TLP:GREEN  ·  States / Public Sector
Critical RMM Supply Chain Exploitation Hits State and Local Government:

What IT Leaders Must Do Now

ELEVATED. Sustained from prior cycle. A critical authentication bypass in N-able N-central — the RMM platform used by thousands of MSPs serving government clients — is being actively exploited against state and local government environments, with a mandatory federal patch deadline of August 6. Simultaneously, a self-propagating npm worm called "ChainDrop" is racing through the software supply chain, water/wastewater infrastructure remains under sustained targeting pressure, and a specialized extortion group is actively hunting organizations with limited cybersecurity maturity — a profile that uncomfortably matches many state agencies.

I am a
My sector

DateDevelopmentImpact
Pre-July 14 → PresentINC Ransomware (UTA0533) actively exploiting SonicWall SMA1000 (CVE-2026-15409/15410) against U.S. government targetsRansomware-aligned actors maintaining persistent access via VPN appliance exploitation
July 25, 2026DHS discloses Salt Typhoon and Volt Typhoon persistent access in state agency and National Guard networksConfirmed nation-state pre-positioning; no remediation reported
July 30, 2026CISA issues renewed water/wastewater PLC targeting alert; Schneider Electric IGSS SCADA advisory publishedExpanded critical infrastructure threat surface
August 1, 2026CVE-2026-18577 exploitation confirmed in the wild against MSP environmentsRMM supply chain compromise active
August 2, 2026APT29 "CaptiveCrunch" campaign stealing M365 credentials via compromised hotel Wi-Fi; Kali365 device-code OAuth token theft campaign active against government M365 usersRussian intelligence credential harvesting and OAuth token theft both active
August 3, 2026CISA adds CVE-2026-18577 to KEV catalog; 55%+ of N-central cloud servers remain unpatched; Silent Ransom Group (Luna Moth) confirmed actively targeting organizations with limited security maturityFederal patch mandate issued; majority of servers still exposed; encryption-free extortion threat active
August 4, 2026ChainDrop npm worm actively spreading — 56+ packages compromised within a single hourSoftware supply chain under active attack

TimeframeActor / CampaignTargetStatus
Pre-July 14 → PresentINC Ransomware (UTA0533)U.S. government via SonicWall SMA1000 (CVE-2026-15409/15410)Active exploitation
July 25 → PresentSalt Typhoon / Volt Typhoon (Chinese MSS)State agency & National Guard networksPersistent pre-positioning confirmed
August 1 → PresentUnknown actors (ransomware-aligned)State/local gov via N-able N-central MSPsActive exploitation, 9+ orgs compromised
August 2 → PresentAPT29 / Midnight Blizzard (Russian SVR)Government travelers via hotel Wi-FiActive credential harvesting
August 3 → PresentBANISHED KITTEN (IRGC-affiliated)Water/wastewater PLCs across 7+ U.S. statesActive, confirmed physical consequences
August 4 → PresentChainDrop (unattributed)npm ecosystem / CI/CD pipelinesActive worm propagation
ActiveSilent Ransom Group (Luna Moth)Orgs with limited security maturityCallback phishing → data extortion
ActiveKali365 (unattributed)Government M365 users via device-code phishingOAuth token theft

CVE-2026-18577 is an incomplete patch for an earlier vulnerability (CVE-2026-18556) in N-able N-central, a remote monitoring and management platform widely used by MSPs that serve state and local government. Attackers are exploiting this flaw to bypass authentication entirely, gain administrative console access, and then pivot to every endpoint managed by that N-central instance using the built-in "Take Control" remote access feature.

Why it matters for state government: If your agency — or any MSP partner serving your agency — runs N-central, a single compromised console grants attackers administrative remote access to potentially thousands of state endpoints. Huntress has confirmed compromises across at least 9 organizations under a single partner account. Attackers are deploying Cloudflare tunnels for persistent backdoor access and dropping malicious executables disguised as system processes.

Scale of exposure: Over 55% of N-central cloud servers remained unpatched days after the hotfix was released. The CISA KEV deadline for federal agencies is August 6, 2026.

T1078T1021T1090T1133T1569

A self-propagating worm is spreading through the npm package ecosystem by stealing maintainer authentication tokens and publishing compromised versions of legitimate packages. Dozens of packages were poisoned within a single hour, including widely-used caching libraries (cache-manager, cacheable, flat-cache, file-entry-cache) and packages under organizational scopes. The worm uses obfuscated preinstall scripts to download a Bun runtime and harvest CI/CD credentials, with command-and-control communications routed through Ethereum blockchain dead-drop infrastructure.

Why it matters for state government: Any state agency building citizen-facing web applications, portals, or internal tools on Node.js/npm stacks may have transitive dependencies on compromised packages. A single poisoned dependency deep in the dependency tree can expose CI/CD pipeline credentials, enabling further supply chain attacks against your production systems.

T1195.002T1059.007T1552.001T1102.001

CISA issued a renewed alert on July 30 documenting a "significant increase" in threat actors targeting programmable logic controllers (PLCs) in water and wastewater systems. This follows confirmed attacks attributed to Iran-linked actors (assessed BANISHED KITTEN alignment) that expanded from Minnesota to 7+ U.S. states by August 3, with confirmed physical consequences including manipulation of water treatment parameters.

Why it matters for state government: State agencies with oversight responsibility for municipal water systems, or those operating their own water/wastewater treatment facilities, face direct risk. Additionally, a new Schneider Electric IGSS SCADA vulnerability (advisory ICSA-26-211-04) affects systems commonly deployed in water treatment and building management — both relevant to state operations.

Silent Ransom Group (also known as Luna Moth), a Conti ransomware successor, has refined a data extortion model that deliberately avoids deploying ransomware. They use callback phishing — sending emails with fake IT support numbers — to trick employees into installing legitimate remote access tools (AnyDesk, Zoho Assist, Atera). Once inside, they exfiltrate sensitive data via WinSCP or Rclone and demand payment to prevent publication. They operate a botnet across 18 countries with Fast Flux DNS for resilience.

Why it matters for state government: SRG explicitly targets organizations with "limited cybersecurity maturity and regulatory pressure" — a description that matches many state agencies operating under tight budgets with significant compliance obligations. Because they never deploy ransomware, traditional ransomware detection (file encryption behavior, ransom notes) will not trigger. The first indication of compromise may be the extortion demand itself.

T1566.003T1219T1567T1048T1568.001

Chinese MSS-affiliated groups Salt Typhoon and Volt Typhoon maintain confirmed persistent access in state agency and National Guard networks per the July 25 DHS disclosure. No remediation has been publicly reported. APT29 (Russian SVR) launched the "CaptiveCrunch" campaign on August 2, stealing Microsoft 365 credentials from government travelers via compromised hotel Wi-Fi captive portals. The Kali365 campaign continues exploiting Microsoft's device-code authentication flow to steal OAuth tokens from government employees — a technique that bypasses traditional phishing detection because victims authenticate on Microsoft's legitimate login page.

T1528T1078.004

ScenarioProbabilityBasis
Additional N-central exploitation with ransomware deployment as follow-on75% (HIGH)55%+ servers unpatched; confirmed active exploitation; ransomware operators historically monetize RMM access within days
ChainDrop worm scope expands; additional compromised packages discovered affecting state dev pipelines50% (MODERATE)Worm is self-propagating; state agencies likely have transitive dependencies on affected packages
Silent Ransom Group or similar extortion actor targets a state/local government entity via callback phishing40% (MODERATE)Explicit targeting of orgs with limited maturity + regulatory pressure; state gov matches this profile
Volt Typhoon / Salt Typhoon activity surfaces in state network telemetry20% (LOW)Pre-positioning designed to remain silent; detection would require proactive hunting, not passive alerting
Iran-linked PLC manipulation expands to additional states or causes service disruption35% (MODERATE)Campaign already expanded from 1 to 7+ states; CISA alert confirms "significant increase" in targeting

Hypothesis 1: N-central compromise via CVE-2026-18577:

What to look for: Windows service named "Cloudflared" on any endpoint; svchost.exe present in user Documents folders (not System32); anomalous Take Control sessions from the mspsupport@n-able.com account; connections to Synology/QuickConnect dynamic DNS domains Detection logic: Query EDR for process creation events where svchost.exe parent path is NOT C:\Windows\System32\; alert on new Windows service installations matching "Cloudflared"; monitor DNS for .synology.me and .quickconnect.to resolutions Log sources: N-central BASupSrvc logs (C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz), Windows System event log (service installations), firewall/proxy logs

Hypothesis 2: ChainDrop npm supply chain compromise:

What to look for: Unexpected preinstall script execution in CI/CD pipelines; Bun runtime downloads on build servers; outbound connections from CI/CD runners to Ethereum RPC endpoints; modified lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml) with unexpected version bumps Detection logic: Monitor build systems for unexpected binary downloads (Bun runtime); alert on CI/CD secret access patterns outside normal deployment windows; diff lockfiles against known-good baselines

Hypothesis 3: Silent Ransom Group callback phishing:

What to look for: Installation of AnyDesk, Zoho Assist, or Atera on endpoints where these tools are not sanctioned; large outbound file transfers via WinSCP or Rclone; employees reporting calls from "IT support" they didn't initiate Detection logic: Application allowlisting alerts for unauthorized RAT installations; NetFlow analysis for large (>500MB) outbound transfers to cloud storage or unfamiliar endpoints; DNS analytics for Fast Flux patterns (high TTL variance, many IPs per domain)

Hypothesis 4: Kali365 device-code token theft:

What to look for: Azure AD sign-in logs showing device-code authentication from unexpected locations or for user accounts (not service accounts/kiosks); OAuth token grants without corresponding interactive sign-in; Conditional Access policy gaps for device-code flow Detection logic: Azure AD sign-in logs filtered for authenticationProtocol = deviceCode where user is not in approved device-code user group; alert on device-code authentications from non-corporate IP ranges

ThreatATT&CK
Hypothesis 1: N-central compromise via CVE-2026-18577T1078 T1021 T1090 T1133 T1569
Hypothesis 2: ChainDrop npm supply chain compromiseT1195.002 T1059.007 T1552.001 T1102.001
Hypothesis 3: Silent Ransom Group callback phishingT1566.003 T1219 T1567 T1048 T1568.001
Hypothesis 4: Kali365 device-code token theftT1528 T1078.004
IOC Blocking Table:
173.249.252[.]20087.249.138[.]3437.19.210[.]3268.235.46[.]21437.153.90[.]8892.118.112[.]181mousears.synology[.]mewagoosh.direct.quickconnect[.]towho-ripped-one.direct.quickconnect[.]to

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:

Financial Services
State Treasury, Revenue, Benefits Systems
Primary threat
Silent Ransom Group targets organizations handling sensitive financial data under regulatory pressure. State revenue and benefits systems hold millions of tax records and payment information — prime extortion targets
Secondary threat
Kali365 device-code phishing could grant persistent M365 access to financial communications and documents
Actions
  • Implement application allowlisting on systems processing financial data to prevent unauthorized RAT installation (AnyDesk, Zoho Assist, Atera)
  • Monitor for bulk data access patterns on tax/benefits databases that deviate from normal business hours or volume
  • Restrict device-code authentication flow via Conditional Access
Energy
State Facilities, Building Management, Utility Oversight
Primary threats
Schneider Electric IGSS SCADA vulnerability (ICSA-26-211-04) directly affects building management and utility systems. State-operated facilities using IGSS for HVAC, power management, or water treatment are exposed
Secondary threat
Volt Typhoon pre-positioning in state networks may include energy management systems as targets for disruption during a geopolitical crisis
Actions
  • Inventory all Schneider IGSS installations across state facilities
  • Apply vendor patches per advisory
  • Validate network segmentation between IT and OT/BMS networks — no direct internet exposure for any SCADA/BMS system
Healthcare
State Health Agencies, Medicaid Systems, Public Health
Primary threat
N-central RMM exploitation (CVE-2026-18577) is particularly dangerous for health agencies that rely on MSPs for endpoint management of distributed clinic and field office systems. A single compromised MSP console could expose patient health information across hundreds of locations
Secondary threat
Silent Ransom Group's data extortion model is devastating for healthcare — stolen PHI creates both regulatory liability and patient safety concerns even without system encryption
Actions
  • Immediately confirm with all MSP partners whether they use N-central and verify patch status
  • If unpatched, demand emergency remediation or disconnect managed endpoints from the platform
  • Review BAA obligations — an MSP compromise may trigger HIPAA breach notification requirements
Government
Executive Agencies, Public Safety, Elections
Primary threats
The convergence of N-central supply chain compromise, nation-state pre-positioning (Salt Typhoon/Volt Typhoon), and credential theft campaigns (APT29 CaptiveCrunch, Kali365) creates a multi-vector threat to core government operations
Actions
  • Conduct emergency inventory of all RMM tools in use across agencies — not just N-central but any remote management platform
  • Implement network-level monitoring for Cloudflare tunnel traffic (cloudflared service) which attackers are using for persistent access
  • Brief all agency security liaisons on the callback phishing threat
  • With election infrastructure preparation underway, validate that no election management systems are accessible via MSP remote management tools
Aviation / Logistics
State DOT, Fleet Management, Airport Authorities
Primary threats
ChainDrop npm worm threatens any web-based logistics, scheduling, or fleet management applications built on Node.js stacks. State DOT systems managing traffic infrastructure, permitting portals, or fleet tracking may have vulnerable dependencies
Secondary threat
SonicWall SMA1000 exploitation (CVE-2026-15409/15410) by INC Ransomware may affect remote access infrastructure at distributed DOT field offices and maintenance facilities
Actions
  • Audit all Node.js applications supporting transportation operations
  • Freeze npm dependency updates until lockfiles are verified clean
  • Specifically check for compromised packages: cache-manager@7.2.10, cacheable@2.5.1, flat-cache@6.1.24, file-entry-cache@11.1.6

Verify ALL N-able N-central instances (agency-operated and MSP-managed) are upgraded to version 2026.3.1.7 or later. If any instance cannot be patched immediately, restrict administrative console access to specific trusted IP addresses only.
Incident Responder
Hunt for indicators of N-central compromise: Windows service "Cloudflared," svchost.exe in user Documents folders, connections to IOC IPs listed above. Review all Take Control remote sessions from the past 14 days.
SOC AnalystThreat Hunter
Block attacker domains (mousears.synology[.]me, wagoosh.direct.quickconnect[.]to, who-ripped-one.direct.quickconnect[.]to) and IPs at DNS, proxy, and firewall layers.
SOC Analyst
Contact all MSP partners to confirm their N-central patch status. If any partner cannot confirm patching, consider temporarily disconnecting managed endpoints until verification is complete.
Incident Responder
No immediate actions for the selected roles.
Audit all npm lockfiles across state application repositories for ChainDrop compromised packages (specifically cache-manager@7.2.10, cacheable@2.5.1, flat-cache@6.1.24, file-entry-cache@11.1.6). If any are found, rotate ALL CI/CD tokens and secrets immediately.
Threat Hunter
Restrict Microsoft device-code authentication flow via Conditional Access policy — allow only for designated service accounts and kiosk devices. Block for all standard user accounts to prevent Kali365-style OAuth token theft.
IAM Analyst
Confirm no PLCs in water/wastewater systems under state oversight are internet-exposed. Validate Schneider Electric IGSS installations are patched per ICSA-26-211-04. Document network segmentation posture for all OT environments.
ICS / OT
Deploy detection rules for unauthorized remote access tool installation (AnyDesk, Zoho Assist, Atera) and large outbound file transfers via WinSCP/Rclone to detect Silent Ransom Group TTPs.
SOC Analyst
No 7-day actions for the selected roles.
Brief all agency heads on Silent Ransom Group's callback phishing model. Update security awareness training to include vishing scenarios — employees must never call back "IT support" numbers from unsolicited emails without verification through official channels.
CISO / Exec
Commission a formal third-party security assessment of all MSP and managed service relationships, with particular focus on RMM platform patch cadence, access controls, and incident notification obligations.
CISO / Exec
Update incident response playbooks to account for encryption-free data extortion. Current ransomware playbooks may not trigger for SRG-style attacks where no files are encrypted. Add data exfiltration indicators as IR triggers.
CISO / ExecIncident Responder
Conduct comprehensive inventory of ALL remote management tools deployed across state agencies (not just N-central). Establish an approved RMM tool list and detection rules for any unauthorized remote access software.
CISO / Exec
Conduct a tabletop exercise simulating an MSP supply chain compromise where attackers gain remote access to agency endpoints through a trusted vendor's management platform. Include legal counsel to address breach notification obligations.
CISO / ExecIncident Responder
Draft holding statements for a scenario where a state MSP partner is compromised via N-central and citizen data is potentially exposed. Pre-coordinate with the state AG's office on notification timelines.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The exploitation of N-able N-central is not a future risk — it is happening now, against state and local government environments, with confirmed victims. The CISA KEV deadline of August 6 is two days away. Every hour an unpatched N-central instance remains exposed is an hour that attackers have administrative remote access to every endpoint it manages. But patching alone is insufficient. If your environment was exposed before the patch, you must assume compromise and hunt. The indicators are specific and actionable. The attacker tradecraft — Cloudflare tunnels, dynamic DNS for C2, abuse of built-in remote access features — is detectable with the right queries. Beyond the immediate crisis, this week's intelligence paints a clear picture: the attack surface for state government is expanding faster than most agencies' defensive capabilities. The organizations that will weather this threat environment are those that hunt proactively, verify their supply chain partners' security posture, and treat every remote management tool as a potential adversary access vector until proven otherwise.

1
Is your N-central instance patched to 2026.3.1.7? The CISA KEV deadline is August 6 — two days away — and 55%+ of servers remain unpatched.
2
Have you audited your npm lockfiles for ChainDrop's compromised packages? A single poisoned dependency can expose your entire CI/CD pipeline.
3
Does your IR playbook cover encryption-free extortion? Silent Ransom Group never deploys ransomware — the extortion demand may be your first indicator of compromise.
No items found.