Home
Elezar
Sol Threat Intelligence

June 2026
Energy, Gas, Oil and Utilities
Regional Sector Brief

Download PDF
1 Jun to 30 Jun 20263 regional assessments4 pages per regionPrepared by Kaartheeswaran Ravichandran
A futuristic energy grid showing a cyber intrusion across critical infrastructure
Americas
Executive Summary
VOLTZITE pre-positioning and FortiBleed compound the world’s highest ransomware exposure

The Americas, led by the United States, carried the highest ransomware burden in every June reporting week. The United States accounted for 32.10 to 45.59 percent of global ransomware victims, while Canada reached 7.35 percent in the week of 2 to 8 June. Energy and utilities also faced a distinct nation-state threat through VOLTZITE pre-positioning against electric and water infrastructure, plus FortiBleed, a Russian-speaking initial-access campaign that compromised more than 430,000 FortiGate devices and captured over 110 million credentials. No source report named a specific Americas energy victim, so the brief separates region-wide exposure from confirmed sector targeting.

Key Insights
1
VOLTZITE was confirmed conducting slow, low-noise reconnaissance and pre-positioning against US electric, water and utility infrastructure.
2
FortiBleed affected more than 430,000 FortiGate devices, with 10.1 percent of compromised devices located in the United States.
3
The United States represented between 32.10 and 45.59 percent of all global ransomware victims across June reporting weeks.
4
DragonForce explicitly targeted organizations above USD 15 million revenue and used SimpleHelp exploitation plus BYOVD EDR termination.
5
The 3AM chain used email flooding, IT-helpdesk vishing, Quick Assist, a QEMU-hosted backdoor and 868 GB of pre-encryption exfiltration.
6
Operation Endgame disrupted Amadey and StealC, but already-stolen remote-access and browser credentials remained available to access brokers.
Attack chains, vulnerabilities and indicators
CVEProductCVSSJune context
CVE-2026-0257Palo Alto PAN-OS9.1Widely deployed perimeter technology
CVE-2026-20253Splunk Enterprise9.8SIEM and monitoring risk
CVE-2024-57726/27/28SimpleHelp RMMHighMSP and remote substation support
CVE-2023-28252Windows CLFSHighRansomware privilege escalation
CVE-2023-46805 / CVE-2024-21887Ivanti Connect SecureCriticalRemote-access exploitation
CVE-2022-42475FortiGate SSL VPNCriticalVOLTZITE edge access and FortiGate exposure
CVE-2021-44228Apache Log4j10.0Persistent public-application risk
VOLTZITE OT pre-positioning
Attack PathELEZAR
01
Exploit FortiGate, Ivanti or ManageEngine edge service
T1190
02
Use valid accounts and LOLBins
T1078 · T1218
03
Route C2 through JDY-compromised routers
T1090
04
Enumerate AD and OT-adjacent assets
T1003.003
05
netsh portproxy and data staging
T1560
06
Maintain low-noise access for future disruption
FortiBleed credential harvesting
Attack PathELEZAR
01
Mass FortiGate scanning and credential stuffing
T1110.004
02
Native diagnose sniffer packet command
T1040
03
Passive capture of Kerberos, NTLM, RADIUS and LDAP traffic
04
Hash exfiltration to GPU cracking infrastructure
T1048
05
Downstream exploitation and SMB or DFS collection
T1021.002
06
Access brokerage and ransomware hand-off
3AM helpdesk compromise
Attack PathELEZAR
01
Mailing-list flood
02
Spoofed IT helpdesk call
T1566.004
03
Microsoft Quick Assist session
T1219
04
QEMU Windows 7 VM with QDoor
T1610
05
C2 to 88[.]118[.]167[.]239 and 172[.]86[.]121[.]134
06
Nine-day dwell and GoodSync exfiltration
T1567.002
07
Backup deletion and .threeamtime encryption
T1490 · T1486

Selected indicators

TypeIndicatorAttribution
IP149[.]248[.]3[.]38:13339VOLTZITE / JDY
ProcessauditdyJDY botnet
IP88[.]118[.]167[.]239:443 / 172[.]86[.]121[.]1343AM QDoor
TaskWindowsSensor153AM persistence
DriverTruesight.sys / RentDrv.sysDragonForce
IP185[.]215[.]113[.]206 / 185[.]215[.]113[.]17 / 62[.]204[.]41[.]151Amadey / StealC
Commandwbadmin.exe delete systemstatebackup -keepVersions:0 -quiet3AM backup destruction
Prioritized defensive guidance

Recommendations are calibrated for distributed utility operations, OT and ICS estates, remote-access infrastructure, MSP dependencies and high-impact service continuity requirements.

Immediate: act within 7 days
1. Treat FortiGate credentials that traversed exposed devices as potentially compromised and rotate them.
2. Patch PAN-OS and Ivanti gateways or isolate them behind allowlisted management paths.
3. Block and hunt DragonForce BYOVD drivers across Windows and OT-adjacent systems.
Urgent: act within 30 days
1. Deploy VOLTZITE living-off-the-land hunting for netsh portproxy, csvde, certutil, 7-Zip and ntds.dit access.
2. Detect QEMU processes, ACOW2 or QCOW2 files and WindowsSensor15 scheduled tasks.
3. Patch SimpleHelp and review all MSP sessions into substations and OT-support networks.
4. Rotate VPN, WinSCP and browser-stored credentials exposed through infostealer ecosystems.
5. Audit GPO changes and prevent domain-wide Chrome credential harvesting.
Ongoing detection and resilience
1. Maintain offline immutable backups for historians, SCADA databases and engineering files.
2. Deploy TLS certificate hunting for AsyncRAT-family C2 infrastructure.
3. Use OT NDR to identify slow reconnaissance and anomalous IT-to-OT communication.
4. Map response procedures to NERC CIP and relevant utility-sector reporting obligations.
June source reports: DomainTools and Dragos VOLTZITE reporting, Lumen JDY analysis, SOCRadar FortiBleed reporting, Red Piranha weekly reports, and Operation Endgame reporting from June 2026.
EMEA
Executive Summary
Ransomware, credential theft and RAT infrastructure dominate the sector risk

EMEA energy and utilities faced a criminally dominated threat environment in June 2026. No source report named a specific EMEA energy victim, but Europe was heavily represented in global ransomware activity, with Germany accounting for 5.15 percent of victims during the week of 2 to 8 June. The most important sector risks were LockBit-derived ransomware families, the Amadey and StealC credential ecosystem, a broad AsyncRAT family infrastructure footprint and the emergence of AiLock with post-quantum key encapsulation and GDPR-focused extortion pressure.

Key Insights
1
Deadlock, Qilin, The Gentlemen, Brain Cipher and DragonForce maintained broad European reach through RaaS affiliate structures.
2
AiLock explicitly weaponized GDPR notification pressure and used ChaCha20 with NTRUEncrypt256.
3
Securotrop, a Qilin affiliate, deployed a GPO-based PowerShell script to steal Chrome credentials across domain-joined hosts before encryption.
4
DragonForce used SimpleHelp exploitation and BYOVD drivers, creating direct risk for energy operators dependent on MSPs.
5
Operation Endgame removed 47 domains and actioned 182 Amadey and StealC C2 IPs, but the source code and replacement infrastructure remained available.
6
Censys identified 13 live AsyncRAT descendants, including VenomRAT, DCRat and Gh0st RAT variants.
Attack chains, vulnerabilities and indicators
CVEProductCVSSJune context
CVE-2026-0257Palo Alto PAN-OS9.1Perimeter VPN and firewall exposure
CVE-2026-20253Splunk Enterprise9.8Monitoring platform compromise
CVE-2024-57726/27/28SimpleHelp RMMHighMSP supply-chain access
CVE-2023-28252Windows CLFSHighRansomware privilege escalation
CVE-2023-46805 / CVE-2024-21887Ivanti Connect SecureCriticalRemote access gateway exploitation
CVE-2021-44228Apache Log4j10.0Persistent initial-access vector
CVE-2025-5777Citrix NetScalerCriticalSession theft and remote access risk
LockBit-derived ransomware
Attack PathELEZAR
01
Exposed VPN, RDP, public application or MSP access
T1190
02
PowerShell and cmd execution
03
CLFS LPE or BYOVD EDR termination
T1068
04
LSASS and Chrome credential theft
T1003.001 · T1555.003
05
RDP, SMB, PsExec, WMIC and GPO spread
T1021
06
Service stop and event-log clearing
T1489
07
Shadow-copy deletion, encryption and double extortion
T1490 · T1486
AiLock post-quantum RaaS
Attack PathELEZAR
01
Operator launches with -full, -path or -shares
02
Token impersonation and dynamic API resolution
T1134.001
03
Network-share enumeration through WNet APIs
T1021.002
04
ChaCha20 file encryption
T1486
05
NTRUEncrypt256 key encapsulation
06
.AiLock extension, Readme.txt and regulatory pressure
T1657
Amadey to StealC
Attack PathELEZAR
01
Malicious installer or phishing delivery
T1204.002
02
Amadey host fingerprinting and persistence
03
Hidden admin, RDP and SOCKS5 enablement
T1136.001 · T1021.001 · T1090
04
StealC APC injection into suspended process
T1055.004
05
Browser, Outlook, WinSCP and wallet credential theft
T1555.003
06
RC4-encrypted HTTP exfiltration

Selected indicators

TypeIndicatorAttribution
SHA256410db536a57c511b0ccac2639e0eb3320f303fc5c90242379ab43364c51ef321DragonForce
DriverTruesight.sys / RentDrv.sysDragonForce
FileC:\temp\w.exeSecurotrop staging
MutexFAUSTAiLock
IP185[.]215[.]113[.]206 / 185[.]215[.]113[.]17 / 62[.]204[.]41[.]151Amadey / StealC
IP192[.]229[.]116[.]23 / 192[.]238[.]134[.]73 / 107[.]175[.]159[.]134AsyncRAT family
TaskWindowsSensor153AM persistence
Prioritized defensive guidance

Recommendations are calibrated for distributed utility operations, OT and ICS estates, remote-access infrastructure, MSP dependencies and high-impact service continuity requirements.

Immediate: act within 7 days
1. Patch PAN-OS and Ivanti gateways or isolate them behind trusted source restrictions.
2. Block Truesight.sys and RentDrv.sys with HVCI or WDAC and hunt Sysmon driver-load events.
3. Predefine GDPR and NIS2 incident-notification decisions before ransomware extortion occurs.
Urgent: act within 30 days
1. Audit GPO modifications and disable Chrome password storage on OT-adjacent workstations.
2. Patch SimpleHelp and require MSP remote-access controls and evidence of compliance.
3. Detect QEMU, QCOW2 or ACOW2 artifacts used to run backdoors outside EDR visibility.
4. Block Quick Assist where not required and train distributed helpdesks against vishing.
5. Rotate privileged credentials potentially exposed through Amadey and StealC infections.
Ongoing detection and resilience
1. Hunt AsyncRAT TLS certificate patterns on non-standard ports.
2. Maintain air-gapped or immutable backups resilient to network-share encryption.
3. Protect backups from in-guest shadow-copy deletion using hypervisor or cloud immutability.
4. Evaluate AS-level blocking for repeat bulletproof-hosting infrastructure.
June source reports: Red Piranha weekly reports, Bitsight and Microsoft Operation Endgame reporting, and Censys AsyncRAT family infrastructure analysis from June 2026.
APAC
Executive Summary
State-sponsored OT pre-positioning meets a high-tempo ransomware ecosystem

APAC energy, gas, oil and utilities faced two parallel threat streams during June 2026. Chinese state-sponsored groups focused on long-term access to utility and OT-adjacent environments, while criminal operators maintained pressure through ransomware, credential theft and edge-device exploitation. VOLTZITE was the most strategically significant actor because its confirmed targeting scope includes Australia, New Zealand, Singapore, Taiwan and India. Earth Lusca also expanded its capability by deploying a Windows version of SprySOCKS with rootkit functionality. No source report named a specific APAC energy victim during the month, so this brief distinguishes confirmed actor targeting from inferred sector exposure.

Key Insights
1
VOLTZITE, also tracked as Volt Typhoon, continued pre-positioning against water, electric and utility infrastructure using compromised edge devices and living-off-the-land techniques.
2
The JDY botnet exceeded 1,500 compromised SOHO and IoT devices and scanned Fortinet and other edge services used across distributed utility environments.
3
Earth Lusca released SprySOCKS for Windows with a RawWNPF kernel rootkit capable of hiding processes, files, registry keys and network connections.
4
DragonForce, Brain Cipher, AiLock and 3AM remained active ransomware risks with APAC reach, although no named APAC energy victim was confirmed in the source set.
5
Operation Endgame disrupted Amadey and StealC infrastructure, but replacement loader and credential-theft capability appeared during the same reporting window.
6
The June corpus rose from 164 to 455 reports, a 177 percent increase from May, indicating a materially more active threat environment.
Attack chains, vulnerabilities and indicators
CVEProductCVSSJune context
CVE-2026-0257Palo Alto PAN-OS9.1Perimeter authentication bypass risk
CVE-2026-20253Splunk Enterprise9.8Unauthenticated RCE against monitoring infrastructure
CVE-2024-57726/27/28SimpleHelp RMMHighMSP and remote-management supply-chain access
CVE-2023-28252Windows CLFSHighBrain Cipher privilege escalation
CVE-2023-46805 / CVE-2024-21887Ivanti Connect SecureCriticalVOLTZITE and ransomware entry vector
CVE-2022-42475FortiGate SSL VPNCriticalVOLTZITE edge-device exploitation
CVE-2021-44228Apache Log4j10.0Earth Lusca and ransomware exploitation
VOLTZITE utility pre-positioning
Attack PathELEZAR
01
Edge-device exploitation or valid credentials
T1190 · T1078
02
LOLBin execution with PowerShell, WMIC, netsh and cmd
T1059.001
03
Internal discovery and ntds.dit targeting
T1003.003
04
netsh portproxy and SOHO proxy infrastructure
T1090
05
Data staging in C:\Windows\Temp
T1560
06
Long-term access to OT-adjacent systems
Earth Lusca SprySOCKS
Attack PathELEZAR
01
Public-facing application exploit
T1190
02
Print Processor persistence through VSPMsg.dll
T1547.012
03
Token theft from spoolsv.exe
T1134.002
04
AES-encrypted loader files
05
Process Doppelgänging into svchost.exe
T1055.013
06
RawWNPF kernel rootkit
T1014
07
TCP, UDP or WebSocket C2 on fallback channels
T1071
Ransomware double extortion
Attack PathELEZAR
01
VPN, RMM or public-app exploitation
T1190
02
PowerShell and cmd orchestration
03
BYOVD or Windows LPE
T1068
04
LSASS and browser credential theft
T1003.001
05
RDP, PsExec, WMIC or GPO lateral movement
T1021
06
Backup and security service termination
T1489
07
Shadow-copy deletion, encryption and extortion
T1490 · T1486

Selected indicators

TypeIndicatorAttribution
IP149[.]248[.]3[.]38:13339VOLTZITE / JDY payload server
ProcessauditdyJDY botnet process
DriverTruesight.sys / RentDrv.sysDragonForce BYOVD
SHA256410db536a57c511b0ccac2639e0eb3320f303fc5c90242379ab43364c51ef321DragonForce
IP88[.]118[.]167[.]239:443 / 172[.]86[.]121[.]1343AM QDoor C2
FileX1B5206BDC1743DD.datSprySOCKS encrypted payload
RegistryHKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\VSPMsgSprySOCKS persistence
Prioritized defensive guidance

Recommendations are calibrated for distributed utility operations, OT and ICS estates, remote-access infrastructure, MSP dependencies and high-impact service continuity requirements.

Immediate: act within 7 days
1. Patch or isolate PAN-OS, Ivanti and FortiGate edge systems under active exploitation.
2. Block and hunt Truesight.sys and RentDrv.sys driver loads across Windows estates.
3. Remove public exposure from PLC, HMI and SCADA management interfaces, and rotate default credentials.
Urgent: act within 30 days
1. Replace or harden SOHO and IoT devices used at remote substations and utility sites.
2. Disable unnecessary Print Spooler services and audit new Print Processor registry entries.
3. Detect SprySOCKS at the network layer because RawWNPF hides host-level indicators.
4. Restrict Quick Assist and train helpdesks against email-flood plus vishing attacks.
5. Patch SimpleHelp and require MSP attestation for remote-management security.
Ongoing detection and resilience
1. Hunt VOLTZITE living-off-the-land patterns including csvde, netsh portproxy, certutil and 7-Zip staging.
2. Control executable downloads from public cloud storage and inspect unexpected WebSocket traffic.
3. Maintain offline immutable backups for historians, engineering shares and OT-support systems.
4. Prepare legal and incident-response procedures for regulatory-notification extortion.
June source reports: DomainTools nation-state targeting of water systems reports, Lumen Black Lotus Labs JDY botnet analysis, ESET SprySOCKS for Windows, and Red Piranha weekly reports for June 2026.