CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Recreation-management platform webshell intrusions (September 2026)

incident · incident:recreation-platform-webshell-municipal-tenants-2026-09 single-source

Huntress-observed intrusions from 2026-09-10 against three web servers of a shared recreation-management platform: a self-registered member account used to upload .aspx webshells, a hunt for database credentials and card data, and a return with the same account that planted a credential-harvesting script in the login page's jQuery file (Huntress, 2026-09-30).

Coverage
1
first 2026-10-04 → last 2026-10-04
Latest activity
2026-10-04
Huntress: a member account plus an .aspx upload gave an attacker webshells on three servers and a hunt for…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector
Sources cited
1
1 hosts

Defender insights

What each entry about Recreation-management platform webshell intrusions (September 2026) tells a defender to do, newest first.

2026-10-04NOTABLEHuntress: a member account plus an .aspx upload gave an attacker webshells on three servers and a hunt for card data

Triage · detection

Story timeline

  1. 2026-10-04A self-registered account and an unrestricted upload turn a shared recreation-management platform into a webshell and card-data foothold, and the actor returns after cleanup
    active-threatsHuntress: a member account plus an .aspx upload gave an attacker webshells on three servers and a hunt for card data

Hunting pivots

ATT&CK techniques (12 across 7 tactics)

12 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell
  • PersistenceServer Software Component: Web Shell
  • StealthMasquerading: Match Legitimate Resource Name or Location · Indicator Removal: Timestomp
  • Credential AccessInput Capture: Web Portal Capture · Unsecured Credentials: Credentials In Files
  • DiscoverySystem Owner/User Discovery · System Information Discovery · File and Directory Discovery
  • CollectionData from Local System · Input Capture: Web Portal Capture

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

T1059.003Command and Scripting Interpreter: Windows Command Shell×1

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Stealth TA0005

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

T1070.006Indicator Removal: Timestomp×1

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Credential Access TA0006

T1056.003Input Capture: Web Portal Capture×1

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Discovery TA0007

T1033System Owner/User Discovery×1

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

T1056.003Input Capture: Web Portal Capture×1

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.

Evidence: 2026-10-04/recreation-platform-upload-webshell-card-data-foothold · ATT&CK page ↗

Entries about Recreation-management platform webshell intrusions (September 2026) (1)

2026-10-04 · view entry permalink →

NOTABLENATOB2

A self-registered account and an unrestricted upload turn a shared recreation-management platform into a webshell and card-data foothold, and the actor returns after cleanup

Huntress observed on 2026-09-10 a threat actor compromising multiple tenants of a shared recreation-management platform with one repeatable method: "register a member account, upload a malicious file, and turn it into a webshell" (Huntress, 2026-09-30). Huntress's summary calls the three compromised web servers municipal and says the actor aimed to steal payment data; the post names neither the platform vendor nor a CVE. On the first server the actor spent roughly six hours on failed unauthenticated attempts (login brute force, IIS 8.3 tilde enumeration, WebDAV verbs, upload-handler bypasses, forced browsing); what worked was registering an account and uploading 14 files into the member-files directory, the .aspx ones as webshells (Huntress, 2026-09-30).

Through the webshells, run from the IIS worker process, the actor enumerated the host and IIS sites, read configuration files for connection strings and keys, connected to the database with the harvested SQL credentials, searched files for card data and read a payment gateway's plain-text webhook logs to extract card numbers, expiry dates and card verification codes (Huntress, 2026-09-30). On a third server it uploaded five webshells, copied them under names resembling site assets, set their timestamps to match web.config and probed the payment-module folders (Huntress, 2026-09-30).

When that server was put back into production prematurely, the actor returned with the same registered account, re-uploaded webshells and appended an obfuscated loader to a jQuery file that the authentication page loads, intending to turn every browser that loads the page into an encrypted command client that evaluates pushed code and harvests credentials in real time (Huntress, 2026-09-30). Huntress deduces from a Simplified Chinese locale in a PowerShell user-agent that the actor is most likely based in China, and says script comments suggest AI-generated code. It does not state how many cards were exposed or whether any data left the servers.

Exposure: any web platform that lets an anonymous visitor self-register and then upload files into a directory served by IIS with script execution enabled; with no vendor or CVE named, check whether a member upload directory accepts .aspx files and executes them (Huntress, 2026-09-30).

Triage: legitimate member uploads of documents and images land in the same directory; the discriminator is a script-capable extension there, or a file there that is requested directly and then spawns child processes (Huntress, 2026-09-30).

register a member account, upload a malicious file, and turn it into a webshell.

When the third server was put back into production prematurely, the threat actor returned with a vengeance.

creating their own account on the platform and finding a flaw in the upload function

Huntress 2026-09-30
incident04 Oct 04:40Zsingle-sourceOpen finding →
Sources: Huntress

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • huntress.com1 (100%)