TLP:GREEN  ·  States / Public Sector
Chinese State Hackers Are Stealing Government Records:

Through Your Network Switches - And Your Backup Infrastructure Is Next

ELEVATED. Increased from prior cycle. A Chinese-speaking threat actor has compromised nearly 1,000 network switches across 48 countries and is actively exfiltrating US government records. A trivially exploitable privilege escalation vulnerability in Veeam backup software now has a public proof-of-concept, threatening the infrastructure agencies depend on for ransomware recovery. And LockBit 5.0 has resurfaced with fresh breach claims after a period of relative quiet.

I am a
My sector

DevelopmentWhy It Matters for State Government
CVE-2026-7273 added to CISA...Chinese-nexus actor mass-exploiting Zyxel GS1900...
CVE-2026-32996 public...Trivial local privilege escalation to SYSTEM on...
LockBit 5.0 breach claims resume...First fresh LockBit signal in several cycles...
TASK#STOMP backdoor campaign...Sophisticated, unattributed Windows backdoor...
CVE-2026-90817 — REDCap...Any state health department or university partner...
WordPress Click2Shell...Same Chinese-nexus actor exploiting Zyxel...
7 ICS advisories published by...Schneider Electric Modicon M340, Hitachi Energy...
DPRK TraderTraitor (Lazarus...Weaponized Terraform files delivering FLATROOF...
Software supply chain threats...Malware embedded in runtime application code...
BigDiskBuster Defender bypass...Proof-of-concept silently blocks Windows Defender...

DateEventSeverity
August 2026Chinese-nexus actor begins mass exploitation of...🔴 Critical
14 Sep 2026Public proof-of-concept released for...🟠 High
17 Sep 2026CISA publishes 7 ICS advisories affecting...🟡 Moderate
18 Sep 2026CISA adds three Linux kernel CVEs to KEV catalog...🟠 High
21 Sep 2026CISA adds CVE-2026-7273 (Zyxel GS1900) to KEV...🔴 Critical
21 Sep 2026LockBit 5.0 claims breach of Siinqee Bank; 11...🟠 High
21 Sep 2026BigDiskBuster proof-of-concept documented —...🟠 High
22 Sep 2026Securonix publishes TASK#STOMP analysis —...🟡 Moderate
22 Sep 2026Detailed technical analyses of CVE-2026-32996...🟠 High
22 Sep 2026WordPress patches Click2Shell vulnerability...🟡 Moderate

A Chinese-speaking actor exploited a stack-based buffer overflow in Zyxel GS1900-48HPv2 switches (firmware under 2.90) to compromise ~996 devices across 48 countries. The US is among the top five affected nations, with confirmed exfiltration of government records. No authentication required - a crafted HTTP request to the management interface...

T1190T1059T1041

A low-privileged local user reads an elevated session GUID from a plaintext log file, then replays it over a named pipe to execute commands as NT AUTHORITY\SYSTEM - no special tools required, and the PoC is public. Most state agencies contract MSPs for backup management, and those MSPs almost certainly deploy Veeam Agent - a compromised...

T1134T1059

LockBit 5.0 resurfaced with 11 claimed breaches across financial, government, energy, entertainment, retail, and technology sectors - government remains an explicitly named target industry across 115 countries.

TASK#STOMP is a purpose-built document-theft backdoor targeting Word, PDF, Excel, and...

T1486T1490T1059.001T1070.006

CVE-2026-90817 (CVSS 9.8): unauthenticated RCE in REDCap, widely used by state health departments and universities for research data collection. No patch is currently available - any entity running an affected version with public survey access faces critical risk.

BigDiskBuster: a public PoC silently...

T1562.001

DPRK's TraderTraitor group weaponizes Terraform lock files in fake job-interview GitHub repos, delivering FLATROOF and ROOFDECK macOS backdoors - a supply chain threat to state IT developer staff. The npm indexed-btree campaign embeds malware in runtime code rather than install-time scripts, defeating traditional scanning. Volt Typhoon and Salt...

T1566.003T1204.002T1195.002

ScenarioProbabilityBasis
CVE-2026-7273 (Zyxel) exploitation expands to...HIGH (>70%)Active campaign, trivial exploit, 996 devices...
CVE-2026-32996 (Veeam) sees in-the-wild...MODERATE-HIGH (50-65%)Public PoC, trivial exploitation, ransomware...
LockBit 5.0 claims a US state or local government...MODERATE (40-60%)Resumed operational tempo, government as named...
TASK#STOMP or similar document-theft backdoor is...MODERATE (35-50%)Sophisticated evasion techniques make detection...
CVE-2026-90817 (REDCap) is exploited against a US...MODERATE (40-55%)CVSS 9.8, unauthenticated, no patch available...
Additional Chinese-nexus exploitation of network...MODERATE (40-55%)Three active network device exploitation...

Priority 1 — Zyxel GS1900 Exploitation (CVE-2026-7273):

Hunt Hypothesis: Compromised...

Priority 2 — Veeam Agent Exploitation Indicators (CVE-2026-32996):

Hunt Hypothesis: An attacker...

Priority 3 — TASK#STOMP Indicators:

Block immediately at DNS/proxy:...

Priority 4 — LockBit 5.0 / Ransomware Precursors:

Hunt Hypothesis: Ransomware...

Priority 5 — Defender Signature Integrity:

Continuing from prior cycle: The...

ThreatATT&CK
Priority 1 — Zyxel GS1900 Exploitation...T1190 T1059...
Priority 2 — Veeam Agent Exploitation Indicators...T1134 T1059...
Priority 3 — TASK#STOMP IndicatorsT1059.001 T1059.005...
Priority 4 — LockBit 5.0 / Ransomware PrecursorsT1003 T1021...
IOC Blocking Table:
corecloudfileshare[.]xyzattachmentsharingdrive[.]xyz82.192.72[.]4103.102.31[.]18202.144.192[.]149

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01
Priority 1 — Zyxel GS1900 Exploitation (CVE-2026-7273)
Compromised Zyxel switches may be exfiltrating data or serving as pivot points into agency LANs. Look for anomalous outbound traffic from switch management IPs, unexpected DNS queries from network device subnets, and HTTP POST requests to external IPs from switch management interfaces.
HUNT 02
Priority 2 — Veeam Agent Exploitation Indicators (CVE-2026-32996)
An attacker with low-privilege access may attempt to read Veeam session GUIDs and replay them for SYSTEM access. Monitor for:
HUNT 03
Priority 3 — TASK#STOMP Indicators
TASK#STOMP uses legitimate Windows binaries for execution. Look for:
HUNT 04
Priority 4 — LockBit 5.0 / Ransomware Precursors
Ransomware operators typically establish access days or weeks before encryption. Look for:

Financial Services
Treasury, Revenue, Benefits
Primary threat
LockBit 5.0's confirmed financial institution breach is a direct warning; treasury and benefits...
Actions
  • Verify backup infrastructure is patched against CVE-2026-32996; validate offline backup restoration
Energy
SCADA, OT Network Devices
Primary threats
7 ICS advisories affect Schneider, Hitachi, and ABB equipment; the Zyxel campaign proves network...
Actions
  • Cross-reference ICS advisories against OT inventory; verify OT network switches are patched
Healthcare
REDCap, Research Data
Primary threat
CVE-2026-90817 is the most urgent sector-specific threat given REDCap's widespread use for...
Actions
  • Determine REDCap version in use; restrict public survey access immediately if vulnerable
Government
Field Offices, DMV Branches
Primary threats
At the intersection of every threat this cycle: nation-state targeting, ransomware, document theft...
Actions
  • Emergency audit Zyxel switches across all agency locations; coordinate MSP Veeam patching confirmation
Aviation / Logistics
Transportation OT
Primary threat
Mitsubishi GX Works3 and Bransys ELD advisories directly relevant to transportation infrastructure.
Actions
  • Review ICS advisories against transportation OT inventories; verify segmentation from general agency networks
No sector cards match the selected filters.

Audit all Zyxel GS1900 switches statewide; patch above...
Incident Responder
Identify all Veeam Agent deployments at version 13.0.1.2067 or...
Incident Responder
Block TASK#STOMP C2 domains at DNS/proxy; deploy EDR alerts...
SOC Analyst
Confirm REDCap version in use; restrict public survey access...
Incident Responder
No immediate actions for the selected roles.
Update all state WordPress installations for Click2Shell...
Incident Responder
Review the 7 CISA ICS advisories against OT/SCADA asset...
ICS / OT
Verify Linux kernel patching for the three current KEV-listed...
Incident Responder
Request MSP written confirmation that Veeam and ScreenConnect...
CISO / Exec
No 7-day actions for the selected roles.
Complete a statewide network device inventory - three active...
CISO / Exec
Implement runtime behavior analysis in CI/CD pipelines given...
CISO / Exec
Evaluate an MSP Attack Surface monitoring program given...
CISO / Exec
Escalate OSINT collection procurement given the reduced...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The threats documented in this report are not speculative. A Chinese-nexus actor is actively stealing government records through network switches that may be deployed in your branch offices right now. A public exploit for your backup infrastructure is circulating. LockBit 5.0 is back and listing government as a target. A CVSS 9.8 vulnerability in a platform used by state health departments has no patch. The two decisions that cannot wait: authorize emergency Zyxel patching or isolation across...

1
Authorize emergency Zyxel patching or isolation today.
2
Coordinate immediate Veeam Agent upgrades with your MSPs.
3
Confirm REDCap patch status if your agency runs it.
No items found.