Full Report
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
Analysis Summary
The provided article describes a convergence of multiple state-sponsored and criminal threat actors rather than a single group. Below is the summary of the actors and their collaborative/co-incidental exploitation patterns as identified in the report.
# Threat Actor: Multi-Nexus Convergence (State-Sponsored & Criminal)
## Attribution & Identity
The report identifies a convergence of five distinct threat nexus categories independently exploiting the same edge infrastructure:
* **China-Nexus:** UTA0218, PurpleHaze.
* **Russia-Nexus:** APT29 (Midnight Blizzard/Cozy Bear).
* **DPRK-Nexus:** Lazarus Group (Hidden Cobra).
* **Iran-Nexus:** Fox Kitten (Pioneer Kitten).
* **Ransomware/Criminal:** INC Ransomware and other unattributed groups (e.g., UTA0533).
## Activity Summary
Recent activity centers on the exploitation of critical vulnerabilities (CVEs) in edge networking and development infrastructure. The report highlights a trend of "espionage-to-ransomware succession," where state actors often utilize zero-days first, followed rapidly by ransomware groups exploiting the same vulnerabilities.
## Tactics, Techniques & Procedures
* **Initial Access via Edge Devices:** Exploiting vulnerabilities in VPNs, firewalls, and gateways to bypass traditional endpoint security.
* **Zero-Day Exploitation:** State-sponsored actors (specifically China-nexus) leading with zero-day attacks.
* **Lateral Movement:** Moving from compromised edge infrastructure into the internal network.
* **Serial Exploitation:** Targeting the same product lines (e.g., Ivanti) repeatedly as new vulnerabilities emerge.
**MITRE ATT&CK IDs Mentioned/Implied:**
* **T1190:** Exploit Public-Facing Application
* **T1021:** Remote Services (Lateral Movement)
## Targeting
* **Sectors:** Broad targeting across all sectors using vulnerable edge infrastructure; specifically focuses on users of large-scale enterprise networking vendors.
* **Geography:** Global (implied by the scale of Tenable and SentinelOne telemetry).
* **Victims:** Organizations utilizing F5, Check Point, Ivanti, Citrix, and Fortinet.
## Tools & Infrastructure
**Vulnerable Infrastructure Targeted:**
* **F5:** (54% of customer environments found exposed).
* **Citrix:** (High exposure, median 461 days to patch).
* **Ivanti:** Connect Secure and EPMM.
* **Check Point:** Quantum Gateways.
* **Palo Alto Networks:** PAN-OS GlobalProtect.
* **SonicWall:** SMA1000.
* **JetBrains:** TeamCity.
**Specific CVEs Exploited:**
* CVE-2026-15409 (SonicWall)
* CVE-2023-42793 (JetBrains TeamCity)
* CVE-2024-3400 (PAN-OS)
* CVE-2024-24919 (Check Point Quantum)
## Implications
The study reveals that edge infrastructure is a "shared attack surface." There is no longer a clear distinction between the targets of state-sponsored espionage and financially motivated cybercrime. If a state actor finds a way in, criminal groups are likely to follow, often within the same exploitation window. The high "median time to patch" (up to 461 days for some vendors) provides a massive window for multi-nexus exploitation.
## Mitigations
* **Aggressive Patching:** Prioritize edge infrastructure updates; the study notes a 24-day remediation gap for high-priority CVEs that must be closed.
* **Attack Surface Minimization:** Disable unnecessary features and services on edge devices (feature-set minimization).
* **Endpoint Protection:** Run internal endpoints in "protect mode" to intercept lateral movement originating from compromised edge devices where security agents cannot be installed.
* **Vulnerability Management:** Focus on the "Vendor Attack Surface" rather than just individual CVEs, as certain vendors (Ivanti, F5) are targeted serially.