TLP:GREEN  ·  States / Public Sector
Russian State, China-Nexus & AI-Autonomous Attacks Converge on State IT:

Three Active Campaigns. One Week to Act.

ELEVATED. Three simultaneous nation-state campaigns are targeting technologies state agencies operate today. A joint CISA/NSA advisory confirms Russian state actors are actively phishing Zimbra users. A China-nexus group is deploying dual ransomware through SharePoint exploitation. And the first confirmed AI-autonomous post-exploitation against a government ministry has been documented — compressing attacker dwell time from hours to minutes. If any of these platforms are unpatched in your environment, your risk posture is materially worse than it was 48 hours ago.

I am a
My sector

DevelopmentDateWhy It Matters
CISA/NSA Joint Advisory AA26-204A — Russian state actors actively phishing Zimbra Collaboration Suite users2026-07-23Multiple state agencies still operate Zimbra — this is a direct, confirmed threat to state attack surface
CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1) confirmed actively exploited; added to KEV2026-07-22Attacker gains full admin privileges and can silently rewrite firewall policies
Storm-2603 (China-nexus) confirmed exploiting SharePoint with LockBit Black + Warlock dual ransomware via four CVEs2026-07-24State agencies running unpatched on-premises SharePoint are directly vulnerable to an active campaign
7 ICS advisories published — Johnson Controls C-CURE 9000 RCE (ICSA-26-204-01) and Rockwell ThinManager file write (ICSA-26-204-05)2026-07-23C-CURE 9000 controls physical access to state buildings; Rockwell systems run water and transportation infrastructure
Hermes AI agent used for autonomous post-exploitation against Thailand Ministry of Finance — first confirmed government case2026-07-24Machine-speed post-exploitation compresses SOC detection windows from hours to minutes; tool is open-source with no kill switch
Golden Chickens MaaS resurfaces with ClickFix delivery and ChromEggscalator Chrome session hijacking2026-07-24Sector-agnostic credential theft; ChromEggscalator bypasses traditional phishing detection — no malicious link required

DateEventActor / CVEImpact
2026-07-22CVE-2026-16232 added to CISA KEV catalogCheck Point / CISAUnauthenticated firewall policy rewrite; CVSS 9.1
2026-07-22CVE-2026-41940 (cPanel/WHM auth bypass) added to KEV; ~6,100-node GitHub Actions botnet confirmedCISADual KEV additions in one day; botnet-scale exploitation confirmed
2026-07-23CISA/NSA Joint Advisory AA26-204A — Russian state Zimbra phishing campaignRussian state (likely GRU/FSB)Direct targeting of government webmail; state agencies are in-scope
2026-07-237 ICS advisories published (C-CURE 9000, ThinManager, Panduit IntraVUE, libIEC61850)CISA / Vendor disclosuresRCE in building access control; file write in water/transportation SCADA
2026-07-23ConnectWise/Action1 RMM phishing campaigns confirmed activeCriminal operatorsLegitimate RMM tools weaponized as RATs against government targets
2026-07-24Storm-2603 SharePoint dual ransomware (LockBit Black + Warlock) confirmed — ak47c2 C2 frameworkStorm-2603 (China-nexus, CVE-2025-49704/49706/53770/53771)Active exploitation of four SharePoint CVEs with BYOVD AV kill
2026-07-24Golden Chickens resurfaces — TinyEgg, ChonkyChicken, ChromEggscalatorGolden Chickens / Venom SpiderClickFix social engineering delivering Chrome DevTools session hijack
2026-07-24Hermes AI agent autonomous post-exploitation against Thai Ministry of Finance confirmedChinese-speaking operator (Hong Kong IP 103.97.0[.]57)First confirmed AI-autonomous offensive operation against government

Actors: Russian state-supported, likely GRU or FSB, based on historical Zimbra campaign attribution. CISA/NSA published this advisory with DoD co-authorship — a signal of high confidence and urgency. Russian state actors have a documented history of targeting Zimbra since 2022–2023 (APT28/Fancy Bear).

What they're doing: Credential harvesting via spearphishing links leading to Zimbra webmail interface exploitation. Every day a Zimbra instance remains operational without MFA and current patches is accepted risk against a confirmed nation-state campaign. State agencies that still operate Zimbra for legacy mail are directly in the crosshairs.

T1566.002T1078T1114.002T1114.003

Status: Actively exploited, CISA KEV. An unauthenticated remote attacker obtains an application login token, gains full administrative privileges, and can silently rewrite firewall security policies and configurations — opening paths for lateral movement, disabling inspection, or creating persistent backdoors in your perimeter security without triggering alerts from the firewall itself.

Check Point confirms exploitation affecting a small number of customers, but the KEV listing means federal agencies must patch within prescribed timelines. State agencies should treat this with equivalent urgency. Apply hotfix sk185169 if the Management Server is internet-exposed; if not, confirm Trusted Client restrictions are enforced.

T1190T1078.004T1562.001

Actors: Storm-2603, China-based (medium confidence), associated with Linen Typhoon (APT27) and Violet Typhoon (APT31). Exploiting CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 in SharePoint Server. Deploying LockBit Black and Warlock/x2anylock simultaneously via the ak47c2 framework with HTTP and DNS tunneling.

Three compounding risk factors: (1) Dual ransomware is a hedging strategy — if EDR catches one strain, the other may execute. (2) BYOVD driver (ServiceMouse.sys) kills AV processes before payload delivery. (3) China-nexus actors deploying ransomware blurs espionage and criminal boundaries — response must address both data theft and availability impact simultaneously. SharePoint Server is ubiquitous in state government. Unpatched instances are directly vulnerable; campaign currently confirmed in LATAM and APAC with high expansion probability.

T1190T1574.001T1071.004T1562.001T1486

Seven ICS advisories published 23 July 2026 include vulnerabilities with direct state government exposure:

  • Johnson Controls C-CURE 9000 (ICSA-26-204-01): Remote code execution via network access. C-CURE 9000 controls physical access to state buildings — badge readers, door locks, visitor management. RCE enables unlocking doors, disabling alarms, or denying facility access.
  • Rockwell Automation ThinManager (ICSA-26-204-05): Arbitrary file write (authenticated). ThinManager is deployed in state water treatment and transportation SCADA. File write enables implant deployment on thin client management infrastructure.
  • Panduit IntraVUE (ICSA-26-204-04): IT-to-OT manipulation. If compromised, this network visibility tool becomes a pivot from IT networks into operational technology.
  • MZ Automation libIEC61850 (ICSA-26-204-06): Unauthenticated crash of IEC 61850 services — the protocol underpinning substation automation.
T1059T1562T1021

A threat actor deployed the open-source Hermes AI agent in "YOLO mode" (all approval prompts disabled) for autonomous post-exploitation against Thailand's Ministry of Finance. The agent independently performed privilege escalation scanning, filesystem enumeration, and personnel record crawling — without human operator approval per action. Attribution indicators point to a Chinese-speaking operator (SSH from Hong Kong IP 103.97.0[.]57, FOFA API key, ShadowPad/VShell C2 history).

Why this changes the threat model for state government: Human attackers operate at human speed. An AI agent executes reconnaissance-to-exfiltration in minutes. There is no vendor kill switch — Hermes runs locally and cannot be account-banned. The operator's custom LinPEAS variant checks for CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, and CVE-2026-43503 automatically. State Linux servers with unpatched kernels are vulnerable to the same automated escalation chain. This is the first confirmed AI-autonomous offensive operation against a government target. It will not be the last.

T1059T1068T1083T1087

Actors: Golden Chickens / Venom Spider / TAG-195 (developer); historical customers include Cobalt Group, Evilnum, and FIN6. New malware families: TinyEgg, ChonkyChicken, ChromEggscalator. Delivery via ClickFix social engineering — tricking users into running malicious commands themselves.

ChromEggscalator uses Chrome DevTools Protocol to hijack active browser sessions, including M365 web sessions. For state agencies using Microsoft 365 via browser, this represents a credential theft vector that bypasses traditional phishing detection — no malicious link or attachment is required. The user executes the payload themselves. State employees are susceptible to the social engineering lures used for initial delivery.

T1204.002T1059.001T1185T1571

ScenarioProbabilityBasis
CISA issues Binding Operational Directive or Emergency Directive related to ZimbraMODERATE (70%)
within 30 days
Joint advisory publication pattern historically precedes BODs; DoD co-authorship signals elevated urgency
Storm-2603 SharePoint exploitation expands to U.S. government targetsMODERATE (60%)
within 14 days
Campaign currently LATAM/APAC; SharePoint ubiquity in U.S. gov makes expansion likely; four CVEs actively weaponized
Additional CISA KEV entries for SharePoint CVEs (CVE-2025-49704/49706/53770/53771)MODERATE (50%)
within 14 days
Active exploitation confirmed; KEV listing typically follows within days of confirmed exploitation
AI-autonomous post-exploitation tools adopted by ransomware operatorsMODERATE (55%)
within 90 days
Hermes is open-source; ransomware operators historically adopt effective tools quickly after proof-of-concept demonstrations
Russian Zimbra campaign yields confirmed state/local government compromiseMODERATE (45%)
within 30 days
Active confirmed campaign + state Zimbra instances + MFA gaps = sustained exploitation opportunity
ICS advisory vulnerabilities exploited in the wild (C-CURE 9000 or ThinManager)LOW (30%)
within 60 days
No exploitation evidence yet; RCE in building access control is high-value but requires more targeted effort

Zimbra Credential Harvesting (AA26-204A):

Alert on Zimbra logins from new geolocations, impossible travel, or following email link clicks. Monitor for bulk mailbox access (T1114.002) post-authentication. Conduct Zimbra authentication log review for successful logins from non-U.S. IPs in the past 30 days. Audit for email forwarding rules (T1114.003) created recently forwarding to external addresses. Verify Zimbra admin accounts for unauthorized changes.

Check Point SmartConsole Exploitation (CVE-2026-16232):

Audit SmartConsole logs for token generation from unexpected IPs. Alert on policy modifications outside change windows (T1562.001). Confirm Management Server is NOT internet-exposed without Trusted Client restrictions — if exposed, treat as potentially compromised pending hotfix application.

Storm-2603 SharePoint Campaign:

Monitor SharePoint ULS logs for exploitation signatures against CVE-2025-49704/49706/53770/53771. Alert on w3wp.exe spawning cmd.exe or powershell.exe. Alert on 7z.exe, MpCmdRun.exe, or clink_x86.exe loading DLLs from non-standard paths. Query for ServiceMouse.sys driver load events. Block and alert on DNS queries to updatemicfosoft[.]com and micfosoft[.]com; monitor high-entropy DNS TXT queries from internal hosts. Search for dnsclient.exe or bbb.msi on SharePoint servers.

Golden Chickens ClickFix / ChromEggscalator:

Alert on mshta.exe or rundll32.exe loading .ocx files from %TEMP% or user Downloads directories. Monitor for WebSocket connections from non-browser processes (T1571). Monitor Windows certificate store for new Trusted Root CA additions outside GPO-managed deployments (T1553.004). Check Chrome extensions for unauthorized DevTools Protocol access.

AI-Autonomous Post-Exploitation Patterns:

Develop a behavioral baseline for command execution cadence. Alert on more than 10 sequential commands within 60 seconds without human typing patterns (no backspaces, consistent inter-command timing) — this is the signature of an AI agent operating in YOLO mode. Monitor for SSH connections from 103.97.0[.]57. Hunt for LinPEAS or custom privilege escalation scripts targeting CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-43503 on Linux hosts.

ThreatATT&CK
Zimbra — Russian State Phishing (AA26-204A)T1566.002 T1078 T1114.002 T1114.003
Check Point CVE-2026-16232 ExploitationT1190 T1078.004 T1562.001
Storm-2603 SharePoint / ak47c2 / BYOVDT1190 T1574.001 T1071.004 T1486
Golden Chickens ClickFix / ChromEggscalatorT1204.002 T1059.001 T1185 T1571
Hermes AI Agent Autonomous Post-ExploitationT1059 T1068 T1083
IOC Blocking Table:
updatemicfosoft[.]com micfosoft[.]com update.updatemicfosoft[.]com update.micfosoft[.]com 103.97.0[.]57 ServiceMouse.sys dnsclient.exe bbb.msi

Storm-2603 C2 infrastructure: block all four domains (and all subdomains) at DNS and firewall. 103.97.0[.]57 — Hermes AI agent operator SSH origin, Hong Kong. Block at perimeter; alert on historical connections. Driver: ServiceMouse.sys — BYOVD AV process killer; block driver load at endpoint. SHA-256: f711b14efb7792033b7ac954ebcfaec8141eb0abafef9c17e769ff96e8fecdf3 (Storm-2603 MSI installer, LockBit Black delivery). Monitor digicert[.]com for anomalous DNS resolution indicating AiTM — do not block (legitimate domain). Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Storm-2603 has already compromised an unpatched SharePoint instance and established ak47c2 persistence?
Search DNS logs for queries to updatemicfosoft[.]com or micfosoft[.]com. Search proxy logs for HTTP POST requests with PDB path strings containing "ak47c2". Check for dnsclient.exe or bbb.msi on SharePoint servers. Query EDR for w3wp.exe spawning shells.
HUNT 02 · T1114
Russian state actors have already harvested Zimbra credentials from state employees via AA26-204A?
Review Zimbra authentication logs for successful logins from non-U.S. IPs in the past 30 days. Check for email forwarding rules created recently pointing to external addresses (T1114.003). Audit Zimbra admin accounts for unauthorized setting changes in the past 60 days.
HUNT 03 · T1562
A BYOVD attack has already disabled endpoint protection on a SharePoint or file server?
Query EDR for ServiceMouse.sys driver load events. Check for gaps in EDR telemetry — hosts that stopped reporting to the console. Verify AV service status on all SharePoint servers, file servers, and DC-adjacent systems. Search for processes running as SYSTEM without corresponding service entries.
HUNT 04 · T1204
ClickFix social engineering has led to Golden Chickens implant deployment on a workstation?
Search for mshta.exe executions with command-line arguments referencing .ocx files. Look for new WebSocket connections originating from non-browser processes in the past 72 hours. Check Chrome extension store for unauthorized DevTools Protocol access grants. Audit recently installed root certificates for additions outside GPO management.

Financial Services
State Treasury, Revenue, Pension Systems
Primary threat
Storm-2603 dual ransomware via SharePoint — Treasury and revenue agencies commonly use SharePoint for document workflows. A ransomware event during tax processing season would be catastrophic.
Secondary threat
Golden Chickens ChromEggscalator targeting banking web sessions and browser-based financial portals.
Actions
  • Prioritize SharePoint patching for financial agencies — all four Storm-2603 CVEs
  • Enforce hardware token MFA for all financial system access
  • Segment financial SharePoint farms from general agency infrastructure
Energy
State-Operated Utilities, Public Power
Primary threat
libIEC61850 vulnerability (ICSA-26-204-06) enabling unauthenticated crash of substation automation services. State-operated utilities using IEC 61850 for substation monitoring face denial-of-service risk.
Secondary threat
Volt Typhoon / Salt Typhoon pre-positioning — no new activity detected this cycle, but absence does not equal safety for pre-positioned actors.
Actions
  • Assess libIEC61850 and lib60870 exposure in substation environments
  • Ensure OT network segmentation prevents IT-side compromise from reaching substation controllers
  • Maintain out-of-band monitoring capability independent of IT network health
Healthcare
State Health Agencies, Medicaid Systems
Primary threat
Ransomware (LockBit Black, Warlock) via SharePoint exploitation. Health agencies managing Medicaid enrollment, vital records, and public health data on SharePoint are directly exposed.
Secondary threat
Zimbra phishing campaign — health agency staff handling sensitive PII are high-value credential harvesting targets.
Actions
  • Verify SharePoint patch status for all health-related agency instances
  • Implement data loss prevention rules for Medicaid PII
  • Ensure offline backup capability for vital records systems; validate backup restoration time
Government
Executive Agencies, Legislature, Courts
Primary threat
Russian state Zimbra phishing campaign (AA26-204A) targeting government agencies with legacy Zimbra deployments for credential harvesting and email collection.
Secondary threat
Johnson Controls C-CURE 9000 RCE (ICSA-26-204-01) — state capitol buildings, courthouses, and agency offices using C-CURE for physical access control face risk of unauthorized access or lockout.
Actions
  • Accelerate Zimbra migration timeline — patch and enforce MFA immediately for remaining instances
  • Patch C-CURE 9000 and segment physical access control networks from general IT
  • Brief executive staff on Zimbra phishing indicators; provide specific email subject/link patterns from AA26-204A
Aviation / Logistics
State DOT, Airports, Port Authorities
Primary threat
Rockwell Automation ThinManager arbitrary file write (ICSA-26-204-05). State DOT and transportation authorities using Rockwell systems for traffic management, tunnel ventilation, or bridge operations face implant deployment risk.
Secondary threat
Panduit IntraVUE IT-to-OT manipulation (ICSA-26-204-04) — network visibility tools in transportation OT environments as pivot points into operational systems.
Actions
  • Patch ThinManager instances; audit for unauthorized file creation in management directories
  • Review Panduit IntraVUE deployments for unnecessary IT-OT connectivity
  • Ensure transportation SCADA systems have independent safety instrumented systems not overrideable via network access
No sector cards match the selected filters.

Verify all Zimbra instances have MFA enforced and current patches applied. Audit for phishing indicators per CISA AA26-204A — review authentication logs for logins from non-U.S. IPs in the past 30 days; check for forwarding rules to external addresses.
Incident ResponderIAM Analyst
Confirm Check Point Management Server is NOT internet-exposed without Trusted Client restrictions. Apply hotfix sk185169 if exposed. Audit SmartConsole logs for anomalous token generation from unexpected source IPs.
Incident Responder
Validate all on-premises SharePoint Server instances are patched against CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Isolate unpatched instances from internet access pending emergency patching.
Incident Responder
Block updatemicfosoft[.]com and micfosoft[.]com (all subdomains) at DNS and firewall. Also block 103.97.0[.]57 and alert on ServiceMouse.sys driver load events. Confirmed Storm-2603 C2 infrastructure and BYOVD AV killer.
SOC Analyst
Brief executive leadership on the convergence of three active nation-state threats — authorize emergency patching windows for Zimbra, Check Point, and SharePoint this week. Delay is not a neutral position; threat actors are not pausing.
CISO / Exec
No immediate actions for the selected roles.
Deploy detection for DLL sideloading via 7z.exe, clink_x86.exe, and MpCmdRun.exe loading non-Microsoft DLLs from non-standard paths. Alert on ServiceMouse.sys driver load events and EDR telemetry gaps (hosts that stopped reporting).
SOC AnalystThreat Hunter
Patch Johnson Controls C-CURE 9000 and Victor application servers per ICSA-26-204-01. Segment physical access control systems from general IT network. Validate segmentation between IT and ThinManager-managed thin client infrastructure.
ICS / OTIncident Responder
Create detection for ClickFix execution patterns: mshta.exe or rundll32.exe loading .ocx files from %TEMP% or user Downloads. Alert on WebSocket C2 traffic from non-browser processes. Monitor Windows certificate store for unauthorized Trusted Root CA additions.
SOC Analyst
Assess and patch libIEC61850 and lib60870 vulnerabilities in substation automation and telecontrol systems. If patching is not immediately possible, network segmentation must prevent unauthenticated access to IEC 61850 service endpoints.
ICS / OT
Conduct Zimbra email forwarding rule audit across all instances — identify any rules created in the past 60 days forwarding to external addresses. This detects potential prior compromise from the Russian phishing campaign before full credential review is complete.
SOC AnalystIncident Responder
No 7-day actions for the selected roles.
Commission assessment of AI-autonomous threat readiness. Evaluate whether SOC detection logic can identify automated post-exploitation (rapid sequential command execution without human typing cadence). Current detection architecture assumes human-speed adversaries — the Hermes incident confirms this assumption is no longer valid.
CISO / Exec
Develop migration plan for remaining Zimbra instances to M365 or a hardened alternative with a firm timeline. Persistent Russian state targeting of Zimbra makes continued operation a risk acceptance decision that should be documented at the executive level.
CISO / ExecIncident Responder
Conduct tabletop exercise simulating dual-ransomware scenario — two strains executing simultaneously with AV disabled via BYOVD. Test: Can the IR team handle two concurrent encryption events? Are backups resilient to both? Does the IR playbook account for the AV kill step?
Incident ResponderCISO / Exec
Update IR playbooks to address AI-speed post-exploitation. Define escalation thresholds for automated attack detection. Reframe dwell-time assumptions — the Hermes incident demonstrates reconnaissance-to-exfiltration in minutes, not the hours current playbooks assume.
Incident Responder
Evaluate and enforce RMM tool allowlisting policy. Only authorized RMM agents (ConnectWise, SimpleHelp) should execute in the environment; block unauthorized RMM installations at endpoint. Continued weaponization of legitimate RMM tools as RATs is a persistent and underdetected vector.
Incident Responder
No 30-day actions for the selected roles.
Bottom Line

State government IT environments face simultaneous, active exploitation of three platform categories — Zimbra, Check Point firewall management, and SharePoint Server — by confirmed nation-state actors. The addition of AI-autonomous post-exploitation to the threat landscape means the window between initial compromise and data exfiltration is shrinking from days to minutes. Three questions determine your immediate risk posture today.

1
Are your Zimbra instances patched and MFA-enforced against an active Russian state phishing campaign confirmed by a joint CISA/NSA/DoD advisory?
2
Is your Check Point Management Server internet-exposed without Trusted Client restrictions against a CVSS 9.1 actively exploited vulnerability that grants full firewall policy write access?
3
Are your on-premises SharePoint Server instances patched against four CVEs currently being weaponized with dual ransomware and a driver-based AV kill by a China-nexus group?
No items found.