TLP:GREEN  ·  States / Public Sector
When Your Network Edge Becomes the Front Door:

MikroTik Exploitation, MSP Tool Vulnerabilities, and APT28's Evolving Playbook

ELEVATED. Upgraded from GUARDED - active MikroTik exploitation across 122,500 exposed devices globally, a CVSS 10.0 SonicWall zero-day, unpatched MSP tool vulnerabilities, and continued government ransomware worldwide.

I am a
My sector

DevelopmentDetails
MikroTik "MikroTrick" exploitation went active. CVE-2026-67276/86060 confirmed exploited (CERT.PL) - 122,500 devices exposed.County/municipal MikroTik networks at direct risk
ConnectWise ScreenConnect disclosed an unpatched file-transfer flaw. No CVE, no patch.Documented ransomware/APT exploitation history
N-able N-central got an emergency hotfix for a pre-auth RCE (CVE-2026-86218).Same servers MSPs use to manage state endpoints
APT28 refined its HOOKEDGE backdoor - new variants (Jun-Jul) targeting European government via webhook[.]site C2.12 new file hashes available for detection
Qilin added the Philippine Ports Authority (885+ victims); Rhysida demanded 30 BTC from Berlin - refused.Continued international government ransomware targeting
Telerik UI 4-CVE chain enables padding oracle, DLL upload, RCE.Legacy .NET citizen portals/benefits systems at risk; patch 2026.2.708
FalconFlank PoC published - Falcon's macro-remediation abused for local privesc.Novel: EDR remediation becomes the escalation vector

DateEventSignificance
Jan-Apr 2026Winona County, MN pays $128,539 ransom, struck by a different group 3 months laterDouble-ransomware risk for local government
Jun-Jul 2026APT28 deploys new HOOKEDGE backdoor variants against European government targetsRussian GRU continues investing in government-targeting capabilities
Aug 28, 2026Rhysida demands 30 BTC from Berlin city government for 5.79TB of exfiltrated dataGovernment ransomware targeting continues internationally
Sep 1, 2026CVE-2026-83548 (CVSS 10.0) pre-auth SSRF in SonicWall SMA 1000, active exploitationCritical perimeter zero-day
Sep 3, 2026MikroTik releases RouterOS patches for MikroTrick CVEs122,500 devices remain exposed
Sep 5, 2026Qilin adds Philippine Ports Authority to leak site; total victims exceed 885Government port authority targeted; Qilin expanding aggressively
Sep 7, 2026CISA ICS advisories published for Rockwell, Schneider Electric, IXON, Inductive Automation, OPC UAOngoing ICS/SCADA vulnerability disclosures affecting critical infrastructure

CVE-2026-67276 (SSH auth bypass) + CVE-2026-86060 (SSH privesc) combine for full admin access; CVE-2026-67277 causes memory leak/DoS. MikroTik sits at county edges with weak patch discipline. Patches: RouterOS 7.24.2/7.23.4/6.49.21.

T1078T1552.004T1021.004

ScreenConnect: unpatched file-transfer flaw, disable TransferFiles (~6,000 exposed). N-central: pre-auth RCE (CVE-2026-86218), Hotfix 4 released. A compromised MSP platform compromises every client simultaneously.

T1219T1078T1190T1133

New variants (Jun-Jul) use msedge.exe as HTTP client, webhook[.]site C2, two-tier beaconing (30-61 min, 5-min high-value). Targets are European, but APT28 has a U.S. state/local history - TTPs transfer.

T1566.001T1059.003T1053.005T1071.001

Qilin (885+ victims) added the Philippine Ports Authority. Rhysida demanded 30 BTC from Berlin - refused. Playbook: VPN exploitation -> AD lateral movement -> exfil before encryption. Winona County paid $128,539, struck again by a different group 3 months later.

4 CVEs chain a Telerik padding oracle into DLL upload and RCE - web shell in IIS. Fixed in 2026.2.708. FalconFlank: a PoC abuses Falcon's macro-remediation for SYSTEM privesc (post-compromise only).

T1190T1059.001T1505.003

Predicted ScenarioProbabilityBasis
Ransomware (Qilin, Rhysida) targets state/local government via VPN/RMMHIGH (75-85%)Active targeting; unpatched ScreenConnect/N-central; Winona precedent
Exploitation of unpatched MikroTik devices at county/municipal edgesHIGH (70-80%)Active exploitation; 122,500 exposed; slow county patching
APT28 HOOKEDGE-style webhook C2 targets state government via spearphishingMODERATE (40-55%)Confirmed European targeting; TTPs transferable; no direct U.S. evidence yet
MSP compromise cascades to state endpoints via ScreenConnect/N-centralMODERATE (45-60%)3 MSP vulnerabilities in 24h; proven lateral movement path
Volt/Salt Typhoon pre-positioning in state government networksMODERATE (35-50%)Silence may indicate improved OPSEC, not reduced activity
Exploitation of Telerik UI in state legacy web appsLOW-MODERATE (25-40%)PoC published; exposure depends on deployment
FalconFlank adopted by ransomware affiliatesLOW-MODERATE (20-35%)PoC verified; typical adoption 30-90 days

Priority 1 - MikroTik MikroTrick Exploitation:

Monitor 82.192.72[.]4/103.102.31[.]18; logs for login failure for user -2. Block inbound SSH; patch RouterOS.

Priority 2 - APT28 HOOKEDGE Backdoor:

Monitor msedge.exe->webhook[.]site tasks; 30-61/5-min beaconing; hashes below in EDR.

Priority 3 - MSP Tool Exploitation (ScreenConnect & N-central):

Monitor anomalous file transfers, off-hours sessions, unauthenticated API calls. Disable TransferFiles; patch N-central.

Priority 4 - Telerik UI Exploitation:

Monitor w3wp.exe spawning cmd.exe/PowerShell; unexpected DLLs/aspx files. Upgrade to 2026.2.708+; add WAF rules.

Priority 5 - CrowdStrike FalconFlank Privilege Escalation:

If Falcon runs Phase 3 with "Suspicious Macro Removal" enabled, a foothold could escalate to SYSTEM. Disable per CrowdStrike's Tech Alert; verify Cloud Anti-malware remains active.

ThreatATT&CK
P1 - MikroTik MikroTrickT1078 T1552.004
P2 - APT28 HOOKEDGET1566.001 T1071.001
P3 - MSP Tool ExploitationT1105 T1219 T1190
P4 - Telerik UIT1190 T1505.003
IOC Blocking Table:
82.192.72[.]4103.102.31[.]18webhook[.]site

Block above at perimeter/DNS. HOOKEDGE SHA-256 hashes (sample): 206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991, 231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1, 58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e - 9 additional variant hashes available via ThreatStream Next-Gen.

Hunting Hypotheses:
HUNT 01 · T1078
MikroTik already compromised via MikroTrick
See Priority 1 above.
HUNT 02 · T1566.001
APT28 HOOKEDGE already delivered to a government employee
See Priority 2 above.
HUNT 03 · T1219
MSP tool (ScreenConnect/N-central) already exploited
See Priority 3 above.
HUNT 04 · T1190
Telerik RadAsyncUpload chain already exploited for a web shell
See Priority 4 above.
HUNT 05 · T1068
FalconFlank privilege escalation already used post-compromise
See Priority 5 above.

Financial Services
State Treasury, Revenue, Benefits
Primary threat
Telerik-based revenue/benefits portals face web-shell risk; JSCeal steals Chrome cookies bypassing Google auth.
Actions
  • Prioritize Telerik patching + WAF rules; enforce FIDO2 for financial access
Energy
State-Managed Utilities
Primary threats
This cycle ICS advisories plus Volt Typhoon silence keep energy at elevated risk.
Actions
  • Request a CISA briefing on Volt Typhoon activity
  • Patch IXON VPN with MFA-restricted access
Healthcare
Medicaid, Public Hospitals
Primary threat
Rhysida's Berlin op shows willingness to exfiltrate massive volumes before encryption; MSP flaws create a path to healthcare endpoints.
Actions
  • Validate HIPAA breach-notification readiness; require healthcare MSPs to confirm mitigation within 24h
Government
Executive Agencies, Elections
Primary threat
APT28 HOOKEDGE is the top nation-state concern; Qilin port-authority add signals deliberate government targeting.
Actions
  • Deploy the HOOKEDGE hashes to EDR; verify Chrome fleet updated for CVE-2026-85046
Aviation / Logistics
State DOT, Port Authorities
Primary threat
Qilin port-authority targeting and MikroTik at remote DOT/weigh-station sites both apply here.
Actions
  • Review Qilin TTPs against your architecture; include transportation sites in MikroTik patching
No sector cards match the selected filters.

Patch MikroTik RouterOS to 7.24.2/7.23.4/6.49.21; block internet SSH pending patch.
Incident Responder
Deploy APT28 HOOKEDGE IOCs to EDR/SIEM; alert on msedge.exe->webhook[.]site.
SOC Analyst
Mitigate ScreenConnect - disable TransferFiles across all instances/MSP partners.
Incident Responder
Patch N-able N-central (Hotfix 4, CVE-2026-86218); direct MSP partners to confirm mitigation within 48h (24h healthcare).
Incident ResponderCISO / Exec
No immediate actions for the selected roles.
Patch Telerik UI to 2026.2.708+; hunt unexpected DLLs, w3wp.exe->cmd.exe.
Incident Responder
Assess FalconFlank exposure - disable macro-removal policy if active.
SOC Analyst
Verify Chrome/SonicWall patched - Chrome 152.0.7977.82+, SonicWall SMA 1000 (CVSS 10.0).
Incident Responder
Review CISA ICS advisories against asset inventories.
ICS / OT
No 7-day actions for the selected roles.
Assess federated SSO trust; require email verification + MFA at the IdP.
CISO / Exec
Request a CISA briefing on Volt/Salt Typhoon; establish MSP attestation in contractual SLAs.
CISO / Exec
Build a unified perimeter device inventory across agencies/county partners.
CISO / Exec
Update ransomware IR playbooks for double-ransomware scenarios (Winona precedent).
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

State government networks face a convergence that individually would warrant urgent action - together they demand it. MikroTik exploitation is confirmed, SonicWall's CVSS 10.0 zero-day is active, 122,500 devices are exposed. Your MSP supply chain is a direct attack path - one exploited ScreenConnect/N-central instance grants access to every client agency. APT28's HOOKEDGE refinement signals sustained intent. Volt/Salt Typhoon have gone quiet - not reassurance for pre-positioning groups. No new U.S. state/local ransomware victims this cycle - positive, but not a trend.

1
MikroTik/MSP mitigations cannot wait for the next maintenance window.
2
The APT28 IOCs should be in your EDR blocklists today.
3
SSO trust assessment and MSP contractual requirements determine readiness for what comes next.
No items found.