2026 </p> </td> </tr> <tr> <td> <p> <strong> 7 new ICS advisories from CISA </strong> </p> </td> <td> <p> Jun 18&ndash;23 </p> </td> <td> <p> Mitsubishi, Schneider Electric, Rockwell systems used in state water/energy infrastructure affected </p> </td> </tr> </tbody> </table> <h2> <strong> Threat Timeline </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Date </strong> </p> </th> <th> <p> <strong> Event </strong> </p> </th> <th> <p> <strong> Actor/Source </strong> </p> </th> <th> <p> <strong> Impact to State Government </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Jun 12 </p> </td> <td> <p> VOID MANTICORE breaches California water utility </p> </td> <td> <p> IRGC-affiliated (Iran) </p> </td> <td> <p> Demonstrates active targeting of U.S. water infrastructure </p> </td> </tr> <tr> <td> <p> Jun 17&ndash;18 </p> </td> <td> <p> 73,932 FortiGate admin credentials published (FortiBleed / CVE-2026-25815) </p> </td> <td> <p> UNC5435 (Russia-nexus) </p> </td> <td> <p> Government entities identified in criminal sales catalogs </p> </td> </tr> <tr> <td> <p> Jun 18 </p> </td> <td> <p> CISA issues initial Fortinet hardening directive </p> </td> <td> <p> CISA </p> </td> <td> <p> Mandatory action for all federal/state Fortinet operators </p> </td> </tr> <tr> <td> <p> Jun 21 </p> </td> <td> <p> SLICKDEMON supply chain malware targets government in 7 countries </p> </td> <td> <p> China-nexus (unattributed) </p> </td> <td> <p> State agencies using DAEMON Tools potentially exposed </p> </td> </tr> <tr> <td> <p> Jun 22 </p> </td> <td> <p> CISA updates Fortinet guidance with latest Fortinet remediation steps </p> </td> <td> <p> CISA </p> </td> <td> <p> Confirms ongoing exploitation; raises urgency for credential rotation </p> </td> </tr> <tr> <td> <p> Jun 23 </p> </td> <td> <p> Salt Typhoon SNAPPYBEE loader IOC refreshed &mdash; U.S. government targeted </p> </td> <td> <p> Salt Typhoon / Earth Estries (China) </p> </td> <td> <p> Direct espionage threat to state government networks </p> </td> </tr> <tr> <td> <p> Jun 23 </p> </td> <td> <p> Texas TPWD vendor breach &mdash; 3,087,721 records exposed </p> </td> <td> <p> Unknown actor </p> </td> <td> <p> <strong> Licensing/permitting vendors confirmed as high-value targets </strong> </p> </td> </tr> <tr> <td> <p> Jun 23 </p> </td> <td> <p> Adobe-spoofing phishing delivers ConnectWise ScreenConnect RAT </p> </td> <td> <p> Unattributed </p> </td> <td> <p> State employees targeted with legitimate-looking RMM tools </p> </td> </tr> <tr> <td> <p> Jun 23 </p> </td> <td> <p> Document-themed phishing delivers MSP360 RMM </p> </td> <td> <p> Unattributed </p> </td> <td> <p> Second RMM delivery campaign same day &mdash; suggests coordinated operation </p> </td> </tr> <tr> <td> <p> Jun 23 </p> </td> <td> <p> Gentlemen RaaS GentleKiller EDR-killing framework disclosed </p> </td> <td> <p> Gentlemen (RaaS) </p> </td> <td> <p> Advanced EDR defeat capability; geographic expansion to U.S. probable </p> </td> </tr> </tbody> </table> <h2> <strong> Key Threat Analysis </strong> </h2> <h3> <strong> 1. Salt Typhoon Returns with Active Government Targeting </strong> </h3> <p> <strong> Actor: </strong> Salt Typhoon (aliases: Earth Estries, FamousSparrow, GhostEmperor, UNC2286) </p> <p> <strong> Origin: </strong> China (state-sponsored) </p> <p> <strong> Malware: </strong> SNAPPYBEE loader (DgApi.dll) </p> <p> Salt Typhoon &mdash; the group responsible for the 2024&ndash;2025 compromise of major U.S. telecommunications providers &mdash; has refreshed its operational infrastructure with indicators specifically targeting U.S. government and telecommunications networks. The SNAPPYBEE loader uses DLL search order hijacking (DgApi.dll sideloading) to establish persistent access, a technique consistent with this group's established tradecraft. </p> <p> <strong> Why this matters for state government: </strong> Salt Typhoon's previous telecom compromises gave them access to communications metadata and potentially wiretap systems. Their pivot to direct government targeting suggests they are expanding collection beyond telecom intermediaries to government endpoints themselves. State agencies that share network infrastructure with telecom providers or use state-managed telecom services face elevated risk. </p> <h3> <strong> 2. Fortinet Credential Exposure &mdash; The Clock Is Running </strong> </h3> <p> <strong> Actor: </strong> UNC5435 (Russia-nexus) </p> <p> <strong> CVE: </strong> CVE-2026-25815 (FortiBleed) </p> <p> <strong> Scope: </strong> 73,932 FortiGate administrator credentials published </p> <p> CISA's June 22 update to its Fortinet hardening directive is not routine maintenance &mdash; it reflects ongoing, confirmed exploitation of stolen credentials against government networks. The original credential dump from June 17&ndash;18 explicitly included government entities in criminal sales catalogs. Any state agency operating internet-accessible FortiGate devices that has not completed full credential rotation must assume those credentials are in adversary hands. </p> <p> <strong> Probability assessment: </strong> We assess a <strong> 75&ndash;85% probability </strong> that ransomware operators will deploy against state infrastructure within 7&ndash;14 days using these stolen credentials, targeting organizations that have not completed rotation. This estimate is based on the historical time-to-exploitation pattern following major credential dumps and the confirmed presence of government entities in the data. </p> <h3> <strong> 3. Third-Party Vendor Breach at Scale &mdash; Texas as Warning </strong> </h3> <p> <strong> Victim: </strong> Texas Parks and Wildlife Department (via unnamed vendor) </p> <p> <strong> Records exposed: </strong> 3,087,721 </p> <p> <strong> Data types: </strong> Driver's license numbers, passport numbers, email addresses, phone numbers, residential addresses </p> <p> This breach demonstrates a systemic vulnerability in state government: citizen-facing licensing and permitting systems are frequently operated by third-party vendors whose security posture the state does not directly control. The vendor remains unnamed, breach notifications contained conflicting information about SSN exposure, and no technical indicators have been published &mdash; all signs of an immature vendor incident response capability. </p> <p> <strong> Every state agency using external vendors for hunting/fishing licenses, DMV processing, professional licensing, or benefits administration carries this identical risk profile. </strong> </p> <h3> <strong> 4. Dual-RMM Phishing &mdash; Hiding in Plain Sight </strong> </h3> <p> Two parallel phishing campaigns detected on June 23 deliver legitimate remote management tools &mdash; ConnectWise ScreenConnect and MSP360 &mdash; as initial access vectors. The ConnectWise campaign uses Adobe-themed lures with a kill chain of batch file &rarr; PowerShell &rarr; MSI installer, communicating with C2 at pulsegrid365[.]site. The MSP360 campaign uses document-themed lures delivering via docum[.]info. </p> <p> <strong> The detection challenge: </strong> State agencies that legitimately use MSPs (and their associated RMM tools) cannot simply block these applications at the network level. ConnectWise and MSP360 traffic from an unauthorized installation looks identical to traffic from a legitimate one. Detection must be behavioral &mdash; <em> which user installed it, on which endpoint, at what time, and was it authorized? </em> </p> <h3> <strong> 5. Gentlemen Ransomware &mdash; EDR Is No Longer Your Safety Net </strong> </h3> <p> <strong> Actor: </strong> Gentlemen (RaaS operation) </p> <p> <strong> Tool: </strong> GentleKiller (8 variants), plus HexKiller, ThrottleBlood, HavocKiller </p> <p> <strong> Capability: </strong> Operator-maintained EDR-killing framework with rapid BYOVD weaponization </p> <p> The Gentlemen ransomware group has emerged as a top-5 most active RaaS operation in Q1 2026, distinguished by a critical capability: the operators (not affiliates) maintain a dedicated EDR-killing toolset that incorporates new Bring Your Own Vulnerable Driver (BYOVD) exploits within <em> days </em> of public proof-of-concept release. Their 90% affiliate revenue share is aggressively recruiting operators from other groups. </p> <p> <strong> Current targeting: </strong> Southeast Asia, South America, Western Europe (Thailand, Brazil, France). <strong> Not currently U.S.-focused </strong> &mdash; but the low barrier to affiliate entry and operator-provided EDR defeat tools make geographic expansion to U.S. state government a matter of when, not if. </p> <p> <strong> Probability assessment: </strong> We assess a <strong> 40&ndash;55% probability </strong> of Gentlemen affiliates targeting U.S. state/local government within 60 days, based on the group's aggressive recruitment, high affiliate share, and the historical pattern of RaaS operations expanding to U.S. government targets once they achieve operational maturity. </p> <h3> <strong> 6. ICS/SCADA Advisories &mdash; Water and Energy Infrastructure </strong> </h3> <p> CISA issued seven ICS advisories (June 18&ndash;23) affecting systems commonly deployed in state-managed critical infrastructure: </p> <ul> <li> <strong> Mitsubishi MELSEC iQ-F </strong> (2 advisories) &mdash; used in water treatment automation </li> <li> <strong> Schneider Electric Easergy, PowerLogic, Saitel </strong> &mdash; power distribution and grid monitoring </li> <li> <strong> Rockwell FactoryTalk Historian </strong> &mdash; industrial data historian used across water/energy </li> <li> <strong> AzeoTech DAQFactory </strong> &mdash; data acquisition in utility SCADA environments </li> </ul> <p> These advisories arrive in the context of confirmed Iranian targeting of U.S. water infrastructure (VOID MANTICORE, June 12) and ongoing Chinese pre-positioning concerns (Volt Typhoon). </p> <h2> <strong> Predictive Analysis </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Scenario </strong> </p> </th> <th> <p> <strong> Probability </strong> </p> </th> <th> <p> <strong> Timeframe </strong> </p> </th> <th> <p> <strong> Basis </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Ransomware deployment against state agencies via stolen Fortinet credentials </p> </td> <td> <p> 75&ndash;85% </p> </td> <td> <p> 7&ndash;14 days </p> </td> <td> <p> Historical time-to-exploitation after credential dumps; government entities confirmed in data </p> </td> </tr> <tr> <td> <p> Salt Typhoon follow-on activity with additional IOCs targeting government </p> </td> <td> <p> 70&ndash;80% </p> </td> <td> <p> 48&ndash;72 hours </p> </td> <td> <p> IOC freshness (updated Jun 23) indicates active campaign infrastructure </p> </td> </tr> <tr> <td> <p> Additional state vendor breaches in licensing/permitting systems </p> </td> <td> <p> 60&ndash;70% </p> </td> <td> <p> 30 days </p> </td> <td> <p> Texas breach demonstrates systemic vendor security gaps across states </p> </td> </tr> <tr> <td> <p> Gentlemen RaaS expansion to U.S. government targets </p> </td> <td> <p> 40&ndash;55% </p> </td> <td> <p> 60 days </p> </td> <td> <p> Aggressive affiliate recruitment; EDR-killing capability removes key defensive barrier </p> </td> </tr> <tr> <td> <p> Exploitation of unpatched ICS systems in state water/energy infrastructure </p> </td> <td> <p> 50&ndash;60% </p> </td> <td> <p> 30 days </p> </td> <td> <p> VOID MANTICORE precedent + fresh CISA ICS advisories + known scanning activity </p> </td> </tr> </tbody> </table> <h2> <strong> SOC Operational Guidance </strong> </h2> <h3> <strong> Immediate Detection Priorities </strong> </h3> <p> <strong> Hunt for Salt Typhoon SNAPPYBEE Loader: </strong> </p> <ul> <li> Search all endpoints for SHA256: 25b9fdef3061c7dfea744830774ca0e289dba7c14be85f0d4695d382763b409b </li> <li> Alert on DgApi.dll loaded from non-standard paths (T1574.001 &mdash; DLL Search Order Hijacking) </li> <li> <strong> Hunting hypothesis: </strong> If Salt Typhoon has established persistence, look for DLL sideloading in directories where legitimate applications reside but where DgApi.dll is not a standard component </li> </ul> <p> <strong> Block RMM Phishing Infrastructure: </strong> </p> <ul> <li> Block at DNS/proxy: pulsegrid365[.]site, zonedocshring[.]it[.]com, docum[.]info, hokkien[.]org[.]my </li> <li> Alert on file hashes: </li> <ul> <li> MD5 cbb11db5f8fed9168ed620ecc4fed3b0 (malicious batch installer) </li> <li> MD5 f862f698aeb77f05795f1ade8722d0ce (PowerShell loader) </li> <li> MD5 87174fdc992ba9b5186de223703754cd (ScreenConnect MSI) </li> <li> MD5 386529af136fe96a23da6aaa39711e2b (MSP360 RMM installer) </li> </ul> <li> Monitor for Telegram bot communications: bot6724358070:AAHKifpAmQc04JM0HtznvefY-CqavBsKwWU (T1071 &mdash; Application Layer Protocol) </li> </ul> <p> <strong> Fortinet Credential Abuse Detection: </strong> </p> <ul> <li> Monitor FortiGate authentication logs for logins from unusual source IPs or at unusual times (T1078 &mdash; Valid Accounts) </li> <li> Alert on new VPN sessions from geographic locations inconsistent with your workforce (T1133 &mdash; External Remote Services) </li> <li> Hunt for configuration changes on FortiGate devices made outside change windows </li> </ul> <h3> <strong> ATT&amp;CK-Mapped Detection Matrix </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Technique </strong> </p> </th> <th> <p> <strong> ID </strong> </p> </th> <th> <p> <strong> What to Monitor </strong> </p> </th> <th> <p> <strong> Tool/Log Source </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> DLL Search Order Hijacking </p> </td> <td> <p> T1574.001 </p> </td> <td> <p> DgApi.dll in non-standard paths </p> </td> <td> <p> EDR (Sysmon Event 7) </p> </td> </tr> <tr> <td> <p> Valid Accounts </p> </td> <td> <p> T1078 </p> </td> <td> <p> Anomalous FortiGate/VPN logins </p> </td> <td> <p> FortiGate logs, SIEM </p> </td> </tr> <tr> <td> <p> External Remote Services </p> </td> <td> <p> T1133 </p> </td> <td> <p> New VPN sessions, geo-impossible travel </p> </td> <td> <p> VPN logs, UEBA </p> </td> </tr> <tr> <td> <p> Remote Access Software </p> </td> <td> <p> T1219 </p> </td> <td> <p> Unauthorized RMM installations </p> </td> <td> <p> EDR, software inventory </p> </td> </tr> <tr> <td> <p> Phishing: Spearphishing Link </p> </td> <td> <p> T1566.002 </p> </td> <td> <p> Adobe/document-themed emails with R2.dev URLs </p> </td> <td> <p> Email gateway </p> </td> </tr> <tr> <td> <p> PowerShell Execution </p> </td> <td> <p> T1059.001 </p> </td> <td> <p> sc_hidden_install.ps1 or similar hidden install scripts </p> </td> <td> <p> Script block logging </p> </td> </tr> <tr> <td> <p> Impair Defenses </p> </td> <td> <p> T1562.001 </p> </td> <td> <p> EDR service stops, driver loads from temp paths </p> </td> <td> <p> EDR tamper protection alerts </p> </td> </tr> <tr> <td> <p> Exploitation for Privilege Escalation </p> </td> <td> <p> T1068 </p> </td> <td> <p> Unsigned/revoked driver loads (BYOVD) </p> </td> <td> <p> Driver load monitoring </p> </td> </tr> <tr> <td> <p> Data Encrypted for Impact </p> </td> <td> <p> T1486 </p> </td> <td> <p> Mass file modification, encryption artifacts </p> </td> <td> <p> EDR, file integrity monitoring </p> </td> </tr> </tbody> </table> <h3> <strong> Hunting Hypotheses </strong> </h3> <ol> <li> <strong> "Has Salt Typhoon already established persistence?" </strong> &mdash; Search for any DLL sideloading activity in the past 30 days where the loaded DLL was not part of the original application package. Focus on government workstations with access to sensitive data or telecom-adjacent systems. </li> <li> <strong> "Are stolen Fortinet credentials being used against us?" </strong> &mdash; Correlate FortiGate successful authentications against the known credential dump timeline (Jun 17+). Any new VPN session established after Jun 17 from an IP not previously seen in your environment warrants investigation. </li> <li> <strong> "Do we have unauthorized RMM tools in our environment?" </strong> &mdash; Run a full software inventory scan for ConnectWise ScreenConnect, MSP360, AnyDesk, TeamViewer, and MeshCentral installations. Compare against your authorized RMM allowlist. Any discrepancy is a potential compromise indicator. </li> <li> <strong> "Is our EDR resilient to kernel-level attacks?" </strong> &mdash; Review EDR tamper protection logs for the past 14 days. Any alerts about service interruption, driver load failures, or protection downgrades should be treated as potential GentleKiller-style reconnaissance. </li> </ol> <h2> <strong> Sector-Specific Defensive Priorities </strong> </h2> <h3> <strong> Financial Services (State Treasury, Revenue, Tax Systems) </strong> </h3> <ul> <li> <strong> Primary threat: </strong> Credential theft via Fortinet exploitation leading to access to financial transaction systems </li> <li> <strong> Action: </strong> Ensure all state financial systems behind FortiGate devices have completed credential rotation. Implement transaction anomaly detection for any financial system accessed via VPN in the past 7 days. </li> <li> <strong> Vendor risk: </strong> Review any third-party payment processors or tax filing vendors for security posture &mdash; the Texas breach pattern applies to financial data vendors equally. </li> </ul> <h3> <strong> Energy (State-Managed Utilities, Grid Oversight) </strong> </h3> <ul> <li> <strong> Primary threat: </strong> ICS exploitation via Schneider Electric Easergy/PowerLogic/Saitel vulnerabilities; Iranian actor precedent (VOID MANTICORE) </li> <li> <strong> Action: </strong> Prioritize patching Schneider Electric systems per CISA advisories. Verify network segmentation between IT and OT environments. Confirm that no ICS/SCADA systems are reachable from FortiGate VPN segments with potentially compromised credentials. </li> <li> <strong> Monitoring: </strong> Alert on any IT-to-OT lateral movement attempts, particularly from VPN-connected sessions. </li> </ul> <h3> <strong> Healthcare (State Health Agencies, Medicaid Systems) </strong> </h3> <ul> <li> <strong> Primary threat: </strong> Ransomware via stolen Fortinet credentials targeting systems containing protected health information (PHI) </li> <li> <strong> Action: </strong> Validate backup integrity for all Medicaid and health information exchange systems. Ensure offline/immutable backups exist and have been tested within the past 30 days. </li> <li> <strong> Vendor risk: </strong> Health IT vendors processing PHI face the same third-party breach risk demonstrated in Texas. Confirm BAA breach notification SLAs are &le;72 hours. </li> </ul> <h3> <strong> Government (Executive Branch Agencies, Citizen Services) </strong> </h3> <ul> <li> <strong> Primary threat: </strong> Multi-vector &mdash; Salt Typhoon espionage, ransomware via Fortinet credentials, vendor breaches exposing citizen PII </li> <li> <strong> Action: </strong> Immediate Fortinet credential rotation verification. Conduct emergency vendor security review for all citizen-facing licensing/permitting systems. Deploy Salt Typhoon IOCs across all agency endpoints. </li> <li> <strong> Identity: </strong> Implement conditional access policies requiring MFA for all VPN and remote access &mdash; even for accounts with valid credentials. </li> </ul> <h3> <strong> Aviation / Logistics (State DOT, Port Authorities, Transit) </strong> </h3> <ul> <li> <strong> Primary threat: </strong> Salt Typhoon targeting transportation sector; ICS vulnerabilities in traffic management and transit SCADA </li> <li> <strong> Action: </strong> Hunt for SNAPPYBEE indicators on transportation management systems. Review Rockwell FactoryTalk Historian deployments in transit/traffic infrastructure for patch status. </li> <li> <strong> Monitoring: </strong> Alert on unusual data exfiltration patterns from transportation planning systems &mdash; Salt Typhoon's intelligence collection objectives include infrastructure mapping. </li> </ul> <h2> <strong> Prioritized Defense Recommendations </strong> </h2> <h3> <strong> IMMEDIATE (Within 24 Hours) </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Owner </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 1 </p> </td> <td> <p> IT Operations </p> </td> <td> <p> <strong> Confirm Fortinet credential rotation is COMPLETE </strong> on all FortiGate devices per CISA June 22 guidance. Any device not rotated must be assumed compromised. Report compliance to CISO by end of day. </p> </td> </tr> <tr> <td> <p> 2 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Deploy Salt Typhoon IOC </strong> (SHA256: 25b9fdef...b409b / DgApi.dll) to all EDR platforms. Hunt retroactively for 30 days. Alert on DLL sideloading from non-standard paths. </p> </td> </tr> <tr> <td> <p> 3 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Block phishing infrastructure </strong> at DNS and web proxy: pulsegrid365[.]site, zonedocshring[.]it[.]com, docum[.]info, hokkien[.]org[.]my. Deploy file hash alerts for all four MD5 indicators listed above. </p> </td> </tr> <tr> <td> <p> 4 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Verify no internet-exposed FortiGate management interfaces </strong> remain accessible. Scan external attack surface for TCP/443 and TCP/8443 on FortiGate devices. </p> </td> </tr> </tbody> </table> <h3> <strong> 7-DAY Actions </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Owner </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 5 </p> </td> <td> <p> IT Operations </p> </td> <td> <p> <strong> Audit all RMM tools </strong> across state agencies. Create a definitive allowlist of authorized remote management software. Configure EDR to alert on any RMM installation not on the allowlist (ConnectWise, MSP360, AnyDesk, TeamViewer, MeshCentral). </p> </td> </tr> <tr> <td> <p> 6 </p> </td> <td> <p> CISO / Procurement </p> </td> <td> <p> <strong> Initiate emergency vendor security review </strong> for all third-party vendors operating citizen-facing licensing, permitting, and benefits systems. Confirm breach notification SLAs, data minimization practices, and encryption-at-rest requirements. </p> </td> </tr> <tr> <td> <p> 7 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Deploy BYOVD detection rules </strong> &mdash; monitor for unsigned or revoked driver loads, known vulnerable driver hashes, and EDR service interruptions. The Gentlemen RaaS group weaponizes new BYOVD exploits within days of public PoC release. </p> </td> </tr> <tr> <td> <p> 8 </p> </td> <td> <p> IT Operations </p> </td> <td> <p> <strong> Implement conditional access policies </strong> requiring hardware MFA token or FIDO2 for all VPN and remote access sessions &mdash; even for accounts with valid passwords. This neutralizes stolen credential value. </p> </td> </tr> </tbody> </table> <h3> <strong> 30-DAY Actions </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Owner </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 9 </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Commission purple team exercise </strong> simulating GentleKiller-style EDR defeat (certificate impersonation + BYOVD + EDR process termination). Validate that compensating controls (network detection, identity anomalies, immutable backups) function when EDR is disabled. </p> </td> </tr> <tr> <td> <p> 10 </p> </td> <td> <p> OT/ICS Team </p> </td> <td> <p> <strong> Patch ICS systems </strong> per CISA advisories: Mitsubishi MELSEC iQ-F, Schneider Electric PowerChute/Easergy/Saitel, Rockwell FactoryTalk Historian, AzeoTech DAQFactory. Coordinate maintenance windows with operations. </p> </td> </tr> <tr> <td> <p> 11 </p> </td> <td> <p> CISO / Legal </p> </td> <td> <p> <strong> Review and update incident response plans </strong> for third-party vendor breach scenarios. Ensure plans address conflicting vendor notifications, citizen notification timelines, and credit monitoring activation &mdash; all issues demonstrated in the Texas breach. </p> </td> </tr> <tr> <td> <p> 12 </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Establish vendor security scoring program </strong> with continuous monitoring for all vendors handling &gt;100,000 citizen records. Require annual penetration testing evidence and real-time breach notification capabilities. </p> </td> </tr> </tbody> </table> <h3> <strong> Executive / IR Preparedness </strong> </h3> <ul> <li> <strong> Tabletop exercise recommendation: </strong> Within 14 days, conduct a ransomware tabletop exercise using the specific scenario of "Fortinet credential compromise &rarr; lateral movement &rarr; EDR disabled via BYOVD &rarr; ransomware deployment." This is not hypothetical &mdash; every component of this kill chain is confirmed active. </li> <li> <strong> Board communication: </strong> The Texas vendor breach and Fortinet credential exposure together represent material cyber risk to citizen data and state operations. Prepare a board-level briefing on third-party vendor risk posture and credential exposure remediation status. </li> </ul> <h2> <strong> IOC Blocking Table </strong> </h2> <p> The following indicators are confirmed from intelligence collection and should be deployed to defensive systems immediately: </p> <table> <thead> <tr> <th> <p> <strong> Type </strong> </p> </th> <th> <p> <strong> Value </strong> </p> </th> <th> <p> <strong> Context </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Domain </p> </td> <td> <p> pulsegrid365[.]site </p> </td> <td> <p> ConnectWise ScreenConnect C2 </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> zonedocshring[.]it[.]com </p> </td> <td> <p> Phishing delivery infrastructure </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> docum[.]info </p> </td> <td> <p> MSP360 RMM phishing delivery </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> hokkien[.]org[.]my </p> </td> <td> <p> Phishing staging (compromised site) </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> 25b9fdef3061c7dfea744830774ca0e289dba7c14be85f0d4695d382763b409b </p> </td> <td> <p> Salt Typhoon SNAPPYBEE loader </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> cbb11db5f8fed9168ed620ecc4fed3b0 </p> </td> <td> <p> Malicious Adobe_Installer.bat </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> f862f698aeb77f05795f1ade8722d0ce </p> </td> <td> <p> PowerShell loader (sc_hidden_install.ps1) </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> 87174fdc992ba9b5186de223703754cd </p> </td> <td> <p> Weaponized ScreenConnect MSI </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> 386529af136fe96a23da6aaa39711e2b </p> </td> <td> <p> Weaponized MSP360 RMM installer </p> </td> </tr> </tbody> </table> <p> Additional IOCs for the campaigns discussed in this report are available through Anomali ThreatStream Next-Gen and partner feeds. </p> <h2> <strong> Bottom Line </strong> </h2> <p> The threat environment facing state government has not escalated to CRITICAL today &mdash; but the margin is thin. Three conditions would trigger that escalation: confirmed ransomware deployment against a state agency using Fortinet credentials, Salt Typhoon lateral movement detected in a government network, or a second state vendor breach of comparable scale. </p> <p> Two of those three conditions have confirmed precursors already in motion. </p> <p> The actions in this report are not aspirational security improvements &mdash; they are responses to confirmed, active threats with known timelines. Fortinet credential rotation that isn't complete today is a breach waiting to happen. Vendor security reviews that wait for the next budget cycle are accepting the Texas outcome as your own. EDR that hasn't been tested against kernel-level attacks is providing false confidence. </p> <p> The adversaries targeting state government &mdash; Salt Typhoon, UNC5435, VOID MANTICORE, and an expanding ransomware ecosystem &mdash; are operating on timelines measured in days, not quarters. Your defensive response must match that tempo. </p> <p> <em> Anomali CTI Desk &mdash; June 23, 2026 </em> </p> <p> <em> For questions or additional context on any finding in this report, contact your Anomali intelligence team. </em> </p>

FEATURED RESOURCES

July 24, 2026
Anomali Cyber Watch

Iranian Cyber Retaliation Is No Longer Theoretical — It's Happening Now

Read More
December 24, 2025
Anomali Cyber Watch

Anomali Cyber Watch: Sample

LockBit 5.0 Ransomware Targets Windows, Linux, and VMware ESXi in Active Campaigns. Google Patches Actively Exploited Chrome Zero-Day CVE-2026-2441. Infostealer Targets OpenClaw Configuration Files to Capture Credentials and User Context. And more...
Read More
July 14, 2026
Anomali Cyber Watch

The Silence Before the Storm: Iranian Cyber Retaliation Is Imminent — What CISOs Must Do Now

Read More
Explore All