r/Malware 6d ago

Open directory held custom exploit tooling and an EtherHiding loader used against Philippine targets

https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor

The Hunt.io research team found an open directory staging the tooling behind an intrusion into a Philippine nuclear agency and a naval contractor.

The custom pieces: a stage-1 ELF loader (multi_backupd) that pulls a Mettle stage-2 over TCP, a Go build of the CVE-2024-28000 LiteSpeed Cache exploit with a PHP-parity MT19937 implementation, and five Python scripts abusing ownCloud CVE-2023-49105 via empty-secret pre-signed URLs. Sliver, Metasploit, and Mettle were also staged on the host.

Separately, on the compromised WordPress site we found an active EtherHiding loader. A malicious script pulls ethers.js from public CDNs and reads HTML from an Ethereum smart contract, rendered via the NoChain framework impersonating a Google verification page, then runs a ClickFix-style lure launching mshta. A HuntSQL query on the contract address returned 174 unique IPs hosting the same loader.

Hashes, domains, and full IOCs: https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor

3 Upvotes

Duplicates

Philippines 4d ago

NewsPH Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

146 Upvotes

cybersecurity 6d ago

Threat Actor TTPs & Alerts ☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

19 Upvotes

redteamsec 6d ago

Real-world tradecraft from a recovered intrusion set against a Phillipine Nuclear Agency: forged ownCloud pre-signed URLs, custom MT19937 exploit, low-and-slow exfil

13 Upvotes

pwnhub 6d ago

☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

11 Upvotes

threatintel 6d ago

☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator

8 Upvotes

netsec 6d ago

☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator

26 Upvotes

InfoSecNews 6d ago

☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

0 Upvotes

NowInCyber 6d ago

☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator

1 Upvotes

MalwareAnalysis 6d ago

Custom stage-1 ELF loader and a PHP-parity MT19937 exploit build recovered from an attacker's open directory

1 Upvotes

blueteamsec 6d ago

incident writeup (who and how) ☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

4 Upvotes