r/Malware • u/Straight-Practice-99 • 6d ago
Open directory held custom exploit tooling and an EtherHiding loader used against Philippine targets
https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractorThe Hunt.io research team found an open directory staging the tooling behind an intrusion into a Philippine nuclear agency and a naval contractor.
The custom pieces: a stage-1 ELF loader (multi_backupd) that pulls a Mettle stage-2 over TCP, a Go build of the CVE-2024-28000 LiteSpeed Cache exploit with a PHP-parity MT19937 implementation, and five Python scripts abusing ownCloud CVE-2023-49105 via empty-secret pre-signed URLs. Sliver, Metasploit, and Mettle were also staged on the host.
Separately, on the compromised WordPress site we found an active EtherHiding loader. A malicious script pulls ethers.js from public CDNs and reads HTML from an Ethereum smart contract, rendered via the NoChain framework impersonating a Google verification page, then runs a ClickFix-style lure launching mshta. A HuntSQL query on the contract address returned 174 unique IPs hosting the same loader.
Hashes, domains, and full IOCs: https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor
Duplicates
Philippines • u/Minsan • 4d ago
NewsPH Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
cybersecurity • u/Straight-Practice-99 • 6d ago
Threat Actor TTPs & Alerts ☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
redteamsec • u/Straight-Practice-99 • 6d ago
Real-world tradecraft from a recovered intrusion set against a Phillipine Nuclear Agency: forged ownCloud pre-signed URLs, custom MT19937 exploit, low-and-slow exfil
pwnhub • u/Straight-Practice-99 • 6d ago
☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
threatintel • u/Straight-Practice-99 • 6d ago
☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator
netsec • u/Straight-Practice-99 • 6d ago
☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator
InfoSecNews • u/Straight-Practice-99 • 6d ago
☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
NowInCyber • u/Straight-Practice-99 • 6d ago