HomeCyber BalkansAttacker Joins Parks and Recreation Platform to Plant Webshells and Seek Card...

Attacker Joins Parks and Recreation Platform to Plant Webshells and Seek Card Data

Published on

spot_img

Security researchers from Huntress have unveiled a sophisticated multi-stage intrusion that targeted three web servers belonging to a prominent recreation management platform utilized by local municipalities and park organizations. This incident showcases the evolving tactics employed by threat actors, who managed to implant webshells and aim for the extraction of payment card data from the compromised environment.

The malicious activity was first detected on September 10, 2026. Initially, the attacker engaged in noisy attempts to breach the first server over a span of approximately six hours. They employed a series of unauthenticated techniques, including brute-force attacks on both the admin and member login pages, IIS 8.3 tilde enumeration, abuse of the WebDAV method, and upload-handler parser bypasses. Despite the range of strategies attempted, none proved effective against the server’s defenses.

Turning to a more straightforward approach, the attacker registered a new member account on the platform. Exploiting the file upload feature allocated for members, they succeeded in uploading .aspx webshells to a publicly accessible directory within the system. This tactic allowed them to conduct reconnaissance on the server effectively, pulling the global IIS configuration file while also combing through web.config and C# source files in search of sensitive data such as connection strings, passwords, and API keys.

With obtaining the database credentials, the attacker’s motives crystallized. Their focus shifted towards identifying card-related strings, payment provider names, and eventually extracting sensitive data from webhook logs associated with payment integrations. This extraction revealed critical information, including card numbers, expiry dates, and CVVs—data that could be leveraged for illicit financial gain.

Subsequently, the same approach was executed on a second server. However, this time the attacker operated with significantly less noise, which likely hampered detection efforts until Huntress’s Security Operations Center (SOC) intervened and eliminated the webshells that had been planted.

The attacker’s change of strategy became evident on the third server. In a more insidious move, they relocated their webshells to seemingly innocuous locations, naming the files as css_bundle.aspx and webresource.aspx. Additionally, they manipulated the metadata of these files to appear as if they were legitimate components of the website, a technique known as “timestomping.” Though they attempted to introduce further copies into the payment module directories, this effort fell short.

The most alarming phase of the breach occurred when the compromised third server was reinstated into a production environment before undergoing complete security remediation. Armed with the account they had previously registered, the attacker executed PowerShell “planter” scripts to append an obfuscated dropper to an authentic jQuery file that was integral to the platform’s authentication page. This trojanized script proceeded to pull a second-stage browser agent hosted on Cloudflare Workers, creating encrypted WebRTC and WebSocket channels designed specifically to harvest user credentials in real time.

An additional layer of analysis conducted by Huntress revealed that a zh-CN locale present in the PowerShell user-agent string hints that the attacker is likely based in China. Furthermore, researchers speculate that AI-generated scripts were utilized throughout the entire attack lifecycle. The high volume of initial access attempts, combined with the structure of the final PowerShell scripts, revealed comments that appeared to incorporate fragments of instructions imparted by AI, suggesting a sophisticated level of automation and planning in the attack.

As the cyber threat landscape continues to evolve, this incident underscores the importance of robust security protocols and monitoring systems for organizations, particularly those handling sensitive payment information. The research findings from Huntress serve as a crucial reminder for municipalities and park organizations to enhance their defenses and remain vigilant against increasingly audacious cybercriminal tactics.

Source link

Latest articles

OpenAI Blames Moonshot AI for Coordinated Model Distillation

OpenAI Disrupts Alleged Coordinated Campaign by Moonshot AI to Extract Model Data In a recent...

Attackers Exploit ChatGPT Feature and ClickFix to Deploy RAT

Cybercriminals have developed a sophisticated malware campaign that combines the legitimate features of ChatGPT...

Cyber Briefing – 2026.09.30 – CyberMaterial

Cybersecurity Landscape: Key Developments and Threats In the realm of cybersecurity, significant incidents and updates...

Accountability for AI Agents Handling Sensitive Data Webinar

George Gerchow: A Leader in Cybersecurity and AI Governance Chief Security Officer, Bedrock Data George Gerchow...

More like this

OpenAI Blames Moonshot AI for Coordinated Model Distillation

OpenAI Disrupts Alleged Coordinated Campaign by Moonshot AI to Extract Model Data In a recent...

Attackers Exploit ChatGPT Feature and ClickFix to Deploy RAT

Cybercriminals have developed a sophisticated malware campaign that combines the legitimate features of ChatGPT...

Cyber Briefing – 2026.09.30 – CyberMaterial

Cybersecurity Landscape: Key Developments and Threats In the realm of cybersecurity, significant incidents and updates...