TLP:GREEN  ·  States / Public Sector
Perimeter Under Siege:

Two CISA KEVs Hit State Network Infrastructure as New Ransomware Tooling Emerges

ELEVATED. CISA added critical vulnerabilities in FortiOS and MikroTik RouterOS - two platforms widely deployed across state perimeters - to its KEV catalog, confirming active exploitation. Security researchers disclosed SloppyRAT, a ransomware pre-positioning tool using ClickFix to bypass email security entirely, and a new IoT botnet (KATARU) weaponizing three Linux kernel privesc vulnerabilities affecting state data centers and OT environments.

I am a
My sector

DevelopmentDetails
FortiOS CVE-2025-25249 added to CISA KEV (Sep 9). Heap-based buffer overflow enabling RCE; PivotC2 RAT observed post-exploitation. CVSS 8.1.178 FortiGate devices already confirmed infected
MikroTik RouterOS CVE-2026-67277 added to CISA KEV (Sep 10). Unauthenticated bandwidth-test flaw allows memory disclosure/kernel restart. CERT.PL confirms active exploitation.Affects RouterOS 6.x/7.x branches
SloppyRAT disclosed by Zscaler (Sep 11). New RAT via ClickFix, purpose-built for ransomware lateral movement - Defender manipulation, reverse SOCKS proxy, Polygon C2 fallback.Same delivery used by espionage actor UNC6924
KATARU IoT botnet disclosed by Nozomi Networks (Sep 11). Brute-forces Telnet then escalates to root via 3 Linux kernel exploits.Affects Linux servers, not just IoT devices
3 CISA ICS advisories (Sep 10) covering AVEVA, Orthanc DICOM, and NextGen Mirth Connect.State pipeline, hospital, Medicaid systems
Storm-3121/Storm-3032 M365 vishing confirmed active (Sep 9-10). Passkey-themed vishing targeting personal devices to pivot into M365 tenants.Both clusters active against state M365 environments

DateEventSeverityState Gov Relevance
May 2026 (ongoing)Storm-3121 / Storm-3032 begin passkey-themed vishing against M365 usersHIGHState M365/Entra ID tenants are targets
Sep 9, 2026CISA adds CVE-2025-25249 (FortiOS) to KEV; 178 U.S. FortiGate devices confirmed infected with PivotC2 RATCRITICALDirect exposure if state FortiGates unpatched
Sep 10, 2026CISA adds CVE-2026-67277 (MikroTik) to KEV; CERT.PL confirms active exploitationHIGHMikroTik deployed in branch/remote offices
Sep 10, 2026CISA publishes ICS advisories for AVEVA, Orthanc DICOM, NextGen Mirth ConnectHIGHState utilities, hospitals, health IT
Sep 11, 2026Zscaler publishes SloppyRAT analysis - ClickFix-delivered ransomware pre-positioning toolHIGHClickFix bypasses email security; targets all sectors
Sep 11, 2026Nozomi Networks publishes KATARU botnet analysis - Linux kernel LPE weaponizationMODERATEState Linux servers and OT-adjacent devices exposed

CVE-2025-25249 (FortiOS) heap overflow enables RCE. PivotC2 RAT confirmed post-exploitation tooling; 178 devices already infected.

CVE-2026-67277 (MikroTik) allows unauthenticated memory disclosure/kernel restart. CERT.PL confirms active exploitation.

Perimeter exploitation is accelerating across vendors - a rolling patch emergency.

T1190T1219T1078

SloppyRAT's delivery chain abuses legitimate binaries: finger.exe (TCP 79) initiates download, renames curl.exe to a numeric .com file, IronPython executes CastleLoader/CastleRAT, then SloppyRAT loads reflectively in memory. It modifies Defender and deploys a reverse SOCKS proxy - ransomware pre-positioning.

Convergence risk: the same delivery was previously used by espionage actor UNC6924.

T1218T1036T1059.006T1562.001T1090.003

KATARU weaponizes 3 Linux kernel privesc CVEs: Dirty Frag (8.8), Fragnesia (7.8), Copy Fail (7.8, KEV) - affecting standard Linux kernels, not just IoT. State Linux servers in OT-adjacent environments (SCADA, building automation) share the exposure. ARM samples show broken shellcode, but ported variants are expected soon. Encrypted C2 and persistence across 12+ init systems make remediation hard.

T1110.001T1068T1543.002
ActorStatus
Volt/Salt Typhoon (China)Pre-positioned; silence likely a collection gap
CyberAv3ngers (Iran)Water/pipeline targeting continues
APT15/Mirage (China)Fresh gov/healthcare hashes
Storm-3121/3032 (Criminal)Active M365 passkey vishing
APT28/29/41Updated activity Sep 10-11

ScenarioProbabilityBasis
Additional exploitation of FortiOS CVE-2025-25249 against state FortiGate devicesHIGH (>70%)PivotC2 RAT already in the wild; 178 devices confirmed compromised
SloppyRAT attributed to a named ransomware group (e.g., Rhysida, SafePay)MODERATE (40-60%)Purpose-built tooling rarely stays unattributed
ClickFix delivery adopted by additional threat actors beyond UNC6924/SloppyRATMODERATE (40-60%)Technique is proving effective; low barrier to adoption
KATARU derivative with correctly ported architecture-specific LPE exploitsMODERATE (40-60%)Current ARM binary broken; fix is trivial
Ransomware incident against a U.S. state/local government entityMODERATE (40-60%)Rhysida/SafePay active; SloppyRAT adds a new vector
Volt Typhoon or Salt Typhoon activity surfaces in public reportingLOW-MODERATE (25-40%)Absence likely a collection gap

Priority 1: ClickFix Delivery Chain (SloppyRAT + UNC6924):

Alert on finger.exe outbound (TCP 79) - zero legitimate use in state gov; curl.exe renamed to numeric .com; IronPython/Python from user-writable paths; spoofed explorer.exe parent; reflective DLL loading; unauthorized SOCKS proxy connections.

Priority 2: FortiGate Post-Exploitation Indicators:

Monitor for unexpected admin accounts, modified firewall rules, new VPN tunnels; anomalous outbound connections; syslog gaps. Verify firmware integrity.

Priority 3: MikroTik Exploitation:

Monitor unexpected bandwidth-test (btest) traffic; unscheduled reboots; SSH from IOC IPs; new/modified user accounts.

Priority 4: Linux Kernel LPE (KATARU-related):

Monitor Telnet brute-force (especially OT-adjacent); unexpected privesc events; new systemd/cron/udev entries outside change management.

Priority 5: M365 Identity Hijacking (Storm-3121/Storm-3032):

Monitor M365 sign-ins from unusual locations/devices following vishing reports; unrequested passkey/MFA registrations; Conditional Access bypass attempts.

ThreatATT&CK
P1: ClickFix Delivery ChainT1218 T1036 T1059.006 T1090.003
P2: FortiGate Post-ExploitationT1190 T1219 T1070
P3: MikroTik ExploitationT1078
P4: Linux Kernel LPET1110.001 T1068 T1543.002
P5: M365 Identity HijackingT1078.004
IOC Blocking Table:
82.192.72[.]4103.102.31[.]18

Block above at perimeter/DNS. SHA-256 hashes via Anomali ThreatStream Next-Gen.

Hunting Hypotheses:
H1
ClickFix already used to deliver SloppyRAT or similar
See Priority 1.
H2
FortiGate already exploited with PivotC2 deployed
See Priority 2.
H3
MikroTik already exploited for network pivot
See Priority 3.
H4
Linux system already rooted via kernel LPE
See Priority 4.
H5
M365 credentials already compromised via passkey vishing
See Priority 5.

Financial Services
State Revenue, Treasury
Primary threat
SloppyRAT's ClickFix delivery specifically targets financial services; revenue agency staff are high-risk for fake tax portal prompts.
Actions
  • Block finger.exe execution; restrict Python/IronPython in user dirs
Energy
State Water, Pipeline
Primary threat
CyberAv3ngers targets water PLCs; AVEVA vulnerabilities allow code execution on pipeline systems.
Actions
  • Inventory AVEVA deployments; segment from enterprise IT
Healthcare
State Hospitals, Medicaid
Primary threat
CISA advisories for Orthanc DICOM and NextGen Mirth Connect; Rhysida has historically targeted healthcare.
Actions
  • Patch Orthanc DICOM and Mirth Connect; verify offline backups
Government
Executive Agencies, M365
Primary threat
FortiOS/PivotC2 threatens perimeter security; Storm-3121/3032 passkey vishing threatens the shared M365 backbone.
Actions
  • Emergency FortiOS patching is the top priority
Aviation / Logistics
State DOT, Transportation
Primary threats
MikroTik routers at remote DOT sites are vulnerable to CVE-2026-67277 and often under-maintained.
Actions
  • Inventory MikroTik devices; prioritize firmware updates
No sector cards match the selected filters.

Patch all FortiGate firewalls to 7.6.4+/7.4.9+/7.2.12+/7.0.18+; verify FortiSwitchManager.
Incident Responder
Update all MikroTik RouterOS to 6.49.21+/7.23.4+/7.24.2+. Audit branch/remote-site inventory.
Incident Responder
Deploy ClickFix detection: alert on finger.exe outbound, renamed curl.exe, IronPython/Python from user paths.
SOC Analyst
Block outbound TCP port 79 (Finger) at all perimeter firewalls - zero legitimate use in state government.
SOC Analyst
Authorize emergency patching for FortiOS/MikroTik outside normal change windows - KEV deadline is Sep 12.
CISO / Exec
No immediate actions for the selected roles.
Audit Linux/IoT devices for Dirty Frag/Fragnesia/Copy Fail kernels; add SloppyRAT/KATARU IOCs to EDR/SIEM.
Incident ResponderSOC Analyst
Review AVEVA, Orthanc DICOM, Mirth Connect per CISA advisories; coordinate OT vendor patching.
ICS / OT
Conduct a FortiGate compromise assessment - assume breach until verified.
SOC Analyst
Review M365 Conditional Access to block unmanaged-device sign-ins post-vishing; enable MFA number matching.
IAM Analyst
No 7-day actions for the selected roles.
Update phishing training for ClickFix; establish a consolidated perimeter patch dashboard.
CISO / Exec
Commission an external compromise assessment covering FortiGate, MikroTik, Cisco; evaluate Telnet exposure.
CISO / Exec
Update IR playbooks for FortiGate compromise, ClickFix ransomware, and IoT/OT botnet scenarios.
Incident Responder
No 30-day actions for the selected roles.
The Bottom Line

The threat landscape facing state government networks is defined by a single reality: the perimeter is under simultaneous attack from multiple directions. FortiGate firewalls, MikroTik routers, Linux servers, IoT devices, and M365 identities all face active exploitation at the same time. The good news: the most impactful actions are also the most straightforward - patch FortiOS and MikroTik today, block TCP port 79, deploy ClickFix detection, and audit Linux kernel versions on OT-adjacent systems. ClickFix deserves particular attention - it bypasses email security entirely by tricking users into executing commands themselves. No attachment to scan, no link to block. The defense is user awareness plus technical controls, and both are needed.

1
Authorize emergency patching for FortiOS and MikroTik outside normal change windows.
2
Ensure your SOC has detection coverage for the ClickFix delivery chain.
3
Verify your OT environments are not running unpatched Linux kernels.
No items found.