ctipilot.ch

Everest

actor · actor:everest-ransomware

Russian-speaking closed-group double-extortion ransomware / initial-access-broker operation that emerged in December 2020 with a code-level connection to BlackByte; runs an IAB service (since Nov 2021) and a paid corporate-insider recruitment programme (since Oct 2023); documented initial access via internet-exposed RDP without MFA and vulnerable VPN endpoints (Halcyon threat-actor profile, 2025-11-19). Claimed the July 2026 breach of a Stadler Rail supplier data-exchange platform (CHF 10M demand, refused; swissinfo.ch / Swiss IT Magazine, 2026-07-21). Per the Halcyon profile the group also claimed, in October 2025, attacks on a European national electricity-transmission operator, aviation systems at multiple European airports, and telecom networks — the group's own leak-site claims, unconfirmed by the named victims.

Coverage timeline
4
first 2026-06-08 → last 2026-07-22
Peak priority
high
2 high · 2 notable
Sources cited
12
8 hosts
Sections touched
3
active-threats, deep-dive, trending-vulnerabilities
Co-occurring entities
4
see Related entities below
ATT&CK techniques
5
pinned v19.1 · see below
2026-06-084 appearances2026-07-22

ATT&CK techniques

5 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

T1136Create Account×1

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Story timeline

  1. 2026-07-22Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay
    active-threatsEverest reaches Stadler Rail through a supplier's data-exchange platform, not Stadler's own perimeter
  2. 2026-06-08CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch
    trending-vulnerabilities
  3. 2026-06-08CVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation campaign
    deep-diveCVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation
  4. 2026-06-08CVE-2026-3300 — Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale
    trending-vulnerabilities

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • trending-vulnerabilities2
  • deep-dive1
  • active-threats1

Source distribution

  • attack.mitre.org4 (33%)
  • bleepingcomputer.com2 (17%)
  • halcyon.ai1 (8%)
  • heise.de1 (8%)
  • itmagazine.ch1 (8%)
  • swissinfo.ch1 (8%)
  • thehackernews.com1 (8%)
  • wordfence.com1 (8%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (12)

Entries about Everest (4)

2026-07-22 · view entry permalink →

NOTABLENATOB2

Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay

Stadler Rail disclosed on 2026-07-21 that unauthorised parties gained access, in mid-July, to a data-exchange platform Stadler uses with an (unnamed) supplier, and that the Everest ransomware/extortion group claimed the intrusion and demanded a CHF 10 million ransom (swissinfo.ch, 2026-07-21). Stadler states it does not pay ransoms under any circumstances, has filed a criminal complaint with Thurgau cantonal police, and reports that its own IT systems were unharmed, no security-relevant or personal data was stolen, and worldwide rail-vehicle production and in-service fleets are unaffected — the accessed information belonged to the supplier and is described as not security-relevant (Swiss IT Magazine, 2026-07-21).

Everest is a Russian-speaking, closed-group double-extortion operation that emerged in December 2020, with a code-level connection to the BlackByte ransomware family; it has run hybrid Initial Access Broker services since November 2021 and a corporate-insider recruitment programme offering cash/profit-sharing since October 2023, and its documented infection vectors are internet-exposed RDP without MFA, vulnerable VPN endpoints, and credentials bought from other brokers (Halcyon, 2025-11-19). Per the same profile the group claimed, in October 2025, attacks on critical infrastructure including a European national electricity transmission operator, aviation systems affecting multiple European airports (Heathrow, Brussels and Berlin), and telecommunications networks — recurring targeting of the European critical-infrastructure and transport space, though those victim claims are the group's own leak-site assertions and are unconfirmed by the named organisations.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

Die Produktion laufe aktuell weltweit normal weiter

swissinfo.ch 2026-07-21
incident22 Jul 04:34Zmulti-sourceOpen finding ↗

2026-06-08 · view entry permalink →

NOTABLECVE-2026-3300exploited

CVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation campaign

Why this is the deep dive now. CVE-2026-3300 is a textbook web-app RCE that matters less for its novelty than for what it shows about patch lag in the commercial-plugin supply chain: the vendor fixed it on 18 March 2026, yet Wordfence has logged sustained mass exploitation from 13 April through at least 6 June, with a single-day peak of 17,900 blocked attempts on 16 May (Wordfence, 2026-06-06). WordPress underpins a large share of cantonal, municipal and agency web estates, so any public-sector site still running Everest Forms Pro ≤ 1.9.12 is exposed to a fully unauthenticated site takeover today — the patch existing for three months does not help a site that never applied it.

The bug. The vulnerability lives in the process_filter() function of the plugin's Calculation Addon, which builds a PHP expression string from user-submitted form-field values and evaluates it with eval() (BleepingComputer, 2026-06-06). The only input handling applied is sanitize_text_field(), which strips tags and normalises whitespace but does not escape single quotes or PHP syntax metacharacters. An unauthenticated attacker who submits a form containing a calculation field can therefore inject a single quote to terminate the intended string literal, append arbitrary PHP, and comment out the trailing remainder of the generated expression with //. Because the sink is eval(), this is direct code execution in the WordPress PHP context — no file write, no upload, no authentication. The CVE prerequisite is narrow but common: the form must include the Calculation Addon. Affected versions are ≤ 1.9.12; fixed in 1.9.13. The flaw was credited to researcher h0xilo (BleepingComputer, 2026-06-06).

Observed exploitation chain. The dominant in-the-wild payload uses the code-execution primitive to call WordPress's own wp_insert_user() and create a rogue account with the administrator role — converting a single unauthenticated POST into persistent privileged access to the site, from which attackers typically install webshells, SEO-spam injectors or redirect malware. Mapped to MITRE ATT&CK: initial access via T1190 Exploit Public-Facing Application; execution of injected PHP via T1059 Command and Scripting Interpreter; persistence by T1136 Create Account, after which the attacker operates with T1078 Valid Accounts.

Detection concepts (no IOCs). The highest-fidelity signal is unexpected administrator-account creation: hunt WordPress user_register events that assign the administrator role, and reconcile the live admin-user list against a known-good baseline — any account you cannot attribute to a person or process is suspect. At the request layer, alert on POSTs to the form-handling endpoints (admin-ajax.php and the plugin's AJAX actions) whose parameters contain PHP-syntax artefacts such as stray single quotes followed by function-call tokens or trailing // comment markers. Post-exploitation, watch for new or modified PHP files in wp-content/ and for outbound requests from the web host that correlate with webshell or SEO-spam behaviour. These are behavioural concepts, not signatures — tune to your own form traffic.

Hardening. Update Everest Forms Pro to 1.9.13 or later immediately; if you cannot patch on the spot, disable the Calculation Addon (the vulnerable code path) or take affected forms offline, and audit for already-created rogue admin accounts before re-enabling. A WAF rule blocking PHP-metacharacter patterns in form-submission parameters is a reasonable compensating control, but it is mitigation, not a fix. More broadly, this CVE is an argument for maintaining an inventory of commercial plugins and their versions across your WordPress estate and wiring plugin-update monitoring into change management — the recurring failure mode here is not the vulnerability class but the months-long gap between a vendor fix and its deployment.

Why this is the deep dive now.

ctipilot v2 brief (migrated)
vulnerability08 Jun 05:00Zmulti-sourceOpen finding ↗

2026-06-08 · view entry permalink →

CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch

Acer warned of two maximum-severity zero-days in Wave-7 mesh routers on firmware T7c_GBL_1.01.000055 and earlier, with no patch available and a fix targeted only for end-June 2026 (BleepingComputer, 2026-06-03; heise, 2026-06-05). CVE-2026-49200 (broken access control) exposes acer_cgi.log — which stores cleartext web-admin and Telnet credentials — to any unauthenticated client that can reach the management interface. CVE-2026-49201 (hardcoded cryptographic key) is a fixed AES key in the upload.cgi backup handler, letting an attacker decrypt, modify and re-encrypt a device backup to inject a persistent backdoor. Together they form an unauthenticated takeover-plus-persistence chain. Inclusion gate: CVSS 10.0 critical-severity, no patch; no confirmed in-the-wild exploitation or public PoC observed yet. Audience relevance is SME / home-office edge rather than core public-sector infrastructure, but the no-patch status makes the interim controls time-sensitive. Mitigations (Acer): disable remote administration, restrict the management interface to trusted internal segments, change default credentials, and watch for unauthorized logins or config changes. Detection concept: alert on unauthenticated HTTP GETs to /acer_cgi.log and unexpected backup restore events via upload.cgi.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-3300 Everest Forms Pro (WordPress) 9.8 ~30% No Yes (mass, since 2026-04-13) v1.9.13 (2026-03-18) Wordfence
CVE-2026-49200 Acer Wave-7 mesh router 10.0 n/a No No (no PoC seen) None (≈end-June 2026) BleepingComputer
CVE-2026-49201 Acer Wave-7 mesh router 10.0 n/a No No (no PoC seen) None (≈end-June 2026) BleepingComputer
vulnerability08 Jun 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (1)