Executive Summary
In mid-July 2026, Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI) suffered a financially motivated double-extortion ransomware attack that halted nationwide digital land-registry operations. DNSC interim technical analysis T66/22.07.2026 describes unauthorized activity against the agency datacenter that culminated in bytetocrypt ransomware on VMware ESXi hosts, deletion of approximately 100 of approximately 1,083 VMs, and underground advertising by ByteToBreach / ByteToBreach33.
ANCPI IT detected the incident at approximately 2026-07-14 05:45 UTC. The DNSC timeline places the first foothold at 2026-07-10 15:23:57 UTC against internet-facing OpenAM/ForgeRock authentication for ePay (T1190), then WebSphere, unpatched GitLab, monitoring/SIEM, then vCenter. The Path B baseline of 2026-07-20 correctly highlighted credential reuse and a destructive wipe, but DNSC shows initial access was Exploit Public-Facing Application via a known OpenAM/ForgeRock CVE chain, with Valid Accounts (T1078) driving escalation into virtualization management. Credential compromise remains central but incomplete without the public-facing exploit foothold.
Official messaging (DNSC, The Record): Oracle Exadata technical/legal cadastral databases are not evidenced as compromised; land-book integrity was preserved. Confirmed exfiltration: credential samples and application code fragments (approximately 2 million OpenDJ userPassword hashes; GitLab source for e-Terra/RENNS/payments/GIS); attempted domain-controller VMDK copy. Actor claims of broader citizen data exceed DNSC confirmation.
Impact: e-Terra, email, and portals froze; the real-estate market stood still. Recovery moved toward the Romanian Government Cloud (STS/Cyberint/DNSC). e-Terra restarted on 2026-08-11; as of 2026-09-13 local reporting, Geoportal, MyEterra, Registrul Proprietarilor, Titluri de proprietate, and Registrul de Transcripțiuni și Inscripțiuni remained unrestored publicly. The attack is characterized as financially motivated, not highly complex, exploiting known weaknesses plus leaked/reused credentials. KELA-reported personal attribution of ByteToBreach to Oran, Algeria has not been verified by Romanian authorities.
This advisory refreshes the July 2026 Path B write-up against DNSC T66 and recovery reporting through mid-September 2026.
Technical Information
Victim: ANCPI. Attack: double-extortion ransomware (bytetocrypt on ESXi) plus VM deletion and leak claims. Actor: ByteToBreach / ByteToBreach33. No verified state or APT attribution.
Key timeline (DNSC):
- 2026-07-10 — OpenAM foothold; later JSP webshell
dec3.jsp. - 2026-07-11 — WebSphere JMX/RMI.
- 2026-07-12 — GitLab CVE-2021-22205; Zabbix Scripts reverse shell; FortiSIEM credential store; Ligolo-ng; Sliver masquerading as auditd.
- 2026-07-13 — vCenter admin login (~1,083 VMs); ESXi bytetocrypt; ~100 VMs deleted; SCP to
66.163.118.234. - 2026-07-14 — detect/notify.
- 2026-07-22 — DNSC T66.
- 2026-08-11 — e-Terra restart.
- 2026-09-13 — other portals still down in public reporting.
DNSC cites CVE-2021-35464 (ForgeRock/OpenAM, CISA KEV) as primary initial access; it also pairs CVE-2024-36401 (NVD: GeoServer—a citation anomaly relative to the OpenAM foothold). GitLab CVE-2021-22205 is in CISA KEV. vCenter 6.0.0 build 5112529 is end-of-life. FortiGate log retention was approximately seven minutes. BitDefender was present on workstations only.
MITRE ATT&CK mappings below are taken from DNSC T66 §8 only; this advisory does not invent additional technique IDs:
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1072 Software Deployment Tools
- T1505 Server Software Component
- T1078 Valid Accounts
- T1068 Exploitation for Privilege Escalation
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1552 Unsecured Credentials
- T1110 Brute Force
- T1003 OS Credential Dumping
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1018 Remote System Discovery
- T1046 Network Service Discovery
- T1083 File and Directory Discovery
- T1210 Exploitation of Remote Services
- T1021 Remote Services
- T1550 Use Alternate Authentication Material
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1090 Proxy
- T1219 Remote Access Software
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
Path B correction: lead with the known-CVE public-facing foothold, and keep the credential-reuse and destructive-wipe elements.
Affected Product Versions
No new ANCPI-specific CVE is assigned by this advisory. Named infrastructure in DNSC reporting:
- OpenAM/ForgeRock (version unpinned); OpenDJ
- IBM WebSphere
- GitLab (unpatched at time of compromise)
- Zabbix 7.4
- vCenter 6.0.0 build 5112529; ESXi
- FortiSIEM 7.2; FortiGate 300E
- Juniper SRX650 / EX9214
- BitDefender (workstations)
- Oracle Exadata (not accessed)
Custom tooling names only: bytetocrypt, Sliver, Ligolo-ng, dec3.jsp.
Workaround and Mitigation
- Patch ForgeRock/OpenAM CVE-2021-35464.
- Inventory GeoServer separately for CVE-2024-36401 (do not collapse that CVE into the OpenAM foothold).
- Enforce MFA on privileged paths.
- Upgrade GitLab past CVE-2021-22205.
- Prohibit password reuse GitLab → Kerberos → vCenter.
- Authenticate WebSphere JMX.
- Least-privilege Zabbix Scripts.
- No reversible SIEM secrets.
- Extend WAF log retention well beyond ~7 minutes.
- Retire end-of-support vCenter.
- Immutable, restore-tested backups.
- EDR on servers, not workstations only.
- KEV aging for IAM/DevOps tooling in TPRM questionnaires.
Indicators of Compromise
No comprehensive public IoC package has been published. Contextual indicators from DNSC reporting only:
66.163.118.234dec3.jsp- bytetocrypt
- Sliver masquerading as auditd
- Ligolo-ng
- ByteToBreach / ByteToBreach33
No hashes are published in this advisory. Prefer behavioral detection over inventing hash lists, and validate any future indicators before enforcement.
References
- Risky Business, “Hacker wipes Romania's entire land registry database,” 2026-07-20 — https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/
- The Record, “Romania races to restore land registry after cyberattack disrupts property market,” 2026-07-20 — https://therecord.media/romania-cyberattack-land-registry
- DNSC T66/22.07.2026 interim technical analysis (PDF mirror, go4it.ro) — https://www.go4it.ro/wp-content/uploads/2026/07/DNSC-T66-v2026.07.22-Anexa-tehnica-incident-ANCPI.pdf
- CyberShield DNSC T66 PDF mirror — https://www.cybershield.org/wp-content/uploads/2026/07/DNSC-T66-v2026.07.22-Anexa-tehnica-incident-ANCPI.pdf
- AGERPRES, “Guvern: Aplicația informatică e-Terra și-a reluat activitatea,” 2026-08-12 — https://agerpres.ro/politic/2026/08/12/guvern-aplicatia-informatica-e-terra-si-a-reluat-activitatea--1584272
- AGERPRES, Government press release on staged e-Terra restart, 2026-08-11 — https://agerpres.ro/comunicate/2026/08/11/comunicat-de-presa---guvern--1584011
- iDevice.ro, “Geoportal ANCPI și eTerra, ce servicii ANCPI sunt funcționale la 2 luni,” 2026-09-13 — https://www.idevice.ro/2026/09/13/geoportal-ancpi-eterra-servicii-ancpi-sunt-functionale-2-luni-hack-care-blocat-cadastrul-657941/
- NVD CVE-2021-35464 — https://nvd.nist.gov/vuln/detail/CVE-2021-35464
- NVD CVE-2021-22205 — https://nvd.nist.gov/vuln/detail/CVE-2021-22205
- NVD CVE-2024-36401 — https://nvd.nist.gov/vuln/detail/CVE-2024-36401
- CISA Known Exploited Vulnerabilities Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- CISA alert on exploitation of ForgeRock OpenAM (CVE-2021-35464) — https://www.cisa.gov/news-events/alerts/2021/07/22/cisa-issues-alert-exploitation-forgerock-openam-access-management
- GeoServer / OSGeo CVE-2024-36401 advisory — https://geoserver.org/vulnerability/2024/07/02/geoserver-2-cve-2024-36401.html
Third-Party Risk Bridge: KEV Aging, Secrets, and Hypervisor Blast Radius
ANCPI shows TPRM is not only confidentiality: a financially motivated IAB-style actor used known CISA KEV weaknesses (ForgeRock/OpenAM, GitLab), monitoring/SIEM, and end-of-support vCenter to freeze property markets while Exadata databases stayed intact. Demand KEV aging, secrets/MFA that block password reuse, log-retention SLAs, hypervisor segmentation, and restore-tested immutable backups.
Book a demo to see how Rescana tracks KEV-aged IAM, GitLab, and virtualization chokepoints in the third-party estate, and whether password-reuse, log-retention, and restore-tested backup evidence is on file before residual availability risk is closed.
Forward this advisory to TPRM, procurement, and NIS2 owners; use the ANCPI path identity → app server → GitLab → monitoring/SIEM → end-of-support vCenter as a questionnaire checklist.



