home.social

#credentialharvesting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credentialharvesting, aggregated by home.social.

  1. Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers

    A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.

    Pulse ID: 6abf5aa04b47ef1458d7472a
    Pulse Link: otx.alienvault.com/pulse/6abf5
    Pulse Author: AlienVault
    Created: 2026-10-02 07:17:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CredentialHarvesting #Deploy #OTX #AlienVault

  2. Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers

    A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.

    Pulse ID: 6abf5aa04b47ef1458d7472a
    Pulse Link: otx.alienvault.com/pulse/6abf5
    Pulse Author: AlienVault
    Created: 2026-10-02 07:17:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CredentialHarvesting #Deploy #OTX #AlienVault

  3. Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers

    A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.

    Pulse ID: 6abf5aa04b47ef1458d7472a
    Pulse Link: otx.alienvault.com/pulse/6abf5
    Pulse Author: AlienVault
    Created: 2026-10-02 07:17:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CredentialHarvesting #Deploy #OTX #AlienVault