Executive Summary
Facts Only
* On September 10, 2026, the threat actor observed compromising multiple tenants on a shared recreation management software platform.
* The compromise involved registering a member account, uploading a malicious file, and turning it into a webshell.
* Webshells were used to execute malicious activity across three web servers.
* Attackers attempted initial access via brute-forcing logins, IIS 8.3 tilde enumeration, WebDAV write verbs, and upload-handler parser bypasses.
* Access was ultimately gained by registering a new account and uploading files directly to the /documents/MemberFiles/ directory.
* Webshells executed commands that enumerated host information, listed IIS servers, and hunted for cardholder data.
* Enumeration commands included `cmd.exe /c whoami`, `cmd.exe /c hostname`, `cmd.exe /c ipconfig`, and calls to `appcmd.exe` and `powershell.exe`.
* The attacker extracted server-wide settings from `applicationHost.config` and searched configuration files for database connection strings and credentials.
* Payment log files were targeted, including raw webhook logs from a Fortis integration.
* The final stage involved injecting a payload into `/auth/default.aspx` via uploaded PowerShell and JavaScript files which established connections to attacker-controlled infrastructure.
Full Take
The progression of this engagement demonstrates a critical shift in adversary behavior, moving from high-noise brute-force attempts to refined, context-aware reconnaissance, culminating in an AI-assisted, highly stealthy payload delivery. The initial failure to gain access via noisy methods forced the actor toward a more manual approach involving account creation and exploiting upload functions, suggesting that automated scripting was secondary to establishing a foothold. The subsequent acts show a clear pattern of adapting knowledge gained from prior compromises—specifically learning file naming conventions (e.g., using account IDs in filenames) and internal directory structures—to reduce noise on subsequent systems. This adaptability reveals an understanding of defensive responses, where failures lead to incremental, refined attacks rather than complete resets. The use of timestomping and AI-generated scripts in the final act highlights a sophisticated operational maturity, indicating that the focus shifted from simple data theft to establishing persistent, low-observable control over payment systems. This process underscores that detection efficacy relies not just on catching initial exploits, but on analyzing the iterative refinement of tactics post-detection.
BRIDGE QUESTIONS:
What systemic controls existed across the three compromised servers that could have prevented the exploitation of common file upload mechanisms?
How does the operational efficiency gained by adapting attack methods—moving from brute force to file upload to in-memory script injection—change the necessary defensive focus for security operations centers?
If attackers consistently employ AI tools for generating complex payloads, what new detection signatures must be prioritized beyond known IOCs to monitor for emergent, context-aware attack logic?
From the original · Huntress Labs
Acknowledgments: Special thanks to Olly Maxwell for his contributions to this investigation and write-up. Background On September 10, 2026, Huntress observed a threat actor compromising multiple tenants on a shared recreation management software platform using one repeatable trick: register a member account, upload a malicious file, and turn it into a webshell.Read the full story at huntress.com
Sentinel — Uncertain
The text reads like a meticulously reconstructed technical investigation heavily reliant on structured, operationalized details, suggesting AI assistance in synthesizing complex command sequences and narrative structure.
