TLP:GREEN  ·  States / Public Sector
Ransomware Retooling for Government, Rockwell ICS Disclosures & PRC Novel Initial-Access Technique:

When Silence Is the Loudest Signal

ELEVATED. The absence of a breach headline doesn't mean the threat environment has cooled. CISA added four actively exploited vulnerabilities to the KEV catalog — including a CVSS 10.0 unauthenticated RCE running as root — Rockwell Automation disclosed four ICS advisories in a single day affecting water and transportation systems, and a Chinese espionage group debuted a captive-portal hijack technique that delivers malware without a phishing email or any user click. Seven ransomware groups are simultaneously targeting government entities, and Cactus and Space-Pirates refreshed payloads explicitly tagged to government-regional targeting within the last 48 hours.

I am a
My sector

DevelopmentDateWhy It Matters for State Government
CISA adds 4 CVEs to KEV catalog — including CVE-2026-0770 (Langflow unauthenticated RCE, runs as root) and CVE-2021-27137 (DD-WRT UPnP, C0xmo botnet)2026-07-21Any state agency experimenting with AI/ML workflow tools may have fully uncompromised exposure with no authentication barrier
Rockwell Automation releases 4 ICS advisories in one day — 1734 POINT I/O, 1718-AENTR, Studio 5000 Logix Designer, FactoryTalk Services Platform user impersonation2026-07-21State water utilities and transportation systems running Rockwell PLCs face coordinated disclosure with an open exploitation window
Cactus ransomware + Space-Pirates refresh government-targeting payloads — three new hashes tagged explicitly to "government-regional" and "government-public-services"2026-07-21/22Adversaries are actively retooling for state and local government — not opportunistic, deliberate sector targeting
Qilin affiliate STAC4365 conducting ScreenConnect credential harvesting against cloud administrators2026-07-22Compromised admin credentials provide direct ransomware deployment access across managed endpoints — a tool widely used in state government managed services
PRC actor UNC6384 pioneers captive portal hijack technique — intercepts browser connectivity checks (gstatic.com) via compromised edge devices to deliver SOGU.SEC/PlugX2026-07-22Novel initial access that requires no phishing email, no malicious link, no user click — bypasses email security and web filtering entirely
SocGholish/FakeUpdates C2 infrastructure refreshed — domain cdn-js.tobaccobazaar[.]com confirmed active2026-07-22Active domain feeding the ClickFix-to-ransomware kill chain that has already compromised government targets
FSB Center 16 continues exploiting CVE-2018-0171 (Cisco Smart Install, 7 years old) against U.S. critical infrastructureOngoingState agencies with legacy Cisco IOS devices and Smart Install still enabled remain exposed to Russian intelligence collection

DateEventActor / CVEImpact
Jun 2026VOID MANTICORE breaches California water utility — destructive attack on U.S. critical infrastructureIRGC-affiliated / VOID MANTICOREDemonstrated destructive attack on U.S. water infrastructure — theoretical risk became operational reality
2026-06-22Active exploitation of SonicWall SMA 1000 zero-day chain beginsUTA0533 / CVE-2026-15409 + CVE-2026-15410CVSS 10.0; LDAP credential harvesting — existing VPN access remains viable ransomware entry point
2026-07-16CISA adds FortiSandbox CVE-2026-25089 (CVSS 9.8) to KEVMultiple actorsFourth Fortinet KEV addition this cycle — sustained pressure on perimeter appliances
2026-07-19APT28 (GRU Unit 26165) refreshes Bumblebee loader infrastructureAPT28 / Russian GRUTargeting U.S. government networks — sustained Russian espionage tooling refresh
2026-07-21CISA adds 4 new CVEs to KEV catalog — Langflow RCE + DD-WRT UPnP botnetMultiple actors / CVE-2026-0770, CVE-2021-27137Langflow RCE runs as root with no authentication — any exposed instance is fully compromised
2026-07-21Rockwell Automation releases 4 ICS advisories in single dayN/A (vendor disclosure)1734 POINT I/O, 1718-AENTR, Studio 5000, FactoryTalk — coordinated disclosure creates open exploitation window
2026-07-21/22Cactus and Space-Pirates refresh government-targeting malware hashesCactus, Space-PiratesThree new samples explicitly tagged to government-regional and government-public-services verticals
2026-07-22SocGholish C2 domain cdn-js.tobaccobazaar[.]com confirmed activeFakeUpdates / GhoLoaderFeeds ClickFix social engineering → ransomware deployment kill chain already hitting government targets

Seven ransomware groups — Qilin, LockBit 5, Akira, AiLock, Interlock, Kairos, and Gunra — are simultaneously targeting government entities this cycle. This is not coincidence. Cactus and Space-Pirates refreshed payloads within the last 48 hours carrying explicit "government-regional" and "government-public-services" targeting tags. Industry-wide, Flashpoint data shows ransomware attack volume increased 179% in H1 2025 compared to the prior year; the trend has not abated.

Qilin affiliate STAC4365 is conducting credential harvesting campaigns against ScreenConnect cloud administrators — a remote management tool widely deployed across state government managed services environments. Compromised admin credentials bypass perimeter defenses entirely, providing direct access to deploy ransomware across every managed endpoint in the environment. The probability that Cactus ransomware will claim a U.S. government victim within 14 days is assessed at 60%; the probability that existing VPN access from the SonicWall zero-day chain will be weaponized for ransomware within 2–4 weeks is 75–85%.

T1486T1078T1021T1569.002T1204.002

Volt Typhoon / Salt Typhoon are known for "living off the land" pre-positioning in U.S. government and critical infrastructure networks using legitimate admin tools to avoid detection. No new IOCs this cycle — but silence from a pre-positioning actor is not reassurance. It is doctrine. These actors are specifically designed to remain undetected until activation during a geopolitical crisis.

UNC6384 debuted a captive portal hijack technique that intercepts browser connectivity checks (HTTP requests to gstatic.com/generate_204) via compromised edge devices to deliver SOGU.SEC/PlugX malware. This bypasses email security, web filtering, and user awareness training entirely. Any browser on a network with a compromised router or firewall becomes a delivery target with zero user interaction required. A 40% probability is assessed that this technique will be adopted by other PRC clusters within 30 days — technique sharing is common within China's cyber ecosystem.

PRC supply chain operations — the SLICKDEMON campaign via DAEMON Tools supply chain compromise was updated July 21, continuing a pattern of software supply chain infiltration targeting developer environments.

T1078T1218T1036T1189T1195.002T1071.001

Four Rockwell Automation advisories in a single day is not routine. The most critical is the FactoryTalk Services Platform user impersonation vulnerability — an attacker can impersonate an authorized user on the FTSP server, gaining unauthorized access to ICS operations without needing the authorized user's credentials. For state agencies operating water treatment, wastewater, or transportation SCADA systems on Rockwell platforms, this is a direct path from IT network compromise to physical process manipulation.

The other three advisories — 1734 POINT I/O (remote code execution), 1718-AENTR (denial of service), and Studio 5000 Logix Designer (arbitrary file execution on engineering workstations) — compound the exposure. Combined with the VOID MANTICORE destructive attack on a California water utility in June 2026, the threat to state-operated water and transportation infrastructure is no longer theoretical. A 25% probability is assessed for Rockwell vulnerability exploitation in a state OT environment within 30 days — no active exploitation confirmed yet, but coordinated disclosure plus widespread state agency deployments creates elevated window risk.

T1078T1190T1204.002T1485

FSB Center 16 (Russian intelligence) continues exploiting CVE-2018-0171 — a seven-year-old Cisco Smart Install vulnerability — against U.S. critical infrastructure networks. The 12-nation advisory from earlier this cycle confirmed active, global scanning. State agencies with legacy Cisco IOS/IOS XE devices deployed years ago and never hardened are carrying intelligence collection exposure they may not be aware of.

CVE-2021-27137 (DD-WRT UPnP buffer overflow) is now on the KEV catalog, with the C0xmo botnet actively exploiting it. State agencies with legacy network equipment that hasn't been inventoried or patched in years — routers acquired outside the main procurement cycle, devices at remote facilities — are silently exposed to botnet recruitment and subsequent lateral movement.

T1190T1078T1048T1601.001

ScenarioProbabilityBasis
Existing VPN access (SonicWall SMA 1000 zero-day chain) weaponized for ransomware deploymentHIGH (75–85%)Historical dwell-time-to-monetization patterns; SonicWall compromise provides persistent, low-detection access; 7 ransomware groups actively hunting government
Cactus ransomware claims a U.S. state or local government victimMODERATE (60%)Refreshed gov-targeting IOCs in past 48 hours; 179% ransomware volume increase trend; explicit "government-regional" payload tagging
Additional CISA KEV entries from July 21 batch identified — full bulletin not yet publishedMODERATE (70%)Partial data available; pattern of batched KEV additions with staggered full disclosure
UNC6384 captive portal technique replicated by other PRC clustersLOW-MODERATE (40%)Technique sharing is common within China's cyber ecosystem; novel initial access with no user interaction is high-value enough to spread quickly
Rockwell vulnerability exploitation in a state OT environmentLOW (25%)No active exploitation confirmed yet; coordinated disclosure + widespread state Rockwell deployments = elevated window risk; OT exploitation requires deeper access

SocGholish / FakeUpdates (Drive-by Ransomware Chain):

Block cdn-js.tobaccobazaar[.]com at DNS and web proxy immediately — this is the confirmed active C2 for the ClickFix social engineering → ransomware deployment kill chain. Monitor for JavaScript injection patterns on legitimate websites; alert on mshta.exe or wscript.exe execution following browser activity. Hunt for PowerShell with encoded commands spawned from browser processes.

Cactus / Space-Pirates Government-Targeting Payloads:

Deploy the three SHA-256 hashes below to EDR blocklists immediately. Behavioral detection: alert on unexpected service installation (T1569.002) from non-standard paths; monitor for Ramnit-pattern behavioral signatures on endpoints. These payloads were refreshed within 48 hours and carry explicit government sector tags — treat any hash match as an active incident.

UNC6384 Captive Portal Hijack:

Monitor network edge for unexpected HTTP 302 redirects on requests to gstatic.com/generate_204 that do not originate from legitimate captive portal infrastructure. Alert on SOGU.SEC/PlugX behavioral signatures: DLL sideloading from non-standard paths, unusual outbound connections from browser connectivity check processes. Any browser on a network with a compromised router or firewall is a potential delivery target.

Volt Typhoon / Salt Typhoon LOTL Activity:

Hunt for anomalous use of T1078 (Valid Accounts), T1218 (System Binary Proxy Execution — mshta, rundll32, regsvr32 with unusual command-line arguments), and T1036 (Masquerading — processes mimicking legitimate Windows services from non-standard paths) across domain controllers and critical servers. Silence from a pre-positioning actor is doctrine, not reassurance — establish a baseline and look for statistical anomalies rather than known-bad signatures.

Langflow / VPN Appliance Exploitation:

Query software inventory and container registries for any Langflow instance. CVE-2026-0770 is unauthenticated RCE running as root — any exposed instance should be treated as fully compromised until proven otherwise. For SonicWall SMA 1000 appliances: if CVE-2026-15409/15410 is unpatched, monitor for unexpected outbound connections and hunt for LDAP credential theft patterns.

ThreatATT&CK
SocGholish / FakeUpdates Drive-by DeliveryT1189 T1071.001
Cactus / Space-Pirates Ransomware PayloadsT1204.002 T1569.002 T1195.002
UNC6384 Captive Portal HijackT1189 T1036
Volt Typhoon / Salt Typhoon LOTL Pre-PositioningT1078 T1218 T1036
Langflow Unauthenticated RCE (CVE-2026-0770)T1190
ScreenConnect Credential Harvesting (STAC4365)T1078 T1021
FSB Center 16 Router Exploitation (CVE-2018-0171)T1601.001 T1048 T1078
IOC Blocking Table:
cdn-js.tobaccobazaar[.]com new.sys-update[.]online util.advertising-platform[.]top mediareleaseupdates[.]com

Active C2 and malware delivery infrastructure — block at DNS, web proxy, and firewall. SHA-256 hashes (Cactus/Space-Pirates gov-targeting): ee5853b029179d9369927c59b89448ac8fbce1495313d84a563967f4017352ef (severity: very-high), 90b89a6dc4565c9817e7db8323702006860cb2b49f352863f2b18ba21c66b435 (T1195.002), 0b1440414ac5c9109cf4c4714f5e7b23e19f8a572ddde6f3a4c3306d13a80ee9 (Ramnit behavioral). Domain mediareleaseupdates[.]com — serves AdobePlugins.exe payload. Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1021
Do we have unauthorized ScreenConnect instances deployed by Qilin affiliate STAC4365?
Query EDR for ScreenConnect or ConnectWise Control binaries not deployed via your standard IT operations toolchain. Focus on instances installed in the past 30 days; cross-reference against your authorized RMM inventory. Any unrecognized instance is a potential beachhead for ransomware deployment across all managed endpoints.
HUNT 02 · T1189
Are any edge devices intercepting browser connectivity checks and delivering malware (UNC6384 captive portal technique)?
Monitor for HTTP 302 redirects on requests to gstatic.com/generate_204 that don't originate from documented captive portal infrastructure. Alert on SOGU.SEC/PlugX behavioral indicators following browser connectivity check processes. Any unexpected redirect of this specific URL pattern at your network edge warrants immediate investigation.
HUNT 03 · T1601.001
Is Smart Install still enabled on any Cisco device, giving FSB Center 16 a direct exploitation path?
Run show vstack config across your entire Cisco IOS/IOS XE device inventory. Any device returning "Role: Client" or "Role: Director" has Smart Install active and is a live target for FSB Center 16's current scanning campaign. Disable with no vstack and confirm CVE-2018-0171 patch status.
HUNT 04 · T1190
Do we have Langflow deployed anywhere in the environment — including shadow IT and developer sandboxes?
Query software inventory systems, container registries, and cloud workload catalogs for Langflow instances. CVE-2026-0770 is unauthenticated RCE running as root — a single exposed instance is fully compromised at the OS level regardless of network position. This includes developer laptops, staging environments, and any AI/ML experimentation infrastructure.

Government
State & Local Agencies, Managed Services
Primary threat
Cactus / Space-Pirates payloads with explicit government-regional targeting; Qilin affiliate STAC4365 ScreenConnect credential harvesting enabling ransomware deployment across managed endpoints
Secondary threat
Langflow unauthenticated RCE (CVE-2026-0770) on AI/ML experimentation infrastructure; SonicWall SMA 1000 credential theft (CVE-2026-15409/15410) providing persistent VPN access
Actions
  • Verify zero Langflow exposure across all agency environments including shadow IT and developer sandboxes — CVE-2026-0770 is unauthenticated RCE as root, on CISA KEV
  • Audit ScreenConnect / remote support tool inventory — ensure only authorized instances exist and admin credentials enforce MFA
  • Validate SonicWall SMA 1000 appliances are patched against CVE-2026-15409/15410; if unpatched, assume compromise and initiate credential threat hunt
  • Review Cisco device inventory for Smart Install feature; disable immediately where found (FSB Center 16 actively exploiting CVE-2018-0171)
Energy & Water/Wastewater
State Utilities, Water Treatment, SCADA
Primary threat
Rockwell FactoryTalk Services Platform user impersonation — attacker can impersonate authorized user to gain direct ICS/SCADA access; demonstrated VOID MANTICORE destructive attack on California water utility (Jun 2026)
Secondary threat
Rockwell 1734 POINT I/O and 1718-AENTR DoS vulnerabilities; Siemens RUGGEDCOM APE1808 PAN-OS exposure (ICSA-26-202-02)
Actions
  • Patch Rockwell FactoryTalk Services Platform immediately — user impersonation vulnerability enables direct OT manipulation without credential theft
  • Apply patches for 1734 POINT I/O and 1718-AENTR DoS vulnerabilities — coordinate maintenance windows with facility operators now
  • Verify network segmentation between IT and OT — the VOID MANTICORE California water utility breach demonstrated IT-to-OT lateral movement is actively exploited
  • Audit Siemens RUGGEDCOM APE1808 deployments for PAN-OS vulnerability exposure (ICSA-26-202-02)
Healthcare
Hospitals, Health Systems, Clinical Networks
Primary threat
Cactus ransomware targeting — healthcare remains a top ransomware target alongside government; 179% volume increase means incident probability is at historic highs
Secondary threat
SocGholish / ClickFix drive-by delivery via patient-facing web applications and healthcare portals
Actions
  • Block Cactus/Space-Pirates IOCs at EDR and network layers — three new government/healthcare-targeting hashes confirmed this cycle
  • Monitor for SocGholish / ClickFix delivery on healthcare portals — patient-facing web applications are high-value drive-by targets
  • Ensure backup isolation and recovery testing — at 179% ransomware volume increase, incident probability is at historic highs; backup integrity is your primary recovery guarantee
Financial Services
State Treasury, Revenue, Banking Infrastructure
Primary threat
Volt Typhoon / Salt Typhoon LOTL pre-positioning — financial infrastructure is a confirmed pre-positioning target for potential disruptive activation during geopolitical crisis
Secondary threat
Qilin affiliate STAC4365 ScreenConnect credential harvesting — financial services MSPs are high-value targets enabling mass ransomware deployment
Actions
  • Hunt for Volt Typhoon / Salt Typhoon LOTL indicators — anomalous use of legitimate admin tools (T1078, T1218, T1036) on financial infrastructure systems
  • Monitor for credential harvesting via ScreenConnect compromise — financial services MSPs are high-value Qilin affiliate targets
  • Validate supply chain integrity for software deployment pipelines — SLICKDEMON (DAEMON Tools supply chain) updated July 21
Aviation & Transportation
State Transit, Port Operations, Logistics
Primary threat
Rockwell Studio 5000 Logix Designer arbitrary file execution — affects engineering workstations used in transportation ICS; coordinated with three other Rockwell advisories released simultaneously
Secondary threat
UNC6384 captive portal hijack targeting networks with compromised routers or firewalls; DD-WRT router exploitation via CVE-2021-27137 (now on CISA KEV, C0xmo botnet)
Actions
  • Patch Rockwell Studio 5000 Logix Designer — arbitrary file execution vulnerability affects engineering workstations managing transportation ICS
  • Audit edge device firmware across all facilities — UNC6384 captive portal technique targets any network with a compromised router or firewall
  • Review DD-WRT router deployments (if any) — CVE-2021-27137 is now on CISA KEV with active C0xmo botnet exploitation; disable UPnP or replace devices
No sector cards match the selected filters.

Block cdn-js.tobaccobazaar[.]com at DNS and web proxy — active SocGholish C2 feeding ClickFix social engineering → ransomware deployment kill chain that has already hit government targets.
SOC Analyst
Deploy Cactus/Space-Pirates SHA-256 hashes to EDR blocklists: ee5853b029179d9369927c59b89448ac8fbce1495313d84a563967f4017352ef, 90b89a6dc4565c9817e7db8323702006860cb2b49f352863f2b18ba21c66b435, 0b1440414ac5c9109cf4c4714f5e7b23e19f8a572ddde6f3a4c3306d13a80ee9. All three are freshly refreshed and explicitly government-targeted.
SOC Analyst
Verify Langflow is NOT deployed anywhere in the agency environment — including developer sandboxes, staging, and container registries. CVE-2026-0770 is unauthenticated RCE as root on CISA KEV. Any exposed instance is fully compromised.
Incident Responder
Confirm SonicWall SMA 1000 patch status for CVE-2026-15409/15410. If unpatched, initiate incident response for potential credential compromise — the zero-day chain has been actively exploited since June 22; assume VPN credentials are at risk.
Incident Responder
Brief executive leadership: 60% probability of a U.S. government ransomware incident within 14 days based on Cactus/Space-Pirates retooling. Validate IR playbook readiness and confirm emergency patching authorization channels are active.
CISO / Exec
No immediate actions for the selected roles.
Apply patches for all four Rockwell Automation advisories — FactoryTalk Services Platform, 1734 POINT I/O, 1718-AENTR, and Studio 5000 Logix Designer. Coordinate OT maintenance windows with facility operators now; do not wait for scheduled cycles.
ICS / OT
Conduct enterprise-wide audit for unauthorized ScreenConnect instances. Qilin affiliate STAC4365 is deploying rogue RMM tools via compromised admin credentials. Any unrecognized instance is a potential active beachhead for ransomware deployment across all managed endpoints.
SOC AnalystIncident Responder
Audit DD-WRT router deployments for UPnP enabled status. CVE-2021-27137 is now on CISA KEV with active C0xmo botnet exploitation. Disable UPnP where found, or replace devices — legacy network equipment that hasn't been inventoried is likely exposed.
Incident Responder
Proactive threat hunt for Volt Typhoon LOTL indicators — anomalous use of T1078 (Valid Accounts), T1218 (System Binary Proxy Execution), and T1036 (Masquerading) across domain controllers and critical servers. Silence from a pre-positioning actor is doctrine, not reassurance.
Threat Hunter
Review and validate IR playbook for ransomware scenario with initial access via compromised VPN appliance (SonicWall). Confirm backup isolation, recovery RTO/RPO, and communications chain. The 75–85% probability of SonicWall-based ransomware deployment makes this exercise urgent, not routine.
CISO / Exec
No 7-day actions for the selected roles.
Implement captive portal anomaly detection — monitor for unexpected HTTP 302 redirects on browser connectivity checks (gstatic.com) at the network edge. UNC6384 uses this for SOGU.SEC/PlugX delivery with zero user interaction; it cannot be caught by email security or user awareness training.
SOC AnalystThreat Hunter
Commission review of all Cisco IOS/IOS XE devices for Smart Install feature. Run show vstack config enterprise-wide; disable where found with no vstack. FSB Center 16 is actively exploiting CVE-2018-0171 globally — seven years on, this vector remains viable because legacy devices are rarely re-audited.
Incident Responder
Establish a dedicated OT vulnerability tracking workflow separate from IT patching processes. Four Rockwell advisories in a single day exceeds normal OT patch management capacity — state agencies need a distinct process for coordinating ICS patches with physical facility operators without disrupting operations.
ICS / OTCISO / Exec
Conduct tabletop exercise: ransomware scenario with initial access via compromised VPN appliance (SonicWall) and lateral movement to OT systems. The California water utility destructive attack and current Rockwell vulnerabilities make this scenario operationally realistic for state agencies, not hypothetical.
Incident ResponderCISO / ExecICS / OT
Evaluate adding redundant open-source intelligence feeds (Google Threat Intelligence, Flashpoint) to CTI collection. Seven ransomware groups simultaneously active against government, plus nation-state operations — single-source collection creates blind spots at exactly the wrong time.
CISO / Exec
No 30-day actions for the selected roles.
Bottom Line

The convergence of three factors makes this week more dangerous than most. Ransomware groups are not just targeting government — they are retooling specifically for government, refreshing payloads with explicit sector tags within 48 hours. The ICS/OT attack surface is expanding faster than state agencies can patch it; four Rockwell advisories in a single day, combined with a demonstrated destructive attack on a U.S. water utility last month, means theoretical OT risk has become operational reality. And nation-state actors are innovating around every control in your stack — UNC6384's captive portal technique delivers malware without a phishing email, a malicious link, or any user interaction whatsoever.

1
Block the SocGholish C2 domain, deploy the Cactus/Space-Pirates hashes to EDR, and verify Langflow is absent from your environment — all within 24 hours. These three actions close the highest-probability immediate attack vectors.
2
Patch all four Rockwell ICS advisories and audit for unauthorized ScreenConnect instances within 7 days. The FactoryTalk user impersonation vulnerability is a direct path from IT compromise to physical process manipulation — the California water utility breach proved the adversary will walk that path.
3
The 14-day window before a likely government ransomware incident is not a prediction to file away. It is a countdown. Authorize emergency patching. Validate your IR playbook. Hunt for Volt Typhoon LOTL indicators before the next crisis — not during it.
No items found.