CERT.LV LVM/Olpha ransomware intrusion (2026)
incident · incident:cert-lv-lvm-olpha-ransomware-2026
Ransomware/data-extortion intrusion against Latvia's state forestry company LVM (initial access 11 June 2026, detonation 22-23 June) via a ~2-year-unpatched exposed system, 44 GB exfiltrated; the same foreign financially-motivated actor also compromised a server at essential-services provider AS Olpha with log-wiping. CERT.LV assesses the actor has hit other NATO/EU member-state institutions (CERT.LV, 2026-07).
Aliases: Latvijas valsts meži ransomware, LVM cyberattack
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
CERT.LV warns a financially-motivated crew that breached Latvian state forestry and an essential-services…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, healthcare · regions: europe, nordics
Sources cited
4
3 hosts
Action items (3)
Do-now tasks recorded on the entries about CERT.LV LVM/Olpha ransomware intrusion (2026), newest first. Check the date before acting on an older one.
- Treat any authentication material (passwords, hashes, service-account credentials, certificates/keys) tied to an internet-exposed system that has gone unpatched for an extended period as already compromised and rotate it, LVM's 44 GB exfiltration included user passwords and their hashes.2026-07-10CERT.LV warns a financially-motivated crew that…
- Inventory internet-facing systems for anything unpatched beyond ~1 year and prioritise it for patching or isolation; CERT.LV names long-unpatched exposed systems as the entry point here.2026-07-10CERT.LV warns a financially-motivated crew that…
- Hunt for abuse of legitimate tunnelling services (Cloudflare Tunnel, Microsoft Dev Tunnels, ngrok-class tunnels) and open-source C2 frameworks (Sliver) as an egress/C2 class, and deploy out-of-band log retention that survives host encryption or deliberate log deletion.2026-07-10CERT.LV warns a financially-motivated crew that…
Defender insights
What each entry about CERT.LV LVM/Olpha ransomware intrusion (2026) tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
ATT&CK techniques (4 across 5 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Exploit Public-Facing Application
- PersistenceValid Accounts
- Privilege EscalationValid Accounts
- StealthIndicator Removal · Valid Accounts
- Command and ControlApplication Layer Protocol
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
Stealth TA0005
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat · ATT&CK page ↗
Entries about CERT.LV LVM/Olpha ransomware intrusion (2026) (1)
Where this entity is cited
Source distribution
- cert.lv2 (50%)
- bnn-news.com1 (25%)
- therecord.media1 (25%)
All cited sources (4)
- bnn-news.comBNN News (Baltic News Network)https://bnn-news.com/hacker-remained-undetected-in-latvijas-valsts-mezi-system-for-several-days-281634
- cert.lvCERT.LV (Latvia national CERT)https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija
- cert.lvCERT.LV (Latvia national CERT)https://cert.lv/lv/2026/07/cert-lv-rekomendacijas-infrastrukturas-kiberdrosibas-noturibas-uzlabosanai-pret-kiberuzbrukumiem
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/latvia-state-owned-foresty-company-lvm-ransomware