TLP:GREEN  ·  States / Public Sector
When MFA Isn't Enough:

AiTM Phishing, Active Zero-Days, and the Escalating Threat to State Government Networks

ELEVATED. Two AiTM phishing campaigns, active exploitation of network edge devices, China-nexus mass exploitation of SharePoint, and an escalating Iranian ICS threat demand immediate attention. MFA alone no longer stops the most active credential theft campaigns - one platform actively disables FIDO2 hardware keys.

I am a
My sector

DevelopmentDetails
Two independent M365 AiTM campaigns with shared infrastructure emerged. BigBear 2.0 (PhaaS) and PREY-0058 (vishing) both use NodeMaven residential proxies to replay stolen sessions. BigBear stole 5,100+ credentials from 258 orgs.Shared infrastructure suggests common supply chain
MikroTik "MikroTrick" exploitation confirmed active in the wild. CERT Polska warns of CVE-2026-67276/86060, allowing unauthenticated SSH and full admin takeover.122,500 devices globally remain exposed
China-nexus actors mass-exploiting SharePoint CVE-2025-53770 (CVSS 9.8) for government access across 8+ countries.Deserialization flaw enabling webshell deployment
SAP September Patch Day includes a CVSS 10.0 vulnerability (CVE-2026-44756), no auth required.State financial/HR SAP systems need immediate assessment
CrowdStrike FalconFlank PoC verified - a Falcon Sensor config creates a local privesc path to SYSTEM.Phase 3 + macro removal enabled agencies affected
U.S. State Dept announced a $10M reward for IRGC Cyber Chief Amir Yaryab, head of CyberAv3ngers.Signals water/wastewater infra remains a priority Iranian target

DateEventSeverity
Nov 2023 - Jan 2024CyberAv3ngers (IRGC) compromise 75+ Unitronics PLCs including 34 U.S. water systemsCRITICAL
Jul 2025Microsoft confirms in-the-wild exploitation of SharePoint CVE-2025-53770 (CVSS 9.8)CRITICAL
Sep 1, 2026SonicWall discloses CVE-2026-83548 (CVSS 10.0) in SMA 1000 - active exploitationCRITICAL
Sep 3, 2026MikroTik patches "MikroTrick" chain; 122,500 devices globally still exposedHIGH
Sep 7, 2026BigBear 2.0 PhaaS disclosed - 258 orgs compromised, 5,137 credentials stolenHIGH
Sep 8, 2026$10M reward announced for IRGC Cyber Chief Amir Yaryab (CyberAv3ngers)HIGH
Sep 8, 2026SAP September Patch Day - CVE-2026-44756 (CVSS 10.0) plus 3 more critical CVEsHIGH

BigBear 2.0 is an Evilginx2-based PhaaS platform compromising 258 orgs across 40+ countries (474 MFA-bypassed sessions, 1,032 passwords, 4,148 cookies), using custom JavaScript to actively disable FIDO2/WebAuthn.

PREY-0058 calls executives impersonating IT help desk, directing them to rogue portals for session theft. Both use NodeMaven residential proxies to geo-match victim locations, defeating impossible-travel detection.

T1557T1539T1078

CVE-2026-67276 (SSH auth bypass) chains with CVE-2026-86060 (privesc via crafted username) for full admin control. CERT Polska confirms active exploitation; 122,500 devices remain exposed despite patches (RouterOS 6.49.21/7.23.4/7.24.2).

T1190T1068T1562.004

Multiple Chinese groups actively exploit CVE-2025-53770 (CVSS 9.8) against on-premises SharePoint, targeting government, financial, manufacturing, tech, and telecom across 8+ countries with webshell deployment. A separate TWOPIPE backdoor campaign targets similar sectors across 19 countries.

T1190T1505.003T1059.001

The $10M reward for Amir Yaryab (IRGC-CEC chief) is itself an intelligence signal - CyberAv3ngers compromised 75+ Unitronics PLCs including 34 U.S. water systems (2023-24) via default credentials on port 20256, replaced ladder logic, and disabled remote engineering.

T1190T1078.001T0831T0836

SAP's September release has 4 critical CVEs: CVE-2026-44756 (10.0), CVE-2026-58240 (9.8), CVE-2026-76969 (9.4), CVE-2026-66768 (9.0). No exploitation reported yet but demands assessment.

FalconFlank: a verified PoC demonstrates local privesc to SYSTEM via Falcon's macro remediation. No CVE assigned; disable the policy.

T1190T1068

ScenarioProbabilityTimeframeBasis
Additional AiTM phishing campaigns target state M365 tenants using BigBear or similar PhaaS platformsHIGH (75-85%)Next 7 daysBigBear's affiliate model incentivizes rapid expansion; 258 orgs already compromised
FIDO2-disabling technique proliferates to other PhaaS platformsHIGH (70-80%)Next 30 daysEffective, technically straightforward; PhaaS operators share tooling
China-nexus actors expand SharePoint CVE-2025-53770 exploitation to additional U.S. state targetsMODERATE-HIGH (60-70%)Next 30 daysGovernment is an explicit target; public PoC; many instances lag patching
MikroTik exploitation adopted by ransomware affiliates for state/local government accessMODERATE (50-60%)Next 30 daysRansomware groups historically adopt weaponized edge exploits within weeks
CyberAv3ngers/successor conducts new ICS targeting against U.S. water/wastewaterLOW-MODERATE (30-40%)Next 90 daysReward may disrupt operations but signals persistence
Ransomware group (Qilin, Rhysida, SafePay) successfully attacks a U.S. state/local entityHIGH (70-80%)Next 30 daysAll three maintain active targeting; identity-based access is the dominant vector

1. Residential Proxy Session Replay (BigBear / PREY-0058):

Query Entra ID logs for auths from residential proxy ASNs. Escalate: proxy sign-in + SharePoint enumeration or bulk downloads within 60 min.

2. FIDO2 Downgrade Detection:

Compare registered vs. actual auth method in Entra ID. Flag FIDO2 accounts falling back to push/SMS.

3. MikroTik Compromise Indicators:

Monitor DNS changes; run /system/device-mode/print for compromise flags.

4. SharePoint Webshell and Post-Exploitation:

Monitor IIS logs for new .aspx files; alert on w3wp.exe spawning shells.

5. IT Help Desk Vishing (PREY-0058):

Alert on exec sign-ins from new devices with SharePoint enumeration or bulk downloads.

6. ICS/OT Monitoring (CyberAv3ngers):

Scan for exposed Unitronics PLCs/HMIs (port 20256); verify no default credentials.

ThreatATT&CK
1. Residential Proxy Session ReplayT1557 T1539 T1078
2. FIDO2 Downgrade DetectionT1557 T1539
3. MikroTik Compromise IndicatorsT1190 T1068 T1562.004
4. SharePoint WebshellT1190 T1505.003 T1059.001
5. IT Help Desk VishingT1566.003 T1213.002 T1530
6. ICS/OT MonitoringT1190 T1078.001 T0831
IOC Blocking Table:
pulse.neuralorbitgrid9[.]lolloadway[.]besteyedonation.bmscloud.in[.]thabcsgftr[.]cct[.]m-kosche[.]comleaguejazire[.]comriyazinikokar[.]xyzbsc-testnet-rpc[.]publicnode[.]cominvokere[.]com

Do NOT block Pastebin[.]com - legitimate service abused for C2/exfil; alert on programmatic access instead. SHA-256: 2a695840f9f1f8dc945009e9fd0df25f51bb148b2d637653b0f2b20583ec1516 +7 more; SHA-1: 77556c57999805fa7815a114da51d91cf24fbea9 +1 more. Full list via Anomali ThreatStream Next-Gen.

Hunting Hypotheses:
HUNT 01
Residential proxy session replay already occurring
See Priority 1 above.
HUNT 02
FIDO2 already downgraded via BigBear injection
See Priority 2 above.
HUNT 03
MikroTik already compromised via MikroTrick
See Priority 3 above.
HUNT 04
SharePoint already webshelled via CVE-2025-53770
See Priority 4 above.
HUNT 05
An executive already fell for PREY-0058 vishing
See Priority 5 above.

Financial Services
State Treasury, Revenue
Primary threat
SAP ERP faces risk from CVE-2026-44756/58240. PREY-0058 targets CFOs.
Actions
  • Prioritize SAP patch
  • Brief CFOs vishing
Energy
Water/Wastewater
Primary threats
The $10M IRGC reward signals water/wastewater priority; ICS advisories cover Rockwell/Schneider/IXON.
Actions
  • Audit exposed PLCs (port 20256)
  • Segment OT
Healthcare
Medicaid, EHR
Primary threats
High-value target for Qilin, Rhysida, SafePay; BigBear is sector-agnostic.
Actions
  • Verify backups
  • Enforce compliance
Government
Executive Agencies
Primary threat
Broadest surface; China-nexus SharePoint targets government explicitly.
Actions
  • Verify SharePoint fixes
  • Brief on vishing
Aviation / Logistics
DOT, Ports
Primary threat
ICS/SCADA for traffic shares water/wastewater flaws; MikroTik at weigh stations under active exploitation.
Actions
  • Patch MikroTik at remote sites
  • Include SAP for fleet mgmt
No sector cards match the selected filters.

Block NodeMaven proxy ASNs.
IAM AnalystSOC Analyst
Patch MikroTik to 6.49.21/7.23.4/7.24.2.
Incident Responder
Verify SharePoint fix.
Incident Responder
Brief directors on PREY-0058 vishing.
SOC AnalystCISO / Exec
Scan Unitronics PLCs (port 20256).
ICS / OT
No immediate actions for the selected roles.
Inventory SAP versions (CVE-2026-44756/58240).
Incident Responder
Enforce FIDO2.
IAM Analyst
Disable CrowdStrike macro removal; block 5 APT28 domains.
Incident Responder
Audit exposed PLCs per CISA advisories.
ICS / OT
No 7-day actions for the selected roles.
Implement CAE for M365.
IAM Analyst
Tabletop AiTM/ransomware scenario.
CISO / Exec
Segment OT/ICS with unidirectional gateways.
ICS / OT
No 30-day actions for the selected roles.
The Bottom Line

The threat landscape has shifted materially this week. AiTM phishing that defeats MFA, actively exploited edge-device zero-days, nation-state SharePoint exploitation targeting government, and an escalating Iranian ICS threat create a multi-vector risk no single control addresses. MFA is necessary but no longer sufficient - when adversaries disable FIDO2 keys and replay sessions through geo-matched residential proxies, defense must shift to device compliance, continuous access evaluation, and behavioral detection. The edge is under siege: MikroTik, SharePoint, SonicWall, SAP - every internet-facing service is a potential entry point.

1
Emergency MikroTik patching and M365 hardening are not optional.
2
SharePoint mitigation verification and executive vishing awareness respond to active campaigns targeting you right now.
3
Act today.
No items found.