Last Updated On

CCTTII--22002266--11000099
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

SonicWall Intrusions And AhsayCBS Backup Breaches Weaponize Enterprise Infrastructure Systems

Adversaries are actively exploiting critical vulnerabilities in AhsayCBS backup platforms and probing SonicWall SMA 1000 remote access appliances across global enterprise networks. Threat actors chain AhsayCBS flaws CVE-2026-105133 and CVE-2026-105134 to execute arbitrary commands as SYSTEM, dropping JSP web shells and evasive cryptominers that halt when administrators inspect processes. Crucially, AhsayCBS version 10.3.4 remains vulnerable despite earlier remediation notices.

Simultaneously, honeypot sensors captured exploitation probes targeting SonicWall SMA 1000 flaw CVE-2026-102255, where crafted HTTP OPTIONS requests abuse reverse proxy pathways to access internal CouchDB databases on port 5984. Citrix also warned administrators to patch critical NetScaler memory overflow flaw CVE-2026-107406 across SAML configured environments, while Cisco resolved root execution flaw CVE-2026-76471 on Nexus switching hardware.

Compounding these threats, an international government coalition disrupted state linked contractor Integrity Technology Group, seizing infrastructure supporting MicroScan reconnaissance and FishHub phishing frameworks. Defensive teams must immediately isolate exposed AhsayCBS consoles, apply SonicWall hotfixes 12.4.3-03670 and 12.5.0-03082, upgrade NetScaler builds, and purge unauthorized VPN persistence mechanisms.

#CyberSecurity #ThreatIntelligence #VulnerabilityManagement #AhsayCBS #SonicWall #Citrix #Cisco #InfoSec

10

CVSS Score

50

IOC Count

20

Source Count

82

Confidence Score

CVEs

CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894, CVE-2026-76465, CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-88771, CVE-2026-88772, CVE-2026-88779, CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-105133, CVE-2026-105134, CVE-2026-107406

Actors

Flax Typhoon, Integrity Technology Group, Ethereal Panda, Red Juliett, UAC-0099, UAT-11985

Sectors

Managed Service Providers, Critical Infrastructure, Government, Financial Services, Healthcare, Information Technology, Energy, Aviation, Education, Manufacturing, Telecommunications

Regions

Global, North America, Europe, Asia Pacific, United States, Taiwan, Japan, Poland, Ukraine

Chapter 01 - Executive Overview

Security operations centers face concurrent crises across critical data protection platforms and remote access appliances. Adversaries have transitioned from theoretical vulnerability exploitation to immediate host compromise, weaponizing enterprise backup management systems while aggressively scanning external access appliances.

[+] Active Unauthenticated Remote Code Execution Across AhsayCBS Backup Platforms: Threat actors are actively exploiting a preauthentication vulnerability chain in AhsayCBS backup consoles, identified as CVE-2026-105133 and CVE-2026-105134. Incident responders confirmed intrusions across multiple organizations where attackers bypassed authentication and achieved immediate code execution as SYSTEM. Post exploitation activity deployed JSP web shells, established persistence via deceptive Windows services, and dropped evasion scripts capable of pausing cryptomining processes whenever system administration utilities are opened. Crucially, version 10.3.4 remains vulnerable, invalidating earlier vendor remediation guidance.

[+] In the Wild Probing of SonicWall SMA 1000 Server Side Request Forgery: Sensor networks and honeypot infrastructure confirmed active weaponization attempts targeting CVE-2026-102255, a maximum severity flaw carrying a CVSS score of 10.0 within SonicWall SMA 1000 series appliances. Threat actors submit crafted HTTP OPTIONS requests to the WorkPlace Extraweb interface to force reverse proxy daemons to communicate with internal loopback databases running on port 5984. Systems updated to September baseline firmware remain completely vulnerable, leaving more than four hundred internet accessible installations exposed to configuration extraction.

[+] Urgent Preemptive Patch Warning for Citrix NetScaler SAML Memory Overflow: Citrix disclosed critical vulnerability CVE-2026-107406, carrying a CVSS score of 9.5, impacting NetScaler ADC and Gateway appliances configured as SAML Identity Providers or Service Providers. The flaw enables remote code execution or complete system crashes without requiring authentication. While consulted sources confirm no unmitigated in the wild exploitation at publication time, more than twenty one thousand fingerprinted appliances remain visible online, representing high risk targets given the extensive exploitation of NetScaler appliances during recent campaign cycles.

[+] Judicial Disruption and Multi Agency Action Against Integrity Technology Group: An international coalition spanning the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, and partner foreign intelligence agencies announced the court authorized seizure of seven operational domains tied to Integrity Technology Group. The state linked contractor enabled intrusion clusters known as Flax Typhoon, Ethereal Panda, and Red Juliett. The operators deployed custom MicroScan reconnaissance frameworks and FishHub spear phishing infrastructure against critical infrastructure, energy grids, aviation hubs, and educational institutions globally.

[+] Feature Dependent Root Takeover Exposed on Cisco Nexus Switching Hardware: Cisco released security updates addressing CVE-2026-76471, a critical input validation vulnerability in the NX-API interface of Nexus 3000 and 9000 series switches carrying a CVSS score of 9.8. Unauthenticated attackers transmitting crafted HTTP requests can execute arbitrary commands with root privileges or induce denial of service conditions. Exposure remains strictly dependent on whether the optional NX-API feature is enabled, while Cisco UCS 6300 Fabric Interconnects require low privileged credentials for exploitation.

Chapter 02 - Threat & Exposure Analysis

Adversaries are pursuing parallel intrusion vectors that combine low level memory corruption, web application logic subversion, and massive automated scanning infrastructures.

[+] AhsayCBS Multi Vulnerability Weaponization Mechanics: Exploitation telemetry confirms that adversaries chain authentication bypass flaw CVE-2026-105133 within the checkSysPwd component with command injection flaw CVE-2026-105134 located in the Replication Receiver endpoint. The attack sends crafted requests to the application programming interface, triggering unauthenticated remote command execution under the NT AUTHORITY\SYSTEM context. Attackers immediately establish persistence by dropping JSP web shells into server directories, downloading payloads from Alibaba Cloud storage hosts, and registering malicious Windows services masquerading as legitimate Microsoft Edge update components.

[+] Evasion Engineering within AhsayCBS Cryptomining Campaigns: The post exploitation payload deploys XMRig cryptominers alongside a specialized PowerShell monitoring script named Taskgmr.ps1. The script continuously inspects running processes for Taskmgr, tasklist, and ProcessHacker. Upon identifying these tools, the script immediately halts the malicious mining service to prevent performance degradation from alerting administrators. Once administrative tools terminate, the script restarts mining operations. The campaign also drops a vulnerable WinRing0x64.sys driver to manipulate kernel privileges and bypass endpoint security controls.

[+] SonicWall SMA 1000 WorkPlace Loopback Exploitation: Attackers target the unauthenticated WorkPlace Extraweb forward proxy interface on SonicWall SMA 1000 models 6210, 7210, and 8200v virtual appliances. The threat actor delivers an HTTP OPTIONS request containing path traversal sequences aimed at the internal Apache CouchDB service bound to 127.0.0[.]1:5984. By invoking CouchDB design document rewrite functions with default administrative credentials, attackers query internal databases to extract user session tables, local credential stores, and configuration settings.

[+] NetScaler SAML Implementation Memory Corruption Primitives: Vulnerability CVE-2026-107406 stems from unsafe memory handling within the NetScaler Packet Processing Engine when parsing SAML assertions. Deployments configured as SAML Identity Providers or Service Providers, alongside Secure Private Access Hybrid architectures, fail to bound memory allocations during malformed authentication transactions. This logic failure induces heap corruption, granting attackers code execution or triggering kernel panics that reboot appliances. Over twenty one thousand exposed instances face risk, with threat actors historically weaponizing NetScaler flaws within days of vendor disclosure.

[+] Integrity Technology Group State Linked Espionage Infrastructure: The joint advisory reveals that Integrity Technology Group operated automated scanning and intrusion tooling dating back to 2017. Their proprietary MicroScan platform utilized Mirai variant botnet nodes to execute automated reconnaissance against energy suppliers in South Carolina and Taiwan, international airports in Japan and Poland, and twenty Taiwanese academic institutions. Concurrently, their FishHub framework orchestrated spear phishing campaigns to deploy SoftEther VPN clients disguised as conhost.exe or dllhost.exe, while EBurst automated password spraying against Microsoft Exchange endpoints to exfiltrate email archives.

[+] Supplementary Malicious Infrastructure Clusters: Consulted sources identify persistent activity across peripheral campaigns. The FakeGit operation resumed distribution across seventeen thousand weaponized GitHub repositories, tricking software developers into downloading ZIP archives that drop SmartLoader and StealC infostealers. The Midnight Mimosa campaign weaponized low cost MediaTek mobile hardware across one hundred fifty countries, embedding firmware level backdoors that execute ad fraud and route residential proxy traffic. Meanwhile, actor UAC-0099 evolved MATCHBOIL downloader variants targeting Ukrainian energy and transport entities using scheduled tasks and obfuscated payload retrieval.

Chapter 03 - Operational Response

Defensive teams must execute urgent containment protocols across backup infrastructure, remote access hardware, and enterprise identity providers.

[+] Immediate AhsayCBS Management Plane Quarantine and Inspection: Organizations operating AhsayCBS must immediately remove the management interface from direct internet exposure. Restrict administrative access exclusively to isolated management networks or internal VPNs with phishing resistant multifactor authentication. Defensive teams must not assume version 10.3.4 provides safety. Inspect the operating system for unauthorized child processes spawned by cbssvcX64.exe or cbssvcX86.exe, audit web roots for rogue JSP files, and inspect Windows services for unauthorized entries such as MicrosoftEdgeUpdateSvc pointing to Temp directories.

[+] SonicWall SMA 1000 Firmware Upgrade and Session Purge: Administrators managing SMA 1000 appliances must verify installed firmware releases. Systems running versions 12.4.3-03526 or 12.5.0-02952 remain vulnerable and must be upgraded immediately to hotfix releases 12.4.3-03670 or 12.5.0-03082. If anomalous HTTP OPTIONS requests targeting workplace extraweb are identified in historical web server logs dating back to October 6, treat the appliance as compromised. Perform a complete system rebuild, rotate all appliance administrative secrets, revoke active SSL VPN session tokens, and regenerate all user multifactor authentication seeds.

[+] NetScaler SAML Role Classification and Firmware Deployment: Network engineering teams must audit NetScaler ADC and Gateway appliances to determine their SAML profile. Execute diagnostic commands show authentication samlAction and show authentication samlIdPProfile via the command line interface to identify active SAML configurations. Prioritize immediate firmware upgrades to builds 14.1-73.46, 13.1-64.29, or corresponding FIPS compliant releases. Prior to patch deployment, ensure web application firewalls drop malformed SAML authentication payloads.

[+] Cisco Nexus Feature Triage and Access Restriction: Network operations teams must audit Cisco Nexus switches to identify whether the NX-API feature is operational by executing show feature | include nxapi. If the service is running and not strictly required for software defined orchestration, disable the feature immediately. If operational dependencies mandate NX-API, restrict access using control plane access control lists to authorized administrative jump hosts. On Cisco UCS 6300 Fabric Interconnects, audit low privileged accounts and upgrade infrastructure to release 4.3(6j).

[+] Threat Hunting and Eviction for Integrity Technology Group Footholds: Organizations must ingest all seized and identified campaign domains into enterprise DNS and proxy blocking lists. Security operations teams should search Microsoft Exchange and Microsoft 365 authentication telemetry for distributed password spraying across Autodiscover, EWS, and OWA interfaces. Hunt across Windows server estates for unsanctioned SoftEther VPN installations, particularly executables running outside standard paths or masquerading under system names. Inspect Active Directory replication logs for DCSync operations executed by non domain controller machine accounts.

The following timeline details the disclosure milestones, weaponization observations, and law enforcement interventions recorded across consulted sources.

Date and Time (UTC)

Affected System or Entity

Observed Operational Event

2017/01/01

Integrity Technology Group

Earliest operational deployment of the MicroScan automated vulnerability scanning platform.

2021/01/15

Integrity Technology Group

Threat actors begin leveraging custom command line exploit utilities against cloud environments.

2026/10/04

AhsayCBS Backup Server

Vulnerability records CVE-2026-105133 and CVE-2026-105134 published to vulnerability tracking databases.

2026/10/04

FakeGit Campaign

Adversaries reactivate repository automation, deploying over thirteen thousand malicious repositories.

2026/10/06 15:35

SonicWall SMA 1000

SonicWall issues security advisory SNWLID-2026-0017 addressing four vulnerabilities including CVE-2026-102255.

2026/10/07 19:41

Cisco NX-OS Platforms

Cisco updates security advisory for NX-API root execution flaw CVE-2026-76471 documenting platform impacts.

2026/10/07 23:20

AhsayCBS Backup Server

Telemetry records earliest in the wild exploitation chaining authentication bypass to remote code execution.

2026/10/08 14:00

United States DOJ and FBI

Federal court authorizes seizure of seven infrastructure domains operated by Integrity Technology Group.

2026/10/08 15:00

Multi National Coalition

FBI, CISA, NSA, and partner foreign agencies release joint advisory AA26-281A exposing Chinese state tooling.

2026/10/08 18:00

AhsayCBS Backup Server

Research updates confirm that AhsayCBS version 10.3.4 remains vulnerable to active exploitation.

2026/10/08 20:00

Citrix NetScaler Systems

Citrix releases security bulletin CTX697191 detailing memory overflow vulnerability CVE-2026-107406.

2026/10/09 10:15

SonicWall SMA 1000

Honeypot sensors capture active exploitation probes targeting internal CouchDB databases via HTTP OPTIONS.

2026/10/09 15:35

Consolidated Intelligence

Security researchers corroborate honeypot telemetry, escalating SonicWall SMA 1000 threat status.

Chapter 04 - Detection Intelligence

The technical mechanics documented across current intrusion streams illustrate how adversaries circumvent traditional defensive boundaries via architectural logic flaws and memory corruption.

[+] AhsayCBS Deserialization and Process Orchestration Flow: The intrusion begins with an unauthenticated HTTP POST request directed at the checkSysPwd validation module, exploiting improper parameter handling in CVE-2026-105133 to bypass application credentials. The attacker immediately pivots to the Replication Receiver endpoint at /rps/api/json/UpdateReceivers.do under CVE-2026-105134. Due to flawed parameter sanitization, the application passes attacker supplied input directly to the underlying Windows command shell. The core service cbssvcX64.exe spawns cmd.exe and powershell.exe, fetching remote payloads from Alibaba Cloud Object Storage host imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com. The attacker establishes an interactive JSP web shell, drops the Taskgmr.ps1 evasion wrapper, installs NSSM service wrapper msedge.exe, and launches cryptominer edge.exe communicating with mining pool xmr.kryptex[.]network on port 8029.

[+] SonicWall SMA 1000 WorkPlace Loopback Forwarding Mechanics: In CVE-2026-102255, the WorkPlace Extraweb component functions as an unauthenticated reverse proxy designed to broker access to internal web services. Input validation routines fail to restrict outbound proxy targets when handling the HTTP OPTIONS verb. Remote actors deliver requests specifying target paths directed at 127.0.0[.]1:5984. The local reverse proxy connects directly to the internal Apache CouchDB instance. By appending design document rewrite queries alongside Basic Authorization headers containing admin:admin, the adversary interacts directly with internal CouchDB REST APIs. This enables full retrieval of user account databases, session tokens, and system configuration data without authenticating to the appliance.

[+] Citrix NetScaler Packet Processing Engine Heap Corruption: Vulnerability CVE-2026-107406 resides in the NetScaler Packet Processing Engine binary nsprobe and associated authentication modules. When configured as a SAML Identity Provider or Service Provider, the system processes inbound SAML authentication requests and assertions across port 443. Parsing logic fails to validate length attributes on specific XML structures, leading to an integer underflow during buffer copying routines. This triggers a heap based memory overflow that overwrites adjacent memory pointers. Depending on the memory layout, this corruption either causes an instant daemon crash and denial of service reboot or allows an attacker to gain unauthenticated remote code execution with root privileges.

[+] Cisco NX-API Input Sanitization Failure: Vulnerability CVE-2026-76471 exists within the web server subsystem responsible for parsing NX-API HTTP and HTTPS requests on Cisco Nexus switches. When processing crafted HTTP POST payloads directed at the management plane, the input parsing engine fails to properly sanitize specific characters within request headers. This failure allows an unauthenticated remote actor to escape the web service context and inject arbitrary commands directly into the underlying Linux operating system. Injected commands execute with root privileges, granting complete control over the network switch fabric.

[+] Integrity Technology Group Multi Tiered Espionage Toolchain: The threat group leverages a modular toolkit engineered for sustained persistence. The MicroScan framework conducts mass network port scanning, passing vulnerable web targets to automated exploitation scripts. Following initial access, operators deploy EBurst to execute multi protocol password spraying against Microsoft Exchange endpoints, avoiding account lockouts through distributed timing. For persistent external access, the actors install SoftEther VPN clients, renaming service binaries to conhost.exe or dllhost.exe. Once administrative footholds are achieved, the actors initiate DCSync operations to harvest Active Directory password hashes, subsequently executing custom scripts including office-cli and Curlc4.txt to exfiltrate selected user mailboxes through encrypted web channels.

The following indicators comprise verified network infrastructure, file hashes, and operational host artifacts documented across investigated campaigns. All network indicators have been defanged.

Indicator Type

Indicator Value

Associated Campaign or Context

Operational Verdict

IPv4 Address

177.4.12[.]11

AhsayCBS Exploitation Origin

Malicious

IPv4 Address

38.60.252[.]110

AhsayCBS Exploitation Origin

Malicious

IPv4 Address

107.191.47[.]199

AhsayCBS Exploitation Origin

Malicious

IPv4 Address

185.220.236[.]49

AhsayCBS Exploitation Origin

Malicious

IPv4 Address

104.234.26[.]10

AhsayCBS Exploitation Origin

Malicious

IPv4 Address

123.202.208[.]37

AhsayCBS Exploitation Origin

Malicious

IPv4 Address

51.195.127[.]124

AhsayCBS XMRig Mining Pool Host

Malicious

IPv4 Address

149.28.132[.]137

Integrity Tech Script Retrieval Host

Malicious

IPv4 Address

64.95.10[.]223

MATCHBOIL Command and Control Node

Malicious

IPv4 Address

64.95.13[.]210

MATCHBOIL Command and Control Node

Malicious

Domain Name

imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com

AhsayCBS Staged Payload Distribution Host

Malicious

Domain Name

xmr.kryptex[.]network

AhsayCBS Mining Pool Destination

Malicious

Domain Name

c0cc[.]cc

Seized Integrity Tech MicroScan Portal

Malicious

Domain Name

98aiblog[.]com

Seized Integrity Tech SoftEther VPN C2

Malicious

Domain Name

98aicai[.]com

Seized Integrity Tech Operational Host

Malicious

Domain Name

98aicode[.]com

Seized Integrity Tech Operational Host

Malicious

Domain Name

outlook3650[.]com

Seized Integrity Tech Phishing Host

Malicious

Domain Name

youtubecard[.]com

Seized Integrity Tech Phishing Host

Malicious

Domain Name

linkedinns[.]net

Seized Integrity Tech Phishing Host

Malicious

Domain Name

dns.studiocloud[.]xyz

Integrity Tech Espionage Infrastructure

Malicious

Domain Name

natcloudservice[.]com

Integrity Tech Data Exfiltration Endpoint

Malicious

Domain Name

upl.natcloudservice[.]com

Integrity Tech Mailbox Staging Domain

Malicious

Domain Name

hmbcloud[.]com

Integrity Tech Operational Infrastructure

Malicious

Domain Name

hmbcloud[.]net

Integrity Tech Operational Infrastructure

Malicious

Domain Name

hmbiplc-01[.]com

Integrity Tech Operational Infrastructure

Malicious

Domain Name

iepl.node[.]cm

Integrity Tech Operational Infrastructure

Malicious

Domain Name

javacheck.ooguy[.]com

Integrity Tech Dynamic DNS Node

Malicious

Domain Name

javaupdate.giize[.]com

Integrity Tech Dynamic DNS Node

Malicious

Domain Name

sexytube0[.]com

Integrity Tech Operational Infrastructure

Malicious

Domain Name

twimg.co[.]uk

Integrity Tech Masquerading Domain

Malicious

Domain Name

virtualdailyplanner[.]pro

MATCHBOIL Downloader Staging Domain

Malicious

Domain Name

telemetry-conf[.]com

MATCHBOIL Downloader Staging Domain

Malicious

Domain Name

flycloud-service[.]com

MATCHBOIL Downloader Staging Domain

Malicious

Domain Name

airarticlegenerate[.]com

MATCHBOIL Downloader Staging Domain

Malicious

URL

hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/Taskgmr.ps1

AhsayCBS Evasion Script Payload

Malicious

URL

hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/edge.exe

AhsayCBS XMRig Miner Executable

Malicious

URL

hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/msedge.exe

AhsayCBS Modified NSSM Service Wrapper

Malicious

URL

hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/config.json

AhsayCBS Cryptominer Configuration File

Malicious

URL

hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/WinRing0x64.sys

AhsayCBS Vulnerable Kernel Driver

Malicious

SHA-256

05f69ae6b2b89c1c4dcf836bff032232f11bf0109f2b498e2345045d06139034

AhsayCBS NSSM Installer msedge.exe

Malicious

SHA-256

4dcb0202fe8b2d4d7b183764e38184cd6ed50132786cc7e7d1f7f4bce1dd6f3d

AhsayCBS XMRig Binary edge.exe

Malicious

SHA-256

481728a7c9c4c02be07051d9c1958d902ea6397ebb8952ab83944818e3d25d21

AhsayCBS PowerShell Script Taskgmr.ps1

Malicious

SHA-1

B6569B0050B864C4A0D32326954BC2D3852A3958

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

A926889BAB31F3C34663D18C05C4E862EF367028

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

026F892630D0A4FE854A75984695BA99AF0022C4

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

F886B615CB9E23EAD2718FF2A61155ACFB04CE9E

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

1E2C4AAC30EDFF86CD9A30BD08B199BCD3D0CCCE

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

C85D28F7D272CE2BBBFB9DAE71D21BF25B8D00FC

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

6D72B56B86FD5ED9BD188C8C88CFC69476F836E7

MATCHBOIL Downloader Binary Artifact

Malicious

SHA-1

050926727CDD74F0B3A8A098E60B76D10FB06B14

MATCHBOIL Downloader Binary Artifact

Malicious

Defensive detection engineers must deploy the following rules across web proxies, endpoint telemetry agents, and directory audit monitors.

title: AhsayCBS Core Service Spawning Suspicious Child Process
id: a87e14d2-43f1-482a-bc91-23f0198642a1
status: experimental
description: Detects AhsayCBS backup services cbssvcX64 or cbssvcX86 spawning command shells or download utilities indicative of CVE-2026-105134 exploitation.
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\cbssvcX64.exe'
      - '\cbssvcX86.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\curl.exe'
      - '\certutil.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Authorized administrative backup maintenance scripts
level: critical
tags:
  - attack.initial_access
  - attack.t1190
  - attack.execution
  - attack.t1059.001
title: SonicWall SMA 1000 WorkPlace Loopback Probe Attempt
id: 3b1a7d62-9e23-424a-b50a-e5a96023d854
status: experimental
description: Detects HTTP OPTIONS requests directed at SMA 1000 WorkPlace extraweb endpoints targeting internal CouchDB daemons under CVE-2026-102255.
logsource:
  category: webserver
  product: sonicwall_sma
detection:
  selection_endpoint:
    cs-method: 'OPTIONS'
    cs-uri-stem|contains: '/workplace/extraweb'
  selection_payload:
    cs-uri-query|contains:
      - '127.0.0.1'
      - 'localhost'
      - '5984'
      - '_rewrite'
      - '_design'
  condition: selection_endpoint and selection_payload
falsepositives:
  - Unlikely in production environments
level: critical
tags:
  - attack.initial_access
  - attack.t1190
  - attack.discovery
  - attack.t1005
title: Renamed SoftEther VPN Client Execution
id: f421c908-1123-4e3b-9a41-89d1234098aa
status: experimental
description: Detects SoftEther VPN client execution disguised as common Windows binaries associated with Integrity Technology Group persistence.
logsource:
  category: process_creation
  product: windows
detection:
  selection_image:
    Image|endswith:
      - '\conhost.exe'
      - '\dllhost.exe'
  selection_cli:
    CommandLine|contains:
      - 'vpnclient'
      - 'vpncmd'
      - 'SoftEther'
  condition: selection_image and selection_cli
falsepositives:
  - None expected in enterprise environments
level: high
tags:
  - attack.persistence
  - attack.t1133
  - attack.defense_evasion
  - attack.t1036.003
rule Exploit_CVE_2026_102255_SonicWall_CouchDB_Probe {
    meta:
        description = "Detects network payloads and memory traces attempting preauthentication SSRF against SonicWall SMA 1000 CouchDB"
        author = "Inferlume Threat Research"
        date = "2026-10-09"
        reference = "CVE-2026-102255"
        severity = "Critical"
    strings:
        $http_verb = "OPTIONS " ascii
        $endpoint = "/workplace/extraweb" ascii nocase
        $target_ip = "127.0.0.1:5984" ascii
        $rewrite_fn = "_rewrite" ascii
        $auth_token = "YWRtaW46YWRtaW4=" ascii
    condition:
        $http_verb at 0 and $endpoint and ($target_ip or $rewrite_fn or $auth_token)
}
rule Suspicious_AhsayCBS_Taskgmr_Evasion_Script {
    meta:
        description = "Detects PowerShell routines monitoring Taskmgr to halt and resume malicious Windows services"
        author = "Inferlume Threat Research"
        date = "2026-10-09"
        severity = "High"
    strings:
        $ps_proc = "Get-Process" ascii nocase
        $ps_taskmgr = "Taskmgr" ascii nocase
        $ps_stop = "Stop-Service" ascii nocase
        $ps_start = "Start-Service" ascii nocase
        $svc_target = "MicrosoftEdgeUpdateSvc" ascii nocase
    condition:
        all of them
}
index=web_proxy OR index=firewall sourcetype=sonicwall:sma
| where http_method="OPTIONS" AND like(uri_path, "%/workplace/extraweb%")
| eval is_loopback=if(match(uri_query, "(127\.0\.0\.1|localhost|5984|_rewrite)"), 1, 0)
| where is_loopback=1
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, uri_path, uri_query, http_user_agent
index=windows sourcetype=WinEventLog:Security EventCode=4662
| where match(Properties, "1131f6aa-9c07-11d1-f79f-00c04fc2dcd2")
| eval is_dc=if(match(SubjectUserName, "\\$$"), 1, 0)
| where is_dc=0
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, SubjectUserName, ComputerName

The intelligence findings correlate to established adversary tactics, techniques, and defensive countermeasures.

MITRE Tactic

Technique ID

Technique Name

Evidence and Context

Reconnaissance

T1595.002

Vulnerability Scanning

MicroScan automated vulnerability scanning across global critical infrastructure.

Initial Access

T1190

Exploit Public-Facing Application

Observed across AhsayCBS, SonicWall SMA 1000, Citrix NetScaler, and Cisco platforms.

Initial Access

T1189

Drive-by Compromise

Drive by scripts and browser exploitation identified in joint advisory findings.

Execution

T1059.001

PowerShell

Execution of Taskgmr.ps1 in AhsayCBS post exploitation mining campaigns.

Execution

T1059.003

Windows Command Shell

Execution of cmd.exe child processes via cbssvcX64.exe command injection.

Execution

T1059.004

Unix Shell

Command execution on Cisco Nexus switching platforms via NX-API flaws.

Execution

T1059.006

Python

Execution of MicroScan reconnaissance scripts and automated framework modules.

Execution

T1059.007

JavaScript

Exploitation of client side web scripts to capture authentication session tokens.

Persistence

T1505.003

Web Shell

Deployment of JSP web shells into AhsayCBS application directories.

Persistence

T1543.003

Windows Service

Registration of MicrosoftEdgeUpdateSvc utilizing NSSM wrappers.

Persistence

T1133

External Remote Services

Installation of SoftEther VPN clients to maintain network access.

Defense Evasion

T1036.003

Rename Legitimate Utilities

Masquerading SoftEther VPN binaries as conhost.exe or dllhost.exe.

Defense Evasion

T1036.004

Masquerading: Masquerade Task or Service

Naming malicious mining service MicrosoftEdgeUpdateSvc.

Defense Evasion

T1036.005

Masquerading: Match Legitimate Name or Location

Naming NSSM installer and miner msedge.exe and edge.exe.

Defense Evasion

T1564

Hide Artifacts

Concealing cryptominer staging files inside user Temp directories.

Credential Access

T1003.006

DCSync

Requesting directory replication to harvest Active Directory domain credentials.

Credential Access

T1110.001

Password Guessing

Low frequency credential guessing against Microsoft Exchange web interfaces.

Credential Access

T1110.003

Password Spraying

EBurst automated password spraying across enterprise mail access protocols.

Collection

T1114.002

Remote Email Collection

Siphoning mailbox archives utilizing office-cli and custom extraction scripts.

Collection

T1005

Data from Local System

Extracting CouchDB configurations via SonicWall SMA 1000 loopback SSRF.

Command and Control

T1071.001

Web Protocols

Ingress payload staging and C2 over HTTP and HTTPS connections.

Command and Control

T1090

Proxy

Routing loopback requests through SonicWall WorkPlace Extraweb forward proxy.

Exfiltration

T1020

Automated Exfiltration

Automated transfer of sensitive email archives to remote collection nodes.

Impact

T1496.001

Compute Hijacking

Unauthorized execution of XMRig cryptominers across compromised backup hosts.

D3FEND Countermeasure Mappings:
[+] D3-IPA (Inbound Parameter Analysis): Enforces strict input validation on HTTP requests to eliminate command injection in AhsayCBS and Cisco NX-API.

[+] D3-NFA (Network Forwarding Analysis): Restricts loopback and internal forwarding paths to neutralize SSRF vulnerabilities in SonicWall SMA 1000.

[+] D3-MFA (Multi-Factor Authentication): Enforces phishing resistant authentication across webmail portals and remote access gateways to prevent password spraying.

[+] D3-ITR (Inbound Traffic Restriction): Isolates administrative interfaces and backup management consoles from untrusted external networks.

[+] D3-SPP (Software Process Profiling): Monitors core application service daemons to alert on unauthorized execution of command interpreters or script hosts.

Chapter 05 - Governance, Risk & Compliance

Organizations managing compromised or vulnerable infrastructure face severe regulatory liabilities and business continuity disruptions.

[+] Breach Disclosure Triggers Under Data Privacy Legislation: Unauthorized access to AhsayCBS backup repositories exposes corporate data archives, active virtual machine snapshots, and database backups. Confirmed unauthorized access triggers strict notification mandates under the European Union General Data Protection Regulation within seventy two hours and United States Securities and Exchange Commission Form 8-K reporting within four business days. In India, cyber incident reporting guidelines enforce a six hour reporting threshold to the Indian Computer Emergency Response Team upon discovering unauthorized system access.

[+] Supply Chain Risk and Managed Service Provider Liabilities: The weaponization of AhsayCBS directly impacts managed service providers and systems integrators who host centralized backup infrastructure for multiple downstream clients. A successful compromise at the service provider level compromises client data integrity, creating legal exposure under contractual service level agreements and triggering third party incident disclosure obligations.

[+] Federal Compliance Directives and Government Mandates: SonicWall SMA 1000 appliances and Citrix NetScaler systems operating within public sector organizations face urgent remediation oversight. While CVE-2026-102255 awaits formal cataloging, historical precedent regarding edge appliance exploitation indicates that federal agencies must prepare for immediate Binding Operational Directive remediation timelines upon formal designation.

[+] Critical Infrastructure Disruption Risks: The operations documented in the Integrity Technology Group advisory confirm persistent adversary positioning within energy generation facilities, water utilities, and aviation transportation networks. Operational technology asset owners must conduct comprehensive architectural reviews to ensure corporate enterprise network breaches cannot pivot into industrial control networks.

Chapter 06 - Adversary Emulation

Security teams should execute the following purple team scenarios within authorized testing environments to evaluate defensive visibility.

[+] Scenario 1: AhsayCBS Command Injection and Child Process Simulation
Objective: Validate whether endpoint detection agents generate high severity alerts when the backup service process executes command shells.
Validation Steps:

  1. Within an isolated non production Windows laboratory environment hosting AhsayCBS, simulate an administrative diagnostic task that invokes cmd.exe from the parent service cbssvcX64.exe.

  2. Confirm that endpoint detection and response telemetry records the process lineage event.

  3. Validate that behavioral prevention rules block the invocation or generate an immediate critical security alert.

  4. Verify that administrative attempts to register a service pointing to files located in Temp directories trigger immediate service installation alarms.

[+] Scenario 2: SonicWall SMA 1000 Loopback SSRF Inspection
Objective: Verify whether external web application firewalls and internal proxies identify and intercept crafted loopback forwarding requests.
Validation Steps:

  1. From an authorized testing host, transmit a harmless HTTP OPTIONS request toward a non production test endpoint mimicking the WorkPlace Extraweb URI path, including query parameters referencing 127.0.0[.]1:5984.

  2. Verify that external security filtering gateways identify the loopback IP string and terminate the HTTP connection with an HTTP 403 status code.

  3. Review web server access logs to ensure that request method, requested URI stem, and parameter strings are retained for forensic analysis.

[+] Scenario 3: Active Directory DCSync Anomaly Detection
Objective: Evaluate directory audit telemetry coverage against unauthorized directory replication calls.
Validation Steps:

  1. In a staging Active Directory domain, utilize an authorized testing identity that does not possess domain controller privileges to simulate a DS-Replication-Get-Changes request against a domain controller.

  2. Confirm that security information and event management audit pipelines ingest Windows Security Event Code 4662.

  3. Validate that correlation searches identify that the requesting account is not an authorized domain controller and dispatch an immediate incident response notification.

Intelligence Confidence82%

The overall confidence score reflects rigorous evaluation across primary source documentation, technical corroboration, and empirical telemetry.

Evaluation Metric

Assessed Level

Analytical Justification

Primary Authority

High

Direct advisories issued by FBI, CISA, NSA, UK NCSC, SonicWall PSIRT, Citrix PSIRT, and Cisco PSIRT.

Technical Grounding

High

Detailed exploit mechanics, command parameters, and process execution trees verified via Huntress and Previdian.

Attribution Rigor

Medium

High confidence for Integrity Tech judicial domain seizures; activity on AhsayCBS and SonicWall remains Under Attribution.

Telemetry Integrity

High

Concrete file hashes, defanged network destinations, and registry artifacts confirmed across active response investigations.

Conflict Resolution

Resolved

Corrected NVD remediation records regarding AhsayCBS version 10.3.4 and reconciled honeypot probe records.

Consolidated Score

82 / 100

Robust operational confidence supporting immediate patching, access quarantine, and indicator hunting.