CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

ProFTPD 1.3.5: improper access control in the site cpfr and site cpto commands, exploited per AA26-281A and added to CISA KEV 2026-10-08

cve · CVE-2015-3306 single-source-national-cert

Coverage
1
first 2026-10-09 → last 2026-10-09
Latest activity
2026-10-09
Joint advisory: Flax Typhoon-consistent actors spray Exchange and Microsoft 365, steal mail and keep…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, healthcare, manufacturing
Sources cited
6
6 hosts

Defender insights

What each entry about CVE-2015-3306 tells a defender to do, newest first.

2026-10-09NOTABLEexploitedJoint advisory: Flax Typhoon-consistent actors spray Exchange and Microsoft 365, steal mail and keep SoftEther access

Exposure · triage · detection

Story timeline

  1. 2026-10-09AA26-281A: China-linked actors enabled by Integrity Technology Group scan with MicroScan, spray Exchange and Microsoft 365 passwords and steal mail, and five old flaws from the scanner's scripts enter CISA KEV
    active-threatsJoint advisory: Flax Typhoon-consistent actors spray Exchange and Microsoft 365, steal mail and keep SoftEther access
ATT&CK techniques (16 across 8 tactics)

16 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissanceActive Scanning: Vulnerability Scanning
  • Initial AccessExternal Remote Services · Drive-by Compromise · Exploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python · Command and Scripting Interpreter: JavaScript
  • PersistenceExternal Remote Services
  • StealthMasquerading: Rename Legitimate Utilities
  • Credential AccessOS Credential Dumping: DCSync · Brute Force: Password Guessing · Brute Force: Password Spraying
  • CollectionData Staged: Local Data Staging · Email Collection: Remote Email Collection · Archive Collected Data: Archive via Custom Method
  • ExfiltrationAutomated Exfiltration

Reconnaissance TA0043

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Stealth TA0005

T1036.003Masquerading: Rename Legitimate Utilities×1

Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename <code>rundll32.exe</code>). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Credential Access TA0006

T1003.006OS Credential Dumping: DCSync×1

Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1110.001Brute Force: Password Guessing×1

Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Password guessing may or may not take into account the target's policies on password complexity or use policies that may lock accounts out after a number of failed attempts.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1110.003Brute Force: Password Spraying×1

Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Collection TA0009

T1074.001Data Staged: Local Data Staging×1

Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1114.002Email Collection: Remote Email Collection×1

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

T1560.003Archive Collected Data: Archive via Custom Method×1

An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Exfiltration TA0010

T1020Automated Exfiltration×1

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.

Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗

Entries about ProFTPD 1.3.5: improper access control in the site cpfr and site cpto commands, exploited per AA26-281A and added to CISA KEV 2026-10-08 (1)

2026-10-09 · view entry permalink →

NOTABLECVE-2015-3306 +7exploitedNATOA2

AA26-281A: China-linked actors enabled by Integrity Technology Group scan with MicroScan, spray Exchange and Microsoft 365 passwords and steal mail, and five old flaws from the scanner's scripts enter CISA KEV

The FBI, CISA, NSA, NCSC UK and partners from Australia, Canada, Japan, New Zealand and Spain describe Integrity Technology Group as a China-based company with links to the Chinese government that builds and sells cyber tools, hosts infrastructure and compromises networks; the actors it enables use tactics consistent with Flax Typhoon, Ethereal Panda and Red Juliett, among others (FBI IC3, AA26-281A, 2026-10-08). The Justice Department says the FBI seized the domains of MicroScan and the FishHub phishing platform, both operated by Integrity Tech (U.S. Department of Justice, 2026-10-08). Victims include U.S. government services, other critical sectors and organisations in Southeast Asia, Africa and North America; the advisory names no Swiss victim (FBI IC3, AA26-281A, 2026-10-08).

The chain starts with open-source scanners and MicroScan, a Python-based web application of 1,300-plus scripts, used since at least 2017 (FBI IC3, AA26-281A, 2026-10-08). Initial access has mostly come since January 2021 from command-line exploit utilities, and additionally from a cross-site-scripting payload that overlays a login form and offers a ZIP holding an executable that starts a process named like the Windows DiagTrack service (FBI IC3, AA26-281A, 2026-10-08). The actors spray and guess passwords with the EBurst tool against Exchange and Microsoft 365 (ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, ActiveSync) (FBI IC3, AA26-281A, 2026-10-08). Persistence is a SoftEther VPN client, often named conhost.exe or dllhost.exe, which endpoint tools are less likely to flag (FBI IC3, AA26-281A, 2026-10-08). Collection uses a PHP bot and a Linux utility that read mail through Exchange Web Services and Microsoft 365 with application client, tenant and secret values, and a DCSync tool that replicates directory data from a domain controller; mail was stolen from government, law-enforcement and healthcare bodies in Southeast Asia (FBI IC3, AA26-281A, 2026-10-08).

Appendix B lists eight successfully exploited CVEs recovered from MicroScan's scripts: ProFTPD 1.3.5, ISC BIND 9.x, Apache Struts 2.3.19 to 2.3.28, ONLYOFFICE DocumentServer 5.1.5 through 5.6.2 and Strapi up to 4.5.5, plus GNU Bash through 4.3, Pulse Connect Secure and GitLab from 11.9 (FBI IC3, AA26-281A, 2026-10-08); CISA added the first five to its catalogue on 2026-10-08 (CISA KEV catalogue, 2026-10-08). Apache names Struts 2.3.20.3, 2.3.24.3 and 2.3.28.1 as fixed (Apache Struts, 2021-02-13) and Strapi names 4.8.0 (Strapi, 2023-04-17).

Triage: conhost.exe and dllhost.exe are legitimate Windows names, so the file's path, signature and network behaviour separate a downloaded SoftEther client from the system binary (FBI IC3, AA26-281A, 2026-10-08).

The activity in the advisory is reported to be consistent with campaigns also publicly known as Flax Typhoon, Ethereal Panda and Red Juliett among others.

NCSC UK 2026-10-08

Integrity Tech has contracts with the PRC government.

U.S. Department of Justice 2026-10-08

Network defenders should include these interfaces when defending against EBurst.

FBI, CISA, NSA, NCSC UK and partners (joint advisory AA26-281A) 2026-10-08

Builds on: A PRC state-enablement platform leasing commercial proxy subscriptions as anonymisation…

threat09 Oct 03:43Zsingle-source · national CERTOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • cisa.gov1 (17%)
  • cwiki.apache.org1 (17%)
  • ic3.gov1 (17%)
  • justice.gov1 (17%)
  • ncsc.gov.uk1 (17%)
  • strapi.io1 (17%)