Factory Reset: How Attackers Are Halting U.S. Production Floors

Red | Attack
Download PDF
TA2026213 | Factory Reset: How Attackers Are Halting U.S. Production Floors

Threat Advisory • Attack Report • Admiralty Code A1

Factory Reset: How Attackers Are Halting U.S. Production Floors

A landscape assessment of the ransomware ecosystem targeting the U.S. Manufacturing sector, covering 45 distinct campaigns, dominant ransomware brands, exploited edge-appliance CVEs, and the espionage layer operating beneath the extortion economy.

TA Number:TA2026213Date of Publication: July 28, 2026Admiralty Code: A1Targeted Region: United StatesTargeted Sector: Manufacturing
Ransomware: Akira, Qilin, Play, Clop, DragonForce, INC37 CVEs in Scope14 Zero-Days (37.8%)36/37 on CISA KEV (97.3%)36/37 Vendor-Patched45 Campaigns Tracked
RegionUnited States
SectorManufacturing
PlatformsWindows, Linux, VMware ESXi, network appliances
Exploited CVEs37
Malware Families58
Ransomware Groups88
Zero-Days14
CISA KEV Coverage36 / 37
Campaigns Aggregated45

U.S. Manufacturing Under Sustained Ransomware Pressure

The U.S. Manufacturing sector sat at the sharp end of the ransomware curve across the reporting window, with 45 distinct campaigns converging on a single reality: the network perimeter is the front door, and it is unlocked. Akira dominated the leaderboard while emerging brands scaled fastest beneath it, and a synchronised late-2025 pileup pointed to a shared upstream trigger the sector should expect to see repeat. Weaponised CVEs clustered on VPNs, firewalls and remote-support tooling, with backup infrastructure specifically targeted for destruction before encryption. Behind the ransomware volume sat a quieter nation-state espionage layer aimed at long-dwell access, a reminder that for manufacturers with defense, aerospace or semiconductor exposure, the intellectual-property threat is as serious as the extortion one.

Targeted platforms span Windows, Linux, VMware ESXi, and network appliances. Dominant ransomware brands active against U.S. manufacturing include Akira, Qilin, Play, Clop, Dragon Force, and INC. A total of 37 unique CVEs sit in scope for this landscape, 14 of which (37.8%) were exploited as zero-days, and 36 of which (97.3%) are listed on the CISA Known Exploited Vulnerabilities (KEV) catalogue.

By the Numbers
37Exploited CVEs tracked
58Malware families observed
88Ransomware groups tracked
14Exploited as zero-days
Reading the numbers: Nearly all weaponised CVEs (36 of 37) are already CISA KEV-listed, and 36 of 37 have a vendor patch; the exposure is overwhelmingly from known, patchable flaws left unpatched rather than novel zero-days.
Most Recurring Threats

The CVE, ransomware, and malware seen most often against the U.S. manufacturing sector, based on leak-site activity and campaign tracking across the reporting window.

  • 01Most Active Ransomware:Akira — 361 leak-site victim posts
  • 02Most Recurring in Campaigns:Qilin — tracked in multiple campaigns
  • 03Most Recurring Malware:StealC — tied across multiple stealer campaigns
  • 04Most Recurring CVE:CVE-2024-55591 — Fortinet FortiOS auth-bypass

Akira dominates manufacturing leak-site postings, roughly double the next brand (Qilin). Together, the top five ransomware brands — Akira, Qilin, Play, Clop, and DragonForce — account for the bulk of publicly claimed victims. Leak-site victim-post counts reflect publicly claimed victims on each group's data-leak site.

Malware Analysis

58 tracked malware families were grouped by type for this landscape. Ransomware leads at 47% (27 of 58 families), confirming extortion as the primary end goal targeting U.S. manufacturing. Information stealers and backdoors follow at 16% each — stealers harvest the credentials that open the door, while backdoors give the persistent, quiet access espionage crews and ransomware affiliates rely on. Loaders/downloaders (9%) and RATs (7%) round out the delivery-and-control toolkit. Read together, the mix describes a full intrusion lifecycle: steal access, establish persistence, then encrypt or exfiltrate for extortion.

Affected Products

37 exploited CVEs were grouped by the type of product targeted. Edge, VPN, and remote-access appliances dominate, accounting for 18 of the 37 CVEs. Fortinet, Ivanti, Citrix, SonicWall, SimpleHelp, and ConnectWise devices are the principal doorway into manufacturing networks: internet-facing, often under-patched, and sitting directly on the perimeter. Web/application/middleware products (7 CVEs) — SAP NetWeaver, Oracle, Log4j, Confluence, and ColdFusion — and virtualization/hypervisor plus email/collaboration servers (4 CVEs each) round out the attack surface.

The pattern is clear: exposure is concentrated at the network edge and in shared enterprise software beneath production systems. Half of all exploited CVEs target the perimeter itself — the appliances that face the internet before any production system is reached. Segmenting OT/production networks behind these devices, and patching the edge first, delivers the largest reduction in blast radius.

Affected Vendors

Exploited CVEs by vendor area are proportional to the number of weaponised vulnerabilities. Microsoft, Fortinet, and VMware carry the largest weaponised footprint, followed closely by SimpleHelp, SonicWall, and Ivanti. Two themes emerge. First, security and remote-access vendors — Fortinet, SonicWall, Ivanti, Citrix, SimpleHelp, ConnectWise, and F5 — the very products bought to protect the network, are the most-exploited class of appliance. Second, core enterprise platforms — Microsoft, VMware, Oracle, SAP, Adobe, Atlassian, and Apache — underpin production and back-office systems, so a single vendor flaw cascades widely. Concentrating patch and monitoring effort on this short vendor list covers the majority of the sector's exploited exposure.

Vulnerability Posture

How dangerous and how actionable the exploited CVEs are, aggregated across the 37 CVEs tracked in this advisory.

36 / 37Listed in CISA KEV
14 / 37Exploited as zero-days
36 / 37Have a vendor patch

97% of weaponised CVEs are already in CISA's Known Exploited Vulnerabilities catalogue, and 97% have a patch available, meaning the vast majority of manufacturing's exposure is remediable today and is being exploited because patch lag, not novel zero-days, is the gap. The 14 zero-days that do appear cluster in edge appliances (Fortinet, Citrix, Ivanti, Oracle), underscoring why perimeter devices demand the fastest possible patch SLAs.

Exploited CVEs — Full Table

All 37 CVEs aggregated for this landscape, with CISA KEV status and vendor-patch availability. Per-CVE zero-day flags were not separately resolvable from the source table layout; the aggregate 14/37 zero-day figure is presented above in Vulnerability Posture.

CVENameAffected ProductCISA KEVPatch
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityCitrix NetScaler ADC and NetScaler Gateway
CVE-2023-48788Fortinet FortiClient EMS SQL Injection VulnerabilityFortinet FortiClient EMS
CVE-2024-57727SimpleHelp Path Traversal VulnerabilitySimpleHelp Remote Support Software
CVE-2025-5777Citrix NetScaler Gateway Out-of-Bounds Read Vulnerability (“Citrix Bleed 2”)Citrix NetScaler ADC and NetScaler Gateway
CVE-2021-20038SonicWall SMA 100 Appliances Stack-Based Buffer Overflow VulnerabilitySonicWall SMA 100 Appliances
CVE-2009-3960Adobe BlazeDS Information Disclosure VulnerabilityAdobe BlazeDS 3.2 and earlier
CVE-2010-2861Adobe ColdFusion Directory Traversal VulnerabilityAdobe ColdFusion 9.0.1 and earlier
CVE-2018-13379Fortinet FortiOS SSL VPN Path Traversal VulnerabilityFortinet FortiOS, FortiProxy
CVE-2019-0604Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft SharePoint
CVE-2021-31207ProxyShell – Microsoft Exchange Server Security Feature Bypass VulnerabilityMicrosoft Exchange Server
CVE-2021-34473ProxyShell – Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server
CVE-2021-34523ProxyShell – Microsoft Exchange Server Privilege Escalation VulnerabilityMicrosoft Exchange Server
CVE-2024-40766SonicWall SonicOS Improper Access Control VulnerabilitySonicWall SonicOS SOHO (Gen 5)
CVE-2024-53704SonicWall SonicOS SSLVPN Improper Authentication VulnerabilitySonicWALL Gen7 NSv
CVE-2023-27532Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function VulnerabilityVeeam Backup & Replication Cloud Connect
CVE-2024-37085VMware ESXi Authentication Bypass VulnerabilityVMware ESXi
CVE-2024-55591Fortinet FortiOS Authorization Bypass VulnerabilityFortinet FortiOS
CVE-2025-7771TechPowerUp ThrottleStop Privilege Escalation VulnerabilityTechPowerUp ThrottleStop
CVE-2024-21762Fortinet FortiOS SSL-VPN Out-of-Bounds Write VulnerabilityFortinet FortiOS
CVE-2025-31324SAP NetWeaver Unrestricted File Upload VulnerabilitySAP NetWeaver Visual Composer
CVE-2018-0171Cisco IOS and IOS XE Software Smart Install Remote Code Execution VulnerabilityCisco IOS and IOS XE Software
CVE-2021-44228Log4Shell – Apache Log4j Remote Code Execution VulnerabilityApache Log4j2
CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityAtlassian Confluence Server
CVE-2023-46805Ivanti Connect Secure and Policy Secure Authentication Bypass VulnerabilityIvanti Connect Secure and Policy Secure
CVE-2024-21412Microsoft Windows Internet Shortcut Files Security Feature Bypass VulnerabilityMicrosoft Windows Internet Shortcut Files
CVE-2024-21887Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityIvanti Connect Secure and Policy Secure
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) VulnerabilityIvanti Connect Secure, Ivanti Policy Secure and Ivanti Neurons for ZTA
CVE-2024-57726SimpleHelp Missing Authorization VulnerabilitySimpleHelp remote support software
CVE-2024-57728SimpleHelp Path Traversal VulnerabilitySimpleHelp remote support software
CVE-2023-20118Cisco Small Business RV Series Routers Command Injection VulnerabilityCisco Small Business RV Series Routers
CVE-2021-35587Oracle Fusion Middleware Unspecified VulnerabilityOracle Access Manager product of Oracle Fusion Middleware
CVE-2025-61882Oracle E-Business Suite Unspecified VulnerabilityOracle E-Business Suite
CVE-2024-1709ConnectWise ScreenConnect Authentication Bypass VulnerabilityConnectWise ScreenConnect
CVE-2021-22005VMware vCenter Server File Upload VulnerabilityVMware vCenter Server
CVE-2023-34048VMware vCenter Server Out-of-Bounds Write VulnerabilityVMware vCenter Server
CVE-2023-46747F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityF5 BIG-IP Configuration Utility
CVE-2024-38812VMware vCenter Server Heap-Overflow VulnerabilityVMware vCenter Server, VMware Cloud Foundation

Note: the source report hyperlinks CVE patch references to tick marks in the original table; direct patch links are consolidated under References & Patch Links below.


How the Manufacturing Sector Was Compromised

#1

A professionalized ransomware-as-a-service ecosystem

The USA Manufacturing sector has absorbed sustained pressure from a professionalized ransomware-as-a-service ecosystem throughout 2025 and into 2026, layered over persistent espionage activity from state-nexus operators. Across 51 discrete campaigns aggregated for this landscape, ransomware families account for 27 of the 58 malware strains observed, with the balance made up of backdoors, infostealers, remote access trojans, loaders, and a cluster of dual-use tooling.

#2

A shared code lineage across leading ransomware brands

The genealogical thread running through the leading ransomware brands is unmistakable: INC's source code, sold on Russian-speaking forums in May 2024 for $300,000, subsequently propagated into Lynx and then into Sinobi, which listed Manufacturing as its top 2025 vertical. Qilin held the top global ranking for three consecutive quarters through Q1 2026 with over 330 leak-site victims and a cumulative count exceeding 1,800 by late May 2026, expanding from double- to triple-extortion using DDoS pressure and a "Call Lawyer" negotiation feature. The Gentlemen, spun out from Qilin following the hastalamuerte departure in July 2025, scaled from 30 to over 320 publicly listed victims between autumn 2025 and April 2026, with Manufacturing among its most impacted sectors.

#3

Edge infrastructure dominates initial access

Initial access into USA Manufacturing environments is dominated by exploitation of internet-facing edge infrastructure. Fortinet FortiGate appliances have been repeatedly abused via CVE-2024-55591, with one operator maintaining a curated inventory of roughly 14,700 pre-compromised devices, alongside 969 validated brute-forced VPN credentials, thereby reducing the reconnaissance phase to zero for downstream affiliates.

#4

Legacy vulnerabilities remain highly exploitable

Citrix NetScaler exposures (CVE-2023-3519 and the more recent CVE-2025-5777 "Citrix Bleed 2"), Fortinet FortiClient EMS SQL injection (CVE-2023-48788), SimpleHelp remote support flaws, and SonicWall SSL VPN weaknesses have all been chained by multiple families. Ghost ransomware has compromised organizations in more than 70 countries by weaponizing the ProxyShell chain, along with Fortinet, Adobe, and SharePoint flaws dating back to 2009. Of the 37 unique CVEs aggregated, 97.3% already sit on the CISA KEV catalog with vendor patches available.

#5

Post-exploitation tradecraft converges on durable techniques

Post-exploitation tradecraft across the campaign set converges on a small set of durable techniques. Credential harvesting relies on Mimikatz and modified Veeam credential dumpers upgraded for salted-DPAPI; lateral movement uses RDP, PsExec, WMI, WinRM, and Impacket-style atexec and smbexec; and command-and-control traverses Cobalt Strike beacons, SystemBC SOCKS5 proxies, AnyDesk fallback channels, and DNS-over-HTTPS covert tunnels.

#6

Defense evasion has advanced sharply

The Gentlemen exploits CVE-2025-7771 in ThrottleStop.sys via a bring-your-own-vulnerable-driver technique to gain kernel-level code execution and terminate EDR, while Sinobi has been observed uninstalling Carbon Black from a compromised file server. Windows Subsystem for Linux is now used by Qilin to run components from a Linux runtime context on Windows hosts, deliberately evading endpoint tools that lack WSL visibility. Exfiltration overwhelmingly moves through RClone and WinSCP to cloud storage — AWS, BackBlaze, or attacker-controlled buckets.

#7

A quieter nation-state espionage layer

Beyond financially motivated crime, USA Manufacturing has been squarely inside the targeting map of state-nexus espionage. The People's Republic of China-nexus WARP PANDA deployed the BRICKSTORM Go-based ELF backdoor against VMware vCenter environments at U.S. organizations in 2025, creating unregistered malicious virtual machines that are powered down after use to evade forensic recovery.

#8

Long-dwell intelligence collection and irreversible impact tradecraft

Static Tundra, a Russian FSB Center 16 sub-cluster of Energetic Bear active since 2015, continues to weaponize a 2018-era Cisco Smart Install flaw to embed the SYNful Knock firmware implant into network devices for long-term intelligence collection. ShinyHunters has claimed access to CVE-2025-31324 in SAP NetWeaver and CVE-2025-61882 in Oracle E-Business Suite, with stolen datasets priced at up to $1 million. Impact tradecraft has trended toward speed and irreversibility: hybrid Curve25519/AES-128-CTR schemes with per-file keys, configurable partial-file encryption (1-9% on large files), shadow-copy destruction via low-level DeviceIoControl resize, and free-disk-space wiping with double and triple-extortion negotiations through Tor portals, Tox, and Session messengers.


Reducing Manufacturing's Ransomware Exposure

01

Enforce a hard patch SLA on internet-facing appliances

VPN gateways, firewalls, ADCs, and remote-support tooling from Fortinet, SonicWall, Citrix, Ivanti, F5, ConnectWise ScreenConnect, and SimpleHelp are the single highest-risk technology category in this advisory. 14 of 37 tracked CVEs sit on this tier, and 97% are already on the CISA KEV catalogue. Establish a written 72-hour patch SLA from KEV inclusion, with executive escalation if breached, and maintain an authoritative inventory of every internet-facing appliance, including those managed by third parties.

02

Harden backup and recovery infrastructure as a targeted asset

Ransomware tradecraft across Qilin, INC, The Gentlemen, DragonForce, and Sinobi specifically destroys backup services, shadow copies, and ESXi hypervisors before encryption — recovery capability itself is the target. The 3-2-1 rule is no longer sufficient. Deploy immutable, off-network backups on a separate identity plane from the primary Active Directory forest, and test full-restore quarterly against a scenario in which AD and the hypervisor are lost together.

03

Segment the hypervisor and identity-management planes

vCenter, ESXi management, and Domain Controllers must live on separate administrative networks with dedicated privileged access workstations. A compromised helpdesk workstation should not be able to authenticate to vCenter or a Domain Controller. This segmentation directly counters the WARP PANDA / BRICKSTORM and Static Tundra / SYNful Knock intrusion patterns documented in this advisory, both of which pivot through the management plane for multi-year dwell.

04

Establish continuous external attack-surface discovery

Most intrusions in this advisory began with an internet-exposed asset the victim did not know it owned, inherited through a subsidiary, an acquisition, or an MSP handoff. Run a monthly outside-in scan of your public footprint (DNS, ASN ranges, subsidiary domains, third-party-hosted services) and reconcile the delta with the authoritative inventory. Every unknown asset is a candidate initial-access vector — this is a distinct discipline from vulnerability management: it answers what is exposed before asking what is vulnerable.


IOCs (Indicators of Compromise)

Indicators associated with the ransomware, backdoor, stealer, and loader families observed across U.S. manufacturing campaigns in this reporting window, spanning file hashes (SHA256/SHA1/MD5), network indicators (IPv4, domains, URLs), Tor/onion addresses, and threat-actor contact channels (email, Tox ID). Indicator counts are summarized by family and type below; the full indicator-by-indicator list is available on the Uni5Xposure platform.

Attack / Malware FamilyIndicator Types & Counts
Abyss LockerSHA256 (15)
AnubisSHA256 (1)
AsyncRATSHA256 (8)
Beast RansomwareSHA256 (7)
BerserkStealerIPv4 (1), SHA256 (2)
BlackNevas RansomwareTOR (1), Email (15), SHA1 (60), MD5 (4), SHA256 (30)
BRICKSTORMSHA256 (3)
CHROMEPUSHDomain (1), SHA256 (1)
CMD Organization RansomwareSHA1 (1), Email (4), Domain (1), Onion address (1)
Crypto24 RansomwareSHA256 (6)
Daixin Team RansomwareSHA256 (5), File Path (5), Tor Address (2)
DarkCloudSHA256 (10)
DEEPBREATHSHA256 (1)
DenoDomain (11), IPv4 (6)
DEVMANSHA256 (1), SHA1 (1), MD5 (1), Filename (1), Mutex (1), Tox ID (1), TOR Address (1)
Dire Wolf RansomwareSHA256 (2), SHA1 (2), MD5 (2), TOX ID (1), TOR Address (1), File Name (1), MD5 (1)
DragonForceSHA1 (19), SHA256 (1), Tor Address (2)
EvilAISHA256 (1)
FunkSec RansomwareSHA256 (8)
Ghost RansomwareMD5 (14)
Ghost RATMD5 (1), SHA1 (1), SHA256 (2), IPv4:Port (1), File Path (1)
GlassWormSHA256 (13)
GLOBAL RansomwareSHA256 (1), TOR Address (2)
Hellcat RansomwareSHA256 (5)
HYPERCALLDomain (2), SHA256 (2)
INC RansomwareSHA256 (1)
Interlock ransomwareSHA256 (7)
Interlock RATSHA256 (2), IPv4 (2), Domains (6)
Lumma StealerSHA256 (16), Domain (1), Email (1)
Lynx RansomwareSHA256 (6)
Medusa RansomwareSHA256 (9)
MeduzaSHA256 (9)
Mesh AgentSHA256 (2)
MixShellSHA256 (1)
Nitrogen RansomwareSHA256 (10)
AkiraMD5 (1), SHA256 (14)
ClopSHA1 (4)
Dragon ForceSHA1 (10), SHA256 (1)
PlaySHA1 (1), IPv4 (3), URLs (6), Tor Leak Site (1), Ransom Note Filename (3)
QilinIPv4 (2), SHA1 (1), SHA256 (8)
StealCSHA256 (5)

A comprehensive list of IOCs associated with the executed attacks referenced in this advisory is available on the Uni5Xposure platform.


Potential MITRE ATT&CK TTPs

Technique IDTacticDescription
T1190Initial AccessExploit Public-Facing Application
T1566Initial AccessPhishing
T1566.001Initial Access — Sub-techniqueSpearphishing Attachment
T1566.002Initial Access — Sub-techniqueSpearphishing Link
T1566.004Initial Access — Sub-techniqueSpearphishing Voice
T1078Initial AccessValid Accounts
T1078.002Initial Access — Sub-techniqueDomain Accounts
T1195Initial AccessSupply Chain Compromise
T1195.002Initial Access — Sub-techniqueCompromise Software Supply Chain
T1059ExecutionCommand and Scripting Interpreter
T1059.001Execution — Sub-techniquePowerShell
T1569ExecutionSystem Services
T1569.002Execution — Sub-techniqueService Execution
T1204ExecutionUser Execution
T1204.002Execution — Sub-techniqueMalicious File
T1505ExecutionServer Software Component
T1505.003Execution — Sub-techniqueWeb Shell
T1543PersistenceCreate or Modify System Process
T1543.003Persistence — Sub-techniqueWindows Service
T1547PersistenceBoot or Logon Autostart Execution
T1547.001Persistence — Sub-techniqueRegistry Run Keys / Startup Folder
T1542PersistencePre-OS Boot
T1542.001Persistence — Sub-techniqueSystem Firmware
T1068Privilege EscalationExploitation for Privilege Escalation
T1211Defense EvasionExploitation for Defense Evasion
T1562Defense EvasionImpair Defenses
T1562.001Defense Evasion — Sub-techniqueDisable or Modify Tools
T1027Defense EvasionObfuscated Files or Information
T1018DiscoveryRemote System Discovery
T1069DiscoveryPermission Groups Discovery
T1069.002Discovery — Sub-techniqueDomain Groups
T1021Lateral MovementRemote Services
T1021.001Lateral Movement — Sub-techniqueRemote Desktop Protocol
T1021.002Lateral Movement — Sub-techniqueSMB / Windows Admin Shares
T1570Lateral MovementLateral Tool Transfer
T1071Command and ControlApplication Layer Protocol
T1071.001Command and Control — Sub-techniqueWeb Protocols
T1071.004Command and Control — Sub-techniqueDNS
T1573Command and ControlEncrypted Channel
T1573.002Command and Control — Sub-techniqueAsymmetric Cryptography
T1105Command and ControlIngress Tool Transfer
T1567ExfiltrationExfiltration Over Web Service
T1567.002Exfiltration — Sub-techniqueExfiltration to Cloud Storage
T1560CollectionArchive Collected Data
T1560.001Collection — Sub-techniqueArchive via Utility
T1486ImpactData Encrypted for Impact
T1490ImpactInhibit System Recovery
T1489ImpactService Stop
T1498ImpactNetwork Denial of Service

References