<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Anoymask</title>
    <description>The latest articles on DEV Community by Anoymask (@anoymask).</description>
    <link>https://dev.to/anoymask</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4048482%2F63fd1bb1-84ed-45fd-a7bf-f71b390279ee.jpg</url>
      <title>DEV Community: Anoymask</title>
      <link>https://dev.to/anoymask</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/anoymask"/>
    <language>en</language>
    <item>
      <title>macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Sat, 15 Aug 2026 04:23:00 +0000</pubDate>
      <link>https://dev.to/anoymask/macos-screen-sharing-cve-2026-65400-authentication-bypass-leads-to-root-access-and-monero-miner-37kh</link>
      <guid>https://dev.to/anoymask/macos-screen-sharing-cve-2026-65400-authentication-bypass-leads-to-root-access-and-monero-miner-37kh</guid>
      <description>&lt;h1&gt;
  
  
  macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; Critical&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Title:&lt;/strong&gt; Hackers exploit macOS Screen Sharing flaw to deploy Monero miner&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Published Date:&lt;/strong&gt; 2026-08-14&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Updated Date:&lt;/strong&gt; N/A&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Article:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/" rel="noopener noreferrer"&gt;Original Article&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; &lt;a href="https://support.apple.com/en-us/148170" rel="noopener noreferrer"&gt;Apple Security&lt;/a&gt;, &lt;a href="https://advisories.ncsc.nl/2026/ncsc-2026-0280.html" rel="noopener noreferrer"&gt;NCSC-NL NCSC-2026-0280&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malware:&lt;/strong&gt; Monero cryptocurrency miner (Name and hash unknown)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Threat Groups:&lt;/strong&gt; N/A&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVEs:&lt;/strong&gt; CVE-2026-65400&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Products:&lt;/strong&gt; macOS Screen Sharing, macOS Tahoe before 26.6.1, macOS Sequoia before 15.7.9, macOS Sonoma before 14.8.9, VNC/TCP 5900&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Summary
&lt;/h2&gt;

&lt;p&gt;An authentication state management flaw in macOS Screen Sharing exposed to the internet allows attackers to authenticate without valid credentials. Multiple cases have reached root access and the deployment of a Monero miner.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Attack Chain Confirmed in Public Reports
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attacker connects to macOS Screen Sharing from the internet via TCP/5900.&lt;/li&gt;
&lt;li&gt;The attacker exploits the authentication state flaw in CVE-2026-65400 to establish a session without valid credentials.&lt;/li&gt;
&lt;li&gt;The attacker gains the ability to launch applications, access files, and change security settings via remote desktop.&lt;/li&gt;
&lt;li&gt;In multiple cases reported to NCSC-NL, the attacker obtains root access.&lt;/li&gt;
&lt;li&gt;A Monero cryptocurrency miner is installed.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The attacker reaches the public VNC/TCP 5900 service from the internet.&lt;/li&gt;
&lt;li&gt;Initial execution occurs within the macOS Screen Sharing service and the remote GUI session.&lt;/li&gt;
&lt;li&gt;Specific steps for root acquisition, the presence of other vulnerabilities, and miner persistence methods are not publicly disclosed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;No user interaction is required. Screen sharing indicators or cursor/GUI changes may sometimes be visible.&lt;/li&gt;
&lt;li&gt;Administrators may observe TCP/5900 connections from external IPs, screen sharing sessions not tied to regular accounts, root processes, and miners/high CPU usage.&lt;/li&gt;
&lt;li&gt;Because valid accounts are not used, a password reset alone cannot contain the vulnerability.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Screen Sharing is enabled on the affected macOS.&lt;/li&gt;
&lt;li&gt;TCP/5900 is reachable by the attacker.&lt;/li&gt;
&lt;li&gt;Patches are not applied.&lt;/li&gt;
&lt;li&gt;There are no controls to block execution or settings changes after a remote session.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Update to Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9, or later.&lt;/li&gt;
&lt;li&gt;Disable unnecessary Screen Sharing.&lt;/li&gt;
&lt;li&gt;Block TCP/5900 from the internet and restrict it to VPN or management networks.&lt;/li&gt;
&lt;li&gt;Early detection and isolation of remote sessions, root processes, and miner/pool communications.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Remote desktop access without authentication.&lt;/li&gt;
&lt;li&gt;File access, application launching, and security setting changes.&lt;/li&gt;
&lt;li&gt;Root access and Monero miner installation in actual reported incidents.&lt;/li&gt;
&lt;li&gt;Root acquisition paths, persistence, data theft, and lateral movement are not confirmed in public data.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Email
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;None related.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Proxy / SWG / DNS
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DNS queries and traffic to miner pools/Stratum endpoints (Specific IOCs not public).&lt;/li&gt;
&lt;li&gt;Connections to unknown download sources.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint / EDR
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Screen Sharing related processes and sessions.&lt;/li&gt;
&lt;li&gt;Unknown binaries running as root.&lt;/li&gt;
&lt;li&gt;Increased CPU/GPU usage.&lt;/li&gt;
&lt;li&gt;Miner-specific processes and command lines.&lt;/li&gt;
&lt;li&gt;LaunchDaemons (useful if identified, though specific persistence methods are not public).&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Identity / IdP
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Screen Sharing authentication success not tied to a valid account.&lt;/li&gt;
&lt;li&gt;Inconsistencies in local login/authorization events.&lt;/li&gt;
&lt;li&gt;Sessions persisting after password changes.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  SaaS / Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;None related. MDM device versions and compliance can be used to check patch status.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Network
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;TCP/5900 connections from the internet.&lt;/li&gt;
&lt;li&gt;Connections from the same source to multiple Macs.&lt;/li&gt;
&lt;li&gt;Outbound miner pool traffic following a session.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Determination
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Contact Only
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;TCP/5900 scan or SYN packets only.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  User Interaction
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Not required.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Execution
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Screen Sharing session established and GUI/application manipulation observed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Malware or Successful Authentication
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Authentication success without valid credentials, root access, or miner process.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Data Theft / Session Compromise
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Remote desktop sessions can be confirmed, but data exfiltration is not confirmed in public reports.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Compromise Confirmation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirmation of miner installation, security setting changes, additional payloads, or lateral movement.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Trigger
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Internet-exposed TCP/5900.&lt;/li&gt;
&lt;li&gt;macOS versions matching NCSC advisory.&lt;/li&gt;
&lt;li&gt;Unknown Screen Sharing sessions.&lt;/li&gt;
&lt;li&gt;Root miner or high CPU usage.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Verification
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm macOS version, Screen Sharing settings, exposure path, initial source IP, and timestamp.&lt;/li&gt;
&lt;li&gt;Cross-reference account/session logs with valid login activity.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Preserve process trees, launchd entries, file creations, quarantine/xattr attributes, unified logs, and network sockets.&lt;/li&gt;
&lt;li&gt;Identify the start time of root access and the miner binary/hash.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Authentication and Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Check local account/password change history, MDM commands, and SaaS sessions.&lt;/li&gt;
&lt;li&gt;Note that initial access does not require a valid account.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Actions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Hunt for downloads, persistence, pool communication, SSH/remote services, file access, and lateral movement.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Containment
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Block TCP/5900, disable Screen Sharing, isolate the host, apply patches, and terminate all sessions.&lt;/li&gt;
&lt;li&gt;Consider credential rotation and system rebuilding if root compromise is confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Determination Categories
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Scanned&lt;/li&gt;
&lt;li&gt;Unauthenticated Screen Session Confirmed&lt;/li&gt;
&lt;li&gt;Root Access Confirmed&lt;/li&gt;
&lt;li&gt;Miner Installed&lt;/li&gt;
&lt;li&gt;Additional Compromise Confirmed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Single Event
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Internet to TCP/5900 connection.&lt;/li&gt;
&lt;li&gt;Screen Sharing success without a matching valid account.&lt;/li&gt;
&lt;li&gt;Unknown miner running as root.&lt;/li&gt;
&lt;li&gt;Sustained high CPU load.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Time-Series Correlation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Port 5900 connection → Screen Sharing session → GUI/process launch → Root process → Miner download → Pool communication.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Threat Hunting Perspective
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Inventory of Macs exposed to the internet.&lt;/li&gt;
&lt;li&gt;OS versions older than August 6.&lt;/li&gt;
&lt;li&gt;Screen Sharing and remote management unified logs.&lt;/li&gt;
&lt;li&gt;New binaries running as root.&lt;/li&gt;
&lt;li&gt;Stratum or known miner pool connections.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Log Gaps
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Screen Sharing authentication results.&lt;/li&gt;
&lt;li&gt;Remote GUI actions.&lt;/li&gt;
&lt;li&gt;Root acquisition path.&lt;/li&gt;
&lt;li&gt;File access.&lt;/li&gt;
&lt;li&gt;Miner IOCs.&lt;/li&gt;
&lt;li&gt;Launchd modifications.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Priority Actions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Update operating systems.&lt;/li&gt;
&lt;li&gt;Block port 5900 from the internet.&lt;/li&gt;
&lt;li&gt;Set Screen Sharing to default-off.&lt;/li&gt;
&lt;li&gt;Segregate management planes.&lt;/li&gt;
&lt;li&gt;Monitor root processes and egress traffic.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Apple patched CVE-2026-65400 on August 6, 2026.&lt;/li&gt;
&lt;li&gt;The root cause is a state management flaw in Screen Sharing authentication, allowing network attackers to authenticate without valid credentials.&lt;/li&gt;
&lt;li&gt;NCSC-NL reported active abuse on multiple systems with port 5900 exposed to the internet.&lt;/li&gt;
&lt;li&gt;Root access and Monero miner deployment were confirmed in all reported cases.&lt;/li&gt;
&lt;li&gt;Methods for root acquisition, miner names/hashes, and persistence are not publicly disclosed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Macs with TCP/5900 directly exposed to the internet should be prioritized for inventory and patching.&lt;/li&gt;
&lt;li&gt;Confirming a compromise requires correlating post-session root processes and egress traffic, not just authentication logs.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Payloads other than miners could potentially be deployed, though this has not been confirmed in public reports.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;T1190 Exploit Public-Facing Application&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1133 External Remote Services&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1496 Resource Hijacking&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1105 Ingress Tool Transfer&lt;/strong&gt; — Confidence: Medium (Miner download path is not public)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1543.004 Launch Daemon&lt;/strong&gt; — Confidence: Low (Investigation perspective; persistence methods unconfirmed)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Additional Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Specific attack chain for acquiring root access.&lt;/li&gt;
&lt;li&gt;Miner binaries/hashes, download URLs, and pool/C2 servers.&lt;/li&gt;
&lt;li&gt;Presence of persistence, defense evasion, lateral movement, or data access.&lt;/li&gt;
&lt;li&gt;Number of victim systems, geographic locations, and threat actors.&lt;/li&gt;
&lt;li&gt;Consistency between public PoCs and actual attack payloads.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and General Enterprises
&lt;/h2&gt;

&lt;p&gt;Development, design, and research environments often utilize remote Mac support. Organizations should not lower priority based solely on a CVSS score of 7.1. Instead, they should execute emergency patching and retrospective hunting based on exposed port 5900, active exploitation, and root miner risks.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Audience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Evaluate port 5900 contact, unauthenticated sessions, root access, and miners as separate stages, and explicitly note that the root acquisition path remains unknown.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Update to the three patched versions, disable unnecessary Screen Sharing, and never expose port 5900 to the internet.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Users:&lt;/strong&gt; Report unexpected screen activity, sudden high system load, unusual heat generation, or fan noise on Macs to administrators.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>GeoServer jsonArrayContains SQL Injection: Hundreds of Attempts Observed, RCE Conditions, and the 2023 CVE Gap</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Sat, 15 Aug 2026 04:22:49 +0000</pubDate>
      <link>https://dev.to/anoymask/geoserver-jsonarraycontains-sql-injection-zero-day-mass-probes-hours-after-disclosure-rce-159a</link>
      <guid>https://dev.to/anoymask/geoserver-jsonarraycontains-sql-injection-zero-day-mass-probes-hours-after-disclosure-rce-159a</guid>
      <description>&lt;h1&gt;
  
  
  GeoServer jsonArrayContains SQL Injection Zero-Day Report: High Volume Probes, Verify PoC RCE Conditions and Differences from Known Vulnerabilities
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; Critical&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Hackers Exploiting Unpatched GeoServer Zero-Day&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; SecurityWeek&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-14&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Update Date:&lt;/strong&gt; None&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Article:&lt;/strong&gt; &lt;a href="https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/" rel="noopener noreferrer"&gt;Original Article&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://geoserver.org/vulnerability/2023/02/20/ogc-filter-injection.html" rel="noopener noreferrer"&gt;GeoServer OGC Filter Injection Vulnerability Statement (2023-02-20)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://geoserver.org/announcements/2023/02/20/geoserver-2-22-2-released.html" rel="noopener noreferrer"&gt;GeoServer 2.22.2 Release / GEOT-7302 Escape user inputs in SQL queries&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malware:&lt;/strong&gt; None&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Groups:&lt;/strong&gt; None&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVEs:&lt;/strong&gt; Unassigned for the 2026 report (at the time of publication). The 2023 OGC Filter SQL injection involving the same &lt;code&gt;jsonArrayContains&lt;/code&gt; is CVE-2023-25157 (GeoServer) / CVE-2023-25158 (GeoTools).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Products:&lt;/strong&gt; GeoServer, GeoTools, &lt;code&gt;jsonArrayContains&lt;/code&gt; filter/function, PostGIS JDBC data store, Oracle JDBC data store&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Verification Note:&lt;/strong&gt; The SecurityWeek article reports the 2026 issue as an unpatched zero-day. Meanwhile, GeoServer already fixed the OGC Filter SQL injection involving &lt;code&gt;jsonArrayContains&lt;/code&gt; + PostGIS/Oracle in 2023 under CVE-2023-25157/CVE-2023-25158. A PoC reviewed during this analysis claims SQLi/RCE against PostgreSQL, but the currently verifiable GeoTools implementation includes escape processing for the &lt;code&gt;expected&lt;/code&gt; string. It remains unconfirmed whether the 2026 issue is a regression, a different vector, an escape bypass, an unpatched branch/version, or a discrepancy from the PoC description. The PoC itself is not attached or republished in this report or the public article.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;SecurityWeek reported a GeoServer SQL injection zero-day via &lt;code&gt;jsonArrayContains&lt;/code&gt; and a high volume of probes within hours of its public disclosure. However, this function was already targeted and fixed for SQL injection in 2023, and there are discrepancies between the assumptions of the analyzed PoC and the current GeoTools implementation. Therefore, additional confirmation is required to determine the exact root cause, impacted versions, and RCE conditions of the 2026 issue.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  SQL Injection / Probing (SecurityWeek Report)
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;An attacker sends a filter query to a publicly exposed GeoServer endpoint.&lt;/li&gt;
&lt;li&gt;The attacker passes crafted user arguments to &lt;code&gt;jsonArrayContains&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The attacker abuses input processing in the backend JDBC/DB query to attempt SQL injection.&lt;/li&gt;
&lt;li&gt;The attacker attempts SQL query manipulation, DB data access, and DB behavior changes.&lt;/li&gt;
&lt;li&gt;WatchTowr observations cited by SecurityWeek show hundreds of exploit attempts from a small number of source IPs within hours of public disclosure.&lt;/li&gt;
&lt;li&gt;No follow-up compromise after the probes has been confirmed at the time of publication.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Configuration-Dependent RCE on PostgreSQL (Vector Claimed by Analyzed PoC)
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;SQL injection via &lt;code&gt;jsonArrayContains&lt;/code&gt; succeeds.&lt;/li&gt;
&lt;li&gt;Database connection conditions allow stacked queries.&lt;/li&gt;
&lt;li&gt;The PostgreSQL connection user has high privileges required for server-side program execution.&lt;/li&gt;
&lt;li&gt;The attack can lead to OS command execution on the database host via SQL features.&lt;/li&gt;
&lt;li&gt;The execution occurs on the database host side (if PostgreSQL is on a separate host), not on the GeoServer/JVM host.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Blind Data Extraction (Vector Claimed by Analyzed PoC)
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;SQL injection succeeds.&lt;/li&gt;
&lt;li&gt;Differences in database response time are used as a boolean oracle.&lt;/li&gt;
&lt;li&gt;The attacker sequentially infers database names, table/column metadata, and allowed table data.&lt;/li&gt;
&lt;li&gt;The scope of obtainable data depends on the privileges of the database user used by GeoServer.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The attacker sends requests from the internet to the filter processing functions (such as WFS/WMS) of a public GeoServer instance.&lt;/li&gt;
&lt;li&gt;The SQL injection is executed by the backend database connected from GeoServer, and the impact is limited by the database user privileges.&lt;/li&gt;
&lt;li&gt;The RCE vector in the analyzed PoC assumes PostgreSQL server-side program execution. If successful, the resulting OS process, file, or network activity occurs on the database host.&lt;/li&gt;
&lt;li&gt;Regarding Oracle, SecurityWeek and the 2023 official advisory mention it as a target for &lt;code&gt;jsonArrayContains&lt;/code&gt; SQL injection, but the analyzed PoC targets PostgreSQL, and the same RCE vector cannot be generalized to Oracle.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;No user interaction is required, and attack requests may be received concurrently with normal map and service usage.&lt;/li&gt;
&lt;li&gt;Administrators may observe abnormal filters containing &lt;code&gt;jsonArrayContains&lt;/code&gt;, SQL errors, database queries, or long response times.&lt;/li&gt;
&lt;li&gt;If PostgreSQL RCE succeeds, prioritize checking for abnormal processes, file creation, and network connections under the database service, rather than the GeoServer/Java child process.&lt;/li&gt;
&lt;li&gt;A high volume of probes does not mean a successful compromise. Judge HTTP request arrival, SQLi success, database data access, and OS command execution as separate stages.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The target GeoServer/filter endpoint is reachable by the attacker.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;jsonArrayContains&lt;/code&gt; and the relevant String/JSON field are available on the target layer/data store.&lt;/li&gt;
&lt;li&gt;Unidentified vulnerability conditions reported in 2026 actually apply to the target version and configuration.&lt;/li&gt;
&lt;li&gt;The scope of readable/updatable data after SQLi is permitted by database user privileges.&lt;/li&gt;
&lt;li&gt;The stacked-query path in the analyzed PoC requires connection conditions that allow multiple statements to execute.&lt;/li&gt;
&lt;li&gt;PostgreSQL RCE in the analyzed PoC requires additional privileges allowing the database user to execute server-side programs.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Isolate GeoServer from the internet and restrict access to trusted networks/VPNs.&lt;/li&gt;
&lt;li&gt;Block abnormal filter inputs using a WAF or API gateway.&lt;/li&gt;
&lt;li&gt;Temporarily remove vulnerable function and data store combinations from public exposure paths.&lt;/li&gt;
&lt;li&gt;Limit metadata/data access, writes, and server-side program execution using database least privilege.&lt;/li&gt;
&lt;li&gt;If the vendor releases a patch or advisory for the 2026 issue, check the affected versions and apply updates quickly.&lt;/li&gt;
&lt;li&gt;Update environments unpatched for the 2023 CVEs (CVE-2023-25157/CVE-2023-25158) to known fixed versions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;SQL query manipulation&lt;/li&gt;
&lt;li&gt;Data read/modify within database user privileges&lt;/li&gt;
&lt;li&gt;Potential blind data inference via time-based SQLi&lt;/li&gt;
&lt;li&gt;Potential remote OS command execution on the database host in PostgreSQL configurations meeting the additional conditions assumed by the analyzed PoC&lt;/li&gt;
&lt;li&gt;Hundreds of attempts/probing observed at the time of publication, while follow-on compromises remain unconfirmed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Email
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;None related&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Proxy / SWG / DNS
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;jsonArrayContains&lt;/code&gt; filter requests to the GeoServer endpoint&lt;/li&gt;
&lt;li&gt;Abnormal CQL/filter strings containing quotes, comments, or functions&lt;/li&gt;
&lt;li&gt;Repeated requests from the same source&lt;/li&gt;
&lt;li&gt;Unknown egress originating from the database host after RCE success&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint / EDR
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For GeoServer/JVM, check for abnormal terminations, errors, and resource spikes during request processing&lt;/li&gt;
&lt;li&gt;For suspected PostgreSQL RCE, look for unexpected child processes under the database service&lt;/li&gt;
&lt;li&gt;Execution of shells, interpreters, or utilities&lt;/li&gt;
&lt;li&gt;Unexpected file creation on the database host&lt;/li&gt;
&lt;li&gt;Process execution outside normal operations by the database service account&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Identity / IdP
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Initial attacks target web filter processing as an entry point, so IdP authentication events alone are insufficient for determination&lt;/li&gt;
&lt;li&gt;GeoServer/database service credential changes and secret access are targets for follow-on investigation&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  SaaS / Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;WAF/load balancer/API gateway access logs&lt;/li&gt;
&lt;li&gt;GeoServer application logs&lt;/li&gt;
&lt;li&gt;Managed database audit/query logs&lt;/li&gt;
&lt;li&gt;Database service account/role privileges&lt;/li&gt;
&lt;li&gt;Cloud flow logs&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Network
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Many requests from a small number of source IPs&lt;/li&gt;
&lt;li&gt;GeoServer to database sessions&lt;/li&gt;
&lt;li&gt;Unexpected outbound traffic from the database host&lt;/li&gt;
&lt;li&gt;Callbacks/scans if a follow-on occurs&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Determination
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Contact Only
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Observed GeoServer scans or requests containing &lt;code&gt;jsonArrayContains&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  User Interaction
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;None required&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Execution
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Crafted filter requests reached and were processed by the GeoServer application&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  SQL Injection Success
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Database errors/timing, audit queries, or unintended database side effects support SQLi success&lt;/li&gt;
&lt;li&gt;When relying solely on time-based behavior from the analyzed PoC, separation from network latency is required&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  RCE Success
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm unexpected child processes under the database service, file creation, or network connections on the PostgreSQL database host&lt;/li&gt;
&lt;li&gt;Do not rely solely on GeoServer/Java child processes as the condition for RCE success&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Data Theft / Session Compromise
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm database result/data access, metadata enumeration, and external transmission with separate evidence&lt;/li&gt;
&lt;li&gt;Confirm credential/session access as separate follow-on evidence&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Compromise Confirmation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm persistence, internal scans, new accounts, web shells, data modification, and lateral movement&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Trigger
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Abnormal &lt;code&gt;jsonArrayContains&lt;/code&gt; requests&lt;/li&gt;
&lt;li&gt;GeoServer exposure reported in SecurityWeek&lt;/li&gt;
&lt;li&gt;SQL errors or timing spikes&lt;/li&gt;
&lt;li&gt;Unexpected child processes under the database service&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Confirmation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Determine GeoServer/GeoTools version, data stores, public exposure, target layers/fields, and first requests/sources&lt;/li&gt;
&lt;li&gt;Check application status of patches for 2023 vulnerabilities CVE-2023-25157/CVE-2023-25158&lt;/li&gt;
&lt;li&gt;Review HTTP requests/responses, GeoServer logs, and database audit/query logs with time synchronization&lt;/li&gt;
&lt;li&gt;Check PostgreSQL prepared statement settings and database user roles/privileges, while treating impact on the 2026 issue as unconfirmed&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Preserve GeoServer/JVM process trees, application logs, temp/web directories, and sockets&lt;/li&gt;
&lt;li&gt;For separate database hosts, prioritize preserving database process trees, service accounts, file integrity, and sockets&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Authentication / Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Privileges of GeoServer-to-database credentials&lt;/li&gt;
&lt;li&gt;PostgreSQL role membership and server-side program execution capabilities&lt;/li&gt;
&lt;li&gt;Check secret access, managed database audits, and control-plane changes&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Operations
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Database query/data access, metadata enumeration&lt;/li&gt;
&lt;li&gt;Callbacks from the database host&lt;/li&gt;
&lt;li&gt;New users, scheduled tasks, web shells, and lateral movement&lt;/li&gt;
&lt;li&gt;Data modification/exfiltration&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Containment
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Restrict public access&lt;/li&gt;
&lt;li&gt;Apply WAF virtual patches&lt;/li&gt;
&lt;li&gt;Stop public exposure paths for vulnerable functions and data stores&lt;/li&gt;
&lt;li&gt;Implement database least privilege&lt;/li&gt;
&lt;li&gt;Rotate database credentials if necessary&lt;/li&gt;
&lt;li&gt;If RCE evidence exists, isolate the affected database host and decide whether to rebuild&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Determination Categories
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Scanned&lt;/li&gt;
&lt;li&gt;Exploit Attempted&lt;/li&gt;
&lt;li&gt;SQL Injection Suspected&lt;/li&gt;
&lt;li&gt;SQL Injection Confirmed&lt;/li&gt;
&lt;li&gt;Data Access Confirmed&lt;/li&gt;
&lt;li&gt;RCE Confirmed&lt;/li&gt;
&lt;li&gt;Follow-on Compromise Confirmed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Single Events
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;jsonArrayContains&lt;/code&gt; combined with SQL metacharacters or comments&lt;/li&gt;
&lt;li&gt;GeoServer SQL errors&lt;/li&gt;
&lt;li&gt;Database query latency anomalies&lt;/li&gt;
&lt;li&gt;Database service to unexpected child process&lt;/li&gt;
&lt;li&gt;Database host to unexpected outbound traffic&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Time-Series Correlation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Crafted filter -&amp;gt; GeoServer/database error or timing anomaly -&amp;gt; abnormal database query -&amp;gt; database child process/file -&amp;gt; outbound traffic&lt;/li&gt;
&lt;li&gt;Crafted filter -&amp;gt; repeated timing requests -&amp;gt; metadata/data access evidence&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Threat Hunting Perspectives
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Public GeoServer inventory&lt;/li&gt;
&lt;li&gt;GeoServer/GeoTools versions and application status of 2023 OGC Filter SQLi patches&lt;/li&gt;
&lt;li&gt;Use of PostGIS or Oracle&lt;/li&gt;
&lt;li&gt;Layers and JSON fields utilizing &lt;code&gt;jsonArrayContains&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Source concentration after disclosure&lt;/li&gt;
&lt;li&gt;New processes, files, or network activities by PostgreSQL service users&lt;/li&gt;
&lt;li&gt;Database roles with server-side program execution privileges&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Log Gaps
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;HTTP queries/bodies&lt;/li&gt;
&lt;li&gt;GeoServer filter/application logs&lt;/li&gt;
&lt;li&gt;Database audit/query logs&lt;/li&gt;
&lt;li&gt;Database process lineage&lt;/li&gt;
&lt;li&gt;Database service role/privilege snapshots&lt;/li&gt;
&lt;li&gt;Egress traffic&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Priority Countermeasures
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Reduce external exposure&lt;/li&gt;
&lt;li&gt;Apply WAF virtual patches&lt;/li&gt;
&lt;li&gt;Verify application of known 2023 fixed versions&lt;/li&gt;
&lt;li&gt;Implement database least privilege&lt;/li&gt;
&lt;li&gt;Database host EDR/process monitoring&lt;/li&gt;
&lt;li&gt;Monitor vendor advisories/patches for the 2026 issue&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SecurityWeek reported an unpatched GeoServer SQL injection zero-day via &lt;code&gt;jsonArrayContains&lt;/code&gt; on 2026-08-14.&lt;/li&gt;
&lt;li&gt;Information referenced by existing reports from SecurityWeek states that WatchTowr observed hundreds of exploit attempts from a small number of source IPs within hours of disclosure, with no follow-on activity confirmed at the time of publication.&lt;/li&gt;
&lt;li&gt;GeoServer officially announced in 2023 that using &lt;code&gt;jsonArrayContains&lt;/code&gt; with String/JSON fields and PostGIS/Oracle DataStores introduced SQL injection vulnerabilities tracked as CVE-2023-25157/CVE-2023-25158.&lt;/li&gt;
&lt;li&gt;The 2023 issues were fixed in GeoServer 2.22.2, 2.21.4, 2.20.7, 2.19.7, 2.18.7, etc., and GEOT-7302 introduced SQL escaping for user input.&lt;/li&gt;
&lt;li&gt;The analyzed PoC implements time-based SQLi, stacked queries, database metadata/data extraction, and OS command execution via server-side program execution (when extra privileges are present) targeting PostgreSQL.&lt;/li&gt;
&lt;li&gt;The analyzed PoC assumes disabled prepared statements for its SQL/RCE modes using stacked queries, and requires PostgreSQL superuser or equivalent &lt;code&gt;pg_execute_server_program&lt;/code&gt; privileges for OS command execution.&lt;/li&gt;
&lt;li&gt;Currently verifiable GeoTools PostGIS &lt;code&gt;FilterToSqlHelper.constructEquality()&lt;/code&gt; applies &lt;code&gt;escapeJsonLiteral()&lt;/code&gt; to the &lt;code&gt;expected&lt;/code&gt; string, and &lt;code&gt;EscapeSql.escapeLiteral()&lt;/code&gt; escapes single quotes and similar characters.&lt;/li&gt;
&lt;li&gt;The statement at the beginning of the analyzed PoC claiming "&lt;code&gt;expected&lt;/code&gt; is written raw to SQL and only JSON pointers are escaped" does not match current verifiable GeoTools code.&lt;/li&gt;
&lt;li&gt;RCE via H2 cannot be confirmed from the analyzed PoC.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If the 2026 report is correct, there may be a code path different from the 2023 fix, a regression, an escape bypass, or a specific version/branch/configuration issue, but it cannot be identified at this time.&lt;/li&gt;
&lt;li&gt;HTTP requests alone cannot determine SQLi/RCE success; correlation with GeoServer logs, database audit/query logs, and database host processes/network activity is required.&lt;/li&gt;
&lt;li&gt;Focusing solely on GeoServer/Java child processes when detecting RCE may cause analysts to miss the database host RCE assumed by the analyzed PoC.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The high volume of probes in 2026 may be a reuse of known 2023 PoCs, a new 2026 bypass, or a mixture of both. Public information alone cannot distinguish them.&lt;/li&gt;
&lt;li&gt;It is possible that this could evolve into follow-on payloads similar to past GeoServer mass exploitation campaigns, but no such follow-on compromise has been confirmed at the time of the SecurityWeek report.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;T1190 Exploit Public-Facing Application&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1059 Command and Scripting Interpreter&lt;/strong&gt; — Confidence: Medium (If OS command execution succeeds on the database host)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1213 Data from Information Repositories&lt;/strong&gt; — Confidence: Medium (If database data access is confirmed)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1046 Network Service Discovery&lt;/strong&gt; — Confidence: Low (Only if follow-on internal scans are confirmed)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1505.003 Web Shell&lt;/strong&gt; — Confidence: Low (Not confirmed in current reports/PoCs; kept as a follow-on investigation perspective)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Additional Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;CVE identifiers for the 2026 issue, affected GeoServer/GeoTools versions, official vendor advisories, and patch ETAs&lt;/li&gt;
&lt;li&gt;The root cause and exact vulnerable code path that led SecurityWeek/WatchTowr to judge this as a 2026 zero-day&lt;/li&gt;
&lt;li&gt;Technical differences from the 2023 CVE-2023-25157/CVE-2023-25158 vulnerabilities&lt;/li&gt;
&lt;li&gt;Exact GeoServer/GeoTools versions and commits targeted by the analyzed PoC&lt;/li&gt;
&lt;li&gt;The reason for the discrepancy between the PoC's description of raw &lt;code&gt;expected&lt;/code&gt; and the current &lt;code&gt;escapeJsonLiteral()&lt;/code&gt; implementation&lt;/li&gt;
&lt;li&gt;Whether the 2026 issue succeeds when prepared statements are enabled&lt;/li&gt;
&lt;li&gt;2026-specific exploit paths applicable to Oracle and impact conditions equivalent to the PostgreSQL PoC&lt;/li&gt;
&lt;li&gt;Complete source IPs and IOCs&lt;/li&gt;
&lt;li&gt;Real victims where SQLi/RCE success has been confirmed&lt;/li&gt;
&lt;li&gt;Follow-on payloads, actors, and data impact&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and General Organizations
&lt;/h2&gt;

&lt;p&gt;Organizations exposing GeoServer should not automatically assume RCE based solely on 2026 zero-day reports. Instead, they should first inventory internet exposure, GeoServer/GeoTools versions, the application status of 2023 OGC Filter SQLi fixes, PostGIS/Oracle usage, and whether &lt;code&gt;jsonArrayContains&lt;/code&gt; is utilized. Security Operations Centers (SOCs) must separate HTTP probes from successful compromises by incorporating database audit logs and database host process/network telemetry. Until vendors release official advisories for the 2026 issue, prioritize network restrictions, WAFs, and database least privilege.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Role
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Do not judge compromises based on &lt;code&gt;jsonArrayContains&lt;/code&gt; requests alone. Correlate HTTP -&amp;gt; GeoServer -&amp;gt; database queries -&amp;gt; database host processes/network activity. The PoC-assumed RCE targets the database host, so do not rely solely on Java child processes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Verify the version, data stores, and 2023 patch status of public GeoServer instances. Reduce public exposure scopes, deploy WAFs, and enforce database least privilege until a 2026 advisory is confirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For End Users:&lt;/strong&gt; No user action is required. End users cannot take mitigating actions themselves; report any anomalies or service outages in mapping applications to administrators.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Sat, 15 Aug 2026 04:22:37 +0000</pubDate>
      <link>https://dev.to/anoymask/amnesiastealer-macos-infostealer-that-hijacks-in-browser-sessions-via-clickfix-13fg</link>
      <guid>https://dev.to/anoymask/amnesiastealer-macos-infostealer-that-hijacks-in-browser-sessions-via-clickfix-13fg</guid>
      <description>&lt;h1&gt;
  
  
  AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; Jamf Threat Labs&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-13&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Update Date:&lt;/strong&gt; N/A&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Source:&lt;/strong&gt; &lt;a href="https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/" rel="noopener noreferrer"&gt;Original&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; &lt;a href="https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/" rel="noopener noreferrer"&gt;SecurityWeek&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malware:&lt;/strong&gt; AmnesiaStealer, stream_module&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Groups:&lt;/strong&gt; None&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVEs:&lt;/strong&gt; CVE-2020-9771 (Old TCC/APFS bypass. Failed in Jamf testing on current macOS 26)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Products:&lt;/strong&gt; macOS, Chromium-based browsers, Apple Keychain, Apple Notes, Telegram&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;AmnesiaStealer uses a fake GitHub ClickFix page to launch a Rust-based stealer. It steals login passwords, Keychain data, documents, and browser information. It also copies real browser profiles and uses CDP (Chrome DevTools Protocol) to secretly and remotely control active browser sessions.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Stage 0: ClickFix and Payload Launch
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;A fake GitHub page tricks the user into pasting a command into the Terminal.&lt;/li&gt;
&lt;li&gt;The system uses &lt;code&gt;curl&lt;/code&gt; to download a shell script and runs it with &lt;code&gt;nohup bash&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;A password-protected ZIP file (password &lt;code&gt;dulin&lt;/code&gt;) is saved to &lt;code&gt;/tmp&lt;/code&gt; and extracted.&lt;/li&gt;
&lt;li&gt;The system runs &lt;code&gt;xattr -cr&lt;/code&gt;, adds execute permissions, applies an ad-hoc signature, and starts a Rust universal Mach-O binary.&lt;/li&gt;
&lt;li&gt;Temporary files and the shell history are deleted.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Stage 1: Credential Theft, Data Exfiltration, and Persistence
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;A native dialog asks for the macOS login password. The malware verifies it locally using &lt;code&gt;dscl&lt;/code&gt; or &lt;code&gt;sudo -S -v&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The password is saved in plain text in a staging area and at &lt;code&gt;~/.pwd&lt;/code&gt;, then used to try to unlock the Keychain.&lt;/li&gt;
&lt;li&gt;The malware collects data from the Keychain, Apple Notes, Telegram, documents, 16 types of Chromium profiles, crypto wallets, and system info.&lt;/li&gt;
&lt;li&gt;It archives the staging folder (&lt;code&gt;/tmp/&amp;lt;25 characters&amp;gt;&lt;/code&gt;) using &lt;code&gt;ditto&lt;/code&gt; and sends it to the C2 server at &lt;code&gt;/send/&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;It uses the stolen password to create a root LaunchDaemon named &lt;code&gt;com.apple.ReportCrash.agent_&amp;lt;digits&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Stage 2: Hidden Browser Session Hijack
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;When it receives the C2 command &lt;code&gt;remote_stream&lt;/code&gt;, it downloads an extra &lt;code&gt;stream_module&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;It copies the victim's Chromium profile to &lt;code&gt;~/.local/share/.stream/profiles/&amp;lt;browser&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;It launches the real browser in headless mode with remote debugging enabled.&lt;/li&gt;
&lt;li&gt;It uses a WebSocket relay and Chrome DevTools Protocol (CDP) to control tabs, the mouse, the keyboard, and navigation.&lt;/li&gt;
&lt;li&gt;It exports plain text cookies using &lt;code&gt;Network.getAllCookies&lt;/code&gt; and can import them into another session using &lt;code&gt;Network.setCookies&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Bypasses and Destructive Fallbacks That Failed on Current macOS
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;It tries CVE-2020-9771 and TCC database injection, but Jamf's tests on macOS 26 show this fails without Full Disk Access.&lt;/li&gt;
&lt;li&gt;If it fails to get the Chrome Safe Storage key, it has a fallback: it deletes existing items and recreates them with a known password.&lt;/li&gt;
&lt;li&gt;This fallback can destroy the ability to decrypt existing saved data.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Positioning and Execution
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Initial lures and C2 servers run on attacker-controlled web and C2 infrastructure.&lt;/li&gt;
&lt;li&gt;Stage 0 and Stage 1 start with user privileges. After getting the stolen login password, the malware tries to create a root LaunchDaemon.&lt;/li&gt;
&lt;li&gt;Browser remote control runs using a legitimate Chromium app and an extra module on the victim's Mac. The operator controls it through a WebSocket relay.&lt;/li&gt;
&lt;li&gt;Root access and Full Disk Access are separate things. Public reports do not state that root access alone automatically grants access to TCC-protected data.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. What Victims and Administrators See
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Victims see a GitHub-style download page, instructions to paste into the Terminal, and a macOS-style password dialog.&lt;/li&gt;
&lt;li&gt;Administrators see &lt;code&gt;curl&lt;/code&gt;/bash commands from the Terminal, &lt;code&gt;/tmp/.com.apple.dt.*&lt;/code&gt;, ad-hoc signatures, LaunchDaemons, unknown C2 traffic, and headless browsers.&lt;/li&gt;
&lt;li&gt;On macOS 26, using the &lt;code&gt;security&lt;/code&gt; CLI to delete and recreate Chrome Safe Storage creates a strong sign of abnormal activity.&lt;/li&gt;
&lt;li&gt;Stage 2 actions run inside a legitimate browser process. Because of this, identity providers (IdPs) might see them as normal sessions from the victim's device and IP address.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Conditions for Success and Failure
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Conditions for Success
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The user pastes the fake page's command into the Terminal.&lt;/li&gt;
&lt;li&gt;Download/C2 communications, Mach-O execution, and password entry are allowed.&lt;/li&gt;
&lt;li&gt;The stolen password is valid, allowing the creation of a LaunchDaemon.&lt;/li&gt;
&lt;li&gt;The malware can access target browser profiles and cookies.&lt;/li&gt;
&lt;li&gt;For Stage 2, operator commands and WebSocket relays can reach the target.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Conditions for Failure
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Blocking fake domains, &lt;code&gt;curl | bash&lt;/code&gt;, and Terminal pasting.&lt;/li&gt;
&lt;li&gt;The user refuses to run the command or enter the password.&lt;/li&gt;
&lt;li&gt;MDM/EDR blocks unknown Mach-O binaries, ad-hoc signatures, LaunchDaemons, or headless remote debugging.&lt;/li&gt;
&lt;li&gt;Full Disk Access is missing, and the old TCC bypass fails as seen in Jamf testing.&lt;/li&gt;
&lt;li&gt;Quick session revocation, password changes, and C2 blocking.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The theft of the macOS login password, Keychain data, documents, Notes, Telegram, wallets, and browser data.&lt;/li&gt;
&lt;li&gt;Persistence after reboot via a root LaunchDaemon.&lt;/li&gt;
&lt;li&gt;Remote control of logged-in Chromium sessions and cookie export/import.&lt;/li&gt;
&lt;li&gt;Loss of access to existing saved information due to the Chrome Safe Storage fallback.&lt;/li&gt;
&lt;li&gt;Stage 2 capabilities were verified in Jamf's isolated lab. Public reports do not confirm operators using this against real victims yet.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Email
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Public reports do not show email as the initial vector.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Proxy / SWG / DNS
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;github.aoitour[.]com&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;debug.allllowef[.]space&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;allllowef[.]space&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;shlyapadulina[.]space&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;138.124.70[.]84&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;138.124.96[.]160&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;C2 endpoints: &lt;code&gt;/api/bot/join&lt;/code&gt;, &lt;code&gt;/api/bot/actions&lt;/code&gt;, &lt;code&gt;/send/&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Browser WebSocket relays&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint / EDR
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Terminal → &lt;code&gt;curl&lt;/code&gt; → &lt;code&gt;bash&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/tmp/._&amp;lt;digits&amp;gt;.zip&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/tmp/.com.apple.dt.&amp;lt;digits&amp;gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;xattr -cr&lt;/code&gt;, &lt;code&gt;chmod&lt;/code&gt;, &lt;code&gt;codesign&lt;/code&gt;, &lt;code&gt;nohup&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;dscl&lt;/code&gt;, &lt;code&gt;sudo -S -v&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;~/.pwd&lt;/code&gt;, &lt;code&gt;~/.chost&lt;/code&gt;, &lt;code&gt;~/.botid&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/Library/LaunchDaemons/com.apple.ReportCrash.agent_&amp;lt;digits&amp;gt;.plist&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;~/.local/share/.stream/profiles/&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Chromium &lt;code&gt;--remote-debugging-*&lt;/code&gt; flags&lt;/li&gt;
&lt;li&gt;Chrome Safe Storage changes via the &lt;code&gt;security&lt;/code&gt; CLI&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Identity / IdP
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Cookie reuse from the victim's device/IP&lt;/li&gt;
&lt;li&gt;New sessions created after cookie export&lt;/li&gt;
&lt;li&gt;Logins to services using reused passwords&lt;/li&gt;
&lt;li&gt;Active sessions without MFA prompts&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  SaaS / Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;C2 uploads&lt;/li&gt;
&lt;li&gt;SaaS operations performed inside the browser&lt;/li&gt;
&lt;li&gt;Data access to Telegram, Notes, and similar apps&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Network
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;C2 HTTPS traffic&lt;/li&gt;
&lt;li&gt;WebSockets&lt;/li&gt;
&lt;li&gt;Outbound traffic from headless Chromium&lt;/li&gt;
&lt;li&gt;Quick archive uploads&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Determining Attack Success
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Contact Only
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Viewed the fake page, did not run commands.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  User Action
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Pasted commands into the Terminal or entered the password.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Execution
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Process and file artifacts for Stage 0 shell and Rust Mach-O.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Malware or Authentication Success
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;C2 join, password validation, or LaunchDaemon creation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Data Theft or Session Compromise
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Successful &lt;code&gt;/send/&lt;/code&gt; upload, cookie export, C2 receipt, or use of stolen sessions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Post-Compromise Confirmation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirmed Stage 2 module, headless browser, operator commands, or SaaS actions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Trigger
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Terminal &lt;code&gt;curl | bash&lt;/code&gt; execution&lt;/li&gt;
&lt;li&gt;AmnesiaStealer hashes or domains&lt;/li&gt;
&lt;li&gt;Fake CrashReporter LaunchDaemon&lt;/li&gt;
&lt;li&gt;Chrome Safe Storage changes&lt;/li&gt;
&lt;li&gt;Headless Chromium remote debugging&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Verification
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Identify the target URL, command, execution time, login user, and whether a password was entered.&lt;/li&gt;
&lt;li&gt;Correlate C2 DNS/Proxy traffic with the process tree.&lt;/li&gt;
&lt;li&gt;Determine how far the attack reached (Stage 0, 1, or 2).&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Preserve &lt;code&gt;/tmp&lt;/code&gt;, &lt;code&gt;~/.pwd&lt;/code&gt;, the LaunchDaemon, browser profile clones, shell history, and Keychain operations.&lt;/li&gt;
&lt;li&gt;Collect Mach-O hashes, code signatures, parent/child processes, and network sockets.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Authentication &amp;amp; Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Change the macOS password, rotate Keychain/SSO secrets, and revoke all browser and SaaS sessions.&lt;/li&gt;
&lt;li&gt;Check for SaaS actions and cookie usage from the same device/IP.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Actions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Look for access to wallets, Telegram, Notes, and documents.&lt;/li&gt;
&lt;li&gt;Search for additional payloads, operator commands, and credential reuse on other devices.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Containment
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Isolate the host, block C2 traffic, stop the LaunchDaemon, preserve evidence, and rebuild the system.&lt;/li&gt;
&lt;li&gt;Rotate passwords, tokens, cookies, and wallet secrets as needed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Assessment Levels
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Lure Viewed&lt;/li&gt;
&lt;li&gt;Command Pasted&lt;/li&gt;
&lt;li&gt;Payload Executed&lt;/li&gt;
&lt;li&gt;Password Captured&lt;/li&gt;
&lt;li&gt;Stealer Exfiltration Confirmed&lt;/li&gt;
&lt;li&gt;Browser Session Hijack Confirmed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Single Events
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Fake CrashReporter LaunchDaemon&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;~/.pwd&lt;/code&gt; file creation&lt;/li&gt;
&lt;li&gt;Terminal → &lt;code&gt;curl -s&lt;/code&gt; → &lt;code&gt;nohup bash&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Chrome Safe Storage deletion/recreation&lt;/li&gt;
&lt;li&gt;Chromium remote debugging flags&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Timeline Correlation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Fake GitHub view → Terminal paste → ZIP/Mach-O execution → Password dialog → Staging/archive → C2 upload → LaunchDaemon → stream_module → Headless browser&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Threat Hunting Focus
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;com.apple.ReportCrash.agent_&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;~/.local/share/.stream/profiles&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;CDP actions like &lt;code&gt;Network.getAllCookies&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;15-byte XOR keys or C2 IOCs&lt;/li&gt;
&lt;li&gt;Stage 1 and Stage 2 SHA256 hashes&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Log Gaps
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Terminal command lines&lt;/li&gt;
&lt;li&gt;TCC/FDA status&lt;/li&gt;
&lt;li&gt;Keychain item changes&lt;/li&gt;
&lt;li&gt;Browser CDP traffic&lt;/li&gt;
&lt;li&gt;WebSocket payloads&lt;/li&gt;
&lt;li&gt;File access telemetry&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Priority Actions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Use MDM to detect Terminal pasting and &lt;code&gt;curl | bash&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Control and monitor unknown LaunchDaemons.&lt;/li&gt;
&lt;li&gt;Restrict browser remote debugging.&lt;/li&gt;
&lt;li&gt;Shorten session lifetimes and use device binding.&lt;/li&gt;
&lt;li&gt;Minimize Full Disk Access permissions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts, Inferences, and Hypotheses
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Jamf confirmed AmnesiaStealer in a real environment.&lt;/li&gt;
&lt;li&gt;Stage 1 uses a Rust universal Mach-O binary to collect Keychain data, browser data, Notes, Telegram, wallets, and documents.&lt;/li&gt;
&lt;li&gt;It includes code for root LaunchDaemon persistence using a stolen password.&lt;/li&gt;
&lt;li&gt;Jamf's macOS 26 tests showed that old TCC bypasses failed without Full Disk Access.&lt;/li&gt;
&lt;li&gt;Stage 2 successfully tested browser control and cookie exports in an isolated lab.&lt;/li&gt;
&lt;li&gt;There is no public proof that Stage 2 was used by an operator against a real victim.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Because cookies are used inside the victim's real browser, an IdP's location and device checks alone may not spot unauthorized actions.&lt;/li&gt;
&lt;li&gt;After password theft, you must check not just the compromised device, but also SaaS apps and VPNs that use the same password.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Correlating high-frequency CDP commands with screencasts (around 3 fps) from a remote browser might help detect hidden session control.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;T1204.004 Malicious Copy and Paste&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1059.004 Unix Shell&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1105 Ingress Tool Transfer&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1056 Input Capture&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1555.001 Credentials from Password Stores: Keychain&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1539 Steal Web Session Cookie&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1560.001 Archive via Utility&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1543.004 Launch Daemon&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1070.004 File Deletion&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1185 Browser Session Cookie&lt;/strong&gt; — Confidence: Medium (Mapped to session control via CDP)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Total victim count, target regions, and threat actor attribution.&lt;/li&gt;
&lt;li&gt;Whether Stage 2 has been used against real victims.&lt;/li&gt;
&lt;li&gt;Success rates of TCC bypasses on versions other than macOS 26.&lt;/li&gt;
&lt;li&gt;Full lists of C2 servers, IOCs, and build differences.&lt;/li&gt;
&lt;li&gt;Confirmed cases of stolen data and wallet losses.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on Security Operations Centers (SOCs)
&lt;/h2&gt;

&lt;p&gt;Development, design, and media teams often use Mac computers, making them potential targets. Organizations need detection strategies that span across ClickFix awareness training, Terminal command lines, LaunchDaemons, browser remote debugging, and session-level activities.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Role
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOC Teams:&lt;/strong&gt; Track attacks step-by-step from Terminal pasting to LaunchDaemons, C2 uploads, and headless browsers. Avoid confusing root access with Full Disk Access.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For IT Administrators:&lt;/strong&gt; Use MDM and EDR to restrict unknown LaunchDaemons and remote debugging. If an infection happens, revoke passwords, Keychains, and browser sessions all at once.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For End Users:&lt;/strong&gt; Never paste commands into the Terminal based on web page instructions, and never enter passwords into prompt boxes that appear after downloading files.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Sat, 15 Aug 2026 04:22:24 +0000</pubDate>
      <link>https://dev.to/anoymask/sap-commerce-cloud-cve-2026-58231-active-exploit-attempts-for-unauthenticated-rce-4ipp</link>
      <guid>https://dev.to/anoymask/sap-commerce-cloud-cve-2026-58231-active-exploit-attempts-for-unauthenticated-rce-4ipp</guid>
      <description>&lt;h1&gt;
  
  
  SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; Critical&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Max severity SAP Commerce Cloud flaw now targeted in attacks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source:&lt;/strong&gt; BleepingComputer&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-14&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Update Date:&lt;/strong&gt; 2026-08-14&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Article:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/" rel="noopener noreferrer"&gt;Original Source&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; &lt;a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html" rel="noopener noreferrer"&gt;SAP Security Patch Day - August 2026&lt;/a&gt;, &lt;a href="https://onapsis.com/blog/sap-security-patch-day-august-2026/" rel="noopener noreferrer"&gt;Onapsis&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malware:&lt;/strong&gt; None&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Groups:&lt;/strong&gt; None&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;CVEs:&lt;/strong&gt; CVE-2026-58231&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Products:&lt;/strong&gt; SAP Commerce Cloud, Data Hub Adapter, COM_CLOUD 2211, COM_CLOUD 2211-JDK21&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;Attackers chained the default authentication client and input validation flaws in the Data Hub Adapter to target unauthenticated arbitrary code execution. These exploit attempts reached a honeypot three days after the patch was released.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Exploit Flow Confirmed from Public Documents
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attacker reaches the Data Hub Adapter endpoint from the outside.&lt;/li&gt;
&lt;li&gt;The attacker abuses the default authentication client to call specific functions without authentication.&lt;/li&gt;
&lt;li&gt;The attacker sends crafted input to functions with missing validation.&lt;/li&gt;
&lt;li&gt;If successful, this leads to arbitrary code execution and internal component compromise within the application.&lt;/li&gt;
&lt;li&gt;The Defused honeypot observed exploit attempts three days after the patch release.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Location and Execution Point
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Attackers connect to the SAP Commerce Cloud Data Hub Adapter from the Internet or a reachable network.&lt;/li&gt;
&lt;li&gt;Initial execution happens on the Commerce Cloud application/JVM side.&lt;/li&gt;
&lt;li&gt;Because public PoCs, exact payloads/endpoints, and post-exploitation details are not public, a request to the honeypot does not confirm a successful RCE.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;No user action is required. Attacks can happen in the backend even while the storefront runs normally.&lt;/li&gt;
&lt;li&gt;Administrators may see unauthenticated requests from the default client, Data Hub Adapter errors, and JVM child processes/files/networks.&lt;/li&gt;
&lt;li&gt;The 4,200+ IPs reported by Shadowserver are product fingerprints, not counts of unpatched, vulnerable, or compromised systems.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Data Hub Adapter extension is enabled and reachable by the attacker.&lt;/li&gt;
&lt;li&gt;The affected version is unpatched.&lt;/li&gt;
&lt;li&gt;The default authentication client and vulnerable functions are available.&lt;/li&gt;
&lt;li&gt;Crafted input is not blocked by application controls.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Update to the fixed release in SAP Security Note 3771065, then rebuild and redeploy.&lt;/li&gt;
&lt;li&gt;Restrict vulnerable endpoints to trusted DataHub server IPs using IP Filter Sets.&lt;/li&gt;
&lt;li&gt;Isolate the Data Hub Adapter from the Internet.&lt;/li&gt;
&lt;li&gt;Detect and isolate exploit requests and JVM execution.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Unauthenticated arbitrary code execution&lt;/li&gt;
&lt;li&gt;Internal component compromise&lt;/li&gt;
&lt;li&gt;High impact on the confidentiality, integrity, and availability of application data&lt;/li&gt;
&lt;li&gt;Follow-on activities like successful RCE, web shells, credential theft, and data theft are unconfirmed in public information.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Email
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;None&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Proxy / SWG / DNS
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;External HTTP requests to the Data Hub Adapter&lt;/li&gt;
&lt;li&gt;Abnormal calls using the default client&lt;/li&gt;
&lt;li&gt;Unknown downloads or C2 from the SAP host (from a post-RCE investigation perspective)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint / EDR
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Commerce/JVM child processes&lt;/li&gt;
&lt;li&gt;Shells or interpreters&lt;/li&gt;
&lt;li&gt;Unexpected file creation&lt;/li&gt;
&lt;li&gt;Network connections by application service users&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Identity / IdP
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;No normal user login because access is unauthenticated&lt;/li&gt;
&lt;li&gt;Abnormal use of default clients/tokens&lt;/li&gt;
&lt;li&gt;Check subsequent admin accounts/sessions if found&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  SaaS / Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Commerce Cloud deployment/build version&lt;/li&gt;
&lt;li&gt;WAF/API gateway logs&lt;/li&gt;
&lt;li&gt;Application/audit logs&lt;/li&gt;
&lt;li&gt;Cloud/SAP control plane changes&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Network
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;External to Data Hub Adapter&lt;/li&gt;
&lt;li&gt;Application host to internal components&lt;/li&gt;
&lt;li&gt;Unexpected egress&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Determination
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Contact Only
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Scans/fingerprints only&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  User Action
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Not required&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Execution
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Crafted requests reach vulnerable functions&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Malware or Successful Authentication
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm RCE via JVM child processes, shells, files, or callbacks. Do not use the term "authentication success."&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Data Theft or Session Compromise
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm data access/egress or session/token theft with separate evidence&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Compromise Confirmation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm web shells, credential use, internal lateral movement, or data modification&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Trigger
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Defused-style exploit requests&lt;/li&gt;
&lt;li&gt;Unpatched Data Hub Adapter&lt;/li&gt;
&lt;li&gt;Unauthenticated abnormal calls&lt;/li&gt;
&lt;li&gt;JVM child processes&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Initial Check
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Confirm version/build, extension enablement, patch/redeploy time, and external exposure.&lt;/li&gt;
&lt;li&gt;Preserve the initial request, source IP, response, and application errors.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Endpoint
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Check the JVM process tree, temp/web directories, shell history, file integrity, and network sockets.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Authentication / Cloud
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Check default client settings, API tokens, admin sessions, Commerce Cloud deployment/audit logs, and secret access.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Subsequent Actions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Search for web shells, scheduled jobs, new accounts, database queries, internal access, and egress.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Containment
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;IP Filter Set, endpoint isolation, patch/rebuild/redeploy, secret rotation, forensic imaging.&lt;/li&gt;
&lt;li&gt;Rebuild affected nodes if RCE evidence exists.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Judgment Categories
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Fingerprint Only&lt;/li&gt;
&lt;li&gt;Exploit Attempted&lt;/li&gt;
&lt;li&gt;Vulnerable Function Reached&lt;/li&gt;
&lt;li&gt;RCE Confirmed&lt;/li&gt;
&lt;li&gt;Data/Session Compromised&lt;/li&gt;
&lt;li&gt;Follow-on Compromise Confirmed&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Single Event
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Unauthenticated Data Hub Adapter call&lt;/li&gt;
&lt;li&gt;Default client abnormal request&lt;/li&gt;
&lt;li&gt;Commerce JVM to shell&lt;/li&gt;
&lt;li&gt;Unexpected callback&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Time-Series Correlation
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;External crafted request -&amp;gt; application error/success -&amp;gt; JVM child -&amp;gt; file/network -&amp;gt; internal access&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hunting Perspective
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;COM_CLOUD 2211/2211-JDK21 inventory&lt;/li&gt;
&lt;li&gt;Data Hub Adapter exposure&lt;/li&gt;
&lt;li&gt;Unauthenticated requests around 2026-08-14&lt;/li&gt;
&lt;li&gt;Application service user processes/egress&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Log Gaps
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Exact exploit endpoints/payloads&lt;/li&gt;
&lt;li&gt;HTTP body&lt;/li&gt;
&lt;li&gt;Application audit logs&lt;/li&gt;
&lt;li&gt;JVM command lines&lt;/li&gt;
&lt;li&gt;Cloud network flows&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Priority Actions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Apply Note 3771065 and redeploy&lt;/li&gt;
&lt;li&gt;Configure IP Filter Sets&lt;/li&gt;
&lt;li&gt;Keep the backend private&lt;/li&gt;
&lt;li&gt;Monitor JVM processes&lt;/li&gt;
&lt;li&gt;Prepare for secret rotation&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;CVE-2026-58231 is an improper authorization vulnerability with a CVSS score of 10.0.&lt;/li&gt;
&lt;li&gt;Unauthenticated attackers can abuse default authentication clients and crafted input to achieve RCE.&lt;/li&gt;
&lt;li&gt;SAP released a fix in Security Note 3771065 on August 11, 2026.&lt;/li&gt;
&lt;li&gt;Defused observed exploit attempts in their honeypot three days later.&lt;/li&gt;
&lt;li&gt;There were no public PoCs at the time of publication, and SAP did not confirm active exploitation in their advisory.&lt;/li&gt;
&lt;li&gt;The 4,200+ IP fingerprints do not indicate the number of compromises.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Because attack attempts have started without a public PoC, there is practically no patch-waiting window.&lt;/li&gt;
&lt;li&gt;Do not assume compromise success based only on HTTP attempts; JVM/file/network evidence is required.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Attackers may target Commerce credentials or customer data after a successful RCE, but public data does not confirm this.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;T1190 Exploit Public-Facing Application&lt;/strong&gt; — Confidence: High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1059 Command and Scripting Interpreter&lt;/strong&gt; — Confidence: Medium. If shells/interpreters are found after RCE.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1105 Ingress Tool Transfer&lt;/strong&gt; — Confidence: Low. Follow-on payloads are unconfirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;T1505.003 Web Shell&lt;/strong&gt; — Confidence: Low. An investigation perspective; placement is unconfirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Additional Investigations
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Exact vulnerable endpoints/functions, request formats, and response indicators&lt;/li&gt;
&lt;li&gt;Complete list of source IPs/IOCs for exploit attempts&lt;/li&gt;
&lt;li&gt;Success or failure of RCE on the honeypot&lt;/li&gt;
&lt;li&gt;Real victim compromises, payloads, and threat actors&lt;/li&gt;
&lt;li&gt;Number of unpatched instances&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and General Enterprises
&lt;/h2&gt;

&lt;p&gt;When enterprises use SAP Commerce Cloud, they must check the backend exposure of the Data Hub Adapter in addition to the storefront. Prioritize patching, redeployment, and IP restrictions—even during holidays—and strictly separate the investigation of scan attempts from successful RCEs.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Role
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Distinguish unauthenticated requests as attempts, and treat JVM child processes/files/callbacks as confirmed RCEs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Rebuild and redeploy to the fixed release in Security Note 3771065, and use IP Filter Sets to limit access to trusted DataHub servers only.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For End Users:&lt;/strong&gt; No user action is required. Follow the administrator's investigation results regarding e-commerce anomalies or customer data impact.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Fri, 14 Aug 2026 03:01:26 +0000</pubDate>
      <link>https://dev.to/anoymask/jwr-a-real-time-phaas-using-websockets-to-monitor-victim-input-and-remotely-control-screen-ol6</link>
      <guid>https://dev.to/anoymask/jwr-a-real-time-phaas-using-websockets-to-monitor-victim-input-and-remotely-control-screen-ol6</guid>
      <description>&lt;h1&gt;
  
  
  JWR: A Real-Time PhaaS Using WebSockets to Monitor Victim Input and Remotely Control Screen Transitions
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Dissecting the JWR phishing framework&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; Cisco Talos Blog&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-13&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Source:&lt;/strong&gt; &lt;a href="https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/" rel="noopener noreferrer"&gt;https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; Talos IOC repository (linked in the original article)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; JWR, The Outsider, Outsider Enterprise, Shopify, WooCommerce, PayPal, Apple, Klarna, Vue.js, WebSocket&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;JWR is not a static credential-stealing page. It is a Chinese-language PhaaS (Phishing-as-a-Service) that uses AES-CTR encrypted WebSockets to stream credit card details and credentials to attackers as the victim types them. The attacker uses over 40 different commands to dynamically trigger real-time screen switches for OTPs, secondary cards, and banking app approvals.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Real-Time Exfiltration via SMS
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The user receives an SMS disguised as a toll fee, postal service, or delivery company, which leads them to a malicious URL.&lt;/li&gt;
&lt;li&gt;The parent page sets &lt;code&gt;window.__HOST_MODE&lt;/code&gt; and launches the Host Bridge or Vue.js Content Mode.&lt;/li&gt;
&lt;li&gt;It creates a session ID in the format &lt;code&gt;JWRCVV-&amp;lt;timestamp&amp;gt;-&amp;lt;random&amp;gt;-&amp;lt;random&amp;gt;&lt;/code&gt;, and a Web Worker maintains the WebSocket connection.&lt;/li&gt;
&lt;li&gt;An initial beacon sends the IP address, country, referrer URL, and device/OS information to the C2 server.&lt;/li&gt;
&lt;li&gt;Input field values are streamed to the C2 server in real-time &lt;em&gt;before&lt;/em&gt; the user clicks submit, allowing the attacker to review them.&lt;/li&gt;
&lt;li&gt;The attacker uses commands like &lt;code&gt;to_info&lt;/code&gt;, &lt;code&gt;to_card&lt;/code&gt;, &lt;code&gt;to_sms&lt;/code&gt;, &lt;code&gt;to_2fa&lt;/code&gt;, &lt;code&gt;to_pin&lt;/code&gt;, and &lt;code&gt;to_app&lt;/code&gt; to remotely switch the victim's screen.&lt;/li&gt;
&lt;li&gt;Fake errors such as &lt;code&gt;tip_fail&lt;/code&gt; or &lt;code&gt;tip_change_card&lt;/code&gt; are displayed to trick the user into entering a secondary card or re-entering information.&lt;/li&gt;
&lt;li&gt;Upon completion, all &lt;code&gt;cvvform&lt;/code&gt; data is sent via POST to &lt;code&gt;api/open/the_final_interface&lt;/code&gt;, and the user is redirected to the legitimate website.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Alternative Communication Channels
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In environments where WebSockets are blocked, the framework falls back to HTTP long polling via &lt;code&gt;api/open/pollInstruction&lt;/code&gt; to fetch the same commands.&lt;/li&gt;
&lt;li&gt;It supports Host Bridge, plugin iframe, and host iframe modes, even in configurations where child iframes cannot reach the C2 server directly.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  4. Attacker Positioning and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The JWR management console and C2 server run on the attacker's infrastructure.&lt;/li&gt;
&lt;li&gt;The Host Bridge, Vue.js application, and Web Worker run inside the victim's browser.&lt;/li&gt;
&lt;li&gt;The attacker monitors individual sessions from the management dashboard and manually dictates the next screen and error messages.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The victim sees a Shopify or WooCommerce checkout page that accurately replicates real product names, quantities, and amounts.&lt;/li&gt;
&lt;li&gt;Credentials are stolen before the submit button is even pressed, and card declines or OTP failures appear legitimate.&lt;/li&gt;
&lt;li&gt;Security Operations Centers (SOCs) can observe SMS URLs, long-lived binary WebSockets, Web Workers, continuous REST API requests, and the final POST request.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The user opens the SMS link and enters their information.&lt;/li&gt;
&lt;li&gt;WebSockets or long polling are allowed by the network.&lt;/li&gt;
&lt;li&gt;The victim trusts the fake brand, cart information, and screen transitions.&lt;/li&gt;
&lt;li&gt;The attacker successfully keeps pace with the victim's input and legitimate authentication processes in real-time.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SMS URLs or newly registered domains are blocked.&lt;/li&gt;
&lt;li&gt;JWR-specific WebSocket paths, REST endpoints, and JavaScript signatures are detected.&lt;/li&gt;
&lt;li&gt;The user checks the checkout domain and refuses to enter a secondary card after seeing a fake error.&lt;/li&gt;
&lt;li&gt;Financial institutions flag the card or OTP use immediately following exfiltration as high-risk.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;p&gt;Card numbers, CVVs, PINs, up to three sets of web credentials, PayPal, Apple, Klarna accounts, SMS/email OTPs, banking app approvals, ID card images, SSNs, cookies, and device fingerprints may be stolen. The operator can view values as they are typed and select the appropriate authentication screen next.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; The primary vector is SMS. In email-based campaigns, check for spoofed URLs and branding.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; Newly registered domains, WebSocket upgrades, &lt;code&gt;webSocket/QT/...&lt;/code&gt;, &lt;code&gt;api/open/addClick&lt;/code&gt;, &lt;code&gt;getSyncSettings&lt;/code&gt;, &lt;code&gt;pollInstruction&lt;/code&gt;, &lt;code&gt;addCvv&lt;/code&gt;, and &lt;code&gt;the_final_interface&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; Browsers, iframes, Web Workers, and &lt;code&gt;JWRCID&lt;/code&gt; / &lt;code&gt;JwrExecutedInstructions&lt;/code&gt; in sessionStorage. No endpoint malware is required.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; Logins, OTPs, push approvals, and anomalous devices or locations immediately following exfiltration.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; Shopify/WooCommerce order/cart referrers and payment provider fraud logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; Long-lived WebSockets, AES-CTR encrypted binary traffic, and fallback to long polling when WebSockets are blocked.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Progression Stages
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; SMS received, URL accessed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Session:&lt;/strong&gt; &lt;code&gt;addClick&lt;/code&gt; event, &lt;code&gt;JWRCID&lt;/code&gt; generated, WebSocket established.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User Interaction:&lt;/strong&gt; Personal information, credit card, and OTP input events.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data Exfiltration:&lt;/strong&gt; Successful &lt;code&gt;addCvv&lt;/code&gt; or &lt;code&gt;the_final_interface&lt;/code&gt; request, followed by fraudulent use of the data.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication Success:&lt;/strong&gt; Attacker session or card approval confirmed in separate logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Compromise:&lt;/strong&gt; Account takeover or successful fraudulent payment confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; JWR URL, WebSocket path, REST endpoint, ClamAV/Snort detection, or unauthorized login immediately following an OTP prompt.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Verification:&lt;/strong&gt; Preserve SMS messages, URLs, timestamps, input fields, browser history, and DNS/proxy logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint:&lt;/strong&gt; Preserve browser storage, Service Workers/Web Workers, DevTools logs, and cookies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication/Cloud:&lt;/strong&gt; Revoke and review target service sessions, OTPs, push notifications, and card authorizations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Actions:&lt;/strong&gt; Check for secondary card usage, access to email/PayPal/Apple accounts, or identity document misuse.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Revoke sessions, change credentials, block cards, block domains, and report the SMS vector.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Classification:&lt;/strong&gt; Delivered / Session Established / Data Entered / Exfiltrated / Account or Payment Compromised.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Event:&lt;/strong&gt; JWR endpoints, &lt;code&gt;JWRCVV-&lt;/code&gt; strings, unique WebSocket suffixes, and Talos Snort SIDs 66924–66928.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Time-Series Correlation:&lt;/strong&gt; SMS click -&amp;gt; arrival beacon -&amp;gt; WebSocket -&amp;gt; multiple authentication screens -&amp;gt; final POST -&amp;gt; redirect to legitimate site.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; &lt;code&gt;api/open/*&lt;/code&gt;, Vue 2 phishing bundles, 44 page command names, and abuse of Shopify &lt;code&gt;cart_data&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Without cross-referencing SMS, browser WebSockets, POST bodies, and card authorization logs, determining success is difficult.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Actions:&lt;/strong&gt; URL inspection, WebSocket monitoring, step-up authentication for financial transactions, user awareness training, and detecting communication patterns rather than relying solely on IOCs.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Talos confirmed JWR in active SMS campaigns.&lt;/li&gt;
&lt;li&gt;The framework features 44 phishing pages and over 40 operator commands.&lt;/li&gt;
&lt;li&gt;It streams input values to the C2 server sequentially as the user types.&lt;/li&gt;
&lt;li&gt;Talos assesses with medium confidence that this is a variant of The Outsider.&lt;/li&gt;
&lt;li&gt;Management messages are written in Simplified Chinese.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This attack can easily be adapted for regional delivery, toll, and e-commerce brands by simply swapping out templates.&lt;/li&gt;
&lt;li&gt;Blocking WebSockets alone is insufficient because the framework falls back to long polling; correlation between endpoints and behavioral patterns is required.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Rapid screen transitions demanding multiple cards or OTPs after displaying a failure message can serve as a more effective user-side signal than static URL evaluation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1566.002 Spearphishing Link, T1056 Input Capture, T1539 Steal Web Session Cookie, T1111 Multi-Factor Authentication Interception, T1185 Browser Session Cookie, T1071.001 Web Protocols.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1656 Impersonation, T1583.001 Domains, T1041 Exfiltration Over C2 Channel.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns / Areas for Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The relationship between JWR operators and Outsider Enterprise.&lt;/li&gt;
&lt;li&gt;C2 infrastructure, sales channels, total number of victims, and actual financial losses.&lt;/li&gt;
&lt;li&gt;The existence of localized language templates.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and Organizations
&lt;/h2&gt;

&lt;p&gt;SMS messages disguised as delivery services, e-commerce platforms, or toll fees can easily trick users. In addition to securing mobile URLs, organizations must correlate WebSocket traffic, REST fallbacks, and anomalous logins following OTP prompts with financial and identity logs.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Audience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Correlate not only WebSockets, but also REST fallbacks and final POST requests.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Implement JWR signatures, Snort SIDs, SMS URL inspection, and authentication risk scoring.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For End Users:&lt;/strong&gt; Never enter credit card details or OTPs in response to SMS messages about unpaid fees or redelivery links. Stop immediately if a fake error asks for a secondary card.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Fri, 14 Aug 2026 03:01:12 +0000</pubDate>
      <link>https://dev.to/anoymask/vmware-vcenter-cve-2026-59310-active-exploitation-of-unauthenticated-rce-for-persistent-reverse-ssh-57f6</link>
      <guid>https://dev.to/anoymask/vmware-vcenter-cve-2026-59310-active-exploitation-of-unauthenticated-rce-for-persistent-reverse-ssh-57f6</guid>
      <description>&lt;h1&gt;
  
  
  VMware vCenter CVE-2026-59310: Active Exploitation of Unauthenticated RCE for Persistent Reverse SSH
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; Critical&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Critical VMware vCenter RCE flaw exploited for reverse SSH access&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; BleepingComputer&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-13&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Article:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/" rel="noopener noreferrer"&gt;https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; &lt;a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017" rel="noopener noreferrer"&gt;https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017&lt;/a&gt;, &lt;a href="https://www.securityweek.com/critical-vmware-vulnerability-in-attackers-crosshairs/" rel="noopener noreferrer"&gt;https://www.securityweek.com/critical-vmware-vulnerability-in-attackers-crosshairs/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; CVE-2026-59310, VMware vCenter Server, vCenter Syslog Server, reverse_ssh, ESXi&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;Five days after the patch release, attacks were observed exploiting a directory traversal vulnerability in internet-reachable vCenter Syslog Servers. Attackers achieved unauthenticated remote code execution, used cron to launch an open-source &lt;code&gt;reverse_ssh&lt;/code&gt; client, and maintained outbound SSH C2 connections.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;The attacker connects over the network to an unpatched vCenter Syslog Server.&lt;/li&gt;
&lt;li&gt;The attacker exploits the CVE-2026-59310 directory traversal flaw to achieve arbitrary code execution on vCenter without authentication.&lt;/li&gt;
&lt;li&gt;The attacker creates a malicious cron job for persistence.&lt;/li&gt;
&lt;li&gt;The attacker deploys and launches an open-source &lt;code&gt;reverse_ssh&lt;/code&gt; client.&lt;/li&gt;
&lt;li&gt;An outbound reverse SSH connection is established from vCenter to the attacker's C2 server, bypassing inbound firewall rules to maintain a remote shell.&lt;/li&gt;
&lt;li&gt;Public reports do not describe subsequent successful ESXi/VM operations, credential theft, or lateral movement.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The attacker connects to the vCenter Syslog Server from the external network.&lt;/li&gt;
&lt;li&gt;The exploit, cron job, and &lt;code&gt;reverse_ssh&lt;/code&gt; run on the vCenter Server appliance.&lt;/li&gt;
&lt;li&gt;The C2 server is external, and the connection originates outbound from vCenter.&lt;/li&gt;
&lt;li&gt;Although vCenter is the centralized management plane for ESXi and VMs, public data shows no evidence of actual impact on managed targets.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Unauthenticated abnormal Syslog Server requests, directory traversal patterns, and unexpected processes or files on vCenter are visible.&lt;/li&gt;
&lt;li&gt;New or modified cron entries and unusual &lt;code&gt;reverse_ssh&lt;/code&gt; processes remain.&lt;/li&gt;
&lt;li&gt;Long-running SSH-like traffic from vCenter to unknown hosts occurs even without inbound sessions.&lt;/li&gt;
&lt;li&gt;Finding a vulnerable vCenter or a &lt;code&gt;reverse_ssh&lt;/code&gt; binary alone does not confirm successful CVE exploitation. Analysts must check timestamps, parent processes, cron jobs, and outbound C2 traffic together.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Conditions for Success and Failure
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Affected versions of the vCenter Syslog Server are reachable by the attacker.&lt;/li&gt;
&lt;li&gt;The security patch is not applied.&lt;/li&gt;
&lt;li&gt;File creation, cron modifications, and process execution after the exploit are not blocked.&lt;/li&gt;
&lt;li&gt;Outbound communication from vCenter to the attacker's C2 is allowed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The system is updated to a patched version.&lt;/li&gt;
&lt;li&gt;The management plane is isolated from the internet and restricted to a trusted admin network only.&lt;/li&gt;
&lt;li&gt;File, cron, and process changes on the vCenter appliance are detected and blocked.&lt;/li&gt;
&lt;li&gt;Unknown SSH and tunnel destinations are blocked using an egress allowlist.&lt;/li&gt;
&lt;li&gt;Broadcom provides no workaround, meaning mitigation steps cannot replace patching.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;p&gt;Unauthenticated code execution and a persistent remote shell are established on the vCenter appliance. Using vCenter management privileges and stored data to control ESXi and VMs is a severe subsequent risk, but public data does not confirm successful execution, so this is treated as an inference.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; None.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; Outbound traffic from vCenter to unknown C2, DNS resolution, and reverse SSH connections.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; &lt;code&gt;reverse_ssh&lt;/code&gt;, unknown binaries, cron modifications, shells, and file creation on vCenter. If the appliance lacks EDR, use OS auditing or FIM instead.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; Initial exploitation requires no authentication. Subsequent new sessions, tokens, or role changes if vCenter accounts or APIs are used.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; vSphere API tasks, ESXi host/VM operations, snapshots, and credential/secret access.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; Malicious requests to the Syslog Server, long-running outbound connections from vCenter, and abnormal east-west traffic from the management network.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Determining Attack Success
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; Scans or malicious requests only, with no server-side artifacts.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution Suspected:&lt;/strong&gt; Unknown files/shells on vCenter, and errors/requests at the matching timestamp.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;RCE Confirmed:&lt;/strong&gt; Exploit requests and corresponding process/file generation confirmed in the same timeline.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Persistence/C2 Confirmed:&lt;/strong&gt; Malicious cron jobs, &lt;code&gt;reverse_ssh&lt;/code&gt; execution, and outbound C2 sessions.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Compromise:&lt;/strong&gt; Confirmed vSphere tasks, ESXi/VM modifications, or credential usage (not confirmed in public data).&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; CVE-2026-59310 exploit patterns, unknown vCenter cron jobs, &lt;code&gt;reverse_ssh&lt;/code&gt;, and outbound SSH/tunnels.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Check:&lt;/strong&gt; Confirm the vCenter version/build, patch time, external reachability, and initial malicious request.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint:&lt;/strong&gt; Preserve cron jobs, process trees, filesystems, shells/audits/syslogs, binary hashes, and network sockets.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication/Cloud:&lt;/strong&gt; Check vCenter sessions, SSO tokens, roles, API tasks, ESXi trust, and backup/snapshot operations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Operations:&lt;/strong&gt; Investigate host additions/deletions, VM power states, snapshots, guest tools, datastores, credential exports, and lateral movement.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Isolate the vCenter management plane, block C2 traffic, apply patches, rotate credentials/certificates, rebuild compromised appliances, and investigate managed targets broadly.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Judgment Categories:&lt;/strong&gt; Scanned / Exploit Attempted / RCE Confirmed / Persistence-C2 Confirmed / Management Plane Compromised / ESXi-VM Impact Confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Event:&lt;/strong&gt; &lt;code&gt;reverse_ssh&lt;/code&gt; on vCenter, unknown cron jobs, and Syslog Server traversal requests.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timeline Correlation:&lt;/strong&gt; Unauthenticated request -&amp;gt; file/process -&amp;gt; cron -&amp;gt; reverse SSH egress -&amp;gt; vSphere API task.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; Check all vCenter versions, cron differences, unknown ELF binaries, outbound SSH, and traffic after the disclosure date of 2026-08-03.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Appliance EDR, full command lines, Syslog Server requests, egress traffic, and vSphere task retention logs are often missing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Countermeasures:&lt;/strong&gt; Update to versions 9.1.0.0300, 9.0.2.0100, 8.0 U3k / U2f or later, isolate the management plane, and apply egress allowlists.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog Server that leads to unauthenticated arbitrary code execution. The CVSS score is 9.8.&lt;/li&gt;
&lt;li&gt;Broadcom released a patch on 2026-07-29, and there is no workaround.&lt;/li&gt;
&lt;li&gt;Callbacks were observed starting 2026-08-03, and public reports counted 361 victim IPs across 47 countries by 2026-08-07.&lt;/li&gt;
&lt;li&gt;Attackers used cron and the open-source &lt;code&gt;reverse_ssh&lt;/code&gt; client.&lt;/li&gt;
&lt;li&gt;361 IPs do not necessarily equal 361 distinct organizations.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Because reverse SSH uses outbound connections, inbound firewalls alone cannot stop the C2 traffic.&lt;/li&gt;
&lt;li&gt;vCenter compromise can potentially lead to ESXi/VM control, but public data has not confirmed this success.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Due to rapid active exploitation and the high value of centralized management planes, multiple threat actors, including advanced groups, may use the same vulnerability.&lt;/li&gt;
&lt;li&gt;QUIRSO suspects APT involvement, but public evidence alone cannot confirm attribution.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1190 Exploit Public-Facing Application, T1059.004 Unix Shell, T1053.003 Cron, T1105 Ingress Tool Transfer, T1572 Protocol Tunneling.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1071.004 DNS (if C2 name resolution is confirmed), T1090 Proxy, T1210 Exploitation of Remote Services (if subsequent lateral movement is confirmed).&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Full formats of exploit requests and payloads, and the complete set of compromised binaries/C2 IOCs.&lt;/li&gt;
&lt;li&gt;Execution privileges and whether vCenter SSO/certificates/credentials were accessed.&lt;/li&gt;
&lt;li&gt;Actual subsequent operations on ESXi/VMs, data theft, and destructive activities.&lt;/li&gt;
&lt;li&gt;Attacker attribution and the exact number of organizations included in the 361 IPs.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on Organizations and SOCs
&lt;/h2&gt;

&lt;p&gt;vCenter is a centralized management point for virtual infrastructure, making timely updates critical for organizations across industries such as manufacturing, finance, healthcare, and public sectors. Because there is no workaround, patching is the highest priority. Since exploitation began days after disclosure, organizations must conduct emergency changes and post-incident hunting instead of waiting for regular patch cycles.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Role
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Distinguish between exploit attempts and successful RCE/cron/C2 establishment, and track up to vSphere tasks.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Update immediately to patched versions, isolate vCenter, restrict egress traffic, and check credentials and certificates.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Users:&lt;/strong&gt; General users do not need to take action. Report any virtual infrastructure anomalies or VM outages to administrators.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Fri, 14 Aug 2026 03:01:01 +0000</pubDate>
      <link>https://dev.to/anoymask/jewelbug-xg-web-infrastructure-supporting-government-webmail-compromise-and-browser-takeover-god</link>
      <guid>https://dev.to/anoymask/jewelbug-xg-web-infrastructure-supporting-government-webmail-compromise-and-browser-takeover-god</guid>
      <description>&lt;h1&gt;
  
  
  Jewelbug: XG-Web Infrastructure Supporting Government Webmail Compromise and Browser Takeover
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Jewelbug: Espionage and Crypto Fraud Operations Intersect&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; Symantec Threat Hunter Team / Security.com&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-13&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source Link:&lt;/strong&gt; &lt;a href="https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage" rel="noopener noreferrer"&gt;https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Information Sources:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/" rel="noopener noreferrer"&gt;https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; Jewelbug, Earth Alux, REF7707, CL-STA-0049, XG-Web, Antino, ClientKing, Microsoft Graph, Google Docs, Chrome, Firefox, ASUS routers&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;Jewelbug injected JavaScript into government webmails on a shared hosting provider. This stole cookies and pushed fake Flash updates, deploying Antino, malicious browser extensions, Linux/router ClientKing implants, and rootkits. The group also used the same XG-Web infrastructure for cryptocurrency fraud.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  From Government Webmail to Windows Devices
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attackers insert a common malicious &lt;code&gt;script&lt;/code&gt; tag into more than 15 government webmail tenants on a shared hosting provider.&lt;/li&gt;
&lt;li&gt;When users log in or view their mailboxes, the script opens a WebSocket, completes a crypto handshake, and sends page cookies.&lt;/li&gt;
&lt;li&gt;It shows a fake Adobe Flash update to devices that match the target government domain, are uninfected, and run Windows.&lt;/li&gt;
&lt;li&gt;When a user runs the file, a fake Adobe installer or HTA deploys Antino.&lt;/li&gt;
&lt;li&gt;Antino uses the Microsoft Graph API as a C2 channel to sideload a malicious "PDF Viewer" extension and a native messaging helper.&lt;/li&gt;
&lt;li&gt;The extension steals cookies, history, bookmarks, screenshots, clipboard data, and network traffic, and injects arbitrary JavaScript.&lt;/li&gt;
&lt;li&gt;The native helper runs commands via the Windows command interpreter.&lt;/li&gt;
&lt;li&gt;The attackers also access internal virtualization management APIs from the compromised device.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Deploying ClientKing to Linux and Routers
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The malware fetches a new random-XOR payload from Google Docs for each request.&lt;/li&gt;
&lt;li&gt;It deploys the Rust-based ClientKing to Linux, ARM64, and ASUS routers.&lt;/li&gt;
&lt;li&gt;It uses five types of C2 transport, including HTTP and DNS tunneling.&lt;/li&gt;
&lt;li&gt;It provides a shell, a SOCKS proxy, and an in-memory kernel module.&lt;/li&gt;
&lt;li&gt;A companion kernel rootkit and a malicious authentication module steal credentials for SSH, &lt;code&gt;su&lt;/code&gt;, and &lt;code&gt;sudo&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Cryptocurrency Fraud
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attackers create many AI-generated fake exchange pages that mimic OKX, Binance, and others.&lt;/li&gt;
&lt;li&gt;They drive visitors to these sites using click bots and SEO poisoning.&lt;/li&gt;
&lt;li&gt;They manage the scam sites using the same XG-Web control panel and infrastructure.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Locations and Execution Sites
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The injected JavaScript and the XG-Web management infrastructure are on the attacker's side. The initial execution happens inside the victim webmail user's browser.&lt;/li&gt;
&lt;li&gt;Antino, the extension, and the native helper run on Windows devices.&lt;/li&gt;
&lt;li&gt;ClientKing, the rootkit, and the authentication module run on Linux, ARM64, and ASUS routers.&lt;/li&gt;
&lt;li&gt;The infrastructure is the same, but public sources do not confirm the organizational relationship between the espionage team and the crypto fraud team.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Webmail users see an overlay that looks like a Flash update after a normal login.&lt;/li&gt;
&lt;li&gt;Administrators can see common external scripts, WebSockets, cookie exfiltration, HTA or installer files, extension sideloading, and Graph API traffic.&lt;/li&gt;
&lt;li&gt;On Linux and routers, they can see Google Docs requests, DNS tunneling, SOCKS traffic, unknown Rust binaries, kernel modules, and SSH authentication hooks.&lt;/li&gt;
&lt;li&gt;Because the attack uses legitimate services like the Graph API, Google Docs, browser extensions, and shared hosting, simple domain allowlists cannot easily detect it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The attackers successfully compromise a shared host to inject scripts into webmail templates.&lt;/li&gt;
&lt;li&gt;Target users access the site on Windows and run the fake update.&lt;/li&gt;
&lt;li&gt;The environment allows extension sideloading, native messaging, Graph API, Google Docs, and DNS egress.&lt;/li&gt;
&lt;li&gt;The attackers have permissions to load implants and modules on Linux and routers.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Webmail template integrity monitoring removes the common script.&lt;/li&gt;
&lt;li&gt;Users do not run the Flash update requested by the web page.&lt;/li&gt;
&lt;li&gt;The organization blocks unauthorized extensions, native messaging hosts, and HTAs.&lt;/li&gt;
&lt;li&gt;Security tools correlate and block Graph API, Google Docs, and DNS destinations along with device behavior.&lt;/li&gt;
&lt;li&gt;Kernel module allowlists, Secure Boot, and router rebuilds eliminate ClientKing and rootkits.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens Upon Success
&lt;/h2&gt;

&lt;p&gt;Webmail cookies, email bodies, browser cookies, credentials, screenshots, clipboard data, and browsing history are stolen. Attackers gain the ability to run arbitrary commands on the device, relay SOCKS traffic, and explore internal management planes. On the crypto fraud side, victims are directed to fake exchanges and lose funds.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; External scripts in webmail, email body access, and abnormal mailbox viewing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; &lt;code&gt;fonts.chrorne[.]com&lt;/code&gt;, WebSockets, Microsoft Graph, Google Docs, DNS tunneling, and fake exchange sites.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; HTA files, fake Adobe installers, Antino, unauthorized PDF Viewer extensions, native helpers, Chrome native messaging registry keys, Rust binaries, and kernel modules.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; Session reuse from new IP addresses or devices using stolen cookies, and mailbox access without authentication.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; Microsoft Graph API calls, Google Docs payload downloads, and template changes in webmail tenants.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; SOCKS traffic, DNS tunneling, and internal access to &lt;code&gt;https://192.168.x.x:8006/api2/json/cluster/resources&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Determination
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; Malicious script loaded, overlay displayed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User Action:&lt;/strong&gt; Fake update downloaded or HTA executed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution:&lt;/strong&gt; Antino, extension, and native helper created and started.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication/Session Compromise:&lt;/strong&gt; Cookies sent, and a different IP address uses those cookies for a session.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data Theft:&lt;/strong&gt; Cookies, credentials, or email bodies seen in C2 or management panels, or equivalent egress traffic confirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Lateral Expansion:&lt;/strong&gt; ClientKing, rootkit, SOCKS traffic, or internal virtualization API connections confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; External script in webmail templates, &lt;code&gt;chrorne&lt;/code&gt; domain, Graph C2, unauthorized extensions, or DNS tunneling.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Verification:&lt;/strong&gt; Identify affected tenants, template differences, script load times, target users, and cookie lifetimes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoints:&lt;/strong&gt; Preserve downloads, HTAs, extension IDs/manifests, native messaging registry keys, Antino, ClientKing, modules, and shell history.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication and Cloud:&lt;/strong&gt; Revoke webmail and IdP sessions, and check Graph/Google Docs access, mailbox operations, and shared host admin changes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Operations:&lt;/strong&gt; Search for internal virtualization management API access, SOCKS traffic, DNS tunneling, and stolen SSH/&lt;code&gt;su&lt;/code&gt;/&lt;code&gt;sudo&lt;/code&gt; credentials.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Repair templates, revoke sessions, change credentials, remove extensions and native hosts, rebuild infected Linux systems and routers, and block IOCs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decision Categories:&lt;/strong&gt; Script Injected / User Exposed / Payload Executed / Session Stolen / Endpoint Controlled / Internal Expansion Confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Event:&lt;/strong&gt; &lt;code&gt;chrorne[.]com&lt;/code&gt;, unauthorized native messaging host, Flash update HTA, or unknown process communication with the Graph API.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timeline Correlation:&lt;/strong&gt; Webmail script -&amp;gt; cookie egress -&amp;gt; fake update -&amp;gt; HTA -&amp;gt; Antino -&amp;gt; extension -&amp;gt; Graph C2 -&amp;gt; internal API.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; Identical scripts across more than 15 tenants, &lt;code&gt;com.microsoft.runedge&lt;/code&gt; registry keys, changing payloads from Google Docs, DNS tunneling, and ClientKing Rust builds.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Webmail templates, browser extensions, Graph requests, and router/kernel telemetry are often missing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Measures:&lt;/strong&gt; Isolate shared hosting, implement CSP/SRI, use extension allowlists, control native messaging, shorten session lifetimes, monitor DNS, and establish secure network device rebuild procedures.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A common script tag was found in more than 15 government webmail tenants.&lt;/li&gt;
&lt;li&gt;WebSockets were used to steal cookies and distribute Antino via fake Flash updates.&lt;/li&gt;
&lt;li&gt;Antino used Microsoft Graph C2, malicious extensions, and native helpers.&lt;/li&gt;
&lt;li&gt;ClientKing has 37 builds for Linux, ARM64, and ASUS routers, along with 5 C2 transports.&lt;/li&gt;
&lt;li&gt;The management infrastructure recorded over 1 million check-ins, over 580,000 cookies, thousands of credentials, and more than 2,300 email bodies.&lt;/li&gt;
&lt;li&gt;The same XG-Web infrastructure was used for both espionage and cryptocurrency fraud.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A single compromise of shared hosting provided a cross-tenant distribution point for multiple government targets.&lt;/li&gt;
&lt;li&gt;Detection must focus on calling processes and API purposes, not just allowing or blocking SaaS traffic.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The cryptocurrency fraud side most likely supplied access, infrastructure, and distribution capabilities to the espionage side, but the command relationship between the two remains unconfirmed.&lt;/li&gt;
&lt;li&gt;Clipboard replacement for cryptocurrency addresses is implemented, but its use has not been confirmed in public espionage campaigns.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1189 Drive-by Compromise, T1056 Input Capture, T1539 Steal Web Session Cookie, T1176 Browser Extensions, T1059.003 Windows Command Shell, T1102.002 Bidirectional Communication, T1102.003 One-Way Communication, T1071.004 DNS, T1090 Proxy, T1014 Rootkit, T1556 Modify Authentication Process.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1204.002 Malicious File, T1218.005 Mshta, T1021 Remote Services, T1041 Exfiltration Over C2 Channel.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Initial access vector to the webmail shared hosting environment.&lt;/li&gt;
&lt;li&gt;Complete list of victim organizations and countries, and actual damage from each artifact.&lt;/li&gt;
&lt;li&gt;Contractual and command relationships between Jewelbug subgroups and registered companies in Hunan Province.&lt;/li&gt;
&lt;li&gt;Direct targeting of Japanese-language fake exchanges or organizations in Japan.&lt;/li&gt;
&lt;li&gt;Privilege escalation paths when deploying ClientKing and rootkits.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on Global SOCs and Organizations
&lt;/h2&gt;

&lt;p&gt;This campaign poses high relevance to organizations in government, telecommunications, aviation, defense, and cryptocurrency sectors. In environments where Microsoft Graph and Google Docs cannot be fully blocked, organizations must correlate telemetry across browser extensions, native helpers, DNS, and internal management APIs. Network devices, including ASUS routers, cannot be monitored using endpoint EDR agents alone.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Audience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOC Analysts:&lt;/strong&gt; Track webmail scripts, sessions, extensions, Graph API traffic, and DNS tunneling as a single attack chain.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Maintain template integrity, enforce CSP, manage extension and native messaging allowlists, revoke sessions, and prepare router rebuild procedures.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Users:&lt;/strong&gt; Do not run Flash or PDF updates requested by webmail pages, and report unexpected browser extensions.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Fri, 14 Aug 2026 03:00:44 +0000</pubDate>
      <link>https://dev.to/anoymask/akira-intrusion-stopping-edr-via-safe-mode-and-exfiltrating-data-before-encryption-2271</link>
      <guid>https://dev.to/anoymask/akira-intrusion-stopping-edr-via-safe-mode-and-exfiltrating-data-before-encryption-2271</guid>
      <description>&lt;h1&gt;
  
  
  Akira: Intrusion Stopping EDR via Safe Mode and Exfiltrating Data Before Encryption
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Akira Hits Safe Mode: Ransomware Rebooting Around EDR&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; Huntress&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-13&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Article:&lt;/strong&gt; &lt;a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" rel="noopener noreferrer"&gt;https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/" rel="noopener noreferrer"&gt;https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; Akira, SonicWall SSL VPN, Active Directory, WinRAR, s5cmd, Amazon S3, AnyDesk, Microsoft Defender, Windows Safe Mode&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;This is a case where Akira attackers accessed a network via an SSL VPN without MFA. They enumerated Active Directory, compressed and exfiltrated shared data to Amazon S3, and installed AnyDesk for persistence. They then rebooted the system into Safe Mode with Networking to stop EDR. However, the ransomware failed to encrypt files due to low virtual memory.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;After many failed login attempts against a SonicWall SSL VPN, authentication succeeds on 2026-08-04 at 03:52:42 UTC.&lt;/li&gt;
&lt;li&gt;About two hours later, the attackers RDP into the domain controller and run an elevated &lt;code&gt;cmd.exe&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;They use PowerShell commands (&lt;code&gt;Get-ADUser&lt;/code&gt; and &lt;code&gt;Get-ADComputer&lt;/code&gt;) to list users and computers, saving the output to &lt;code&gt;C:\ProgramData&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;On an application server, they use WinRAR to archive files from mapped network shares.&lt;/li&gt;
&lt;li&gt;They use &lt;code&gt;s5cmd cp --sp&lt;/code&gt; to send the archives to an attacker-controlled S3 bucket.&lt;/li&gt;
&lt;li&gt;They install AnyDesk as a service for automatic startup to enable remote sessions, file transfers, and clipboard transfers.&lt;/li&gt;
&lt;li&gt;They configure Safe Mode with Networking and add the AnyDesk service to the registry for SafeBoot.&lt;/li&gt;
&lt;li&gt;After a reboot, they run &lt;code&gt;akira.exe&lt;/code&gt; while Huntress and Defender real-time protection are not running.&lt;/li&gt;
&lt;li&gt;After 13 seconds, a low virtual memory error occurs, and the encryption process fails.&lt;/li&gt;
&lt;li&gt;After returning to normal mode, Defender isolates Akira. Data theft was completed before the encryption failed.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Positioning and Execution Locations
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Initial access happened through an internet-facing SonicWall SSL VPN.&lt;/li&gt;
&lt;li&gt;AD enumeration ran on the domain controller. Compression and exfiltration ran on the application server.&lt;/li&gt;
&lt;li&gt;AnyDesk and Akira ran on Windows hosts. The S3 bucket and AnyDesk infrastructure are external.&lt;/li&gt;
&lt;li&gt;Public reports do not explain additional privilege escalation methods. The use of an elevated shell was confirmed, but the path to obtain those privileges is unknown.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The VPN logs show many short-lived failed logins followed immediately by a successful login.&lt;/li&gt;
&lt;li&gt;Administrators can see RDP connections, bulk AD enumeration, WinRAR, s5cmd, AnyDesk service registration, and Safe Mode reboots.&lt;/li&gt;
&lt;li&gt;During Safe Mode, normal EDR and Defender monitoring stops. Defender Event ID 3002 records the startup failure.&lt;/li&gt;
&lt;li&gt;Even without encrypted files or ransom notes, compression and outbound transfers mean data theft has occurred.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Valid credentials are used on a VPN without MFA.&lt;/li&gt;
&lt;li&gt;RDP or administrative access is available from the VPN to the domain controller and application servers.&lt;/li&gt;
&lt;li&gt;Reading shared data and running WinRAR, s5cmd, and AnyDesk are allowed.&lt;/li&gt;
&lt;li&gt;The attacker has administrative rights to change SafeBoot settings and reboot.&lt;/li&gt;
&lt;li&gt;Communication with external S3 buckets and AnyDesk is allowed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;VPN MFA, blocking failed login spikes, or risk-based authentication blocks access.&lt;/li&gt;
&lt;li&gt;Network segmentation or RDP limits stop lateral movement.&lt;/li&gt;
&lt;li&gt;Large-scale compression, S3 transfers, and AnyDesk installations are detected and isolated.&lt;/li&gt;
&lt;li&gt;SafeBoot changes and Safe Mode reboots are blocked with high priority.&lt;/li&gt;
&lt;li&gt;In this case, Akira ran out of virtual memory and failed to encrypt files.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;p&gt;Shared data is exfiltrated to the attacker's S3 bucket and can be used for double extortion. The attackers stop security products using Safe Mode and aim to encrypt files with Akira. In this case, data theft succeeded, but file encryption was not confirmed.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; Public reports show no email vector.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; Traffic to external S3, AnyDesk, and attacker IP addresses. S3 object upload volume and timestamps.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; &lt;code&gt;Get-ADUser&lt;/code&gt;, &lt;code&gt;Get-ADComputer&lt;/code&gt;, WinRAR, s5cmd, AnyDesk, &lt;code&gt;msconfig.exe&lt;/code&gt;, SafeBoot registry keys, &lt;code&gt;akira.exe&lt;/code&gt;, and virtual memory errors.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; SonicWall VPN failed and successful logins, RDP logons, and privileged logons.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; PUT or multipart uploads to the attacker's S3 bucket. If CloudTrail is missing on the victim side, proxy or network logs must cover this.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; VPN source IP &lt;code&gt;72.23.77.35&lt;/code&gt;, internal RDP, SMB share access, AnyDesk, and S3 egress.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Assessment
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; VPN failure logs only.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Successful Authentication:&lt;/strong&gt; VPN success and session issuance at 03:52:42 UTC.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution:&lt;/strong&gt; Internal RDP and enumeration commands confirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Information Gathering:&lt;/strong&gt; WinRAR archive creation of shared data.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data Exfiltration:&lt;/strong&gt; Confirmed via s5cmd success, S3 transfer volume, or destination objects.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Defense Evasion:&lt;/strong&gt; Safe Mode startup and EDR/Defender stop confirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Encryption:&lt;/strong&gt; Failed in this case. No encrypted files or success logs.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; VPN failure spike followed by success, SafeBoot changes, AnyDesk installation, s5cmd, and Akira detection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Check:&lt;/strong&gt; Identify VPN sessions, source IP, authenticated user, destination, and the first RDP timestamp.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoints:&lt;/strong&gt; Preserve PowerShell logs, processes, registry keys, services, Kernel-Boot Event ID 27, Kernel-General Event ID 12, and Defender Event ID 3002.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication &amp;amp; Cloud:&lt;/strong&gt; Disable VPN credentials, check for RDP and administrative logons using the same ID, and review S3 traffic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Activity:&lt;/strong&gt; Search for &lt;code&gt;AdUsers.txt&lt;/code&gt;, &lt;code&gt;AdComp.txt&lt;/code&gt;, WinRAR archives, s5cmd logs, AnyDesk transfers, and Akira binaries.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Disconnect VPN sessions, change credentials, isolate hosts, remove AnyDesk and SafeBoot persistence, block egress, and run a full scan in normal mode.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Assessment Categories:&lt;/strong&gt; VPN Contact / VPN Compromised / Internal Execution / Exfiltration Confirmed / Defense Evasion Confirmed / Encryption Failed or Confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Event:&lt;/strong&gt; SafeBoot registry changes, &lt;code&gt;SAFEBOOT:NETWORK&lt;/code&gt;, AnyDesk SafeBoot service, s5cmd, and Defender error &lt;code&gt;0x8007043c&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Time-Series Correlation:&lt;/strong&gt; VPN failure spike -&amp;gt; success -&amp;gt; RDP -&amp;gt; AD enumeration -&amp;gt; compression -&amp;gt; S3 transfer -&amp;gt; AnyDesk -&amp;gt; Safe Mode -&amp;gt; Akira.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; &lt;code&gt;C:\ProgramData\AdUsers.txt&lt;/code&gt; and &lt;code&gt;AdComp.txt&lt;/code&gt;, WinRAR commands with multiple share arguments, unknown S3 buckets, and AnyDesk peer &lt;code&gt;1778787240&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Must cover VPN, RDP, process arguments, SMB, egress, and the lack of monitoring during Safe Mode.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Mitigations:&lt;/strong&gt; VPN MFA, administrative network segmentation, blocking SafeBoot changes, RMM allowlists, S3 egress controls, and EDR tamper protection.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Successful authentication was confirmed on a SonicWall SSL VPN without MFA.&lt;/li&gt;
&lt;li&gt;AD enumeration, shared data compression, S3 transfer via s5cmd, and AnyDesk installation were confirmed.&lt;/li&gt;
&lt;li&gt;Huntress and Defender real-time protection did not run during Safe Mode.&lt;/li&gt;
&lt;li&gt;Akira ran out of memory and failed to encrypt files.&lt;/li&gt;
&lt;li&gt;This was the first time Huntress observed Akira using Safe Mode.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Even if encryption fails, extortion risks remain using the stolen data.&lt;/li&gt;
&lt;li&gt;Visibility during Safe Mode is poor, so security teams must correlate pre-reboot settings changes with post-reboot forensic artifacts.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;On hosts with more virtual memory, the same Akira binary might complete encryption.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1133 External Remote Services, T1078 Valid Accounts, T1021.001 RDP, T1087.002 Domain Account Discovery, T1018 Remote System Discovery, T1560.001 Archive via Utility, T1537 Transfer Data to Cloud Account, T1219 Remote Access Software, T1562.001 Impair Defenses, T1486 Data Encrypted for Impact (execution attempted, not successful).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1041 Exfiltration Over C2 Channel. Because of the S3 transfer, organizations may prioritize T1537 based on their ATT&amp;amp;CK framework usage.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The source of the VPN credentials and the path to elevated privileges.&lt;/li&gt;
&lt;li&gt;The full scope of exfiltrated data and how it is used.&lt;/li&gt;
&lt;li&gt;The number of compromised hosts, additional persistence mechanisms, and the full infrastructure of the Akira operators.&lt;/li&gt;
&lt;li&gt;Whether the encryption failure was environment-dependent or binary-specific.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs
&lt;/h2&gt;

&lt;p&gt;Tools like VPNs, RDP, AnyDesk, and WinRAR are common in enterprise environments, making isolated events easy to miss. Safe Mode reboots should not be assumed to be routine maintenance. Security teams should treat enumeration, compression, S3 transfers, and reboots occurring within hours of external VPN authentication as a single malicious intrusion flow.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Audience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Distinguish between file encryption success and data theft success, and correlate forensic evidence before and after Safe Mode.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Enforce VPN MFA, isolate RDP access, monitor SafeBoot changes, and maintain strict allowlists for RMM tools and cloud destinations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Users:&lt;/strong&gt; Immediately report unexpected VPN authentication notifications or unexpected remote desktop activity.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Thu, 13 Aug 2026 02:25:41 +0000</pubDate>
      <link>https://dev.to/anoymask/plug-and-pwn-getting-windows-system-privileges-from-fake-usb-and-rdp-devices-13f</link>
      <guid>https://dev.to/anoymask/plug-and-pwn-getting-windows-system-privileges-from-fake-usb-and-rdp-devices-13f</guid>
      <description>&lt;h1&gt;
  
  
  Plug and Pwn: Getting Windows SYSTEM Privileges from Fake USB and RDP Devices
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Plug and Pwn attack uses fake USB devices for Windows system access&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; BleepingComputer (Original Research: Plug and Pwn)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-12&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original URL:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access/" rel="noopener noreferrer"&gt;https://www.bleepingcomputer.com/news/security/plug-and-pwn-attack-uses-fake-usb-devices-for-windows-system-access/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Source:&lt;/strong&gt; &lt;a href="https://plugandpwn.com/" rel="noopener noreferrer"&gt;https://plugandpwn.com/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; Windows 11, Windows Plug and Play, Windows Update, RDP USB redirection, Sierra Wireless, Sony FeliCa, Intel RealSense, FaceDancer, Cynthion, GreatFET, CVE-2019-10617&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. One-Sentence Summary
&lt;/h2&gt;

&lt;p&gt;This research shows that simply connecting a fake USB device or a virtual USB via RDP can trick Windows Plug and Play into installing official drivers with SYSTEM privileges, leading to a reverse shell by chaining the installation process and known vulnerabilities.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Chain A: Zero-Click SYSTEM Execution via Physical USB
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attacker uses FaceDancer, Cynthion, or GreatFET to fake a USB device descriptor.&lt;/li&gt;
&lt;li&gt;Windows recognizes it as a Sierra Wireless device, automatically downloads a signed vendor package from Windows Update, and installs it with SYSTEM privileges.&lt;/li&gt;
&lt;li&gt;The installed components are used to change DNS settings.&lt;/li&gt;
&lt;li&gt;The same device re-enumerates as a Sony FeliCa device to download extra software via HTTP.&lt;/li&gt;
&lt;li&gt;Poisoned name resolution points the download to the attacker, who writes malicious files with SYSTEM privileges.&lt;/li&gt;
&lt;li&gt;The device re-enumerates as a Sierra device again, loads the malicious files, and gets a SYSTEM reverse shell.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Chain B: NoPlug and Pwn (RDP)
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attacker redirects a crafted USB descriptor through an RDP connection.&lt;/li&gt;
&lt;li&gt;The remote Windows creates it as a local PnP device and selects the Intel RealSense driver package.&lt;/li&gt;
&lt;li&gt;It abuses the load path of the co-installer DLL to run code with SYSTEM privileges.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Chain C: Old Driver Vulnerabilities
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The device enumerates as a composite USB device and offers multiple functions via &lt;code&gt;usbccgp.sys&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The INF installs an old driver as a service.&lt;/li&gt;
&lt;li&gt;Known vulnerabilities, such as CVE-2019-10617, are used for local privilege escalation.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Chain A starts with a person who has physical access to the device's USB port or a malicious peripheral.&lt;/li&gt;
&lt;li&gt;Chain B presents a virtual USB from the RDP connection source, and the code runs with SYSTEM privileges on the destination Windows.&lt;/li&gt;
&lt;li&gt;Driver acquisition, INF processing, and co-installers are executed by the Windows PnP and update systems with SYSTEM privileges.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;No user logon or UAC approval is needed. It looks like a normal "Setting up a device" behavior.&lt;/li&gt;
&lt;li&gt;Administrators will see the enumeration of different vendor devices in a short time, driver downloads from Windows Update, network setting changes, and SYSTEM child processes.&lt;/li&gt;
&lt;li&gt;In an RDP environment, it is observed as a PnP creation from a remote session, even without a physical USB.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Conditions for Success and Failure
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Conditions for Success
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;USB connection or RDP Plug and Play redirection is allowed.&lt;/li&gt;
&lt;li&gt;Compatible driver packages can be downloaded from Windows Update.&lt;/li&gt;
&lt;li&gt;Vulnerable processes remain, such as co-installers of the target package, HTTP downloads, or old drivers.&lt;/li&gt;
&lt;li&gt;Device installation restrictions are not applied.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Conditions for Failure
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The system rejects installations other than allowed Hardware IDs or Device Classes.&lt;/li&gt;
&lt;li&gt;RDP PnP redirection is disabled.&lt;/li&gt;
&lt;li&gt;Driver download sources and HTTP downloads are blocked.&lt;/li&gt;
&lt;li&gt;A blocklist of old vulnerable drivers and application control are applied.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;p&gt;Without user action, the attacker can create files with SYSTEM privileges, load DLLs, create services, change network settings, and get a reverse shell. The published content is a research demo and is not confirmed to be used in actual attack campaigns.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; None in principle. This is only relevant if malicious peripherals are delivered (Hypothesis).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; Windows Update or vendor downloads, HTTP downloads of Sony software, and immediate DNS changes followed by communication with the attacker.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; Kernel-PnP, DriverFrameworks, SetupAPI, &lt;code&gt;C:\Windows\INF\setupapi.dev.log&lt;/code&gt;, new drivers or services, and abnormal DLLs or shells run by SYSTEM.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; RDP authentication, connection source, session ID. The physical chain has no authentication events.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; Usually none.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; RDP USB virtual channel, driver downloads, connections after DNS changes, and reverse shells.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Determination
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; USB insertion or RDP connection only.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution Prep:&lt;/strong&gt; New PnP enumeration, vendor package download.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution:&lt;/strong&gt; SYSTEM-privilege co-installer, service, or malicious DLL load.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Compromise Success:&lt;/strong&gt; DNS modification, SYSTEM shell, external C2 connection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Follow-on Compromise:&lt;/strong&gt; Credential theft, persistence, and lateral movement only occur if additional evidence is found.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; Unauthorized USB, PnP device creation during RDP, rapid re-enumeration of multiple vendors, SYSTEM network traffic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Check:&lt;/strong&gt; Determine connection time, Hardware ID, Device Instance ID, RDP session, and presence of an operator.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint:&lt;/strong&gt; Preserve SetupAPI, PnP events, DriverStore, INF, services, DNS settings, process tree, and memory.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication/Cloud:&lt;/strong&gt; Check RDP logon and source, RD Gateway, MFA, and session reconnection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Follow-up Actions:&lt;/strong&gt; Check for SYSTEM shells, credential access, persistence, and lateral movement.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Consider device isolation, stopping USB or RDP redirection, removing malicious drivers and services, restoring DNS, and rebuilding.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Judgment Categories:&lt;/strong&gt; Device Presented / Driver Installed / SYSTEM Execution / C2 Confirmed / Follow-on Compromise.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Event:&lt;/strong&gt; Unauthorized Hardware ID, new PnP during an RDP session, HTTP download by SYSTEM, DNS change right after driver installation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timeline Correlation:&lt;/strong&gt; USB enumeration -&amp;gt; Signed driver download -&amp;gt; Re-enumeration to another vendor -&amp;gt; DNS change -&amp;gt; Outbound SYSTEM traffic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; SetupAPI showing multiple vendors in a short time, co-installer DLLs, new kernel services, old vulnerable drivers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Requires USB asset inventory, SetupAPI collection, RDP virtual channels, and DNS setting change logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Actions:&lt;/strong&gt; Device Installation Restrictions, Hardware ID allowlist, &lt;code&gt;fDisablePNPRedir&lt;/code&gt;, blocking vulnerable drivers, and blocking HTTP downloads.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Researchers demonstrated a physical chain on a fully updated Windows 11 that reached a SYSTEM shell in about 5 minutes from a logged-out state.&lt;/li&gt;
&lt;li&gt;They also demonstrated "NoPlug and Pwn," which works using only RDP USB redirection.&lt;/li&gt;
&lt;li&gt;Windows runs part of its PnP packages with SYSTEM privileges without UAC.&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;DisableCoInstallers&lt;/code&gt; alone cannot stop this entire class of attacks.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In VDIs, jump servers, and shared conference room terminals, RDP redirection settings act as a boundary equal to physical port control.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The physical chain can be used in actual attacks by delivering malicious peripherals, leaving them in conference rooms, or posing as maintenance personnel.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1200 Hardware Additions, T1068 Exploitation for Privilege Escalation, T1543.003 Windows Service, T1105 Ingress Tool Transfer, T1059.003 Windows Command Shell.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1021.001 RDP, T1562.001 Impair Defenses, and credential access after T1098 only if follow-up actions are confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Additional Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The scope of permanent fixes by Microsoft and various vendors.&lt;/li&gt;
&lt;li&gt;Whether this is used in real attacks and the total number of vulnerable packages.&lt;/li&gt;
&lt;li&gt;Reproducibility across different Windows SKUs and enterprise update management configurations.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and Organizations
&lt;/h2&gt;

&lt;p&gt;Organization endpoints such as VDIs, remote maintenance tools, and factory, conference room, or reception terminals often trust PnP implicitly. Organizations must include not only USB control products, but also RDP redirection, driver downloads, and SetupAPI logs in their asset management and SOC monitoring scope.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Audience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Correlate PnP enumeration, driver downloads, SYSTEM execution, and DNS changes. Distinguish between research demos and real compromises.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Prioritize USB device allowlists and disabling RDP PnP redirection.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Users:&lt;/strong&gt; Do not connect unknown USB devices. Report immediately if an automatic setup starts after connecting a device.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Thu, 13 Aug 2026 02:25:32 +0000</pubDate>
      <link>https://dev.to/anoymask/city-forum-anonymous-data-enumeration-across-salesforce-aura-lwr-and-servicenow-guest-search-c1m</link>
      <guid>https://dev.to/anoymask/city-forum-anonymous-data-enumeration-across-salesforce-aura-lwr-and-servicenow-guest-search-c1m</guid>
      <description>&lt;h1&gt;
  
  
  City-Forum: Anonymous Data Enumeration Across Salesforce Aura / LWR and ServiceNow Guest Search
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; An Advanced Attacker Is Targeting Salesforce and ServiceNow&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; Reco&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-12&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Source:&lt;/strong&gt; &lt;a href="https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow" rel="noopener noreferrer"&gt;https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt; &lt;a href="https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/" rel="noopener noreferrer"&gt;https://www.securityweek.com/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; City-Forum campaign, Salesforce Experience Cloud, Aura, LWR, UI API, GraphQL, ServiceNow Service Portal, &lt;code&gt;158.220.87.79&lt;/code&gt;, &lt;code&gt;city-forum.com&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. One-Sentence Summary
&lt;/h2&gt;

&lt;p&gt;A single Go-based tool uses unauthenticated Salesforce guest permissions to enumerate Aura and LWR GraphQL APIs, and quickly scans ServiceNow's private Service Portal search API from the same source to collect data that site administrators accidentally left public.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Salesforce Aura
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;Finds an Experience Cloud site.&lt;/li&gt;
&lt;li&gt;Sends a POST request to &lt;code&gt;/aura&lt;/code&gt; or &lt;code&gt;/s/sfsites/aura&lt;/code&gt; as a guest.&lt;/li&gt;
&lt;li&gt;Uses &lt;code&gt;HostConfigController.getConfigData&lt;/code&gt; to list Accounts, Contacts, Cases, Leads, Users, and ContentDocuments available to guests.&lt;/li&gt;
&lt;li&gt;Uses &lt;code&gt;SelectableListDataProviderController.getItems&lt;/code&gt; to page through records for each object.&lt;/li&gt;
&lt;li&gt;Adds &lt;code&gt;/SiteRegister&lt;/code&gt; and &lt;code&gt;/CommunitiesSelfReg&lt;/code&gt; to each subsite to check if self-registration is open. No successful registrations were observed.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Salesforce LWR
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;Identifies LWR sites using the &lt;code&gt;lwr_app&lt;/code&gt; Link header or &lt;code&gt;LWR.define(...)&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Sends a guest POST request to &lt;code&gt;/webruntime/api/services/data/vNN.0/graphql&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Queries &lt;code&gt;EntityDefinition&lt;/code&gt; to list objects available via the UI API.&lt;/li&gt;
&lt;li&gt;Scans versions continuously from &lt;code&gt;v56.0&lt;/code&gt; to &lt;code&gt;v66.0&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Uses cursors to retrieve records allowed by guest object permissions, FLS, and sharing rules.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  ServiceNow
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;Opens the guest Service Portal using &lt;code&gt;/$sp.do?...&amp;amp;id=landing&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Sends search terms, portal information, sources, and counts to &lt;code&gt;POST /api/now/sp/search?sysparm_cancelable=true&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Uses response length to distinguish between empty responses and search terms that return content.&lt;/li&gt;
&lt;li&gt;Collects results that Knowledge Bases and custom search sources expose to guests.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The traffic source is &lt;code&gt;158.220.87.79&lt;/code&gt; on Contabo, and &lt;code&gt;city-forum.com&lt;/code&gt; has pointed to this IP since 2025-03-12.&lt;/li&gt;
&lt;li&gt;The tool uses &lt;code&gt;Go-http-client/1.1&lt;/code&gt; and connects from the internet to public Salesforce and ServiceNow Web APIs.&lt;/li&gt;
&lt;li&gt;The processes run under the SaaS Guest User context. No malware runs on victim corporate endpoints.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;There are no user actions, logins, or MFA events.&lt;/li&gt;
&lt;li&gt;In Salesforce, large amounts of &lt;code&gt;AuraRequest&lt;/code&gt;, &lt;code&gt;Sites&lt;/code&gt;, sequential API versions, and self-registration URLs appear.&lt;/li&gt;
&lt;li&gt;In ServiceNow, &lt;code&gt;syslog_transaction&lt;/code&gt; shows Created by = &lt;code&gt;guest&lt;/code&gt;, REST requests, &lt;code&gt;/api/now/sp/search&lt;/code&gt;, and non-human timing intervals.&lt;/li&gt;
&lt;li&gt;HTTP 201 is returned even for empty responses, so status codes alone cannot confirm successful data leaks.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Salesforce Guest Users have read permissions for objects, fields, and sharing rules.&lt;/li&gt;
&lt;li&gt;LWR has "Allow guest users to access public APIs" enabled.&lt;/li&gt;
&lt;li&gt;ServiceNow public portals have search sources without login gates or have loose KB read criteria.&lt;/li&gt;
&lt;li&gt;Rate limits and anomaly detection do not block fast enumeration.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Guest Users are set to minimum privilege, removing unnecessary sharing, FLS, files, and activity permissions.&lt;/li&gt;
&lt;li&gt;LWR guest UI APIs are disabled.&lt;/li&gt;
&lt;li&gt;ServiceNow search sources use &lt;code&gt;gs.isLoggedIn()&lt;/code&gt;, &lt;code&gt;GlideRecordSecure&lt;/code&gt;, and proper roles/read criteria.&lt;/li&gt;
&lt;li&gt;Guest access, non-browser user agents, and high-frequency enumeration are blocked.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;p&gt;Without breaking authentication, an attacker can bulk-collect customers, contacts, cases, documents, and knowledge articles that site owners exposed to Guest Users. This does not breach the Salesforce or ServiceNow platforms themselves; it abuses the anonymous public settings of each tenant. No successful self-registration or escalation to authenticated privileges has been observed.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; Not used in this chain. &lt;code&gt;city-forum.com&lt;/code&gt; allows the IP as an SPF sender, but email attacks are unconfirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; Limited on the external user side. DNS shows &lt;code&gt;city-forum.com&lt;/code&gt; resolving to &lt;code&gt;158.220.87.79&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; No execution on victim terminals.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; Salesforce and ServiceNow Guest Users. Not visible in normal sign-in logs alone.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; Salesforce Event Monitoring logs for AuraRequest/Sites, &lt;code&gt;CLIENT_IP&lt;/code&gt;, &lt;code&gt;USER_AGENT&lt;/code&gt;, &lt;code&gt;ACTION_MESSAGE&lt;/code&gt;, and URIs. ServiceNow &lt;code&gt;syslog_transaction&lt;/code&gt; logs for IP, URL, Created by, User agent, and Output length.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; WAF/CDN logs showing &lt;code&gt;Go-http-client/1.1&lt;/code&gt;, sequential API versions, and high-frequency POST requests to &lt;code&gt;/aura&lt;/code&gt;, &lt;code&gt;/webruntime/&lt;/code&gt;, and &lt;code&gt;/api/now/sp/search&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Determining Attack Success
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; Public site GET requests, empty 201 responses, failed GraphQL calls.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enumeration Started:&lt;/strong&gt; &lt;code&gt;getConfigData&lt;/code&gt;, EntityDefinition, API version sweeps, search term scans.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data Retrieved:&lt;/strong&gt; Increasing response size, paging in batches of 2000, &lt;code&gt;hasNextPage&lt;/code&gt; cursors, and growing ServiceNow output lengths.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Self-Registration Attempted:&lt;/strong&gt; Access to registration URLs only. Without account creation logs, privilege escalation is not confirmed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Follow-on Abuse:&lt;/strong&gt; Using retrieved data, authenticated accounts, or expanding to other SaaS platforms requires additional evidence.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; &lt;code&gt;158.220.87.79&lt;/code&gt;, &lt;code&gt;Go-http-client/1.1&lt;/code&gt;, massive guest Aura requests, LWR version sweeps, and sudden spikes in ServiceNow searches.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Check:&lt;/strong&gt; Identify the target portal, time, source IP, user agent, and response count/length to separate simple contact from data retrieval.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Terminals:&lt;/strong&gt; Generally out of scope. Do not assume administrator terminals are compromised.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication &amp;amp; Cloud:&lt;/strong&gt; Audit Guest Profiles, sharing rules, FLS, UI APIs, self-registration, ServiceNow search sources, and KB read criteria.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Actions:&lt;/strong&gt; Look for phishing using the same data and email addresses, credential attacks, and unauthorized access to other SaaS apps.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Do not just block IOCs. Fix anonymous public permissions and identify the specific records that leaked.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Judgment Levels:&lt;/strong&gt; Scanned / Enumeration Confirmed / Data Returned / Bulk Collection Confirmed / Self-Registration Confirmed / Follow-on Abuse.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Events:&lt;/strong&gt; Guest user + &lt;code&gt;Go-http-client/1.1&lt;/code&gt;, LWR UI API, ServiceNow guest search.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Time-Series Correlation:&lt;/strong&gt; Site discovery -&amp;gt; configuration enumeration -&amp;gt; object paging -&amp;gt; self-registration checks. For ServiceNow, correlate search counts with output lengths.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; Look for &lt;code&gt;ACTION$getConfigData&lt;/code&gt;, &lt;code&gt;ACTION$getItems&lt;/code&gt;, &lt;code&gt;v56.0→v66.0&lt;/code&gt;, &lt;code&gt;SiteRegister&lt;/code&gt;, and guest &lt;code&gt;sp/search&lt;/code&gt; requests.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; If Salesforce Event Monitoring licenses are missing, use CDN/WAF logs as a backup. ServiceNow does not log POST bodies, so search terms cannot be recovered.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Fixes:&lt;/strong&gt; Set Guest Users to minimum privilege, disable LWR guest UI APIs, stop self-registration, audit ServiceNow search sources and KB criteria, and implement rate limiting.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The same IP address and Go tool crossed between Salesforce Aura, LWR, and ServiceNow.&lt;/li&gt;
&lt;li&gt;The largest Salesforce target recorded over 560,000 events.&lt;/li&gt;
&lt;li&gt;This is the first reported real-world observation of Salesforce LWR guest UI API abuse.&lt;/li&gt;
&lt;li&gt;ServiceNow search APIs return HTTP 201 to both anonymous and authenticated users.&lt;/li&gt;
&lt;li&gt;Reco has not attributed the attacker to a specific threat group.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Communications, financial, manufacturing, and public sector organizations with customer portals face similar configuration risks.&lt;/li&gt;
&lt;li&gt;Blocking IOCs alone allows attackers to restart the same guest enumeration from a different IP address.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The collected contact and case information may be used to improve the accuracy of targeted phishing or helpdesk fraud.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1589 Gather Victim Identity Information, T1595 Active Scanning, T1213 Data from Information Repositories, T1530 Data from Cloud Storage (if public documents are retrieved). T1190 Exploit Public-Facing Application is rated Low to Medium because this attack relies on configuration abuse.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1114 / T1567, etc., are not confirmed in this material and apply only if follow-up abuse is discovered.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Additional Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Attacker attribution, storage locations for collected data, and final goals.&lt;/li&gt;
&lt;li&gt;The exact records and sensitivity levels returned to each organization.&lt;/li&gt;
&lt;li&gt;Whether any environments succeeded in self-registration.&lt;/li&gt;
&lt;li&gt;The time gap between infrastructure setup in March 2025 and the actual start of scanning.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and Organizations
&lt;/h2&gt;

&lt;p&gt;SOCs that focus mainly on SaaS authentication logs easily miss this activity. Organizations that publicly expose Salesforce Experience Cloud or ServiceNow Portals must treat Guest Users not as "unauthenticated and therefore without privileges," but rather audit them just like permanent service accounts.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Role
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Monitor guest API enumeration and response volumes. Do not use HTTP 201 or the lack of logins as indicators of safety.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Administrators:&lt;/strong&gt; Audit Salesforce sharing, FLS, LWR UI APIs, and ServiceNow search sources/KB criteria.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Portal Owners:&lt;/strong&gt; Because this attack involves no user actions, portal owners must regularly review the scope of their public information.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Thu, 13 Aug 2026 02:25:23 +0000</pubDate>
      <link>https://dev.to/anoymask/windrelay-spynote-phone-remote-control-and-nfc-relay-for-loan-and-card-fraud-1kij</link>
      <guid>https://dev.to/anoymask/windrelay-spynote-phone-remote-control-and-nfc-relay-for-loan-and-card-fraud-1kij</guid>
      <description>&lt;h1&gt;
  
  
  WindRelay + SpyNote: Phone Remote Control and NFC Relay for Loan and Card Fraud
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Android malware combo takes out loans and relays victims' credit cards&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; BleepingComputer (Investigation by Group-IB)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-12&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Article:&lt;/strong&gt; &lt;a href="https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/" rel="noopener noreferrer"&gt;https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Source:&lt;/strong&gt; &lt;a href="https://www.group-ib.com/masked-actors/tx-nfc/" rel="noopener noreferrer"&gt;https://www.group-ib.com/masked-actors/tx-nfc/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; WindRelay, SpyNote, Android, Accessibility Service, NFC, Host Card Emulation, Mobile Banking&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Summary
&lt;/h2&gt;

&lt;p&gt;This is a complex financial fraud scheme. Attackers call victims while posing as bank staff. They trick victims into installing a SpyNote APK that contains the victim's name and granting Accessibility permissions. The attackers then use remote control to take out loans. Next, they use WindRelay to relay real credit card NFC communication to the attacker's device in real-time, allowing them to make purchases at a legitimate POS terminal.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Device Compromise and Loans
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;An attacker calls the victim and pretends to be a bank employee.&lt;/li&gt;
&lt;li&gt;The attacker tricks the victim into sideloading a SpyNote APK that includes the victim's name.&lt;/li&gt;
&lt;li&gt;The attacker makes the victim enable Android Accessibility Service permissions.&lt;/li&gt;
&lt;li&gt;The attackers use SpyNote's remote control features to silently install WindRelay. In public cases, this required no extra user action.&lt;/li&gt;
&lt;li&gt;The attacker remotely operates the official banking app to apply for a loan in the victim's name.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  NFC Card Relay and Cash-Out
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;Following instructions over the call, the victim taps their real credit card on their smartphone and enters their PIN.&lt;/li&gt;
&lt;li&gt;The victim's device runs WindRelay and acts as a card reader to capture NFC APDU commands.&lt;/li&gt;
&lt;li&gt;The device relays the live traffic, including transaction-specific authentication data, to the attacker's device.&lt;/li&gt;
&lt;li&gt;The attacker's device emulates the card and presents it to a legitimate POS terminal at a physical store.&lt;/li&gt;
&lt;li&gt;Fraudulent payments are completed while the physical card stays safely with the victim.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Location
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Social engineering and remote control happen via phone calls and attacker C2 servers.&lt;/li&gt;
&lt;li&gt;SpyNote and WindRelay run on the victim's Android device.&lt;/li&gt;
&lt;li&gt;NFC relay reception and card emulation run on the attacker's device. Cash-out happens at physical stores with legitimate POS terminals.&lt;/li&gt;
&lt;li&gt;Root permissions are not required. The attack relies mainly on Accessibility, sideloading, and NFC permissions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. View from Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;To the victim, it looks like bank support steps, identity verification, or a card check.&lt;/li&gt;
&lt;li&gt;The APK includes the victim's name, and the user is guided during a phone call, making it look very trustworthy.&lt;/li&gt;
&lt;li&gt;To the bank, the actions may look like normal operations from a normal device, official app, and real card in a short time.&lt;/li&gt;
&lt;li&gt;MDM and EDR tools might detect unknown APKs, Accessibility permissions, inter-app installations, NFC usage, and screen or input operations.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The victim allows the installation of an APK from an unknown source and grants Accessibility permissions.&lt;/li&gt;
&lt;li&gt;The Android device supports NFC, and the victim taps their card and enters their PIN.&lt;/li&gt;
&lt;li&gt;SpyNote successfully controls the banking app remotely.&lt;/li&gt;
&lt;li&gt;The NFC communication delay is within the payment limit, and the attacker can access a POS terminal.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Block unknown APKs, dangerous Accessibility usage, and inter-app installations.&lt;/li&gt;
&lt;li&gt;The bank assesses risks for new loans during phone calls, device state changes, and NFC relay characteristics.&lt;/li&gt;
&lt;li&gt;The user hangs up the phone and calls the official number back.&lt;/li&gt;
&lt;li&gt;The user stops the process when asked to tap a card or enter a PIN by someone claiming to be support.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens Upon Success
&lt;/h2&gt;

&lt;p&gt;The attackers can remotely control the victim's device to take out loans, steal credentials and screen data, and install more APKs. When the NFC relay succeeds, they can complete in-store payments without stealing the card. In the reported case, the entire process took about 13 minutes from the start of the call.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; Not the main path. They might send APK URLs via SMS or messages, but details in public cases are limited.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; APK download sites, SpyNote/WindRelay C2, and short-lived new domains or IP traffic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; Sideload installs, unknown signed APKs, enabled Accessibility, additional APK installations from SpyNote, screen capture/input, and NFC foreground services.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; Mobile banking device registration, sessions, loan applications, authentication methods, and device risk status.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; MDM/MAM non-compliance, Play Protect warnings, and app permission changes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; Low-latency two-way NFC relay traffic, C2 communication, and payment authentication between the attacker's device and the POS.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Stages
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; Impersonation call, receiving an APK URL.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User Action:&lt;/strong&gt; Installing the APK, granting Accessibility permissions, tapping the card, entering the PIN.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution:&lt;/strong&gt; SpyNote starts and connects to C2.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malware Success:&lt;/strong&gt; WindRelay installed, remote screen and input control active.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication &amp;amp; Transaction Breach:&lt;/strong&gt; Loan application approved, NFC relay session active, POS approval.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Loss Confirmed:&lt;/strong&gt; Loan funds transferred, fraudulent payment completed, cash converted by the attacker.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; Loans or payments made during a phone call, unknown APK + Accessibility, remote device operation and POS transaction at the same time.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Check:&lt;/strong&gt; Correlate call times, phone numbers, SMS, APKs, permission grants, card taps, and transaction times.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Device:&lt;/strong&gt; Preserve APKs, signatures, hashes, Package Installer logs, Accessibility settings, notification access, overlays, NFC usage, C2, and screen operation traces.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication &amp;amp; Cloud:&lt;/strong&gt; Check bank sessions, loan workflows, device fingerprints, transaction authentication, and POS locations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Actions:&lt;/strong&gt; Check for additional accounts, transfer destinations, other cards, stolen contacts/SMS, and new device registrations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Enable airplane mode or isolate network, block cards, revoke bank sessions and credentials, put loans and payments on hold, and factory reset the device.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Verdict Categories:&lt;/strong&gt; Social Engineering / SpyNote Installed / Remote Control Confirmed / WindRelay Confirmed / Loan Fraud / NFC Relay Transaction.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Events:&lt;/strong&gt; Accessibility permissions right after a sideload, unknown APK installing another APK, NFC services used while banking.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timeline Correlation:&lt;/strong&gt; Incoming call -&amp;gt; APK installation -&amp;gt; Accessibility enabled -&amp;gt; Banking loan -&amp;gt; Card tap -&amp;gt; Remote POS payment.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Threat Hunting:&lt;/strong&gt; APKs containing victim names, SpyNote permission sets, unknown Accessibility services, NFC relay services, and clusters of C2 IPs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Personal devices often lack MDM, app, Accessibility, and NFC logs. Bank transaction timelines serve as main evidence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Top Priorities:&lt;/strong&gt; Block unknown APKs, detect Accessibility abuse, identify risky devices within apps, require step-up authentication for high-risk transactions during calls, and detect card relay behavior.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Group-IB identified about 20 related samples and 4 C2 IPs between November 2025 and July 2027.&lt;/li&gt;
&lt;li&gt;Public cases targeted the Czech Republic, Slovakia, and Slovenia.&lt;/li&gt;
&lt;li&gt;After SpyNote was installed, WindRelay was installed without extra user actions.&lt;/li&gt;
&lt;li&gt;The phone calls lasted about 13 minutes.&lt;/li&gt;
&lt;li&gt;No root privilege usage was confirmed in the public reports.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Similar vishing attacks targeting banks can be adapted for cryptocurrency and corporate banking app users, even if local APK sideload rates are low.&lt;/li&gt;
&lt;li&gt;Without linking malware detection on devices to financial institution fraud detection, it is hard to see the full picture.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Combining NFC round-trip latency, short-term remote POS usage with the same card, and transactions during phone calls can improve relay detection accuracy.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence (Mobile):&lt;/strong&gt; T1476 Deliver Malicious App via Other Means, T1456.002 GUI Input Capture, T1417 Input Capture, T1646 Exfiltration Over C2 Channel.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1516 Input Injection, T1421 System Network Connections Discovery. NFC relay / HCE techniques do not have an exact match in existing ATT&amp;amp;CK Mobile and are treated as custom methods.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Full APK hashes, C2 servers, package names, and signers.&lt;/li&gt;
&lt;li&gt;Specific steps used to pass loan authentication and bypass bank checks.&lt;/li&gt;
&lt;li&gt;WindRelay communication protocols, encryption, and latency management.&lt;/li&gt;
&lt;li&gt;Expansion into Japanese-speaking regions or other Asian markets.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on SOCs and Organizations
&lt;/h2&gt;

&lt;p&gt;This type of attack requires joint investigations between corporate SOCs, financial SOCs, CSIRT, and Fraud departments. Organizations must manage Accessibility abuse and sideloading on BYOD and corporate Android devices. Financial institutions should prepare to correlate timelines for device risks, phone calls, loans, and NFC payments.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Role
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOC Analysts:&lt;/strong&gt; Correlate APKs, Accessibility, remote control, bank transactions, and POS approvals into a single timeline.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For IT Administrators:&lt;/strong&gt; Restrict sideloading and dangerous Accessibility features. Control financial operations from non-compliant MDM devices.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For End Users:&lt;/strong&gt; Bank staff will never ask you to install an APK, enable Accessibility, tap your card, or enter your PIN over the phone. Hang up and call the official number.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment</title>
      <dc:creator>Anoymask</dc:creator>
      <pubDate>Thu, 13 Aug 2026 02:25:14 +0000</pubDate>
      <link>https://dev.to/anoymask/lazarus-operation-dream-job-from-windows-zero-day-to-edr-bypass-and-backdoor-deployment-1bll</link>
      <guid>https://dev.to/anoymask/lazarus-operation-dream-job-from-windows-zero-day-to-edr-bypass-and-backdoor-deployment-1bll</guid>
      <description>&lt;h1&gt;
  
  
  Lazarus "Operation Dream Job": From Windows Zero-Day to EDR Bypass and Backdoor Deployment
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. Basic Information
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Severity:&lt;/strong&gt; Critical&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Article Title:&lt;/strong&gt; Shattering the Dream: When a Job Offer Becomes a Zero-Day Attack&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publisher:&lt;/strong&gt; Check Point Research&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Publication Date:&lt;/strong&gt; 2026-08-11&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Original Source:&lt;/strong&gt; &lt;a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" rel="noopener noreferrer"&gt;https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Sources:&lt;/strong&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/" rel="noopener noreferrer"&gt;https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820" rel="noopener noreferrer"&gt;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Related Entities:&lt;/strong&gt; Lazarus Group, Operation Dream Job, MISTPEN, Troy, FudModule, ForestTiger, RelayShell, CVE-2026-68820, Windows 11, Microsoft Graph, OneDrive, Roundcube&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  2. Executive Summary
&lt;/h2&gt;

&lt;p&gt;This is a multi-stage attack. It sends fake job offer PDFs to defense and aerospace personnel, uses DLL side-loading to launch MISTPEN, gains SYSTEM privileges and bypasses EDR using the Windows 11 kernel zero-day CVE-2026-68820, and finally deploys the ForestTiger backdoor.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Attack Flow
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Chain A: From Job Document to Kernel Compromise
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The attacker sends fake job offers and interview invites to the target with an encrypted ZIP file.&lt;/li&gt;
&lt;li&gt;A signed PDF viewer inside the ZIP side-loads a malicious &lt;code&gt;libmupdf.dll&lt;/code&gt; file.&lt;/li&gt;
&lt;li&gt;The DLL decrypts the payload (which is also an encrypted PDF), shows a decoy document, and runs MISTPEN in memory.&lt;/li&gt;
&lt;li&gt;MISTPEN uses Microsoft Graph API and OneDrive as C2 servers to fetch AES-encrypted tasks.&lt;/li&gt;
&lt;li&gt;It adds reconnaissance and persistence modules to collect host and environment information.&lt;/li&gt;
&lt;li&gt;An LPE loader exploits CVE-2026-68820 (&lt;code&gt;afd.sys&lt;/code&gt; race condition / use-after-free) to get kernel read and write primitives.&lt;/li&gt;
&lt;li&gt;It loads FudModule to inject code into SYSTEM processes and modify security features, which reduces EDR visibility.&lt;/li&gt;
&lt;li&gt;It deploys the final-stage ForestTiger backdoor.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Chain B: Troy via Fake Websites
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;The target is lured to a fake website or search result that mimics a legitimate company to download &lt;code&gt;SecurityPDF&lt;/code&gt; and a crafted PDF.&lt;/li&gt;
&lt;li&gt;It extracts content using identification strings in the PDF, XOR-decrypts the executable, and saves it as &lt;code&gt;%TEMP%\new.exe&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;It reflectively loads the Troy backdoor.&lt;/li&gt;
&lt;li&gt;Troy uses 17 types of commands for device and process recon, file sending and receiving, archiving, process termination, in-memory DLL injection, and beacon setting changes.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Chain C: Roundcube Relay Infrastructure
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;It logs into Roundcube using credentials that are likely stolen.&lt;/li&gt;
&lt;li&gt;It exploits CVE-2025-49113, an authenticated PHP object deserialization vulnerability.&lt;/li&gt;
&lt;li&gt;It places the RelayShell web shell and uses at least 17 Roundcube servers as relays.&lt;/li&gt;
&lt;li&gt;It uses the compromised Roundcube and WordPress servers as C2 and traffic relays.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  4. Attacker Position and Execution Locations
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Initial delivery and C2 operations happen from attacker-controlled infrastructure, OneDrive, and compromised web servers.&lt;/li&gt;
&lt;li&gt;DLL side-loading, MISTPEN, Troy, and the LPE loader run on the victim's Windows device.&lt;/li&gt;
&lt;li&gt;CVE-2026-68820 and FudModule run in the Windows kernel and use SYSTEM privileges.&lt;/li&gt;
&lt;li&gt;RelayShell runs on compromised Roundcube servers.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Visibility for Victims and Administrators
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Users see a job offer PDF and a normal decoy document, so they do not notice any failure.&lt;/li&gt;
&lt;li&gt;Administrators see a signed viewer load a non-standard DLL, followed by Graph and OneDrive network traffic.&lt;/li&gt;
&lt;li&gt;After EDR is disabled, subsequent processes and file operations may disappear. Correlating Windows events, proxies, and cloud audits is important.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  6. Success and Failure Conditions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Success Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The target extracts the ZIP file and runs the included viewer.&lt;/li&gt;
&lt;li&gt;The executable and malicious DLL exist in the same folder.&lt;/li&gt;
&lt;li&gt;The target Windows 11 build has not patched CVE-2026-68820.&lt;/li&gt;
&lt;li&gt;Network traffic to Microsoft Graph and OneDrive is allowed.&lt;/li&gt;
&lt;li&gt;Security products do not block kernel driver operations or SYSTEM process injection.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Failure Conditions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Isolating attached or downloaded ZIP files, or blocking execution via Mark-of-the-Web and application control.&lt;/li&gt;
&lt;li&gt;Detecting DLL search order abuse and blocking DLL loading from untrusted folders.&lt;/li&gt;
&lt;li&gt;CVE-2026-68820 is patched, so LPE fails.&lt;/li&gt;
&lt;li&gt;Blocking abnormal app and device traffic to the Graph API.&lt;/li&gt;
&lt;li&gt;EDR self-defense, kernel integrity, and driver load controls block modifications.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  7. What Happens on Success
&lt;/h2&gt;

&lt;p&gt;Device reconnaissance, persistence, file operations, and C2 communication become possible, along with SYSTEM privilege escalation, reduced EDR visibility, and additional backdoor deployment. Defense and aerospace design data and credentials are targets, but public articles do not prove successful data theft on every target.&lt;/p&gt;

&lt;h2&gt;
  
  
  8. Observable Logs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Email:&lt;/strong&gt; Job and hiring themes, encrypted ZIP files, external senders, and unknown recruiters.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Proxy/SWG/DNS:&lt;/strong&gt; Fake company websites, non-business app traffic to Graph API and OneDrive, and periodic traffic to compromised Roundcube and WordPress servers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint/EDR:&lt;/strong&gt; Signed PDF viewer loading &lt;code&gt;libmupdf.dll&lt;/code&gt;, in-memory MISTPEN and Troy, &lt;code&gt;%TEMP%\new.exe&lt;/code&gt;, abnormal I/O targeting &lt;code&gt;afd.sys&lt;/code&gt;, SYSTEM process injection, and modification of EDR services and callbacks.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Identity/IdP:&lt;/strong&gt; Abnormal logins to Roundcube and use of stolen credentials. Whether Graph usage requires an organization ID depends on the configuration.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SaaS/Cloud:&lt;/strong&gt; Suspicious object downloads on OneDrive, low-frequency periodic access to the Graph API, and unknown clients or apps.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Network:&lt;/strong&gt; AES-encrypted beacons, relays via compromised web servers, and endpoint connections to Roundcube and WordPress servers that are unrelated to normal business.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  9. Attack Success Determination
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Contact Only:&lt;/strong&gt; Receiving a job email or visiting a URL.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User Action:&lt;/strong&gt; Extracting the ZIP file and opening the PDF viewer.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Execution:&lt;/strong&gt; Loading the malicious DLL and executing MISTPEN or Troy in memory.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malware Success:&lt;/strong&gt; Fetching C2 tasks, sending recon results, and creating persistence modules.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privilege Compromise:&lt;/strong&gt; Obtaining a SYSTEM token after CVE-2026-68820, loading FudModule, and injecting into a SYSTEM process.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data Theft &amp;amp; Further Compromise:&lt;/strong&gt; Creating archives and transferring them outward, continuous beacons from ForestTiger, or using additional stolen credentials.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  10. Investigation Playbook
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trigger:&lt;/strong&gt; PDF viewer abnormal DLL loading, suspected OneDrive C2, SYSTEM process injection, and sudden disappearance of EDR telemetry.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Initial Check:&lt;/strong&gt; Preserve the hashes and sources of the email, ZIP, executable, DLL, and PDF, and determine the exact execution time.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endpoint:&lt;/strong&gt; Investigate Prefetch, Amcache, Shimcache, MFT, memory, driver and kernel events, &lt;code&gt;%TEMP%&lt;/code&gt;, and persistence locations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auth &amp;amp; Cloud:&lt;/strong&gt; Check Graph and OneDrive audits, OAuth apps, Roundcube authentication, and cross-account use of the same credentials.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Subsequent Actions:&lt;/strong&gt; Search for ForestTiger, archives, internal recon, connections to additional hosts, and web shells or relays.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Containment:&lt;/strong&gt; Isolate the endpoint, update Windows, revoke related accounts and tokens, block Graph paths, and isolate or rebuild compromised web servers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Confidence Levels:&lt;/strong&gt; Targeted / User Executed / Initial Payload Confirmed / Kernel LPE Confirmed / Defense Evasion Confirmed / Exfiltration Confirmed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  11. Defense and Detection Ideas
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single Event:&lt;/strong&gt; PDF viewer loading &lt;code&gt;libmupdf.dll&lt;/code&gt; from the same folder, creation of &lt;code&gt;%TEMP%\new.exe&lt;/code&gt;, and unknown processes accessing the Graph API.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Timeline Correlation:&lt;/strong&gt; Receiving a job ZIP -&amp;gt; launching the viewer -&amp;gt; loading the DLL -&amp;gt; OneDrive communication -&amp;gt; kernel anomaly -&amp;gt; missing EDR telemetry.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunting:&lt;/strong&gt; Non-standard DLLs loaded by signed document viewers, non-browser processes using the Graph API, injection into SYSTEM processes, and new PHP files in Roundcube web roots.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log Gaps:&lt;/strong&gt; Missing DLL image loads, kernel I/O, Graph audits, EDR self-defense, and web server FIM make it hard to break the attack chain.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Priority Actions:&lt;/strong&gt; Patch CVE-2026-68820, isolate attachments, use application control, monitor Graph, enable EDR self-defense, update Roundcube, and rotate credentials.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  12. Facts / Inference / Hypothesis
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Facts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Check Point confirmed active exploitation of CVE-2026-68820 in Operation Dream Job targeting defense and aerospace sectors.&lt;/li&gt;
&lt;li&gt;MISTPEN used Microsoft Graph and OneDrive as its C2.&lt;/li&gt;
&lt;li&gt;CVE-2026-68820 uses a race condition / use-after-free in &lt;code&gt;afd.sys&lt;/code&gt; to move from kernel read/write to SYSTEM privileges.&lt;/li&gt;
&lt;li&gt;FudModule and ForestTiger were used in later stages.&lt;/li&gt;
&lt;li&gt;Troy has 17 remote control commands.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Inference
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Missing logs after EDR modification may mean defense evasion rather than "no activity," so network, Windows, and cloud logs should be used to fill the gaps.&lt;/li&gt;
&lt;li&gt;Global defense, heavy industry, and aerospace supply chains also match these job themes and engineering user profiles.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Hypothesis
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Combining OneDrive object names, API call frequency, and parent processes can reduce false positives with legitimate OneDrive usage.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  13. MITRE ATT&amp;amp;CK Mapping
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;High Confidence:&lt;/strong&gt; T1566.001 Spearphishing Attachment, T1204.002 Malicious File, T1574.002 DLL Side-Loading, T1055 Process Injection, T1068 Exploitation for Privilege Escalation, T1562.001 Impair Defenses, T1105 Ingress Tool Transfer, T1071.001 Web Protocols, T1102.002 Web Service: Bidirectional Communication.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Medium Confidence:&lt;/strong&gt; T1547 (persistence details depend on the module), T1560 Archive Collected Data, T1041 Exfiltration Over C2 Channel.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  14. Unknowns and Further Investigation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Initial delivery paths, stolen data, and scope of compromise across all targets.&lt;/li&gt;
&lt;li&gt;Details of the tenants and apps used for Graph and OneDrive C2.&lt;/li&gt;
&lt;li&gt;Specific EDR features disabled by FudModule in each environment.&lt;/li&gt;
&lt;li&gt;Mapping between RelayShell infrastructure and endpoint chains per target.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  15. Impact on Global SOCs and Enterprises
&lt;/h2&gt;

&lt;p&gt;In defense, heavy industry, aerospace, and advanced manufacturing sectors, contacts pretending to be overseas job offers or joint research look very natural. Organizations need to monitor not only Windows updates, but also DLL side-loading of signed apps, Microsoft 365 communication used for C2, and missing EDR telemetry as a single connected chain.&lt;/p&gt;

&lt;h2&gt;
  
  
  16. Summary by Target Audience
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;For SOCs:&lt;/strong&gt; Correlate events in a timeline from the job ZIP to Graph communication, kernel LPE, and missing EDR logs. Do not evaluate OneDrive traffic in isolation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Admins:&lt;/strong&gt; Apply the CVE-2026-68820 patch to Windows 11, and verify application control, Graph audits, and EDR self-defense.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;For Users:&lt;/strong&gt; Do not run encrypted ZIP files or custom PDF viewers from unknown recruiters. Verify job postings through official channels of legitimate companies.&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>threatintel</category>
    </item>
  </channel>
</rss>
