CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2incident

A self-registered account and an unrestricted upload turn a shared recreation-management platform into a webshell and card-data foothold, and the actor returns after cleanup

Huntress: a member account plus an .aspx upload gave an attacker webshells on three servers and a hunt for card data

Analysis

Huntress observed on 2026-09-10 a threat actor compromising multiple tenants of a shared recreation-management platform with one repeatable method: "register a member account, upload a malicious file, and turn it into a webshell" (Huntress, 2026-09-30). Huntress's summary calls the three compromised web servers municipal and says the actor aimed to steal payment data; the post names neither the platform vendor nor a CVE. On the first server the actor spent roughly six hours on failed unauthenticated attempts (login brute force, IIS 8.3 tilde enumeration, WebDAV verbs, upload-handler bypasses, forced browsing); what worked was registering an account and uploading 14 files into the member-files directory, the .aspx ones as webshells (Huntress, 2026-09-30).

Through the webshells, run from the IIS worker process, the actor enumerated the host and IIS sites, read configuration files for connection strings and keys, connected to the database with the harvested SQL credentials, searched files for card data and read a payment gateway's plain-text webhook logs to extract card numbers, expiry dates and card verification codes (Huntress, 2026-09-30). On a third server it uploaded five webshells, copied them under names resembling site assets, set their timestamps to match web.config and probed the payment-module folders (Huntress, 2026-09-30).

When that server was put back into production prematurely, the actor returned with the same registered account, re-uploaded webshells and appended an obfuscated loader to a jQuery file that the authentication page loads, intending to turn every browser that loads the page into an encrypted command client that evaluates pushed code and harvests credentials in real time (Huntress, 2026-09-30). Huntress deduces from a Simplified Chinese locale in a PowerShell user-agent that the actor is most likely based in China, and says script comments suggest AI-generated code. It does not state how many cards were exposed or whether any data left the servers.

Exposure: any web platform that lets an anonymous visitor self-register and then upload files into a directory served by IIS with script execution enabled; with no vendor or CVE named, check whether a member upload directory accepts .aspx files and executes them (Huntress, 2026-09-30).

Triage: legitimate member uploads of documents and images land in the same directory; the discriminator is a script-capable extension there, or a file there that is requested directly and then spawns child processes (Huntress, 2026-09-30).

Cited evidence

register a member account, upload a malicious file, and turn it into a webshell.

When the third server was put back into production prematurely, the threat actor returned with a vengeance.

creating their own account on the platform and finding a flaw in the upload function

Huntress 2026-09-30

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.