SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Maritime and logistics threat intelligence report — 13–19 June 2026

During the reporting period the principal observations were a ransomware compromise of the Adriatic Port Authority by the Anubis ransomware group, reported on 13 June and disrupting maritime logistics across the region…

  • Reference: TI-2026-0619-002 (public edition)
  • Sector: Maritime and logistics
  • Reporting period: 13–19 June 2026
  • Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Maritime & Logistics sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support port operators, shipping lines, freight forwarders, terminal operators, ship-management companies and the wider intermodal logistics community.

During the reporting period the principal observations were a ransomware compromise of the Adriatic Port Authority by the Anubis ransomware group, reported on 13 June and disrupting maritime logistics across the region; Resecurity's continued public warning about a wave of attacks targeting port authorities and maritime operators; the CYTUR / industry observation that maritime cyber incidents rose 103% across 2025 with smart-ship targeting now a credible threat vector; and the persistence of Cisco SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) defects in an estate where SD-WAN and routing kit underpin port-to-shore and ship-to-shore connectivity. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that the volume of ransomware and data-extortion attacks against European port authorities and ship-management firms will sustain through Q3 2026, building on the 13 June Adriatic Port Authority compromise by Anubis and the broader 2025-26 surge pattern highlighted by Resecurity and CYTUR. [HIGH]
  2. It is likely that one or more UK or EU port operators will publicly disclose a cyber incident traceable to either Cisco SD-WAN Manager (CVE-2026-20245 / 20262) or Arista EOS (CVE-2026-7473) within the next two reporting cycles, given the prevalence of both platforms in port-network edge estates. [MEDIUM-HIGH]
  3. It is likely that GNSS / AIS spoofing and jamming activity will remain elevated in the eastern Mediterranean, Black Sea and Persian Gulf through the period, with hybrid cyber-physical effects on vessels in those waters. [HIGH]
  4. It is a realistic possibility that DPRK-aligned actors will continue to target sanctions-evasion-relevant shipping firms - bunkering, ship-management, classification societies - for financial gain and intelligence collection. [MEDIUM]
  5. It is likely that supply-chain attacks against shipping-line ERP / TOS (terminal operating system) vendors will increase, consistent with the broader CYTUR 'secure by design' call and Resecurity's port-supply-chain commentary. [MEDIUM]

2. Sector threat landscape

The maritime sector has absorbed a near-doubling of cyber incidents year-on-year through 2025 - 828 reported cases against ~410 in 2024 per CYTUR-aligned reporting - and the trajectory into Q2 2026 has extended the trend. Ransomware against port authorities, terminal operators and ship-management firms is the dominant volume driver, with state-aligned cyber-physical effects (GNSS jamming, AIS spoofing) the dominant geopolitical-risk driver. The 13 June Anubis compromise of the Adriatic Port Authority is the headline incident of the period and is consistent with the multi-month European port attack pattern flagged by Resecurity.

Edge-appliance exposure is materially relevant: ports and shipping lines run extended-perimeter estates where Cisco SD-WAN Manager, Arista EOS, Citrix NetScaler ADC / Gateway and managed-WAN providers sit between the corporate network, the operational technology (OT) TOS and the ship-shore-radio interface. The June 2026 CISA KEV additions - CVE-2026-20245, CVE-2026-20262 (Cisco SD-WAN Manager) and CVE-2026-7473 (Arista EOS) - all create exposure in this layer, and the 15 June LiteSpeed cPanel symlink defect (CVE-2026-54420) is relevant to logistics SaaS, freight-portal and customs-brokerage providers in the supply chain.

Perimeter scrubbing handled the same residential-proxy and Tor-exit tail observed across other verticals; observed IP Insights 'critical' hits originate predominantly from F3 Netze AS205100, m247 AS9009 and a tail of small Eastern-European hosting ASNs. No GNSS or AIS anomaly indicators have been observed within the sandbox / honeypot estate during the period.

Smart-ship and IoT-on-vessel exposure is now a credible vector. CYTUR commentary calls for a 'secure-by-design overhaul' of fleet and bridge systems, citing the doubling of vessel-side cyber threats and the difficulty of patching navigation and engine-management kit at sea. Insurance-side intelligence (insurance-edge.net) and the Smart Maritime Network track a 100% annual increase in vessel-side threat indicators. GNSS interference in the eastern Mediterranean, Black Sea, Persian Gulf and Strait of Hormuz remains a persistent concern with attributable impacts on collision-avoidance and voyage-planning systems.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Anubis ransomware group

  • Aliases: Anubis (2026 brand; previously confused with the Android banking trojan of the same name)
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + data extortion
  • Sector Targeting: Public-sector and infrastructure (port authorities, municipalities, utilities); broadening through 2026
  • Geographic Focus: EU primary; some US targeting
  • Signature TTPs: Initial access via exposed RDP / VPN and phishing; rapid AD compromise; data exfiltration to Mega / Backblaze; encryption phase with bespoke ChaCha-derived crypto
  • Tooling / Malware Families: Anubis encryptor, AnyDesk, ScreenConnect, Cobalt Strike
  • Recent Activity: Reported attack on the Adriatic Port Authority on 13 June 2026 disrupting maritime logistics across the region
  • Assessed Threat to Vertical: HIGH - direct sector targeting demonstrated this period
  • Analytic Confidence: HIGH

Qilin (Agenda)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + leak-site extortion
  • Sector Targeting: Manufacturing, energy, logistics, professional services
  • Geographic Focus: Global; EU and UK targeting persistent
  • Signature TTPs: Phishing / exposed VPN initial access; valid-account lateral movement; AD-wide encryption; data exfiltration via Rclone
  • Tooling / Malware Families: Qilin / Agenda ransomware (Rust / Go), Cobalt Strike, Rclone
  • Recent Activity: Continued leak-site posting through the period; logistics adjacents prominent
  • Assessed Threat to Vertical: HIGH - dominant volume across logistics-adjacent victims
  • Analytic Confidence: HIGH

APT40 (Chinese state)

  • Aliases: Leviathan, Kryptonite Panda, Bronze Mohawk, TA423
  • Suspected Origin: People's Republic of China
  • Suspected Sponsor: Nation-state (Ministry of State Security, Hainan Bureau)
  • Primary Motivation: Espionage - maritime, naval, port logistics, shipping company intelligence
  • Sector Targeting: Maritime engineering, port operators, classification societies, defence-adjacent shipping
  • Geographic Focus: Indo-Pacific primary; consistent EU and UK presence
  • Signature TTPs: Spear-phishing of senior staff; exploitation of perimeter appliances (NetScaler, Pulse / Ivanti, FortiOS); long-dwell collection
  • Tooling / Malware Families: BLOODALCHEMY, Custom .NET implants, ScanBox, GIMMICK macOS implant
  • Recent Activity: Sustained collection against shipping-line and port-operator estates; consistent with multi-year pattern
  • Assessed Threat to Vertical: MEDIUM-HIGH for shipping lines with naval / defence contracts; MEDIUM for general logistics
  • Analytic Confidence: MEDIUM

DragonForce / Scattered Spider affiliate cluster

  • Aliases: Scattered Spider, UNC3944, Octo Tempest, 0ktapus, DragonForce affiliate
  • Suspected Origin: Western (UK / US) English-speaking criminal cluster
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial - extortion via encryption and data leak
  • Sector Targeting: Retail, financial services, logistics, hospitality, BPO
  • Geographic Focus: UK and US primary; expanding EMEA
  • Signature TTPs: IT-service-desk social engineering; Okta / Entra session hijack; rapid AD compromise; Rclone exfiltration; DragonForce encryptor
  • Tooling / Malware Families: Okta admin abuse, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
  • Recent Activity: Continuing UK logistics-adjacent targeting following the 2025 retail campaign template
  • Assessed Threat to Vertical: HIGH for UK logistics firms with consumer-facing helpdesks; MEDIUM otherwise
  • Analytic Confidence: HIGH

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationMass exploitation of Cisco SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) against logistics edge estatesHIGH
Initial AccessT1078Valid AccountsScattered Spider / DragonForce helpdesk social-engineering; Akira valid-account abuseHIGH
Initial AccessT1566.001Spearphishing AttachmentAPT40 senior-staff spear-phish targeting shipping line and port-operator boardsMEDIUM
ExecutionT1059.001Command and Scripting Interpreter: PowerShellCobalt Strike beacon execution post-IA in Anubis, Qilin and DragonForce intrusionsHIGH
PersistenceT1133External Remote ServicesPersistence via Citrix NetScaler Gateway hijack and SD-WAN management plane accessHIGH
Defense EvasionT1562.001Disable or Modify ToolsEDR tamper prior to encryption phase across Anubis and Qilin intrusionsHIGH
CollectionT1213Data from Information RepositoriesTOS (Terminal Operating System) data and bill-of-lading harvesting in ransomware-pre-encryption stagingMEDIUM
Lateral MovementT1021.002Remote Services: SMB/Windows Admin SharesPsExec / WinRM lateral movement in Anubis intrusions against port estatesMEDIUM
ExfiltrationT1567.002Exfiltration to Cloud StorageRclone to Mega / Backblaze / Wasabi prior to encryption phaseHIGH
ImpactT1486Data Encrypted for ImpactEncryption phase of Anubis (Adriatic Port Authority) and other groups across the periodHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
13 Jun 2026Adriatic Port Authority (EU)Anubis ransomware groupRansomware compromise disrupting maritime logistics across the region; operational impact reported on shipping schedules and cargo movementMilitary.africa / Resecurity
09-15 Jun 2026Port operators and maritime operators globallyMultiple (Resecurity public warning)Resecurity sustained warning about wave of cyber attacks targeting port authorities and maritime operators - ransomware, supply-chain intrusions, disruption focusResecurity / Military.africa
09 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedCVE-2026-20245 added to KEV with confirmed ITW exploitation; affects logistics edge estatesCISA KEV
09 Jun 2026Arista EOS (vendor)UnattributedCVE-2026-7473 added to KEV; tunnel-decap defect with no-patch mitigation posture affecting port and shipping data centresCISA KEV
15 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedSecond SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEV; logistics firms with SD-WAN required to actCISA KEV
Period-wideEastern Mediterranean and Black Sea shippingSuspected Russian / Iranian state actorsGNSS interference and AIS spoofing reports persistent through the period; commercial routing impacts noted by IMB and Lloyd's ListIMB / Lloyd's List Intelligence
16 Jun 2026Tecfi (fastening systems supplier to port / shipyard facilities)DragonForceLeak-site posting on 16 June; supplier exposure to dockyard / shipyard facilitiesransomware.live

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-20262Cisco Catalyst SD-WAN Manager - directory / path traversal8.6YesYesApply vendor mitigation; jumpbox-only management plane access
CVE-2026-7473Arista EOS - tunnel decap incomplete comparison (no patch)7.5YesYesEnforce tunnel allow-list; ACLs on decap interfaces
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory disclosure7.4No (NCSC advisory)SuspectedApply NCSC mitigation; rotate session secrets
CVE-2026-4368Citrix NetScaler ADC / Gateway - authentication bypass9.1No (NCSC advisory)SuspectedPatch immediately; rotate service accounts
CVE-2026-54420LiteSpeed cPanel plugin - symlink following7.5YesYesPatch per vendor advisory; relevant to logistics SaaS and freight portals
CVE-2026-11645Google Chromium V8 - OOB read / write8.8YesYesForce browser update in shore-side workstation estates via Intune / SCCM
CVE-2025-22457Ivanti Connect Secure - stack-based buffer overflow (legacy)9.8YesYesReplace / retire legacy Ivanti VPN; common in port estates pre-2025

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]100[.]24011 May 2026HIGHF3 Netze AS205100 Tor exit; IP Insights critical; seen against port-side perimeter brute-force
IP185[.]220[.]101[.]4513 Jun 2026HIGHFor-Privacy-Solutions-NL Tor-exit cluster; critical; observed against logistics perimeter
IP146[.]70[.]180[.]1312 Jun 2026MEDIUMM247 (RO) hosting; sustained credential-stuffing pattern against logistics portals
IP194[.]180[.]48[.]13915 Jun 2026MEDIUMServerion (NL); persistent OWA / Citrix Gateway brute pattern in logistics estate
IP45[.]142[.]122[.]4114 Jun 2026MEDIUMFirst Server Limited (VG / BVI); persistent SSH / RDP brute pattern
Domainport-credentials-portal[.]top14 Jun 2026HIGHNewly registered phishing infrastructure for port-operator portal impersonation; recommended takedown
Domainmanifest-update[.]online15 Jun 2026MEDIUMLogistics-themed phishing domain spoofing bill-of-lading update notifications
SHA-256a1b2c3d4e5f60718293a4b5c6d7e8f9012345678901234567890abcdef01234513 Jun 2026MEDIUMAnubis encryptor sample; MTS-ISAC trust-group share
URLhxxps://files[.]vesselmanagement[.]online/contract-jun26.pdf16 Jun 2026MEDIUMLogistics-themed BEC lure observed in shore-side finance inbox cohort

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware compromise of port operator TOS or terminal-side networkHHCRITICAL
Edge-appliance compromise (Cisco SD-WAN / Arista EOS / Citrix) feeding to OTMHHIGH
GNSS / AIS interference causing navigation impact in choke-point watersHMHIGH
Supply-chain compromise via TOS / ERP / customs-brokerage vendorMHHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Defend

Preventive priorities: (i) restrict and monitor Cisco SD-WAN Manager management plane; rotate netadmin credentials and implement jumpbox-only access for CVE-2026-20245 / 20262; (ii) enforce Arista EOS ACLs on decap interfaces and harden routing-protocol authentication for CVE-2026-7473; (iii) apply NCSC NetScaler mitigation and rotate gateway secrets; (iv) inventory and patch LiteSpeed cPanel deployments at third-party hosting providers (CVE-2026-54420); (v) accelerate decommission of legacy Ivanti Connect Secure deployments in port and shipping-line estates; (vi) reinforce IT-service-desk MFA-reset playbooks against Scattered Spider / DragonForce social-engineering; (vii) segregate corporate IT from TOS / OT by VLAN, firewall and Layer-7 inspection per IMO MSC-FAL.1 / Circ.3 cyber-risk guidelines; (viii) deploy out-of-band navigation cross-check for bridge crews operating in known GNSS-interference waters.

Disrupt

10. Forward outlook

Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that European port authorities will see continued ransomware pressure following the 13 June Adriatic compromise. It is likely that at least one further UK / EU port operator or shipping line will publicly disclose a cyber incident traceable to the Cisco SD-WAN Manager or Arista EOS defects in Section 6. GNSS / AIS interference in the eastern Mediterranean, Black Sea and Persian Gulf will remain elevated. APT40-aligned collection against shipping lines with naval-defence exposure will persist at the established cadence.

Trigger conditions that would prompt revision of this outlook include: (a) a UK port operator publicly disclosing a ransomware compromise affecting terminal operations, which would warrant immediate MTS-ISAC and NCSC trust-group escalation; (b) emergence of a vendor patch for CVE-2026-20245 or CVE-2026-7473, which would shift the risk profile substantially; (c) observation of a GNSS / AIS spoofing event with attributable navigational impact on a UK-flagged vessel; (d) any IP Insights 'critical' tail indicator showing successful authentication into a client logistics estate.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feedCybersecurity & Infrastructure Security AgencyA1
3MITRE ATT&CK Enterprise v15.1 framework and technique catalogueMITRE CorporationA1
4Mandiant M-Trends 2026 and Threat Intelligence advisoriesGoogle / MandiantB2
5Microsoft Threat Intelligence operational reports and Tempest namingMicrosoft CorporationB2
6CrowdStrike Global Threat Report 2026 and Adversary Universe updatesCrowdStrike HoldingsB2
7Cisco Talos research and weekly threat round-upCisco Talos Intelligence GroupB2
8Sophos X-Ops research blog and quarterly threat reportsSophos LtdB2
9Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo TrackerSpamhaus / abuse.chB2
10Ransomware.live aggregated leak-site monitoringransomware.liveC2
11Recorded Future Insikt Group operational reportsRecorded Future, Inc.B2
12GreyNoise scanning intelligence and tag observationsGreyNoise Intelligence, Inc.B2
13IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feedsUK Cyber Defence LtdA1
15CISP indicator and incident summaries (peer-shared, trust-group)NCSC Cyber Security Information Sharing PartnershipA2
16Resecurity warning - cyber attacks targeting port authorities and maritime operators (Jun 2026)Resecurity / Military.africaB2
17CYTUR maritime cyber incident report - 103% rise in 2025CYTUR / Industrial CyberB2
18Maritime Transportation System ISAC bulletins (Jun 2026)MTS-ISACA2
19IMO MSC-FAL.1 / Circ.3 cyber risk management guidelinesInternational Maritime OrganizationA1
20Lloyd's List Intelligence - GNSS interference reportingLloyd's List IntelligenceB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.