
Threat Advisory • Attack Report • Admiralty Code A1
A landscape assessment of the ransomware ecosystem targeting the U.S. Manufacturing sector, covering 45 distinct campaigns, dominant ransomware brands, exploited edge-appliance CVEs, and the espionage layer operating beneath the extortion economy.
TA2026213Date of Publication: July 28, 2026Admiralty Code: A1Targeted Region: United StatesTargeted Sector: Manufacturing3758881436 / 3745Summary
The U.S. Manufacturing sector sat at the sharp end of the ransomware curve across the reporting window, with 45 distinct campaigns converging on a single reality: the network perimeter is the front door, and it is unlocked. Akira dominated the leaderboard while emerging brands scaled fastest beneath it, and a synchronised late-2025 pileup pointed to a shared upstream trigger the sector should expect to see repeat. Weaponised CVEs clustered on VPNs, firewalls and remote-support tooling, with backup infrastructure specifically targeted for destruction before encryption. Behind the ransomware volume sat a quieter nation-state espionage layer aimed at long-dwell access, a reminder that for manufacturers with defense, aerospace or semiconductor exposure, the intellectual-property threat is as serious as the extortion one.
Targeted platforms span Windows, Linux, VMware ESXi, and network appliances. Dominant ransomware brands active against U.S. manufacturing include Akira, Qilin, Play, Clop, Dragon Force, and INC. A total of 37 unique CVEs sit in scope for this landscape, 14 of which (37.8%) were exploited as zero-days, and 36 of which (97.3%) are listed on the CISA Known Exploited Vulnerabilities (KEV) catalogue.
The CVE, ransomware, and malware seen most often against the U.S. manufacturing sector, based on leak-site activity and campaign tracking across the reporting window.
Akira — 361 leak-site victim postsQilin — tracked in multiple campaignsStealC — tied across multiple stealer campaignsCVE-2024-55591 — Fortinet FortiOS auth-bypassAkira dominates manufacturing leak-site postings, roughly double the next brand (Qilin). Together, the top five ransomware brands — Akira, Qilin, Play, Clop, and DragonForce — account for the bulk of publicly claimed victims. Leak-site victim-post counts reflect publicly claimed victims on each group's data-leak site.
58 tracked malware families were grouped by type for this landscape. Ransomware leads at 47% (27 of 58 families), confirming extortion as the primary end goal targeting U.S. manufacturing. Information stealers and backdoors follow at 16% each — stealers harvest the credentials that open the door, while backdoors give the persistent, quiet access espionage crews and ransomware affiliates rely on. Loaders/downloaders (9%) and RATs (7%) round out the delivery-and-control toolkit. Read together, the mix describes a full intrusion lifecycle: steal access, establish persistence, then encrypt or exfiltrate for extortion.
37 exploited CVEs were grouped by the type of product targeted. Edge, VPN, and remote-access appliances dominate, accounting for 18 of the 37 CVEs. Fortinet, Ivanti, Citrix, SonicWall, SimpleHelp, and ConnectWise devices are the principal doorway into manufacturing networks: internet-facing, often under-patched, and sitting directly on the perimeter. Web/application/middleware products (7 CVEs) — SAP NetWeaver, Oracle, Log4j, Confluence, and ColdFusion — and virtualization/hypervisor plus email/collaboration servers (4 CVEs each) round out the attack surface.
The pattern is clear: exposure is concentrated at the network edge and in shared enterprise software beneath production systems. Half of all exploited CVEs target the perimeter itself — the appliances that face the internet before any production system is reached. Segmenting OT/production networks behind these devices, and patching the edge first, delivers the largest reduction in blast radius.
Exploited CVEs by vendor area are proportional to the number of weaponised vulnerabilities. Microsoft, Fortinet, and VMware carry the largest weaponised footprint, followed closely by SimpleHelp, SonicWall, and Ivanti. Two themes emerge. First, security and remote-access vendors — Fortinet, SonicWall, Ivanti, Citrix, SimpleHelp, ConnectWise, and F5 — the very products bought to protect the network, are the most-exploited class of appliance. Second, core enterprise platforms — Microsoft, VMware, Oracle, SAP, Adobe, Atlassian, and Apache — underpin production and back-office systems, so a single vendor flaw cascades widely. Concentrating patch and monitoring effort on this short vendor list covers the majority of the sector's exploited exposure.
How dangerous and how actionable the exploited CVEs are, aggregated across the 37 CVEs tracked in this advisory.
97% of weaponised CVEs are already in CISA's Known Exploited Vulnerabilities catalogue, and 97% have a patch available, meaning the vast majority of manufacturing's exposure is remediable today and is being exploited because patch lag, not novel zero-days, is the gap. The 14 zero-days that do appear cluster in edge appliances (Fortinet, Citrix, Ivanti, Oracle), underscoring why perimeter devices demand the fastest possible patch SLAs.
All 37 CVEs aggregated for this landscape, with CISA KEV status and vendor-patch availability. Per-CVE zero-day flags were not separately resolvable from the source table layout; the aggregate 14/37 zero-day figure is presented above in Vulnerability Posture.
| CVE | Name | Affected Product | CISA KEV | Patch |
|---|---|---|---|---|
CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Citrix NetScaler ADC and NetScaler Gateway | ✓ | ✓ |
CVE-2023-48788 | Fortinet FortiClient EMS SQL Injection Vulnerability | Fortinet FortiClient EMS | ✓ | ✓ |
CVE-2024-57727 | SimpleHelp Path Traversal Vulnerability | SimpleHelp Remote Support Software | ✓ | ✓ |
CVE-2025-5777 | Citrix NetScaler Gateway Out-of-Bounds Read Vulnerability (“Citrix Bleed 2”) | Citrix NetScaler ADC and NetScaler Gateway | ✓ | ✓ |
CVE-2021-20038 | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | SonicWall SMA 100 Appliances | ✓ | ✓ |
CVE-2009-3960 | Adobe BlazeDS Information Disclosure Vulnerability | Adobe BlazeDS 3.2 and earlier | ✓ | ✓ |
CVE-2010-2861 | Adobe ColdFusion Directory Traversal Vulnerability | Adobe ColdFusion 9.0.1 and earlier | ✓ | ✓ |
CVE-2018-13379 | Fortinet FortiOS SSL VPN Path Traversal Vulnerability | Fortinet FortiOS, FortiProxy | ✓ | ✓ |
CVE-2019-0604 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft SharePoint | ✓ | ✓ |
CVE-2021-31207 | ProxyShell – Microsoft Exchange Server Security Feature Bypass Vulnerability | Microsoft Exchange Server | ✓ | ✓ |
CVE-2021-34473 | ProxyShell – Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft Exchange Server | ✓ | ✓ |
CVE-2021-34523 | ProxyShell – Microsoft Exchange Server Privilege Escalation Vulnerability | Microsoft Exchange Server | ✓ | ✓ |
CVE-2024-40766 | SonicWall SonicOS Improper Access Control Vulnerability | SonicWall SonicOS SOHO (Gen 5) | ✓ | ✓ |
CVE-2024-53704 | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | SonicWALL Gen7 NSv | ✓ | ✓ |
CVE-2023-27532 | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | Veeam Backup & Replication Cloud Connect | ✓ | ✓ |
CVE-2024-37085 | VMware ESXi Authentication Bypass Vulnerability | VMware ESXi | ✓ | ✓ |
CVE-2024-55591 | Fortinet FortiOS Authorization Bypass Vulnerability | Fortinet FortiOS | ✓ | ✓ |
CVE-2025-7771 | TechPowerUp ThrottleStop Privilege Escalation Vulnerability | TechPowerUp ThrottleStop | — | — |
CVE-2024-21762 | Fortinet FortiOS SSL-VPN Out-of-Bounds Write Vulnerability | Fortinet FortiOS | ✓ | ✓ |
CVE-2025-31324 | SAP NetWeaver Unrestricted File Upload Vulnerability | SAP NetWeaver Visual Composer | ✓ | ✓ |
CVE-2018-0171 | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability | Cisco IOS and IOS XE Software | ✓ | ✓ |
CVE-2021-44228 | Log4Shell – Apache Log4j Remote Code Execution Vulnerability | Apache Log4j2 | ✓ | ✓ |
CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | Atlassian Confluence Server | ✓ | ✓ |
CVE-2023-46805 | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | Ivanti Connect Secure and Policy Secure | ✓ | ✓ |
CVE-2024-21412 | Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability | Microsoft Windows Internet Shortcut Files | ✓ | ✓ |
CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | Ivanti Connect Secure and Policy Secure | ✓ | ✓ |
CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | Ivanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA | ✓ | ✓ |
CVE-2024-57726 | SimpleHelp Missing Authorization Vulnerability | SimpleHelp remote support software | ✓ | ✓ |
CVE-2024-57728 | SimpleHelp Path Traversal Vulnerability | SimpleHelp remote support software | ✓ | ✓ |
CVE-2023-20118 | Cisco Small Business RV Series Routers Command Injection Vulnerability | Cisco Small Business RV Series Routers | ✓ | ✓ |
CVE-2021-35587 | Oracle Fusion Middleware Unspecified Vulnerability | Oracle Access Manager product of Oracle Fusion Middleware | ✓ | ✓ |
CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability | Oracle E-Business Suite | ✓ | ✓ |
CVE-2024-1709 | ConnectWise ScreenConnect Authentication Bypass Vulnerability | ConnectWise ScreenConnect | ✓ | ✓ |
CVE-2021-22005 | VMware vCenter Server File Upload Vulnerability | VMware vCenter Server | ✓ | ✓ |
CVE-2023-34048 | VMware vCenter Server Out-of-Bounds Write Vulnerability | VMware vCenter Server | ✓ | ✓ |
CVE-2023-46747 | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability | F5 BIG-IP Configuration Utility | ✓ | ✓ |
CVE-2024-38812 | VMware vCenter Server Heap-Overflow Vulnerability | VMware vCenter Server, VMware Cloud Foundation | ✓ | ✓ |
Note: the source report hyperlinks CVE patch references to tick marks in the original table; direct patch links are consolidated under References & Patch Links below.
Attack Details
A professionalized ransomware-as-a-service ecosystem
The USA Manufacturing sector has absorbed sustained pressure from a professionalized ransomware-as-a-service ecosystem throughout 2025 and into 2026, layered over persistent espionage activity from state-nexus operators. Across 51 discrete campaigns aggregated for this landscape, ransomware families account for 27 of the 58 malware strains observed, with the balance made up of backdoors, infostealers, remote access trojans, loaders, and a cluster of dual-use tooling.
A shared code lineage across leading ransomware brands
The genealogical thread running through the leading ransomware brands is unmistakable: INC's source code, sold on Russian-speaking forums in May 2024 for $300,000, subsequently propagated into Lynx and then into Sinobi, which listed Manufacturing as its top 2025 vertical. Qilin held the top global ranking for three consecutive quarters through Q1 2026 with over 330 leak-site victims and a cumulative count exceeding 1,800 by late May 2026, expanding from double- to triple-extortion using DDoS pressure and a "Call Lawyer" negotiation feature. The Gentlemen, spun out from Qilin following the hastalamuerte departure in July 2025, scaled from 30 to over 320 publicly listed victims between autumn 2025 and April 2026, with Manufacturing among its most impacted sectors.
Edge infrastructure dominates initial access
Initial access into USA Manufacturing environments is dominated by exploitation of internet-facing edge infrastructure. Fortinet FortiGate appliances have been repeatedly abused via CVE-2024-55591, with one operator maintaining a curated inventory of roughly 14,700 pre-compromised devices, alongside 969 validated brute-forced VPN credentials, thereby reducing the reconnaissance phase to zero for downstream affiliates.
Legacy vulnerabilities remain highly exploitable
Citrix NetScaler exposures (CVE-2023-3519 and the more recent CVE-2025-5777 "Citrix Bleed 2"), Fortinet FortiClient EMS SQL injection (CVE-2023-48788), SimpleHelp remote support flaws, and SonicWall SSL VPN weaknesses have all been chained by multiple families. Ghost ransomware has compromised organizations in more than 70 countries by weaponizing the ProxyShell chain, along with Fortinet, Adobe, and SharePoint flaws dating back to 2009. Of the 37 unique CVEs aggregated, 97.3% already sit on the CISA KEV catalog with vendor patches available.
Post-exploitation tradecraft converges on durable techniques
Post-exploitation tradecraft across the campaign set converges on a small set of durable techniques. Credential harvesting relies on Mimikatz and modified Veeam credential dumpers upgraded for salted-DPAPI; lateral movement uses RDP, PsExec, WMI, WinRM, and Impacket-style atexec and smbexec; and command-and-control traverses Cobalt Strike beacons, SystemBC SOCKS5 proxies, AnyDesk fallback channels, and DNS-over-HTTPS covert tunnels.
Defense evasion has advanced sharply
The Gentlemen exploits CVE-2025-7771 in ThrottleStop.sys via a bring-your-own-vulnerable-driver technique to gain kernel-level code execution and terminate EDR, while Sinobi has been observed uninstalling Carbon Black from a compromised file server. Windows Subsystem for Linux is now used by Qilin to run components from a Linux runtime context on Windows hosts, deliberately evading endpoint tools that lack WSL visibility. Exfiltration overwhelmingly moves through RClone and WinSCP to cloud storage — AWS, BackBlaze, or attacker-controlled buckets.
A quieter nation-state espionage layer
Beyond financially motivated crime, USA Manufacturing has been squarely inside the targeting map of state-nexus espionage. The People's Republic of China-nexus WARP PANDA deployed the BRICKSTORM Go-based ELF backdoor against VMware vCenter environments at U.S. organizations in 2025, creating unregistered malicious virtual machines that are powered down after use to evade forensic recovery.
Long-dwell intelligence collection and irreversible impact tradecraft
Static Tundra, a Russian FSB Center 16 sub-cluster of Energetic Bear active since 2015, continues to weaponize a 2018-era Cisco Smart Install flaw to embed the SYNful Knock firmware implant into network devices for long-term intelligence collection. ShinyHunters has claimed access to CVE-2025-31324 in SAP NetWeaver and CVE-2025-61882 in Oracle E-Business Suite, with stolen datasets priced at up to $1 million. Impact tradecraft has trended toward speed and irreversibility: hybrid Curve25519/AES-128-CTR schemes with per-file keys, configurable partial-file encryption (1-9% on large files), shadow-copy destruction via low-level DeviceIoControl resize, and free-disk-space wiping with double and triple-extortion negotiations through Tor portals, Tox, and Session messengers.
Recommendations
Enforce a hard patch SLA on internet-facing appliances
VPN gateways, firewalls, ADCs, and remote-support tooling from Fortinet, SonicWall, Citrix, Ivanti, F5, ConnectWise ScreenConnect, and SimpleHelp are the single highest-risk technology category in this advisory. 14 of 37 tracked CVEs sit on this tier, and 97% are already on the CISA KEV catalogue. Establish a written 72-hour patch SLA from KEV inclusion, with executive escalation if breached, and maintain an authoritative inventory of every internet-facing appliance, including those managed by third parties.
Harden backup and recovery infrastructure as a targeted asset
Ransomware tradecraft across Qilin, INC, The Gentlemen, DragonForce, and Sinobi specifically destroys backup services, shadow copies, and ESXi hypervisors before encryption — recovery capability itself is the target. The 3-2-1 rule is no longer sufficient. Deploy immutable, off-network backups on a separate identity plane from the primary Active Directory forest, and test full-restore quarterly against a scenario in which AD and the hypervisor are lost together.
Segment the hypervisor and identity-management planes
vCenter, ESXi management, and Domain Controllers must live on separate administrative networks with dedicated privileged access workstations. A compromised helpdesk workstation should not be able to authenticate to vCenter or a Domain Controller. This segmentation directly counters the WARP PANDA / BRICKSTORM and Static Tundra / SYNful Knock intrusion patterns documented in this advisory, both of which pivot through the management plane for multi-year dwell.
Establish continuous external attack-surface discovery
Most intrusions in this advisory began with an internet-exposed asset the victim did not know it owned, inherited through a subsidiary, an acquisition, or an MSP handoff. Run a monthly outside-in scan of your public footprint (DNS, ASN ranges, subsidiary domains, third-party-hosted services) and reconcile the delta with the authoritative inventory. Every unknown asset is a candidate initial-access vector — this is a distinct discipline from vulnerability management: it answers what is exposed before asking what is vulnerable.
Indicators of Compromise
Indicators associated with the ransomware, backdoor, stealer, and loader families observed across U.S. manufacturing campaigns in this reporting window, spanning file hashes (SHA256/SHA1/MD5), network indicators (IPv4, domains, URLs), Tor/onion addresses, and threat-actor contact channels (email, Tox ID). Indicator counts are summarized by family and type below; the full indicator-by-indicator list is available on the Uni5Xposure platform.
| Attack / Malware Family | Indicator Types & Counts |
|---|---|
| Abyss Locker | SHA256 (15) |
| Anubis | SHA256 (1) |
| AsyncRAT | SHA256 (8) |
| Beast Ransomware | SHA256 (7) |
| BerserkStealer | IPv4 (1), SHA256 (2) |
| BlackNevas Ransomware | TOR (1), Email (15), SHA1 (60), MD5 (4), SHA256 (30) |
| BRICKSTORM | SHA256 (3) |
| CHROMEPUSH | Domain (1), SHA256 (1) |
| CMD Organization Ransomware | SHA1 (1), Email (4), Domain (1), Onion address (1) |
| Crypto24 Ransomware | SHA256 (6) |
| Daixin Team Ransomware | SHA256 (5), File Path (5), Tor Address (2) |
| DarkCloud | SHA256 (10) |
| DEEPBREATH | SHA256 (1) |
| Deno | Domain (11), IPv4 (6) |
| DEVMAN | SHA256 (1), SHA1 (1), MD5 (1), Filename (1), Mutex (1), Tox ID (1), TOR Address (1) |
| Dire Wolf Ransomware | SHA256 (2), SHA1 (2), MD5 (2), TOX ID (1), TOR Address (1), File Name (1), MD5 (1) |
| DragonForce | SHA1 (19), SHA256 (1), Tor Address (2) |
| EvilAI | SHA256 (1) |
| FunkSec Ransomware | SHA256 (8) |
| Ghost Ransomware | MD5 (14) |
| Ghost RAT | MD5 (1), SHA1 (1), SHA256 (2), IPv4:Port (1), File Path (1) |
| GlassWorm | SHA256 (13) |
| GLOBAL Ransomware | SHA256 (1), TOR Address (2) |
| Hellcat Ransomware | SHA256 (5) |
| HYPERCALL | Domain (2), SHA256 (2) |
| INC Ransomware | SHA256 (1) |
| Interlock ransomware | SHA256 (7) |
| Interlock RAT | SHA256 (2), IPv4 (2), Domains (6) |
| Lumma Stealer | SHA256 (16), Domain (1), Email (1) |
| Lynx Ransomware | SHA256 (6) |
| Medusa Ransomware | SHA256 (9) |
| Meduza | SHA256 (9) |
| Mesh Agent | SHA256 (2) |
| MixShell | SHA256 (1) |
| Nitrogen Ransomware | SHA256 (10) |
| Akira | MD5 (1), SHA256 (14) |
| Clop | SHA1 (4) |
| Dragon Force | SHA1 (10), SHA256 (1) |
| Play | SHA1 (1), IPv4 (3), URLs (6), Tor Leak Site (1), Ransom Note Filename (3) |
| Qilin | IPv4 (2), SHA1 (1), SHA256 (8) |
| StealC | SHA256 (5) |
A comprehensive list of IOCs associated with the executed attacks referenced in this advisory is available on the Uni5Xposure platform.
MITRE ATT&CK TTPs
| Technique ID | Tactic | Description |
|---|---|---|
T1190 | Initial Access | Exploit Public-Facing Application |
T1566 | Initial Access | Phishing |
T1566.001 | Initial Access — Sub-technique | Spearphishing Attachment |
T1566.002 | Initial Access — Sub-technique | Spearphishing Link |
T1566.004 | Initial Access — Sub-technique | Spearphishing Voice |
T1078 | Initial Access | Valid Accounts |
T1078.002 | Initial Access — Sub-technique | Domain Accounts |
T1195 | Initial Access | Supply Chain Compromise |
T1195.002 | Initial Access — Sub-technique | Compromise Software Supply Chain |
T1059 | Execution | Command and Scripting Interpreter |
T1059.001 | Execution — Sub-technique | PowerShell |
T1569 | Execution | System Services |
T1569.002 | Execution — Sub-technique | Service Execution |
T1204 | Execution | User Execution |
T1204.002 | Execution — Sub-technique | Malicious File |
T1505 | Execution | Server Software Component |
T1505.003 | Execution — Sub-technique | Web Shell |
T1543 | Persistence | Create or Modify System Process |
T1543.003 | Persistence — Sub-technique | Windows Service |
T1547 | Persistence | Boot or Logon Autostart Execution |
T1547.001 | Persistence — Sub-technique | Registry Run Keys / Startup Folder |
T1542 | Persistence | Pre-OS Boot |
T1542.001 | Persistence — Sub-technique | System Firmware |
T1068 | Privilege Escalation | Exploitation for Privilege Escalation |
T1211 | Defense Evasion | Exploitation for Defense Evasion |
T1562 | Defense Evasion | Impair Defenses |
T1562.001 | Defense Evasion — Sub-technique | Disable or Modify Tools |
T1027 | Defense Evasion | Obfuscated Files or Information |
T1018 | Discovery | Remote System Discovery |
T1069 | Discovery | Permission Groups Discovery |
T1069.002 | Discovery — Sub-technique | Domain Groups |
T1021 | Lateral Movement | Remote Services |
T1021.001 | Lateral Movement — Sub-technique | Remote Desktop Protocol |
T1021.002 | Lateral Movement — Sub-technique | SMB / Windows Admin Shares |
T1570 | Lateral Movement | Lateral Tool Transfer |
T1071 | Command and Control | Application Layer Protocol |
T1071.001 | Command and Control — Sub-technique | Web Protocols |
T1071.004 | Command and Control — Sub-technique | DNS |
T1573 | Command and Control | Encrypted Channel |
T1573.002 | Command and Control — Sub-technique | Asymmetric Cryptography |
T1105 | Command and Control | Ingress Tool Transfer |
T1567 | Exfiltration | Exfiltration Over Web Service |
T1567.002 | Exfiltration — Sub-technique | Exfiltration to Cloud Storage |
T1560 | Collection | Archive Collected Data |
T1560.001 | Collection — Sub-technique | Archive via Utility |
T1486 | Impact | Data Encrypted for Impact |
T1490 | Impact | Inhibit System Recovery |
T1489 | Impact | Service Stop |
T1498 | Impact | Network Denial of Service |
References & Patch Links