18 techniques observed across 11 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
Resource Development TA0042
T1587.001Develop Capabilities: Malware×1
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
weekly-sector-patternsW33's European breaches all ran through a third party, and in two of them the notification duty landed where the intrusion did not
active-threatsWest University Vasile Goldis Arad notifies DNSC, the data-protection authority and prosecutors after an attack on academic and administrative systems
weekly-long-runningThe Gentlemen status — ReliaQuest ranks it Q2's most-active operator (300 vs Qilin's 289) on an AI-accelerated affiliate kit; it hit Metro Mondego (Portugal)
deep-diveDragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion
Two quarterly ransomware reports landed three days apart this week, counting different populations from different vantage points, and arriving at compatible descriptions of the same structural shift. Taken together they are the closest thing to an outside check on what the operational entries of the last quarter have shown one incident at a time.
Dragos's Industrial Ransomware Analysis for Q2 2026 counts incidents affecting industrial organisations: "Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, an 12% increase over the 1,020 recorded in Q1," with manufacturing the most affected sector at 747 incidents or 65%, and engineering firms, system integrators and equipment manufacturers second at 117 — a distribution that puts the industrial supply chain, not the plant, at the centre. The regional detail is where it becomes a European planning input rather than a US one: the United States remains the most impacted country by a wide margin at 431 incidents or 38% of the total, but "the country with the greatest increase from Q1 (37 incidents) to Q2 (68 incidents) was Germany" (Dragos, 2026-08-10) — an eighty-four per cent rise in a neighbouring jurisdiction whose industrial base overlaps heavily with the Swiss one.
Check Point Research's State of Ransomware Q2 2026 counts leak-site victims across all sectors and describes the ecosystem's shape: "The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report," against a total of 2,139 victims that was essentially flat quarter over quarter and up 33% year over year. Qilin remained the most prolific operator for a fourth straight quarter with 279 victims despite its own count falling 17%, while The Gentlemen surged 62% to 269 and briefly outpaced it; the US share of victims fell from 50% to 42%, which Check Point attributes to the fastest-growing groups — The Gentlemen and the newly active Krybit — targeting the US less often than the ecosystem average (Check Point Research, 2026-08-13). That last point is the one European defenders should read twice: a falling US share in a flat total is not a reduction in activity, it is a redistribution toward everyone else. Check Point also records, independently of this pipeline's own observations this week, that "The exploitation window kept narrowing, with AI increasingly cited as the accelerant."
The single most consequential finding in either report is a negative one, and it belongs to Dragos: "Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system; where operational disruption occurred, it followed encryption or precautionary shutdown of the enterprise and virtualization systems on which OT depends."
Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, an 12% increase over the 1,020 recorded in Q1.
Dragos observed no case in Q2 2026 in which a ransomware operator reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated a control system; where operational disruption occurred, it followed encryption or precautionary shutdown of the enterprise and virtualization systems on which OT depends.
However, the country with the greatest increase from Q1 (37 incidents) to Q2 (68 incidents) was Germany.
The top 10 groups accounted for 57.6% of all victims, down from 71% in Q1, while the number of active groups climbed from 71 to 93, a new high for the period tracked in this report.
The exploitation window kept narrowing, with AI increasingly cited as the accelerant.
A prior weekly recorded European government's own operating infrastructure being compromised directly. This week the shape is different and, for planning purposes, harder: in all six of the week's European public-sector and critical-infrastructure disclosures a third party stood somewhere on the line — supplying the credentials the intruder used, holding the data that was taken, or owning the security work that was not done. In two of them that separation ran all the way to the notification, so the organisation that knows what happened and the organisation that owes an answer are not the same body.
Poland supplies the extreme case. MyDr, one of the country's largest electronic medical record providers, confirmed on 12 August that it was the target of a deliberate external criminal act, said the data is likely historical, and stated it cannot yet say what was taken (MyDr, 2026-08-12). The following day the theft was reported at almost 19 million patients' data, with Poland's digital affairs minister Krzysztof Gawkowski quoted calling it one of the largest incidents in the country's history (Notes from Poland, 2026-08-13); Gazeta Prawna puts the stolen database at over 2 TB (Gazeta Prawna, 2026-08-13), and the data-protection authority UODO stated that the obligation to notify affected individuals rests with the healthcare controllers that used MyDr's services (Gazeta Prawna, 2026-08-13) — around 12,000 medical facilities (Notes from Poland, 2026-08-13). That is not a technicality. It means the single organisation that knows what happened has no duty to tell anyone, and the twelve thousand organisations that have the duty know only what they read in the press. The same structure produced a smaller, cleaner illustration in the Netherlands: one intrusion at CEVA Logistics, the contract-logistics arm of CMA CGM, generated breach reports to the Dutch data-protection authority from ten separate organisations, because CEVA processes fulfilment data on behalf of unrelated clients (TechCrunch, 2026-08-10); bol.com, one of them, told its own partners that two order-processing systems at one fulfilment centre were involved and that customer data may have been viewed or copied (bol.com, 2026-08-06).
Where the third party is on the access path rather than the data path, the same asymmetry shows up as a detection problem. France's Direction générale des Finances publiques confirmed that intrusions in June and July used the stolen credentials of a DGFiP agent and of an authorised third party, and were used to view and extract data on 678,000 individuals and businesses (Ministère de l'Économie et des Finances, 2026-08-14). Żabka's confirmed intrusion reached its ticketing system through an external service provider's account (Niebezpiecznik, 2026-08-03). Retelit, one of Italy's largest business telecommunications and cloud operators, was compromised on 8 June in an extortion attack claimed by Qilin, and made no announcement through its own channels — the confirmation came as a right-of-reply after IrpiMedia published, scoping the damage to virtualisation infrastructure in three of its 38 data centres, one of them the site certified for Retelit's own backup and service continuity (IrpiMedia, 2026-08-04). Retelit serves 193 public administrations; those customers learned about a two-month-old intrusion from a newspaper.
The week's regulator supplied the governance version of the same gap, and it is the most directly usable finding here. The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office on 12 August after an intruder held access to its public website and content management system from August 2022 to March 2023 and staged the data of up to 10,920 people for theft. The ICO's stated cause is not a technology failure: ACRO had contracted patch management to third parties without establishing who internally was responsible for identifying and monitoring critical updates, and did not adequately investigate security alerts that would have surfaced the intrusion earlier. The ICO also names network segmentation among the mitigating factors it weighed, because it kept the attacker out of core systems (UK Information Commissioner's Office, 2026-08-12).
Triage: third-party account misuse is hard to separate from third-party account use, and the discriminators are contextual rather than atomic. A supplier or contractor account is defined by a narrow, repetitive and scheduled access pattern — a fixed set of systems, a working-hours profile matching the supplier's own jurisdiction, a stable set of source addresses belonging to the supplier's estate. The signals worth alerting on are deviations from that shape rather than the access itself: authentication from a network range with no prior relationship to that supplier, access to systems outside the contracted scope, use of the platform's own bulk export or reporting functions by an account that has never used them before, and activity continuing outside the contract's active periods. The DGFiP case adds the timing discriminator that matters most for scoping: the account was cut when the intrusion was detected, and the theft had already happened — so the review that establishes impact has to reconstruct what the account reached before containment, not merely confirm it stopped afterwards.
Retelit is one of Italy's largest business telecommunications and cloud operators, co-owner of a transcontinental submarine fibre cable and operator of 38 data centres across the country. On 2026-08-04 the investigative outlet IrpiMedia reported that it had been compromised in an extortion attack claimed by Qilin, with hundreds of gigabytes of files taken and part of them already published (IrpiMedia, 2026-08-04). Qilin's leak-site page, screenshotted by the outlet on 1 August, listed 270,000 files; IrpiMedia estimated at least 300 GB, because the site itself displayed an apparent placeholder size. The listing first appeared on 11 July and a document-and-passport sample followed on 14 July. The first outlet to report it was not IrpiMedia but an Italian trade blog on 12 July, which IrpiMedia credits as having "riportato la prima volta" the attack (Bismark.it, 2026-07-12) — so the compromise was public knowledge in the Italian trade press for over three weeks before the investigation that finally drew a company response.
Why this reaches a Swiss or European public-sector reader is the customer roster rather than the victim's name: "Tra i clienti dell'azienda figurano società strategiche quali Leonardo, almeno tre gestori di identità digitali e 193 pubbliche amministrazioni" — among the company's customers are strategic firms such as Leonardo, at least three digital-identity providers, and 193 public administrations. That is a statement about who Retelit serves, and it must not be read as a statement about whose data was taken. On that narrower question there is one concrete finding, and it is the outlet's own rather than a criminal claim: IrpiMedia says it examined the published dump and found Internet connectivity provisioning documents for the defence and aerospace group Leonardo's Genoa and Turin offices, dated October 2025 and April 2026. No Italian public administration has confirmed downstream impact.
The disclosure behaviour is the second half of the story. As IrpiMedia recorded before publication, "Non è noto il momento in cui è avvenuto l'attacco, rivendicato da Qilin con un primo post sul proprio sito" — the timing of the attack was unknown, and the company had not communicated the incident publicly nearly two months after its probable discovery. What broke that was the article. Afterwards Retelit sent the outlet a right-of-reply, published in full, which is where the company's own account appears for the first time: "L'attacco informatico attribuito al gruppo criminale Qilin è avvenuto lo scorso 8 giugno, come notificato alle autorità competenti" — an 8 June attack attributed to Qilin, notified to the competent authorities. Retelit adds that it "non ha nascosto quanto avvenuto. Al contrario, ha prontamente informato i clienti impattati, l'Agenzia per la Cybersicurezza Nazionale (ACN), il Computer Security Incident Response Team (CSIRT), la Polizia Postale e, in via prudenziale e cautelativa, il Garante per la Protezione dei Dati Personali" — that it did not conceal the incident and promptly informed affected customers, the national cybersecurity agency, CSIRT, the postal police and, as a precaution, the data-protection authority. It also stood up a war room with the agency and CSIRT alongside external incident-response and forensics firms. Retelit's own scoping is narrower than the reporting implies: "3 dei 38 data center Retelit dislocati sul territorio nazionale e pari a circa il 7% dei sistemi distribuiti nei data center" — a limited part of the virtualisation infrastructure in 3 of 38 national data centres, around 7% of distributed systems. This pipeline reports both characterisations and resolves neither; the gap between them is itself the finding. Separately, this run confirmed against Retelit's own press-release index that no public statement about the incident appears there.
On mechanism the reporting is thinner than on chronology, and its own sourcing tier is lower, which is worth carrying rather than smoothing over. IrpiMedia relays an account from an unnamed source involved in the incident, in the Italian conditional: "Secondo quanto riferito da una fonte coinvolta nell'evento, l'attacco sarebbe partito dal computer di un amministratore di sistema nel quale sono state carpite le password che hanno permesso all'attaccante di compiere dei «movimenti laterali»" — the attack is said to have started from a system administrator's computer, from which passwords were captured that let the attacker move laterally. The detection failure is not reported as fact either but as the outlet's inference from the volume already published: "è deducibile che il presidio di sicurezza (Soc, Security Operations Center) non abbia rilevato i movimenti laterali né la cifratura dei server se non quando era troppo tardi" — it is deducible that the security operations centre did not detect the lateral movement or the encryption of servers until it was too late. Neither claim comes from Retelit, and Retelit's own statement addresses scope rather than sequence.
That sequence is nonetheless the part a responder can act on, because it is ordinary rather than exotic: a privileged administrator endpoint yields stored credentials, those credentials authenticate to systems the endpoint legitimately reaches, and the encryption stage arrives before anything flags the movement between the two. Telemetry-wise it lands in three classes — credential access on administrator workstations, authentication events showing an administrator account reaching hosts it does not normally touch, and volume anomalies on file and virtualisation infrastructure. Triage: an administrator account authenticating across many systems is precisely what administrator accounts do, so breadth alone discriminates nothing; what separates this from routine work is the pairing of credential-store access on the workstation with a subsequent authentication fan-out that does not match the operator's normal maintenance pattern or change window.
Two further facts cut against Retelit's account of its own communications and belong next to it. The company says it "ha prontamente informato i clienti impattati" — promptly informed affected customers — but the same article's 6 August update records the opposite experience from the customer side: after a notification circulated by Italy's public-administration CERT at the end of July, "numerosi clienti riferiscono di aver scritto a Retelit per chiedere come mai non fosse arrivata alcuna comunicazione in seguito al data breach" — numerous customers report having written to Retelit to ask why no communication had arrived after the breach. This pipeline does not adjudicate between the two; both are reported and attributed.
The second fact is the one with the most direct public-sector consequence, and it establishes a notification path that ran around the company rather than through it. IrpiMedia records that Italy's CERT for public administration learned of the incident only on 30 July, and on that date began warning the security officers of every public administration potentially involved or otherwise using Retelit's services — "Tra questi anche Cineca, Lepida e Infocamere", among them a university and research consortium that also acts as a certified digital-preservation provider, and two organisations the article describes as providing Italy's digital-identity and digital-signature services. Those organisations are named as recipients of a precautionary warning, not as confirmed-impacted parties, and the distinction matters: what the record shows is a sector CERT propagating a supplier incident to downstream public bodies seven weeks after it happened, because the supplier had not.
One detail deserves emphasis because it inverts the reassurance the 7% figure is meant to offer. "IrpiMedia è in grado di rivelare esattamente quali sono: Verona, Roma e Milano" — the outlet names the three affected sites, and reports that the Milan site is the one certified by the national agency for Retelit's own backup management and service continuity in the event of a cyber incident. It also reports that customers contacted the newsroom complaining of partial or total failure of backup recovery. A small percentage of an estate is not a small incident when the affected fraction includes the continuity capability itself.
Tra i clienti dell'azienda figurano società strategiche quali Leonardo, almeno tre gestori di identità digitali e 193 pubbliche amministrazioni.
Non è noto il momento in cui è avvenuto l'attacco, rivendicato da Qilin con un primo post sul proprio sito
L'attacco informatico attribuito al gruppo criminale Qilin è avvenuto lo scorso 8 giugno, come notificato alle autorità competenti
3 dei 38 data center Retelit dislocati sul territorio nazionale e pari a circa il 7% dei sistemi distribuiti nei data center
Retelit non ha nascosto quanto avvenuto. Al contrario, ha prontamente informato i clienti impattati, l'Agenzia per la Cybersicurezza Nazionale (ACN), il Computer Security Incident Response Team (CSIRT), la Polizia Postale e, in via prudenziale e cautelativa, il Garante per la Protezione dei Dati Personali.
IrpiMedia è in grado di rivelare esattamente quali sono: Verona, Roma e Milano.
Secondo quanto riferito da una fonte coinvolta nell'evento, l'attacco sarebbe partito dal computer di un amministratore di sistema nel quale sono state carpite le password che hanno permesso all'attaccante di compiere dei «movimenti laterali»
è deducibile che il presidio di sicurezza (Soc, Security Operations Center) non abbia rilevato i movimenti laterali né la cifratura dei server se non quando era troppo tardi