Skip to content

Executive Summary

An adversary compromised multiple web servers on a shared recreation management platform by registering accounts and uploading webshells, which enabled lateral movement and data exfiltration across three distinct systems. The attack unfolded in four acts: initial noisy exploitation, quiet enumeration, deliberate stealth on a third server involving file manipulation, and a final, highly obfuscated payload injection. During the first phase, the attacker used brute-forcing and various web server probing techniques to gain access, ultimately uploading files with .aspx extensions to access sensitive information stored on the servers. Subsequent acts involved adapting tradecraft for each server, utilizing familiar platform conventions for file naming and attempting stealth measures like timestomping. The final stage involved deploying AI-generated PowerShell and JavaScript scripts that injected a trojan into authentication pages to establish C2 communication.

Facts Only

* On September 10, 2026, the threat actor observed compromising multiple tenants on a shared recreation management software platform.
* The compromise involved registering a member account, uploading a malicious file, and turning it into a webshell.
* Webshells were used to execute malicious activity across three web servers.
* Attackers attempted initial access via brute-forcing logins, IIS 8.3 tilde enumeration, WebDAV write verbs, and upload-handler parser bypasses.
* Access was ultimately gained by registering a new account and uploading files directly to the /documents/MemberFiles/ directory.
* Webshells executed commands that enumerated host information, listed IIS servers, and hunted for cardholder data.
* Enumeration commands included `cmd.exe /c whoami`, `cmd.exe /c hostname`, `cmd.exe /c ipconfig`, and calls to `appcmd.exe` and `powershell.exe`.
* The attacker extracted server-wide settings from `applicationHost.config` and searched configuration files for database connection strings and credentials.
* Payment log files were targeted, including raw webhook logs from a Fortis integration.
* The final stage involved injecting a payload into `/auth/default.aspx` via uploaded PowerShell and JavaScript files which established connections to attacker-controlled infrastructure.

Full Take

The progression of this engagement demonstrates a critical shift in adversary behavior, moving from high-noise brute-force attempts to refined, context-aware reconnaissance, culminating in an AI-assisted, highly stealthy payload delivery. The initial failure to gain access via noisy methods forced the actor toward a more manual approach involving account creation and exploiting upload functions, suggesting that automated scripting was secondary to establishing a foothold. The subsequent acts show a clear pattern of adapting knowledge gained from prior compromises—specifically learning file naming conventions (e.g., using account IDs in filenames) and internal directory structures—to reduce noise on subsequent systems. This adaptability reveals an understanding of defensive responses, where failures lead to incremental, refined attacks rather than complete resets. The use of timestomping and AI-generated scripts in the final act highlights a sophisticated operational maturity, indicating that the focus shifted from simple data theft to establishing persistent, low-observable control over payment systems. This process underscores that detection efficacy relies not just on catching initial exploits, but on analyzing the iterative refinement of tactics post-detection.
BRIDGE QUESTIONS:
What systemic controls existed across the three compromised servers that could have prevented the exploitation of common file upload mechanisms?
How does the operational efficiency gained by adapting attack methods—moving from brute force to file upload to in-memory script injection—change the necessary defensive focus for security operations centers?
If attackers consistently employ AI tools for generating complex payloads, what new detection signatures must be prioritized beyond known IOCs to monitor for emergent, context-aware attack logic?

From the original · Huntress Labs

Acknowledgments: Special thanks to Olly Maxwell for his contributions to this investigation and write-up. Background On September 10, 2026, Huntress observed a threat actor compromising multiple tenants on a shared recreation management software platform using one repeatable trick: register a member account, upload a malicious file, and turn it into a webshell.
Read the full story at huntress.com

Sentinel — Uncertain

Confidence

The text reads like a meticulously reconstructed technical investigation heavily reliant on structured, operationalized details, suggesting AI assistance in synthesizing complex command sequences and narrative structure.

Signals Detected
medium severity: Transition homogeneity; use of technical jargon (command-line manipulation) mixed with narrative flow.
medium severity: Suspiciously balanced 'both sides' framing absence; highly structured, procedural recounting of technical steps without subjective interpretation.
high severity: Argumentative skeleton matching known template patterns (four acts of an attack progression); specific enumeration commands listed almost verbatim.
high severity: Quotes and detailed technical command sequences feel perfectly crafted for narrative flow; explicit mention and formatting of potentially AI-generated script comments.
Human Indicators
The initial acknowledgment of an AI-generated script appears in the final act, which is a self-referential meta-commentary often seen in LLM-assisted writing.
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers | Huntaegis