2026 Second quarter attacker campaigns
Campaigns in this report
A visual roadmap of the operations examined in this quarterly review. Select any campaign to move directly to its technical analysis.
Quarterly Attack Trends Briefing
Between July and September 2026, the most consequential intrusions again began at systems that organizations were relying on to keep them safe: a fully updated browser, a WAF rule in front of an ERP server, an MFA-protected VPN gateway, a self-hosted Git server, a content-management platform and the camera network at the perimeter. Several of the operations in this report started in late spring and only became visible this quarter, but each was disclosed, escalated or materially updated between July and September.
The defining trend was the speed at which capability moved from one actor to the next. BlueMoon chained two Chrome V8 zero-days with a Windows kernel bug and was in the hands of four espionage clusters within about two weeks. Red Heron turned public Gitea proof-of-concept code into an automated exploitation framework within days of the advisory. wp2shell was probed on the day it was disclosed and reached CISA's Known Exploited Vulnerabilities catalog four days later. ShinyHunters showed the other side of the same compression: when defenders answered its PeopleSoft zero-day with WAF rules instead of patches, it changed a single character of the request path and walked around them.
Identity and session material were the second theme. CitrixBleed 2 let Anubis affiliates replay stolen NetScaler sessions that had already satisfied MFA. NightEagle logged in to corporate VPNs with valid stolen credentials and then used an Exchange backdoor, RDP tunnels and DCSync to reach domain controllers. UTA0533 took root on SonicWall SMA appliances, where it could sniff LDAP credentials in transit. In each case the attacker inherited a trusted position instead of fighting its way in.
The third theme was where the valuable data lives. Cl0p went after PTC Windchill and FlexPLM, the platforms that hold engineering drawings and product data, and extorted victims without encrypting a single file. Red Heron's access to Gitea reached source code, tokens and, in one environment, root on a Proxmox cluster, while ShinyHunters went after PeopleSoft systems that hold HR, payroll and student records. At the other end of the scale, RustDuck and Operation CameraSwarm showed that exposed Telnet, SSH, ADB and camera-management ports still feed botnets and access brokers at volume.
Taken together, these campaigns show an attacker ecosystem moving toward shorter patch-gap exploitation windows, shared exploit capability, trusted-session abuse, engineering and development systems as extortion targets, and durable access to exposed infrastructure at scale. The technical chapters that follow trace how each operation progressed, which ATT&CK techniques were visible, what evidence defenders can hunt, and where intervention is most likely to break the chain.
Browser zero-day espionage
TA412 and BlueMoon: Chrome-to-Windows exploitation for browser espionage
A China-aligned espionage actor delivered a Chrome V8 exploit chain and a Windows kernel privilege-escalation zero-day through spearphishing links, then installed a fake Gemini extension for browser surveillance and credential theft.
Why TA412 and BlueMoon matters
Researchers identified BlueMoon as an exploit kit that chains CVE-2026-85046 (a V8 type confusion in the TurboFan compiler), CVE-2026-87491 (a V8 sandbox escape through WebAssembly metadata corruption) and CVE-2026-85880 (a Windows ALPC/WNF kernel privilege-escalation zero-day that only works on older builds). Both Chrome flaws were patch-gap zero-days: the upstream fix for the first was committed on 7 August but did not reach stable Chrome until 3 September. TA412 was the first observed user, sending internship and conference lures to a small set of US organizations before a loader installed a malicious Chromium extension posing as Google Gemini.
Visual attack flow
Attack methodology and infection process
- Initial access. Phishing messages posed as students seeking internships or as outreach about the AAS-in-Asia 2026 conference, sometimes after rapport-building exchanges. Victims saw a loading page for several seconds and were then redirected to a legitimate site such as github.com or asianstudies.org.
- Browser exploitation. An orchestration script (driver-html.js) runs as a worker and controls retries and the follow-on download. The TurboFan bug, triggered by mutating an array mid-sort, yields addrof/fakeobj primitives and arbitrary read/write inside the V8 cage; the WebAssembly corruption then runs shellcode outside the sandbox.
- Windows escalation. A reflectively loaded DLL collects the Windows build, token integrity level and kernelbase.dll version. Only Windows 10 1809 through 22H2, Server 2019, Server 2022 and Windows 11 21H2 proceed to the LPE DLL, which obtains kernel read/write and enables SeDebugPrivilege.
- Payload launch. Injector shellcode writes a CreateProcess stub into the parent Chrome broker process and runs a curl command that saves msgbox.exe or ChromeUpdate.exe to %TEMP% and executes it.
- Extension install. The installer extracts the extension to C:\Users\Public\stomp_ext, closes Chrome, Edge, Brave and Vivaldi, recomputes the Secure Preferences HMACs and super_mac, and relaunches the browser with --restore-last-session.
- GemStone surveillance. The extension registers with a Cloudflare Workers C&C, polls for commands every 30 seconds or 60 minutes, and can inject a keylogger, capture cookies and storage, take screenshots and issue arbitrary HTTP requests from the browser context.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1566.002 | Phishing: Spearphishing Link | Internship and conference lures with exploit-page links |
| Execution | T1203 | Exploitation for Client Execution | V8 type confusion and sandbox escape |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | ALPC/WNF kernel exploit CVE-2026-85880 |
| Defense Evasion | T1055 | Process Injection | Stub injected into the Chrome broker process |
| Command and Control | T1105 | Ingress Tool Transfer | curl download of msgbox.exe / ChromeUpdate.exe |
| Persistence | T1176 | Browser Extensions | GemStone installed in Chromium-family browsers |
| Defense Evasion | T1036 | Masquerading | Extension presented as a Google Gemini companion |
| Collection | T1056.001 | Input Capture: Keylogging | Injected keylogger/recorder |
| Credential Access | T1539 | Steal Web Session Cookie | CAPTURE_COOKIES command |
| Collection | T1113 | Screen Capture | SCREENSHOT_NOW and keyword-triggered captures |
| Command and Control | T1102 | Web Service | Cloudflare Workers used for C&C |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| SHA-256 | 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d | driver-html.js (TA412 BlueMoon exploit JavaScript) |
| SHA-256 | 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 | ChromeUpdate.exe / msgbox.exe installer |
| SHA-256 | 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee | GemStone background.js service worker |
| Domain | secboxes[.]com; msbenefit[.]com; attcdn[.]com | TA412 exploit delivery and download domains |
| Hostname | extension-management-portal.centerfjdr658.workers[.]dev | GemStone C&C on a Cloudflare Worker |
| Path | C:\Users\Public\stomp_ext | Extension staging directory |
| Process | chrome.exe → cmd.exe → curl.exe → msgbox.exe | Default BlueMoon process tree |
| Artifact | v8ctf_exp_attempt (sessionStorage); kc_state; portal_sync_config | Exploit retry counter and GemStone extension state keys |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Update Chrome and every Chromium-based browser (Edge, Brave, Vivaldi) as soon as stable builds ship, apply the September 2026 Windows updates, and retire the older Windows builds the LPE targets.
- Alert on chrome.exe spawning cmd.exe or curl.exe, and on executables written to %TEMP% by a browser child process.
- Inventory extensions installed outside the Web Store; hunt for Secure Preferences changes, C:\Users\Public\stomp_ext and Gemini-themed extensions that request cookies and scripting permissions.
- Deploy the public Emerging Threats signatures for the BlueMoon loader and GemStone C&C (SIDs 2071919–2071924 and 2071996–2072001) and restrict workers.dev callbacks where there is no business need.
- Treat confirmed victims as credential and session compromises: revoke sessions, remove the extension and rotate passwords entered in the browser.
Enterprise application exploitation
ShinyHunters: renewed Oracle PeopleSoft mass exploitation
An extortion group re-weaponized a patched PeopleSoft flaw by URL-encoding one character of the request path, bypassing WAF-only mitigations and deploying web shells, a trojanized-installer backdoor and tunneling tools on dozens of servers worldwide.
Why ShinyHunters matters
CVE-2026-35273 is a critical unauthenticated deserialization flaw in PeopleSoft's Environment Management Hub (PSEMHUB) servlet. UNC6240 exploited it as a zero-day between 27 May and 9 June 2026, mostly against universities, and Oracle issued an out-of-band alert on 10 June. Mandiant and Google Threat Intelligence Group now report a second wave in which the group adapted to published guidance: requesting /%50SEMHUB/ instead of /PSEMHUB/ slips past WAF rules that match the literal path before decoding. ShinyHunters also claimed a PeopleSoft-based compromise of FBI infrastructure on 22 September; the point of entry has not been established, and no link to CVE-2026-35273 has been confirmed. [mandiant-peoplesoft]
Visual attack flow
Attack methodology and infection process
- Target verification. Servers typically receive five to 15 POST requests to /%50SEMHUB/hub carrying a serialized Java object. Unpatched servers answer with the host operating system without writing files, which lets the actor confirm exploitability quietly.
- WAF bypass. %50 is the encoded form of P. WAF and proxy rules that match /PSEMHUB before decoding miss the request, while WebLogic decodes the path and serves the vulnerable servlet.
- Exploitation. Two methods were seen: a burst of requests followed by x.jsp or sequentially numbered JSP files in PSEMHUB.war (the repetition likely ensures every node behind a load balancer gets a copy), and fileless execution where command output returns in the HTTP response.
- Post-exploitation tooling. x.jsp accepts hex-encoded commands and detects the operating system; u.jsp and u2.jsp write 150 KB Base64 chunks. On Windows, Ple64.exe masquerades as a signed Light Alloy installer, unpacks a VMProtect-protected launcher and loads SIDEEYE, which talks to its C2 over raw TCP ports 3333 and 3334. Neo-reGeorg tunnel.jsp and tunnel.jspx provide SOCKS5 over HTTP(S).
- Persistence and access. On Linux, UNC6240 deployed MeshAgent and used IT-themed infrastructure (winmanage-me[.]network). A quarter of observed commands ran as root or NT AUTHORITY\SYSTEM; the rest ran as PeopleSoft or WebLogic service accounts, which still expose configuration files and database connection strings.
- Collection and extortion. Defenders should look for large tar, tar.gz or zstd archives, and for rsync, sshpass or curl launched by the WebLogic service account, ahead of extortion contact.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Reconnaissance | T1595.002 | Active Scanning: Vulnerability Scanning | Five to 15 verification POSTs per target |
| Initial Access | T1190 | Exploit Public-Facing Application | CVE-2026-35273 via /%50SEMHUB/hub |
| Persistence | T1505.003 | Server Software Component: Web Shell | x.jsp, u.jsp and tunnel.jsp/jspx |
| Execution | T1059.003 | Windows Command Shell | cmd.exe spawned by the WebLogic Java process |
| Execution | T1059.004 | Unix Shell | /bin/sh reconstructed from an ASCII character array |
| Defense Evasion | T1027 | Obfuscated Files or Information | Hex-encoded commands; VMProtect-packed launcher |
| Credential Access | T1552.001 | Credentials In Files | psappsrv.cfg and application secrets |
| Command and Control | T1090 | Proxy | Neo-reGeorg SOCKS5 over HTTP(S) |
| Command and Control | T1219 | Remote Access Software | MeshAgent / MeshCentral |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol | rsync (TCP 873), SSH and HTTP POST |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| IP | 5.199.162[.]157 | Attack controller, scanner and HTTP callback receiver |
| IP | 104.219.234[.]138 | Exfiltration staging and MeshCentral host |
| IP | 162.219.30[.]165 | SIDEEYE C2 (TCP 3333/3334) |
| Domain | winmanage-me[.]network | MeshCentral infrastructure |
| URI | /%50SEMHUB/ | Percent-encoded WAF bypass; assume other variants exist |
| SHA-256 | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 | Ple64.exe trojanized installer delivering SIDEEYE |
| SHA-256 | 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 | x.jsp (hashes vary with whitespace) |
| Path | PSEMHUB.war/x.jsp; u.jsp; tunnel.jsp; tunnel.jspx; Ple64.exe | Files that are not part of the shipped product |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Apply Oracle's Security Alert patch for CVE-2026-35273; WAF rules and path blocking are not a substitute for patching.
- Disable EMHub in multi-server configurations or remove PSEMHUB in single-server ones, and enforce blocking on the normalized path, including percent-encoded and mixed-case variants.
- Search WebLogic access logs for /PSEMHUB/ and encoded variants, POST requests to /hub, and requests to unexpected .jsp files; check every node behind the load balancer.
- Alert on shell processes spawned by the WebLogic Java process, especially those using base64 -d, curl, /dev/tcp, tasklist or start /b.
- Rotate every credential readable by the PeopleSoft tier and prepare for extortion contact if a web shell is found.
Credential-led cyberespionage
NightEagle: stolen VPN access to GhostContainer and Active Directory compromise
A cyberespionage group that previously focused on Asia used valid VPN credentials, an in-memory Exchange backdoor and legitimate tunneling features to move from the perimeter to Active Directory at Russian manufacturing and construction organizations.
Why NightEagle matters
Incident responders investigated several NightEagle intrusions over the past year. Most began with stolen VPN credentials used from Russian addresses linked to Cloudflare WARP tunnels and from European VPS providers. The operators placed GhostContainer, a .NET backdoor, on Microsoft Exchange servers, hosted their tooling in GitHub repositories named to look benign, exposed RDP through Microsoft dev tunnels and rdp2tcp, and used BlueKeep, Kerberos ticket abuse and DCSync to reach domain controllers. The defensive problem is that almost every step uses a valid account or a legitimate feature.
Visual attack flow
Attack methodology and infection process
- Initial access. In most incidents the operators connected to corporate VPNs with compromised valid credentials, routing through Cloudflare WARP-linked Russian addresses and European virtual infrastructure providers.
- GhostContainer on Exchange. The backdoor is a .NET assembly that incorporates the Neo-reGeorg tunnel, a CVE-2020-0688 exploit and the GhostWebShell class from ysoserial. Analysts assess with high confidence that it was delivered by extracting Exchange cryptographic keys from the ASP.NET configuration, overwriting the VIEWSTATE parameter and injecting a payload that starts the backdoor in memory. C2 commands arrive in x-owa-urlpostdata headers, and the code overwrites addresses in amsi.dll and ntdll.dll to evade AMSI and event logging.
- Tool staging. Archives were hosted in GitHub repositories such as mirror-js/mirror-js and browserthemes/resourcepack, and the executables inside mimic Adobe, TrueConf and 1C software.
- Tunneling. Microsoft dev tunnels published port 3389 on *.devtunnels.ms, rdp2tcp carried TCP traffic over established RDP sessions, and Impacket atexec created scheduled tasks that ran netsh interface portproxy rules.
- Active Directory compromise. In one incident BlueKeep (CVE-2019-0708) created a local account that was added to Administrators and Remote Desktop Users. The operators also requested Kerberos tickets with Forwardable, Proxiable and Renewable flags and attempted DCSync to impersonate a domain controller.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1133 | External Remote Services | Corporate VPN access with stolen credentials |
| Initial Access | T1078 | Valid Accounts | Compromised VPN accounts from WARP and VPS ranges |
| Execution | T1620 | Reflective Code Loading | VIEWSTATE payload starts GhostContainer in memory |
| Defense Evasion | T1562.001 | Impair Defenses: Disable or Modify Tools | AMSI and event-log evasion in the backdoor |
| Command and Control | T1105 | Ingress Tool Transfer | GitHub-hosted archives with disguised executables |
| Command and Control | T1572 | Protocol Tunneling | Dev tunnels, rdp2tcp and netsh portproxy |
| Lateral Movement | T1021.001 | Remote Desktop Protocol | RDP to internal servers through tunnels |
| Lateral Movement | T1210 | Exploitation of Remote Services | BlueKeep (CVE-2019-0708) |
| Execution | T1053.005 | Scheduled Task | Impacket atexec tasks for port forwarding |
| Credential Access | T1003.006 | OS Credential Dumping: DCSync | Replication of the Domain-Password object |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| MD5 | 1dcafb7f8448683281106b06dd22409a | AdobeSync.exe |
| MD5 | 1f3034b706c78b35d8e34044e68c693a | adobe_32.exe |
| MD5 | 3ecd1cd627d0340c92901a478a7caad8; 631fb131a56caf4ca0f287ed73e876ab | App_Web_Container_1.dll (GhostContainer) |
| MD5 | 4aa9fb1bf9223dfcdac920759bc7a3c7 | 1c-office-plugin.exe, 1cbroker.exe, trueconf.exe |
| URL | github[.]com/mirror-js/mirror-js; github[.]com/browserthemes/resourcepack | Repositories hosting the tool archives |
| Domain | *.devtunnels[.]ms | Dev tunnel used to expose RDP |
| Event log | RdpCoreTS Operational events 132/148 with channel name rdp2tcp | Virtual-channel creation by rdp2tcp or random channel names |
| Command | netsh interface portproxy add v4tov4 listenport=443 ... connectport=445 | Port forwarding created through scheduled tasks |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Require strong MFA on VPN access, review VPN accounts that appear in credential leaks, and alert on sessions from Cloudflare WARP or VPS ranges.
- Enable and retain RDP operational logs, scheduled-task auditing, PowerShell logging, DNS records and Active Directory replication auditing.
- Alert on DNS lookups for *.devtunnels.ms, RDP virtual channels named rdp2tcp, and netsh portproxy changes created by remote scheduled tasks.
- Patch or retire systems exposed to BlueKeep and monitor for DCSync requests from hosts that are not domain controllers and for Kerberos tickets with unusual flag combinations.
- Rotate Exchange validation and decryption keys after suspected VIEWSTATE abuse, and hunt for unexpected App_Web_*.dll assemblies on Exchange servers.
Development-infrastructure compromise
Red Heron: Gitea exploitation to virtualization root access
A suspected PRC-linked actor weaponized a critical Gitea RCE within days of its advisory, stole repositories and secrets at scale, and in one Taiwanese environment pivoted from a Synology-hosted Gitea server to root on a three-node Proxmox cluster.
Why Red Heron matters
Gitea 1.27.1 fixed CVE-2026-60004 on 27 July 2026, and the advisory with a working proof of concept followed on 28 July. Acronis TRU found that Red Heron began adapting a public PoC on 29 July and, by early August, had an automated framework (exp_enhanced.py) that registered accounts, exploited servers, dumped repositories and cleaned up traces. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States and Sri Lanka. Because the actor left its staging server open, researchers saw its target lists, command history, stolen repositories and a new Linux implant, JITTERLY, with an embedded rootkit, SIXZUT. [acronis-red-heron]
Visual attack flow
Attack methodology and infection process
- Vulnerability. The diffpatch endpoint runs git apply with three-way merge fallback inside a bare temporary clone. Submitting the same patch twice forces a checkout to disk, so a file written to hooks/post-index-change executes as the Gitea service account. Open registration, enabled by default, removes the need for prior credentials. Affected versions are 1.17 through 1.27.0.
- Targeting. Targets were classified with Simplified Chinese sector labels (defense, elections, energy, aerospace, telecom, government, research); 128 had open signup, and a separate list held 477 Taiwanese instances.
- Exploitation and theft. The framework registers accounts with a word_word_NNN pattern, exploits each server, dumps the filesystem and repositories with --dump-fs, and attempts to remove its traces from the Gitea database. Hashcat was used on stolen bcrypt hashes.
- Persistence. SSH keys named like victim-backdoor and root-shell were planted, a raw TCP backdoor accepted key:command input, and one victim was accessed through the Gitea metrics API.
- Virtualization takeover. On a Taiwanese Synology NAS the actor obtained a Proxmox root@pam ticket, uploaded payloads to three nodes and launched vzdump backups, which could have exposed full VM disk images.
- Implant and rootkit. JITTERLY, a C++ implant compatible with the Adaptix C2 protocol, supports more than 30 commands. SIXZUT drops libglthread.so.2, writes it to LD_PRELOAD, hides files, processes and connections, blocks kill signals and relaunches the implant.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Reconnaissance | T1595.002 | Active Scanning: Vulnerability Scanning | FOFA-driven scan of 1,386 Gitea instances |
| Initial Access | T1190 | Exploit Public-Facing Application | CVE-2026-60004 in the diffpatch workflow |
| Execution | T1059.004 | Unix Shell | Commands run as the Gitea service account |
| Credential Access | T1110.002 | Password Cracking | Hashcat against stolen Gitea bcrypt hashes |
| Credential Access | T1552.001 | Credentials In Files | JWT, internal tokens and SSH host keys from config |
| Persistence | T1098.004 | SSH Authorized Keys | Planted ed25519 backdoor keys |
| Persistence | T1574.006 | Dynamic Linker Hijacking | SIXZUT through /etc/ld.so.preload |
| Defense Evasion | T1014 | Rootkit | Hidden files, processes and connections |
| Collection | T1213.003 | Data from Information Repositories: Code Repositories | Bulk repository and database theft |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Gitea access to Proxmox root administrative access |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| SHA-256 | b441f793c87e54cb7e3f7205e25442aa19920d325cb6af41d2afdc8a0b5cf54f | agent.elf (JITTERLY implant) |
| SHA-256 | 28b132ad55bd310bb5cf3ddb4ace580529ad735204a48cf388830d9039843d8e | SIXZUT rootkit decrypted from JITTERLY |
| Domain | s2.981666[.]xyz:8082 | JITTERLY C2 (parent domain 981666[.]xyz) |
| IP | 72.11.138[.]109 | Staging server (port 8888) |
| Ports | 48931; 48932 | Raw TCP backdoor ports |
| File | libglthread.so.2; .ld_aux_cahe; /tmp/.X11-unix.lk | SIXZUT artifacts (hidden from userland tools) |
| Account | dsaopk; pvenum02; word_word_NNN pattern; @poc.local | Exploit and Proxmox enumeration accounts |
| Network | User-Agent gitea-rce-poc/4.0; /api/v1/metrics?k=<key>&x=<cmd> | Exploit user-agent and metrics-API backdoor |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Upgrade Gitea to 1.27.1 or later, disable open registration, restrict the diffpatch route and keep Gitea behind a VPN or authenticating proxy.
- Review accounts and repositories created since 28 July; alert on Gitea spawning shells, interpreters or curl.
- Check /etc/ld.so.preload and hunt for SIXZUT artifacts from a known-good kernel, offline image or EDR telemetry, because the rootkit hides them on the live host.
- Audit authorized_keys and outbound connections; treat every credential, token and SSH host key stored in Gitea as disclosed and rotate it.
- Rebuild compromised hosts rather than cleaning them, and segment Proxmox and NAS management planes from developer tooling.
Shared zero-day exploitation capability
BlueMoon proliferation: four espionage groups adopt one Chrome-Windows exploit kit
Within days of TA412's first use, three more espionage clusters deployed the same exploit chain with different lures and payloads, including ShadowPad, a Rust loader and a DNS-over-HTTPS-resolved backdoor.
Why BlueMoon proliferation matters
Researchers report that the same orchestration and loading code appeared in every build, so the kit almost certainly came from one source, but it is not known how four actors obtained it. Volexity published parallel research on the same day. Analysts saw rushed deployments: infrastructure created the same day as campaigns, a default payload that is just a curl download, and development artifacts (verbose logging, a markdown handover reference and v8CTF strings) that are consistent with, though not proof of, AI-assisted development. The broader lesson is that open-source patch gaps shorten the time between a public Chromium fix and a working exploit.
Visual attack flow
Attack methodology and infection process
- UNK_LateNight (from 2 September). RFQ-themed emails aimed at US aerospace and defense companies linked to domains spoofing aerospace firms. The loader dropped a DLL-sideloading pair plus an AES-encrypted TMP file, injected ShadowPad into targets such as wmpnetwk.exe, and created the scheduled task EdgeCore_AutoUpdate. ShadowPad unhooks 20 network-monitoring functions and beacons to ms.checrity[.]com.
- UNK_DoubleCheck (from 2 September). Emails from a compromised Southeast Asian government address, themed around vaccination appointments, hit a Vietnamese manufacturer. The only obfuscated BlueMoon variant used curl to fetch wint.exe, calibre-launcher.dll and an RC4-encrypted SysPr.prx, which loads a Rust executable that pulls a second stage from a Cloudflare R2 bucket and uses fracons[.]com for C&C.
- UNK_QuietRacket (from 3 September). Indonesian conference lures (Indo Startup Expo & Forum 2026 and WCCE 2026) targeted government, consulting and finance organizations in Indonesia and Singapore. A modified injector fetched GfExperienceService64.exe and GFExperienceUpdate.dll, which resolve C&C by decrypting Google DoH TXT records and then use Cloudflare Workers.
- Shared pattern. All builds share the exploit chain and the loader structure (p1 reconnaissance DLL, p2 LPE DLL, pp injector shellcode), and the default process tree is chrome.exe, cmd.exe, curl.exe, then the payload.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1566.002 | Phishing: Spearphishing Link | RFQ, vaccination and conference lures |
| Execution | T1203 | Exploitation for Client Execution | V8 type confusion and sandbox escape |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | CVE-2026-85880 on older Windows builds |
| Defense Evasion | T1574.002 | DLL Side-Loading | wint.exe, GfExperienceService64.exe and ShadowPad pairs |
| Persistence | T1053.005 | Scheduled Task | EdgeCore_AutoUpdate, GeForceService, Avpcheckup |
| Persistence | T1546.015 | Component Object Model Hijacking | CLSID InprocServer32 registry write (UNK_DoubleCheck) |
| Defense Evasion | T1055 | Process Injection | Injection into the Chrome broker and wmpnetwk.exe |
| Command and Control | T1102 | Web Service | Cloudflare Workers and R2 buckets |
| Command and Control | T1573 | Encrypted Channel | ChaCha20-decrypted DoH TXT records; ShadowPad binary C&C |
| Collection | T1040 | Network Sniffing | ShadowPad traffic sniffing |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| Process | chrome.exe → cmd.exe → curl.exe → msgbox.exe | Default BlueMoon process tree |
| Task | EdgeCore_AutoUpdate | UNK_LateNight ShadowPad persistence |
| Task | MicrosoftEdgeUpdatesTaskMachine; Avpcheckup | UNK_DoubleCheck persistence |
| Task | GeForceService (C:\ProgramData\GfExperienceService64.exe) | UNK_QuietRacket persistence |
| Domain | ms.checrity[.]com; 79.133.56[.]90 | ShadowPad C&C and fallback IP |
| Domain | brianwilli[.]com; fracons[.]com | UNK_DoubleCheck download and C&C domains |
| Domain | elixnovorem[.]com; getaiexo[.]com; velodynaity[.]com | UNK_QuietRacket DoH TXT lookup domains |
| Artifact | Mutex Dataupcheckinfo; sessionStorage key v8ctf_exp_attempt | UNK_DoubleCheck mutex and exploit retry counter |
| SHA-256 | 295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915 | UNK_LateNight msgbox.exe loader |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Roll out Chrome and Chromium-based browser updates within hours, not weeks, and apply the September Windows updates; move off Windows builds targeted by the LPE.
- Alert on browser child processes running curl and on first-run executables or DLL pairs in %APPDATA%, %TEMP% and ProgramData.
- Hunt for the listed scheduled task names, CLSID registry persistence and unusual DoH or Cloudflare Workers traffic from non-browser processes.
- Apply the published YARA rule (MAL_BlueMoon_ExploitKit) and ET signatures 2071919–2071924 to proxy and web telemetry.
- Expect further adopters: add detections based on the chain, not on any one actor's infrastructure.
WordPress mass exploitation
wp2shell: pre-authentication WordPress RCE moves from disclosure to exploitation
Two WordPress Core flaws chain a REST batch route confusion with a SQL injection into pre-authentication remote code execution, and attacks began on the day of disclosure.
Why wp2shell matters
Searchlight Cyber's Assetnote team disclosed wp2shell on 17 July 2026. It works against default installations with no plugins, and the REST batch endpoint it abuses has shipped since WordPress 5.6. Wordfence recorded probing on the day of disclosure, public PoCs followed within days, and CrowdSec saw first exploitation on 20 July; CISA added the flaws to KEV on 21 July. By 22 August CrowdSec had logged more than 3.1 million matching signals and 62,802 attacking IPs. F5 Labs captured a replayed UNION-based injection but did not observe a web shell in that traffic. [crowdsec-wp2shell]
Visual attack flow
Attack methodology and infection process
- Discovery. Scanners test the batch route in three forms: /wp-json/batch/v1, /index.php?rest_route=/batch/v1 and /?rest_route=/batch/v1, which work when pretty permalinks are off.
- Route confusion. An outer batch request wraps an inner batch with malformed sub-request paths; a parse failure shifts indexes between the validation and match arrays so the dispatcher reaches handlers it should not.
- SQL injection. The posts endpoint maps author_exclude to WP_Query's author__not_in argument, which is not sanitized enough. Detection should key on author_exclude, the name visible in HTTP traffic.
- Escalation (public PoCs). Public tools use the injection to forge cache objects and a changeset that creates an administrator, then upload a plugin to run commands. Observed in-the-wild activity so far is dominated by scanning and injection attempts.
- Post-exploitation. Defenders should look for unexpected administrators, new files in wp-content/plugins/ and wp-content/cache/, and commands launched by the web server process.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Reconnaissance | T1595.002 | Active Scanning: Vulnerability Scanning | Batch endpoint and wp-json enumeration |
| Initial Access | T1190 | Exploit Public-Facing Application | Batch route confusion plus author_exclude injection |
| Collection | T1213 | Data from Information Repositories | Database content exposed through SQL injection |
| Persistence | T1136 | Create Account | Administrator creation in public PoC chains |
| Persistence | T1505.003 | Server Software Component: Web Shell | Plugin-based web shell in public PoC chains |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| IP | 185.242.3[.]238 | Source of an F5-captured, replayed 735-byte exploit |
| Request | POST /wp-json/batch/v1 with nested "requests" arrays and "///" paths | Route-confusion signature |
| Parameter | author_exclude containing UNION, SELECT, hex values or %29+UNION | SQL injection through WP_Query |
| User-Agent | Strings referencing wp2shell | Purpose-built tooling |
| Path | wp-content/plugins/; wp-content/cache/ | Unexpected PHP files or plugins after exploitation |
| Behavior | New administrator account created without a login event | Changeset-forgery outcome |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Update to WordPress 6.9.5, 7.0.2 (or 6.8.6 for the SQL injection alone) or later; auto-updates should be enabled for core.
- Where patching is delayed, block unauthenticated access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the edge.
- Add WAF rules for nested batch requests and for author_exclude values containing SQL metacharacters or hex strings.
- Audit administrator accounts, plugins, wp-content/cache/ and recently modified PHP files on every site exposed before patching.
- Monitor outbound connections from the web tier and rotate database and salt secrets on suspected compromises.
Enterprise data-theft campaign
Cl0p and PTC Windchill: centralized engineering data becomes an extortion target
Cl0p exploited a critical deserialization flaw in PTC Windchill and FlexPLM, planted JSP web shells, stole engineering and product data and extorted victims without deploying ransomware.
Why Cl0p and PTC Windchill matters
CVE-2026-12569 is an unauthenticated deserialization flaw in PTC Windchill PDMLink and FlexPLM, added to CISA's KEV catalog on 25 June. Intrusions were weeks old when Ransom-ISAC began seeing extortion emails titled "Windchill PDMLink module serious data leak" on 20 July, sent to hundreds of employees at each victim. ZeroFox counted 43 organizations posted between 14 and 19 August and read the campaign as a shift from personal and financial records to engineering intellectual property. Cl0p followed its MOVEit, GoAnywhere, Cleo and Oracle E-Business Suite pattern: one widely deployed application, many victims in a short window, then public pressure. [secpod-blog]
Visual attack flow
Attack methodology and infection process
- Discovery. Attackers identify internet-facing Windchill and FlexPLM servers and use reconnaissance against the FlexPLM WSDL functionality.
- Exploitation. Unsafe processing of attacker-controlled serialized data gives unauthenticated code execution; the flaw has been paired with a pre-authentication information disclosure on the FlexPLM WSDL endpoint.
- Web shells. JSP files appear in /Windchill/login/ with 16-character or six-character hexadecimal names, and a dpr_ variant with eight hex characters.
- Implant capability. Reporting describes a custom implant that can decrypt credentials in the Windchill keystore, enumerate connected file repositories and pull data in bulk, rather than a simple command shell.
- Theft. Operators list files, stage selected data and exfiltrate it; some victims claim multi-terabyte theft.
- Extortion. Emails come from compromised accounts, include Cl0p contact details and name Windchill PDMLink. The leak site began naming victims in August; no file encryption was used.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | CVE-2026-12569 against Windchill and FlexPLM |
| Persistence | T1505.003 | Server Software Component: Web Shell | JSP shells in /Windchill/login/ |
| Discovery | T1083 | File and Directory Discovery | flst.txt file listings |
| Credential Access | T1552 | Unsecured Credentials | Keystore credentials and application secrets |
| Command and Control | T1105 | Ingress Tool Transfer | Tooling brought onto compromised servers |
| Collection | T1074 | Data Staged | Selected files prepared for transfer |
| Collection | T1213 | Data from Information Repositories | Engineering and PLM repositories |
| Impact | T1657 | Financial Theft | Data-theft extortion without encryption |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| Path | /Windchill/login/[0-9a-f]{16}.jsp; [0-9a-f]{6}.jsp; dpr_[0-9a-f]{8}.jsp | Web shell hunting patterns |
| Path | /Windchill/login/7c0a0a34c9d8d53b.jsp; 46b158b8607a4c00.jsp | Known web shell names |
| Header | X-windchill-req: ?x8Fmgow | Malicious request header |
| IP | 5.180.41[.]35; 38.60.157[.]212; 74.50.76[.]146; 78.128.113[.]10 | Campaign infrastructure (correlate; not proof alone) |
| IP | 104.194.9[.]14; 137.184.184[.]209; 185.227.83[.]236; 216.152.151[.]204 | Campaign infrastructure |
| SHA-256 | 321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf | Incident-observed file |
| File | flst.txt | File-listing artifact from discovery |
| Subject "Windchill PDMLink module serious data leak" | Extortion message sent to many employees |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Apply PTC's fixes for CVE-2026-12569 on every Windchill and FlexPLM instance and remove direct internet exposure where possible.
- Hunt for JSP files in /Windchill/login/ by pattern, not only by hash, and review logs back to June 2026.
- Search HTTP telemetry for the X-windchill-req header and correlate with JSP execution and outbound connections.
- Rotate keystore, database and service credentials reachable from the Windchill server.
- Prepare an extortion-response plan for data theft without encryption, including legal, customer and IP-exposure assessment.
VPN appliance zero-day exploitation
UTA0533 and KNUCKLEBALL: root-level compromise of SonicWall SMA appliances
A previously unknown actor chained two SonicWall SMA 1000 zero-days to reach root, installed appliance-specific implants and sniffed LDAP credentials before the flaws were disclosed.
Why UTA0533 and KNUCKLEBALL matters
Volexity found the intrusion during incident response in early July after suspicious authentication and lateral-movement attempts originated from SMA appliances. CVE-2026-15409 is a pre-authentication /wsproxy bypass that tunnels to localhost-only services; CVE-2026-15410 is a command injection in the control service's remove-hotfix method that runs a script as root. Patches are in 12.4.3-03453 and 12.5.0-02835. UTA0533 used 200+ source IPs, including commercial VPN ranges, and appears to have had limited success moving laterally. [volexity-sonicwall]
Visual attack flow
Attack methodology and infection process
- Tunnel. Requests to /wsproxy with the right user-agent and bmID return HTTP 101 and open WebSockets to EPMD (1051), CouchDB (1050) and the control service (8188) without a session cookie.
- Root. The actor used CouchDB's built-in admin:admin credentials to stage a script that reads the appliance UUID, then traversed out of the rollback directory (../../../../../tmp/1234.sh) to execute it as root.
- Implants. ROOTRUN (/usr/bin/xzfind) is a setuid root command runner. KNUCKLEBALL (deploy_new.py) injects two JARs into workplace.startup.CommandStartup using the Java Attach API and is made persistent through init.d.
- Java agents. Suo5 is an HTTP proxy tool; ORANGETAIL is a Behinder-style webshell with a hardcoded AES key. Both only answer a specific fake user-agent, so passive scans see 404s.
- Credential theft and pivoting. On the second appliance, tcpdump scripts captured LDAP on TCP 389; the actor leaked hostnames including DESKTOP-5P0TSCP and KALI. A reboot on 2 July removed memory-resident implants there.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | /wsproxy authentication bypass (CVE-2026-15409) |
| Initial Access | T1078.001 | Valid Accounts: Default Accounts | CouchDB admin:admin |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | execRemoveHotfix traversal (CVE-2026-15410) |
| Privilege Escalation | T1548.001 | Abuse Elevation Control: Setuid | ROOTRUN setuid binary |
| Persistence | T1037.004 | RC Scripts | deploy_new.py added to /etc/init.d/workplace |
| Execution | T1059.006 | Python | KNUCKLEBALL injector |
| Defense Evasion | T1055 | Process Injection | JARs injected through the Java Attach API |
| Persistence | T1505.003 | Server Software Component: Web Shell | ORANGETAIL |
| Command and Control | T1090 | Proxy | Suo5 HTTP proxy |
| Credential Access | T1040 | Network Sniffing | tcpdump capture of LDAP traffic |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| SHA-256 | 81a9af3846bad3a1107164ff7cf0a08e020b31a3b32fd17866e17d4c1565f7f2 | ROOTRUN (xzfind) |
| SHA-256 | 8c470301dcb7278f73e622f1950073567b34011c64b60cdfbb0f89803923a5a3 | KNUCKLEBALL (deploy_new.py) |
| SHA-256 | 1e1e68bbb899450a57274a8b12082ed4e2040a2aae77014f20431689d2b4edee | agent_wp8.jar (Suo5) |
| SHA-256 | ea9154e374e4f77bc2cf54282e23543573980342a85bc888cb23f20b8bbba081 | agent_wp9.jar (ORANGETAIL) |
| Path | /usr/bin/xzfind; /usr/lib/python3.11/site-packages/deploy_new.py | Dropped implant files |
| Config | /var/lib/unit/conf.json routes to http://127.0.0.1:8085 | Rewrites for /__api__/login and /__api__/logout |
| Log | /wsproxy?bmID=-3389...&host=0.0.0.0&port=1050 or 8188 (HTTP 101) | Exploitation in extraweb_access.log |
| Log | "running hotfix removal for:../../../../../tmp/..." in ctrl-service.log | CVE-2026-15410 execution |
| UA | Mozilla/6.0 (Windows NT 11.0; ...) Chrome/149.0.0.1 | Gate string for the implants |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Install SonicWall's fixed builds (12.4.3-03453 or 12.5.0-02835) and hunt back to 22 June, not to the disclosure date.
- Review extraweb_access.log, access_servers.log and ctrl-service.log for /wsproxy abuse and traversal strings.
- Check unit/conf.json for unexpected routes, run find / -perm -4000 for unexpected setuid binaries, and inspect /tmp and /var/tmp.
- Monitor appliances for outbound connections and authentication attempts to internal hosts; rebooting alone does not remove persistence.
- Reimage compromised appliances and rotate LDAP, VPN and service credentials that crossed them; use LDAPS to limit sniffing exposure.
Edge-to-ransomware intrusion
CitrixBleed 2 and Anubis: stolen sessions open the path to ransomware
Anubis affiliates reached victims through valid VPN credentials and CitrixBleed 2 session theft, blended in with legitimate RMM tools and encrypted Windows, Linux and NAS systems.
Why CitrixBleed 2 and Anubis matters
Arctic Wolf found that Anubis affiliates entered through valid VPN credentials or CitrixBleed 2, a pre-authentication memory disclosure on NetScaler Gateway and AAA servers that can reveal session tokens and bypass MFA. Because affiliates differ, the report is a catalog of affiliate tradecraft rather than a single operator's playbook. The consistent pattern is remote access, then RDP or SMB movement, RMM deployment, credential access and exfiltration tools before encryption. Patching alone does not evict a stolen session. Victim totals vary by date: Arctic Wolf cited up to 83 at publication and later coverage cites 91. [secpod-blog]
Visual attack flow
Attack methodology and infection process
- Initial access. Valid VPN credentials (including Cisco AnyConnect logins from hosting ASNs) or CitrixBleed 2. In the example log, the session's Source IP (45.227.254[.]25) differed from the original broadband Client_ip.
- Lateral movement. RDP between VPN client ranges and servers that normally get no interactive logons, Hyper-V servers used as jump hosts, and PsExec service creation (PSEXESVC.exe).
- RMM abuse. ScreenConnect from lookalike azuremicrosoft[.]us, Zoho Assist agents under the ZohoMeeting path, MeshAgent (mvtcs.exe, sysagent.exe, MeshUserTask), Remotely, UltraVNC and Total Software Deployment.
- Credential access. Mimikatz in Public and temp folders, Chrome and Edge password exports, and an ntds.dit copy followed within an hour by encryption in one case.
- Tunneling and exfiltration. cloudflared on Synology NAS and Windows servers, an authenticated proxy, ssh -D SOCKS proxies, and S3 Browser, rclone, s5cmd, WinSCP and PuTTY.
- Impact. Defender disablement, SophosUninstall, PCHunter and log clearing preceded encryption. Anubis writes .anubis files and RESTORE FILES.html on Windows and Linux.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | CitrixBleed 2 on NetScaler Gateway / AAA |
| Initial Access | T1078 | Valid Accounts | Stolen VPN credentials and hijacked sessions |
| Lateral Movement | T1021.001 | Remote Desktop Protocol | RDP to RDS servers, DCs and hypervisors |
| Execution | T1569.002 | System Services: Service Execution | PsExec service creation |
| Command and Control | T1219 | Remote Access Software | ScreenConnect, Zoho Assist, MeshAgent and others |
| Credential Access | T1003.001 | LSASS Memory | Mimikatz on Windows servers |
| Credential Access | T1003.003 | NTDS | Copy of ntds.dit |
| Command and Control | T1572 | Protocol Tunneling | cloudflared and SSH dynamic forwarding |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | S3 Browser, rclone and s5cmd |
| Defense Evasion | T1562.001 | Impair Defenses | Defender disabled; Sophos uninstall |
| Impact | T1486 | Data Encrypted for Impact | Anubis encryptors on Windows, Linux and NAS |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| IP | 45.227.254[.]25 | Source of a suspicious NetScaler VPN session |
| IP | 45.76.79[.]92 | Remotely Desktop C2 |
| Domain | azuremicrosoft[.]us; promotds[.]us (relay.promotds[.]us) | ScreenConnect installer and relay lookalikes |
| Task | MeshUserTask | MeshAgent persistence |
| Process | PSEXESVC.exe; tniwinagent.exe; cloudflared in C:\Windows | PsExec, Total Software Deployment and tunnel client |
| Extension | .anubis; RESTORE FILES.html | Encrypted files and ransom note |
| Path | C:\audit\Active Directory\ntds.dit; C:\Users\Public\mimikatz.exe | Credential staging locations |
| Behavior | Remote access → RDP/SMB → RMM → credentials → exfiltration tooling | Sequence that is detectable before encryption |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Patch NetScaler for CVE-2025-5777 and then terminate all active ICA, PCoIP, RDP Proxy and AAA sessions per Citrix guidance.
- Compare Client_ip and Source in gateway logs and alert on VPN sessions from VPS or hosting ASNs.
- Maintain an RMM allow-list; alert on a second or third RMM product appearing on a host within a short window.
- Detect Rclone, S3 Browser, cloudflared and SSH SOCKS tunnels on servers and NAS devices, and tamper attempts against EDR.
- Segment Hyper-V, NAS and backup infrastructure and keep immutable, tested backups.
Resilient IoT botnet activity
RustDuck: a Rust-based DDoS botnet engineered to outlast detection
A still-small DDoS botnet is being rewritten from C to Rust, hardening its loader, anti-analysis checks and C2 encryption while recruiting routers, cameras, Android boxes and exposed servers.
Why RustDuck matters
XLab describes RustDuck as small compared with the largest botnets but fast-moving. The loader has gone through four variants with different encryption schemes, and the core module is shifting to Rust, which resists the toolkit analysts have used on Mirai-style malware. It spreads through weak Telnet and SSH credentials, exposed Android ADB, and known flaws in TVT, Ruijie, TP-Link, ZTE, ThinkPHP, Jenkins, Hadoop YARN and Apache CouchDB, plus CVE-2025-29635, CVE-2017-17215, CVE-2024-1781 and CVE-2018-8007. More than 20 IPs were spreading it, led by 176.65.139[.]204. [xlab-rustduck]
Visual attack flow
Attack methodology and infection process
- Infection paths. Weak or default Telnet and SSH passwords, exposed ADB, and RCE in routers, DVRs and cameras, plus web and enterprise components such as ThinkPHP, Jenkins and YARN.
- Two-stage loading. The loader appends compressed core data and config to an ELF. Variants moved from LCG with XOR and LZ4, to Xoshiro128 with BLZ, to standard XOR with a fixed magic string, to ChaCha20.
- Anti-analysis. The core scores process lists (Wireshark, gdb, frida), TracerPid, injected libraries, an appended SHA-256 checksum, Cowrie and Dionaea files, sandbox environment variables, a connect test to 192.0.2.1, dual-clock sleep timing and VM hardware or MAC prefixes; high scores trigger cleanup and exit.
- C2 protocol. Handshake with Curve25519 and HKDF-SHA256, ChaCha20-Poly1305 for authentication, then AES-GCM with separate uplink and downlink keys; command traffic carries a three-byte header resembling TLS records.
- Commands. Attack (types 3 and 8), stop (9), update (10), status (11) and C2 update (14), so operators can rotate infrastructure without losing bots.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Initial Access | T1110.001 | Brute Force: Password Guessing | Weak Telnet and SSH credentials |
| Initial Access | T1190 | Exploit Public-Facing Application | Device, ThinkPHP, Jenkins, YARN and CouchDB flaws |
| Defense Evasion | T1027 | Obfuscated Files or Information | Encrypted and compressed core; evolving loaders |
| Defense Evasion | T1497.001 | Virtualization/Sandbox Evasion: System Checks | Hardware, MAC, process and honeypot checks |
| Defense Evasion | T1497.003 | Virtualization/Sandbox Evasion: Time Based | Dual-clock sleep comparison |
| Defense Evasion | T1622 | Debugger Evasion | TracerPid and tool checks |
| Command and Control | T1568 | Dynamic Resolution | DuckDNS C2 domains |
| Command and Control | T1573.002 | Encrypted Channel: Asymmetric Cryptography | Curve25519 key exchange |
| Impact | T1498.001 | Network Denial of Service: Direct Network Flood | DDoS attack commands |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| SHA-1 | 8315f650e9e4f67c00277b076ab304eed23db47d | Loader variant 1 |
| SHA-1 | 6aa791c76b3107fca9d57b7ecea8f46d97d83738 | Loader variant 2 |
| SHA-1 | 4d11bd496da82d15b3ed13050f414e44f5a892d4 | Loader variant 3 |
| SHA-1 | d39a3ee96be6b8f5238cb1253514ab55c88f714c | Loader variant 4 |
| IP | 176.65.139[.]204 | Most active delivery source |
| Domain | igmc[.]duckdns[.]org; qewqewqewqtq[.]duckdns[.]org | DuckDNS C2 (more in the XLab report) |
| Domain | dhdsjsdjxc[.]duckdns[.]org; fcfrfxrfrsfs5f[.]duckdns[.]org | Additional DuckDNS C2 hostnames |
| Network | Connection attempt to 192.0.2.1; TLS-like 17 03 03 record header | Sandbox check and C2 framing |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Remove Telnet, SSH and ADB from the internet, and change default passwords on every device.
- Patch or replace end-of-life gear; CISA's guidance for the D-Link DIR-823X is to remove it from service.
- Monitor for DuckDNS or other dynamic-DNS lookups from IoT and server networks and block where unneeded.
- Update analysis tooling to handle Rust binaries and feed XLab's hashes and domains into monitoring, expecting variants to change them.
- Use upstream DDoS mitigation and egress filtering so compromised devices cannot join attacks.
Surveillance infrastructure compromise
Operation CameraSwarm: 14,530 Dahua devices compromised at scale
One operator brute-forced, bypassed and relayed its way into more than 14,000 Dahua cameras in 35 days, planting a backdoor account on 1,923 devices and building transferable admin access.
Why Operation CameraSwarm matters
Hunt.io reconstructed the campaign from a 407 MB operator directory that was left exposed (2,616 files). Three paths ran in parallel: brute force against TCP/37777 reached 12,324 unique IPs, the CVE-2021-33044 and CVE-2021-33045 authentication bypasses planted a backdoor on 1,923 cameras, and abuse of Dahua's P2P relay reached 283 more by serial number. The operator's own code records that 89.4 percent of live serials returned an open channel. Counts come from Hunt.io's analysis and have not been independently confirmed. [secpod-blog]
Visual attack flow
Attack methodology and infection process
- Scanning. masscan swept Russian address space and then the full IPv4 range on port 37777, skipping blocks outside local business hours.
- Brute force. The Easy4IP engine scaled from 300 to 4,000 workers, abandoned hosts after five failures to preserve them for a later CVE pass, captured filtered snapshots and exported results for SMART PSS (13,229 records, 52 XML files).
- Bypass chain. p2pwn exploits NetKeyboard trust (CVE-2021-33044) and a loopback source-address spoof (CVE-2021-33045), then installs the backdoor account over RPC; it survives password changes and, on most firmware, a factory reset.
- P2P relay. Fixed SDK credentials in every Dahua client authenticate to the relay, and a serial number is enough to reach management ports; control still needs credentials or a bypass.
- Transferable access. Offline recovery-code generation and SMART PSS exports led Hunt.io to assess, with moderate confidence, that the toolkit was built to hand access to a third party.
- Separate capability. A UPX-packed Windows binary (SalatStealer-tagged) and a Defender exclusion script on the same host should be treated as a distinct incident.
MITRE ATT&CK mapping
| Tactic | ID | Technique | Observed use |
|---|---|---|---|
| Reconnaissance | T1595.001 | Active Scanning: IP Block Scanning | masscan of TCP/37777 |
| Reconnaissance | T1596.005 | Search Open Technical Databases: Scan Databases | Shodan queries and DDNS enumeration |
| Initial Access | T1190 | Exploit Public-Facing Application | CVE-2021-33044, CVE-2021-33045 and relay abuse |
| Credential Access | T1110.003 | Password Spraying | Asyncio engine against port 37777 |
| Persistence | T1136.001 | Create Account: Local Account | p2pwn account on 1,923 cameras |
| Collection | T1113 | Screen Capture | Snapshot capture with quality filtering |
| Exfiltration | T1567.004 | Exfiltration Over Webhook | Telegram Bot API notifications |
| Lateral Movement | T1210 | Exploitation of Remote Services | Relay tunnel access; ONVIF credential dumping |
Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.
Indicators of compromise and high-signal artifacts
| Type | Indicator | Why it matters |
|---|---|---|
| IP | 154.86.119[.]60 | Operator server with exposed directory |
| IP | 185.132.53[.]56 | Second sighting of the staged Windows payload |
| Account | p2pwn / p2password | Backdoor account on compromised cameras |
| Port | 37777/TCP | Dahua Easy4IP management protocol |
| SHA-256 | 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8 | p2pwn compiled Go ELF |
| SHA-256 | de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c | 1.exe / xeno.exe (SalatStealer-tagged, separate incident) |
| Request | clientType "NetKeyboard"; loginType "Loopback" with ipAddr 127.0.0.1 | Does not occur in legitimate Dahua client traffic |
| Note | easy4ipcloud[.]com relay addresses | Legitimate Dahua infrastructure; do not block |
Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.
Campaign-specific detection and mitigation
- Treat any Dahua camera reachable on port 37777 between June and July 2026 as potentially compromised; search for and remove the p2pwn account.
- Update firmware (Dahua SA-2021-0130 fixes the bypasses), which also stops new recovery codes from working; removing the account alone is not enough.
- Disable P2P unless required and keep port 37777 off the internet.
- Rotate all credentials stored on affected devices and NVRs, including ONVIF accounts.
- Do not block Dahua relay addresses wholesale; detect on login patterns instead.
Consolidated defense
Mitigations across all campaigns
These controls are ordered around the recurring attack surfaces visible across the campaigns: patch gaps and half-measures, trusted sessions and credentials, remote-management and development platforms, incomplete telemetry, and weak recovery assurance.
Close patch gaps, not just exposure
- Treat browser and edge-device updates as hours-level work when exploitation is reported; Chrome, Edge and WordPress core need automatic updates.
- Do not accept WAF rules as a substitute for patches; enforce blocking on normalized paths and verify the fix.
- Retire unsupported Windows builds and end-of-life routers, cameras and appliances.
Protect identities and sessions
- Terminate sessions after patching gateway flaws such as CitrixBleed 2, and correlate VPN logins with identity-provider records.
- Review VPN accounts that appear in leaks; alert on logins from hosting, WARP or commercial-VPN ranges.
- Remove default credentials from embedded services and cameras; rotate secrets reachable from any compromised web tier.
Govern remote management and development platforms
- Keep an approved RMM list and alert on additional tools; restrict Gitea registration and exposure; place Windchill, PeopleSoft and similar systems behind authenticated access.
- Monitor application servers for shell children, new JSP or PHP files and web-root changes.
- Audit browser extensions and treat extension installs outside the store as incidents.
Detect defense impairment and stealth
- Alert on AMSI or ETW tampering, EDR loss, log clearing, LD_PRELOAD changes and unexpected setuid binaries.
- Forward appliance, firewall, VPN, application and camera logs off the device to immutable storage.
- Inspect appliances and Linux hosts from outside the running system when rootkits are suspected.
Prepare for destructive impact and extortion
- Keep offline, immutable, tested backups, and segment hypervisors, NAS, backup and management planes from user networks.
- Rebuild appliances and rootkit-affected hosts instead of cleaning them, then rotate every credential they touched.
- Plan for data-theft extortion without encryption, including intellectual-property exposure assessment.




