Home
Elezar
Sol Threat Intelligence

June 2026
Government, Public Administration and Defense
Regional Sector Brief

Download PDF
1 Jun to 30 Jun 20263 regional assessments4 pages per regionPrepared by Kaartheeswaran Ravichandran
A hardened government communications citadel under cyber espionage pressure
Americas
Executive Summary
Major-event convergence, PeopleSoft exploitation and destructive activity drive risk

The Americas Government, Public Administration and Defense sector faced a convergence of broad-surface exploitation, event-driven targeting and destructive activity in June 2026. The FIFA World Cup across the United States, Canada and Mexico created a shared attack surface across transport, telecommunications, energy and public services. ShinyHunters exploited Oracle PeopleSoft CVE-2026-35273 against government-deployed systems, while Operation Endgame revealed extensive SocGholish reach into government networks. Iranian-linked Ababil of Minab activity added a destructive wiper dimension against US transportation infrastructure.

Key Insights
1
The FIFA World Cup created concurrent nation-state, hacktivist and criminal targeting of tri-national government and critical infrastructure.
2
ShinyHunters exploited PeopleSoft CVE-2026-35273 and used MeshCentral agents disguised as Azure services.
3
SocGholish reached 55 percent of government networks in Infoblox telemetry and progressed to tier-two C2 on a subset.
4
Iranian-linked Ababil of Minab conducted destructive activity against US transportation infrastructure including LACMTA.
5
NKWIPER and FSWIPER samples appeared on the first two tournament days, elevating wiper-monitoring requirements.
6
Government risk came from broad exploitation and event-driven convergence rather than a single precision espionage campaign.
Attack chains, vulnerabilities and indicators
CVEProductSeverityJune context
CVE-2026-35273Oracle PeopleSoftCriticalShinyHunters zero-day exploitation
CVE-2026-21509Document clientHighAPT36 spear-phishing relevance
CVE-2021-40539ManageEngine ADSelfService PlusCriticalIdentity infrastructure exploitation
CVE-2026-48027Nx Console VSCode ExtensionHighGovernment developer supply-chain risk
ShinyHunters PeopleSoft
Attack PathELEZAR
01
Exploit internet-facing PeopleSoft
T1190
02
Unauthenticated RCE
03
Deploy MeshCentral agents with Azure-themed names
T1219 · T1036
04
C2 to azurenetfiles[.]net
05
SSH lateral movement
T1021.004
06
Data staging and exfiltration
T1074
07
Ransomware when exfiltration fails
T1486
SocGholish
Attack PathELEZAR
01
Compromise legitimate WordPress site
02
Traffic distribution and victim fingerprinting
T1497
03
Fake browser-update page
T1189
04
JScript stager execution
T1204.002 · T1059.007
05
Tier-one and tier-two domain-shadowed C2
T1568.001
06
Infostealer or ransomware follow-on for domain-joined hosts
Event and destructive threat
Attack PathELEZAR
01
World Cup themed spoofing or infrastructure probing
T1566
02
DDoS, wiper or critical-infrastructure targeting
T1498
03
Tournament-day malware activity
T1485
04
Potential operational disruption across transport, telecom and public services
T1491

Selected indicators

TypeIndicatorAttribution
Domainazurenetfiles[.]netShinyHunters MeshCentral C2
IP142[.]11[.]200[.]186-190 / 176[.]120[.]22[.]24ShinyHunters
Filemeshagent32-azure-ops.exe / meshagent64-azure-ops.exeShinyHunters
Domainpa-portal[.]benningtonspringsmhp[.]comSocGholish tier one
Domainbilling[.]roofnrack[.]usSocGholish tier one
IP198[.]37[.]123[.]126 / 159[.]203[.]45[.]201Iranian-associated activity
FileRECOVERY_INFO.txt / .laliaLalia ransomware indicators
Prioritized defensive guidance

Recommendations are calibrated for government identity systems, public-service platforms, defense-adjacent networks, cloud services, remote-access infrastructure and high-impact operational continuity requirements.

Immediate: act within 72 hours
1. Patch PeopleSoft CVE-2026-35273 and investigate pre-patch exposure.
2. Block ShinyHunters C2 and hunt unauthorized MeshCentral agents.
3. Audit transportation and public-service systems for destructive Iranian activity.
4. Validate offline recovery for wiper scenarios.
Urgent: act within 2 weeks
1. Deploy DNS-behavioral detection for SocGholish domain shadowing.
2. Hunt JScript execution from browser-download and temporary directories.
3. Maintain elevated World Cup monitoring through the event close.
4. Restrict public PeopleSoft exposure and require VPN-authenticated administration.
Strategic uplift
1. Rotate WordPress administrator credentials and apply file-integrity monitoring.
2. Inventory and allowlist approved RMM tools across government networks.
3. Patch the affected Nx Console extension on developer workstations.
4. Detect Azure-named executables or domains resolving outside Microsoft infrastructure.
June source reports: PolySwarm FIFA World Cup threat assessment, Intel 471 ShinyHunters PeopleSoft analysis, Infoblox Operation Endgame and SocGholish reporting, and CYFIRMA Weekly Intelligence Report dated 5 June 2026.
EMEA
Executive Summary
Cloud-resident C2 and long-dwell espionage define the June threat picture

EMEA Government, Public Administration and Defense faced a multi-vector espionage environment in June 2026. Operation Dragon Weave directly targeted Czech government personnel with RUSTCLOAK and the Azure-resident AZUREVEIL implant. UNC5221 remained relevant through BRICKSTORM operations against European industry and government-adjacent environments, while a regional infrastructure study identified 3,923 malicious C2 servers across Eastern Europe. The wider reporting corpus rose from 164 to 455 reports, a 177 percent increase from May.

Key Insights
1
Operation Dragon Weave used Czech-language government lures and Azure Blob Storage as a long-lived dead-drop C2 channel.
2
BRICKSTORM used DNS-over-HTTPS, WebSocket, Yamux and nested TLS to evade conventional monitoring.
3
Chinese intelligence services were reported using LinkedIn to target government and military personnel.
4
Eastern Europe hosted 3,923 mapped C2 servers across 302 providers, supporting both espionage and ransomware.
5
QV ransomware added ESXi targeting and bootkit persistence to the regional government threat set.
6
Legitimate cloud infrastructure became the defining C2 concealment method for the month.
Attack chains, vulnerabilities and indicators
CVEProductSeverityJune context
CVE-2026-0257Palo Alto GlobalProtectCriticalPARISITE exploitation
CVE-2025-22457Ivanti Connect SecureCriticalUNC5221 initial access
CVE-2025-31324SAP NetWeaverCriticalChinese-nexus exploitation
CVE-2026-35273Oracle PeopleSoftCriticalGovernment and public-sector exposure
CVE-2026-8936Docker Desktop8.2Government DevOps relevance
Operation Dragon Weave
Attack PathELEZAR
01
Czech government spear-phish
T1566.001
02
ZIP with LNK or Rust dropper
T1204.002
03
VBScript and hidden PowerShell
04
DLL sideloading of UnityPlayer.dll
T1574.001
05
RUSTCLOAK sandbox checks and triple-layer decryption
T1497.001 · T1140
06
In-memory AZUREVEIL execution
07
Azure Blob dead-drop C2 and exfiltration
T1102.001 · T1041
UNC5221 BRICKSTORM
Attack PathELEZAR
01
Exploit Ivanti, SAP or network edge appliance
T1190
02
Deploy BRICKSTORM
03
DoH resolution through public resolvers
T1071.004
04
WebSocket upgrade and Yamux multiplexing
05
Nested TLS and serverless reverse proxy
T1090 · T1573.002
06
File operations and TCP, UDP or ICMP tunneling
07
Credential relay and lateral movement
T1021
Eastern European ransomware access
Attack PathELEZAR
01
Social engineering or vulnerable perimeter service
T1566
02
AnyDesk or remote tooling
T1219
03
Mimikatz and LaZagne credential theft
T1003
04
Lateral movement through valid accounts
T1078
05
Event-log clearing and shadow-copy deletion
T1070.001 · T1490
06
Windows or ESXi encryption
T1486

Selected indicators

TypeIndicatorAttribution
Domainnote1ggbbhggdwa1[.]blob[.]core[.]windows[.]netAZUREVEIL C2
FileUnityPlayer.dll / RuntimeBroker_update.exeDragon Weave
Path%LOCALAPPDATA%\WebViewFixUtilityDragon Weave staging
Domainms-azure[.]azdatastore[.]workers[.]devBRICKSTORM proxy
Domainms-azure[.]herokuapp[.]comBRICKSTORM proxy
IP64[.]176[.]166[.]79 / 194[.]48[.]199[.]121BRICKSTORM
Networkapplication/dns-message over HTTPSBRICKSTORM DoH
Prioritized defensive guidance

Recommendations are calibrated for government identity systems, public-service platforms, defense-adjacent networks, cloud services, remote-access infrastructure and high-impact operational continuity requirements.

Immediate: act within 72 hours
1. Revoke long-lived Azure Blob SAS tokens and block the Dragon Weave C2 container.
2. Patch GlobalProtect and Ivanti edge devices as emergency priorities.
3. Block BRICKSTORM IOCs and detect DoH traffic from unauthorized endpoints.
Urgent: act within 2 weeks
1. Detect DLL sideloading from user-writable paths and WebViewFixUtility artifacts.
2. Hunt Yamux-over-WebSocket and nested TLS patterns.
3. Brief government and military personnel on LinkedIn-based intelligence approaches.
4. Audit PeopleSoft and SAP NetWeaver deployments for exploitation artifacts.
Strategic uplift
1. Restrict external Teams contacts and detect unauthorized remote-access tools.
2. Harden ESXi management and test isolated recovery from ransomware.
3. Apply CASB controls to Azure Blob and other legitimate cloud repositories.
4. Enforce monitored DNS resolution and prevent unmanaged DoH.
June source reports: Operation Dragon Weave reporting, CYFIRMA Weekly Intelligence Report dated 12 June 2026, NVISO BRICKSTORM analysis and Hunt.io Eastern European C2 infrastructure mapping.
APAC
Executive Summary
Supply-chain compromise and novel espionage tooling reshape government risk

APAC Government, Public Administration and Defense organizations faced sustained espionage activity in June 2026. Reporting identified three concurrent nation-state campaigns: APT32's domestic targeting pivot through the FireAnt MetaKit supply chain, APT37's NarwhalRAT operation against South Korean personnel, and CL-STA-1062's TinyRCT campaign against Southeast Asian government and state-owned networks. Amaranth-Dragon also weaponized CVE-2025-8088 against Indonesian government and law-enforcement targets. Total reporting rose from 164 reports in May to 455 in June, a 177 percent increase across the wider corpus.

Key Insights
1
APT32 shifted from primarily external espionage to domestic Vietnamese targeting through a compromised MetaKit update channel.
2
APT37 introduced NarwhalRAT with keylogging, screen capture, audio recording, USB collection and dual-channel C2.
3
CL-STA-1062 deployed TinyRCT against Southeast Asian government and state-owned networks and exfiltrated source code and MSSQL data.
4
Amaranth-Dragon became the first observed actor to weaponize WinRAR CVE-2025-8088 against Indonesian government targets.
5
Supply-chain compromise, dead-drop cloud C2 and custom malware all increased compared with May.
6
Four government-focused actor clusters were confirmed active in the June intelligence corpus.
Attack chains, vulnerabilities and indicators
CVEProductSeverityJune context
CVE-2025-8088WinRARHighActively weaponized by Amaranth-Dragon
CVE-2021-44228Apache Log4j10.0Used by Chinese-nexus actors for initial access
CVE-2022-40684Fortinet FortiOSCriticalRelevant to public-facing government infrastructure
CVE-2022-39952FortiNACCriticalRemote code execution risk
Public-facing MSSQL RCEMicrosoft SQL ServerN/AObserved against government-linked infrastructure
APT32 MetaKit supply chain
Attack PathELEZAR
01
Compromise FireAnt update infrastructure
T1195.002
02
Deliver malicious setup.exe through unsigned manifest
T1204
03
Host reconnaissance and staging contact
04
DLL sideloading and process injection
T1055
05
SPECTRALVIPER execution in OneDrive.Sync.Service.exe
T1036
06
Named-pipe lateral orchestration
T1570
07
HTTPS exfiltration with consent-cookie masquerade
T1071.001 · T1041
APT37 NarwhalRAT
Attack PathELEZAR
01
Microsoft security-alert spear-phish
T1566.001
02
ZIP containing malicious LNK
T1204.002
03
cmd and PowerShell execution
T1059.001
04
Renamed Python runtime and scheduled task persistence
T1053.005
05
In-memory RAT loading and anti-VM checks
T1497.001
06
Keylogging, screen, audio and USB collection
T1056.001
07
Compromised websites plus pCloud dead-drop C2
T1102.001
TinyRCT government compromise
Attack PathELEZAR
01
Trojanized Chrome installer
T1036
02
AppDomainManager Injection
T1574
03
TinyRCT C# backdoor
04
SoftEther and VNT tunneling
05
JuicyPotato privilege escalation and Mimikatz credential theft
T1134 · T1003
06
fscan network discovery
T1046
07
Source-code and MSSQL exfiltration
T1041

Selected indicators

TypeIndicatorAttribution
Domainfinancemachinelearning[.]comSPECTRALVIPER C2
IP139[.]162[.]11[.]152 / 142[.]91[.]98[.]77APT32 staging
FileDtlCrashCatch.dllSPECTRALVIPER loader
Domaindaehoat[.]com / webhostingkorea[.]comNarwhalRAT C2 and staging
Fileuserscreen.exe / config.catNarwhalRAT
Mutexi5zJH9FL10cVd3sSW9eyWWErPJNarwhalRAT
Path%APPDATA%\naverwhaleNarwhalRAT staging
Prioritized defensive guidance

Recommendations are calibrated for government identity systems, public-service platforms, defense-adjacent networks, cloud services, remote-access infrastructure and high-impact operational continuity requirements.

Immediate: act within 72 hours
1. Block and hunt SPECTRALVIPER infrastructure and masquerade filenames.
2. Patch WinRAR against CVE-2025-8088 across government endpoints.
3. Isolate software-update mechanisms that lack code signing or transport integrity.
Urgent: act within 2 weeks
1. Detect NarwhalRAT scheduled-task and hidden-directory artifacts.
2. Remove public exposure from MSSQL servers and monitor xp_cmdshell activity.
3. Restrict SoftEther, VNT and other unapproved tunneling tools.
4. Sandbox ZIP archives containing LNK files and brief staff on OTP-security lures.
Strategic uplift
1. Formalize third-party software supply-chain security reviews.
2. Monitor SPECTRALVIPER named pipes and unusual OneDrive process behavior.
3. Hunt AppDomainManager Injection artifacts in .NET environments.
4. Add Havoc-specific detection coverage to SIEM and EDR.
June source reports: CYFIRMA OceanLotus reporting, Korean NarwhalRAT analysis, CyberPress TinyRCT reporting and CYFIRMA Weekly Intelligence Report dated 19 June 2026.