CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Spring Batch

product · product:spring-batch single-source

Coverage
1
first 2026-10-09 → last 2026-10-09
Latest activity
2026-10-09
ReliaQuest: AI agents took a Tomcat server to SYSTEM in under a day through an exposed job-submission feature
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
1
1 hosts

Defender insights

What each entry about Spring Batch tells a defender to do, newest first.

2026-10-09NOTABLEReliaQuest: AI agents took a Tomcat server to SYSTEM in under a day through an exposed job-submission feature

Exposure · detection

Story timeline

  1. 2026-10-09ReliaQuest: LLM-driven agents run most of an intrusion through one unauthenticated Spring Batch job-submission feature on Apache Tomcat, from in-process JavaScript to SYSTEM in under 24 hours
    active-threatsReliaQuest: AI agents took a Tomcat server to SYSTEM in under a day through an exposed job-submission feature

Hunting pivots

Releases covered
Spring Batch
ATT&CK techniques (10 across 7 tactics)

10 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: JavaScript
  • PersistenceCreate Account: Local Account · Server Software Component: SQL Stored Procedures
  • Privilege EscalationAccess Token Manipulation: Token Impersonation/Theft
  • StealthIndicator Removal: File Deletion · Access Token Manipulation: Token Impersonation/Theft · Deobfuscate/Decode Files or Information
  • Credential AccessOS Credential Dumping: Security Account Manager · Unsecured Credentials: Credentials In Files
  • Command and ControlIngress Tool Transfer

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Persistence TA0003

T1136.001Create Account: Local Account×1

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

T1505.001Server Software Component: SQL Stored Procedures×1

Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are code that can be saved and reused so that database users do not waste time rewriting frequently used SQL queries. Stored procedures can be invoked via SQL statements to the database using the procedure name or via defined events (e.g. when a SQL server application is started/restarted).

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Privilege Escalation TA0004

T1134.001Access Token Manipulation: Token Impersonation/Theft×1

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Stealth TA0005

T1070.004Indicator Removal: File Deletion×1

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

T1134.001Access Token Manipulation: Token Impersonation/Theft×1

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Credential Access TA0006

T1003.002OS Credential Dumping: Security Account Manager×1

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-09/reliaquest-llm-agents-spring-batch-tomcat-nashorn-system · ATT&CK page ↗

Entries about Spring Batch (1)

2026-10-09 · view entry permalink →

NOTABLENATOB2

ReliaQuest: LLM-driven agents run most of an intrusion through one unauthenticated Spring Batch job-submission feature on Apache Tomcat, from in-process JavaScript to SYSTEM in under 24 hours

ReliaQuest says the attacker needed no zero-day and no new malware: an internet-facing Apache Tomcat application used Spring Batch, in which a task definition names the code to run, and accepted and ran task descriptions without a login (ReliaQuest, 2026-10-07). The decisive step was submitting tasks that invoked Nashorn, the JavaScript engine in the application's Java environment, so the code ran inside the application with its account privileges and created no child process until a shell was spawned later; results came back through deliberately triggered error messages, in fixed 1,800-byte chunks reassembled over hundreds of requests (ReliaQuest, 2026-10-07). The application's configuration files held plaintext credentials with SQL Server sysadmin rights; the attacker enabled xp_cmdshell, found SeImpersonatePrivilege, uploaded PrintSpoofer and GodPotato in base64 fragments through the same channel and reached SYSTEM when the first tool failed on file permissions and the second worked (ReliaQuest, 2026-10-07). With SYSTEM it saved the SAM, SYSTEM and SECURITY registry hives for offline extraction, created two local administrator accounts and deleted only one, and removed artifacts after the actions that produced them (ReliaQuest, 2026-10-07).

The agent-driven reading rests on a live, unauthenticated Cairn agent-orchestration dashboard (an open-source platform for coordinating AI agents; no source says whether it is the Cairn exploitation engine of Gambit Security's reporting, and it is not Talos' CAIRN toolkit) on the address that sent the opening requests, on command timing (roughly half the gaps five seconds or less), on job names that tracked read offsets and upload parts without a gap, on machine-readable pipe-delimited output, and on payloads whose next version repaired the fault the previous one returned; ReliaQuest says no single indicator establishes it and that it could not determine how many agents ran, which model drove them or how much a person approved (ReliaQuest, 2026-10-07). Submission and collection ran from different addresses, so blocking the submitting address alone would not have stopped retrieval, and the tool assembly is not a fingerprint for any group (ReliaQuest, 2026-10-07).

The attacker entered through an internet-facing application feature on an Apache Tomcat server that accepted and ran task descriptions without requiring a login.

No single one establishes that an LLM agent was involved; a human directing scripts could produce several of them.

ReliaQuest Threat Research 2026-10-07

Builds on: Three off-the-shelf AI agents ran almost the entire card-theft campaign, from discovery to…

threat09 Oct 03:45Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • reliaquest.com1 (100%)