INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Armatura One Exploit Kit Utilizes Spear-Phishing Tactics

| 2026-10-08 12:00 MEDIUM HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE PHISHING & SOCIAL ENGINEERING CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
A critical vulnerability has been discovered in Armatura One, a widely used software solution for manufacturing and energy sectors. The exploit affects versions 4.7.2 and below of the system, which exposes its OpenWire protocol listener on the network by default, making it vulnerable to attacks. Furthermore, the software stores sensitive database credentials in an install configuration file, encrypting them with AES-128-CBC when protection is enabled, but fails to generate unique passwords for each installation. This has led to a known vulnerability (CVE-2023-46604) and multiple other vulnerabilities including deserialization of untrusted data, use of hard-coded cryptographic keys, and insertion of sensitive information into log files. The affected sectors include manufacturing, energy, and transportation systems in the United States.
Technical Mitigations AI-generated
• Implement a secure deserialization mechanism for the OpenWire marshaller to prevent arbitrary code execution. • Use a dynamic encryption key and initialization vector, or implement a secure key management system to protect against key recovery by an attacker with access to the installation package. • Generate unique passwords per installation instead of assigning fixed vendor-defined passwords to database superuser accounts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

re•••••.co
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-94594CVE-2026-94594 CVE-2026-105278CVE-2026-105278 CVE-2023-46604CVE-2023-46604 CVE-2026-72507CVE-2026-72507 CVE-2026-105281CVE-2026-105281 CVE-2026-101022CVE-2026-101022 CVE-2026-71189CVE-2026-71189 CVE-2026-69662CVE-2026-69662 CVE-2026-72510CVE-2026-72510 CVE-2026-94591CVE-2026-94591 CVE-2026-63713CVE-2026-63713 CVE-2026-70356CVE-2026-70356 CVE-2026-100730CVE-2026-100730 CVE-2026-68954CVE-2026-68954 CVE-2026-71302CVE-2026-71302 CVE-2026-85479CVE-2026-85479 CVE-2026-68068CVE-2026-68068 CVE-2026-94593CVE-2026-94593 CVE-2026-104629CVE-2026-104629 CVE-2026-71379CVE-2026-71379 CVE-2026-94592CVE-2026-94592
Target & Sectors
NORTH_AMERICA NORTH_AMERICA manufacturingmanufacturing
Incident Timeline
‎2026/09/29
Threat actors used the Initial Release Date of Armatura One to publish a Legal Notice and Terms of Use on ‎2026/09/29.
industry Legal
organisation Initial Release Date
general_metric 01 Initial Publication
‎2026/10/01
Threat actors used a crafted POST request to exploit the deserialization flaw in Armatura One's OpenWire marshaller, allowing unauthenticated network attackers to trigger deserialization of an arbitrary object graph before authentication is checked.
organisation CVE-2023-46604
infrastructure 4.7.2
infrastructure 4.6.1
infrastructure 9.8
organisation Armatura
organisation Armatura One (USA
organisation CVSS
organisation Vendor Equipment
organisation Armatura LLC
organisation Deserialization of Untrusted Data
organisation Critical Manufacturing
organisation Transportation Systems Countries/Areas Deployed
organisation Armatura One's
organisation POST
organisation CVE-2026-71379
organisation CVE-2026-72510
organisation CVE-2026-71302
organisation CVE-2026-69662
infrastructure 7.6.3
organisation CVE-2026
organisation TopHAT 7.6.3
organisation Toptech Systems
organisation TopHAT Files or Directories Accessible
organisation External Parties
organisation Unrestricted Upload of File
organisation an SQL Command
organisation Background Critical Infrastructure Sectors
organisation Chemical
organisation Initial Release Date
organisation this Privacy & Use
infrastructure 146 TIP-12
organisation Affected Products
organisation Virtual Private Networks
organisation Toptech Systems Product Version
organisation Directories Accessible
organisation PHP
organisation Toptech
organisation TopHAT
Tactical Metrics
Metrics
infrastructure
‎2.9.477
Software Version
Metrics
infrastructure
‎2.9.482
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎2.8.585
Software Version
Metrics
infrastructure
‎2.8.580
Software Version
Metrics
infrastructure
146
Tip-12
Metrics
infrastructure
‎4.7.2
Software Version
Metrics
infrastructure
‎4.6.1
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎7.6.3
Software Version
Intelligence Sources
CISA 2026-09-29
CISA Advisories 2026-10-01
CISA 2026-10-01
CISA Advisories 2026-10-08