Last Updated On

CCTTII--22002266--11000077
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Weaponized Defaults And Encoding Tricks Shatter Citrix NetScaler And PeopleSoft Defenses

Multiple zero day vulnerabilities across Citrix NetScaler, Oracle PeopleSoft, Cisco Catalyst SD-WAN, Fortinet FortiMail, and Zammad Helpdesk are facing active exploitation. Intruders bypass defensive filters using URI encoding and path normalization flaws to establish persistent web shells, proxy tunnels, and root server control.

Concurrently, exposed artificial intelligence model hosts are being absorbed into cryptojacking botnets while hospitality wireless networks are manipulated to intercept corporate identity credentials. Threat actors demonstrate advanced capabilities to subvert standard perimeter inspection rules.

Security operations teams must immediately patch all exposed software, restrict administrative access to internal networks, and hunt for active post exploitation indicators across enterprise environments.

#ThreatIntel #CyberSecurity #VulnerabilityManagement #IncidentResponse #ZeroDay #InfoSec

10

CVSS Score

68

IOC Count

31

Source Count

88

Confidence Score

CVEs

CVE-2026-88771, CVE-2026-88772, CVE-2026-88779, CVE-2026-35273, CVE-2026-21589, CVE-2026-76504, CVE-2026-104286, CVE-2026-102489, CVE-2026-102490, CVE-2026-61500, CVE-2026-102255, CVE-2026-93836, CVE-2026-94504, CVE-2026-5430, CVE-2026-42608, CVE-2026-105192, CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347, CVE-2026-42271

Actors

UNC6240, ShinyHunters, Storm-2945, UAC-0277, UAT-11587, UAT-10027, PoeLLM Botnet Operators, Clop Ransomware

Sectors

Government, Financial Services, Higher Education, Technology, Healthcare, Aerospace, Retail, E-Commerce, Legal Services, Manufacturing, Critical Infrastructure, Cloud Infrastructure, Publishing, Hospitality

Regions

Global, United States, Western Europe, United Kingdom, Japan, Ukraine, Jordan, Netherlands, Germany, India, Philippines, Cambodia, Asia-Pacific

Chapter 01 - Executive Overview

+---------------------------------------------------------------------------------------------------+
|                                 ENTERPRISE THREAT LANDSCAPE MATRIX                                |
+---------------------------+-----------------------+-------------------+---------------------------+
| Affected Platform         | Vulnerability / Flaw  | Technical Impact  | Exploitation Status       |
+---------------------------+-----------------------+-------------------+---------------------------+
| Citrix NetScaler ADC/GW   | CVE-2026-88771/72/79  | RCE & SAML DoS    | Confirmed Wild Attacks    |
| Oracle PeopleSoft         | CVE-2026-35273        | WAF Bypass & RCE  | Active Mass Campaign      |
| Cisco Catalyst SD-WAN     | CVE-2026-76504        | Admin API Bypass  | Confirmed Wild Attacks    |
| Fortinet FortiMail        | CVE-2026-104286       | Arbitrary Write   | Confirmed Wild Attacks    |
| Zammad Helpdesk           | CVE-2026-102489/90    | Root Takeover     | Confirmed Zero Day Chain  |
| Rejetto HFS               | CVE-2026-61500        | Cookie Forgery    | Active Recon & Probing    |
| Atlassian Data Center     | CVE-2026-21589        | File Path Reads   | Post PoC Exploitation     |
| AI Model Hosts (Ollama)   | Exposed APIs          | Botnet & Mining   | Thousands Compromised

[+] Multi Vendor Intrusion Wave: An aggressive wave of unauthenticated zero day and recently disclosed vulnerabilities is actively destabilizing enterprise platforms, including Citrix NetScaler, Oracle PeopleSoft, Cisco Catalyst SD-WAN, Fortinet FortiMail, and Zammad Helpdesk.

[+] Authentication Mechanism Failure: Attackers are deliberately bypassing perimeter filters by weaponizing parsing disparities, such as URI encoding in Cisco SD-WAN, path normalization gaps in PeopleSoft, and buffer overflows in Citrix SAML handling.

[+] Immediate Persistence and Lateral Movement: Initial exploitation consistently leads to custom post exploitation implants, notably WHIPSHOT PHP web shells and SLAPSHOT Python proxy tunnels in NetScaler, as well as SIDEEYE backdoors in PeopleSoft.

[+] Exploitation of Machine Learning Hosts: Unprotected artificial intelligence hosting platforms, specifically Ollama, LiteLLM, and Gotenberg, are being swept into the PoeLLM botnet for distributed scanning and Monero mining.

[+] Identity and Supply Chain Harvesters: Russian state aligned group Storm-2945 has reactivated wireless captive portal attacks against corporate travelers, while software repository ecosystems are experiencing malicious package insertion.

Chapter 02 - Threat & Exposure Analysis

[+] Citrix NetScaler Appliance Infiltration: Threat actors have weaponized three separate vulnerabilities within NetScaler ADC and Gateway systems. Intruders send crafted DTLS network packets to trigger memory corruption under CVE-2026-88771 and CVE-2026-88772, achieving unauthenticated command execution. Following access, adversaries modify the core web server configuration file httpd.conf to instruct the Apache daemon to execute non script files, such as static style sheets, as PHP scripts. Intruders then upload WHIPSHOT, a stealthy PHP web shell disguised within style sheets that parses Base64 commands concealed inside native HTTP headers. To expand operational reach, attackers deploy SLAPSHOT, a Python tunneling utility that forwards arbitrary TCP traffic directly into private internal subnets. Concurrently, attackers trigger CVE-2026-88779 against NetScaler instances configured as SAML service providers, crashing authentication handlers to induce denial of service conditions that facilitate exploitation of adjacent flaws.

[+] Oracle PeopleSoft Mass Intrusion Campaign: Financially motivated group UNC6240, operating under the ShinyHunters collective, has escalated exploitation against Oracle PeopleSoft Enterprise PeopleTools under CVE-2026-35273. While defenders implemented web application firewall rules to block the administrative path /PSEMHUB/, attackers completely bypassed inspect filters by URL encoding the leading character as /%50SEMHUB/hub. Because reverse proxy firewalls frequently evaluate literal string paths without preliminary normalization, the request traverses the filter unaltered, where the back end WebLogic server normalizes the character to P and serves the vulnerable Environment Management servlet. Intruders transmit serialized Java payloads to achieve unauthenticated code execution, followed by the deployment of JSP web shells designated x.jsp and u.jsp. To maintain persistent administrative access, the group stages Neo-reGeorg HTTP tunneling servlets and installs MeshAgent remote management services communicating with winmanage-me[.]network. Attackers deploy SIDEEYE, an advanced backdoor distributed through a trojanized installer named Ple64.exe signed with an enterprise code signing certificate, which maintains raw TCP command channels over ports 3333 and 3334 to orchestrate corporate data extortion.

[+] Cisco Catalyst SD-WAN Manager Authentication Bypass: Attackers are actively targeting CVE-2026-76504 within Cisco Catalyst SD-WAN Manager. The flaw stems from an encoding normalization inconsistency in the handling of the j_security_check authentication endpoint. Intruders issue HTTP POST requests directed toward /%6a_security_check, substituting the literal letter j with its hex encoded representation %6a. The routing layer fails to match the encoded string against restricted authentication rules, yet passes the request to the underlying servlet, granting the attacker unauthenticated administrative API control without credentials.

[+] Fortinet FortiMail Arbitrary File Write: Exploitation of CVE-2026-104286 across Fortinet FortiMail email security gateways combines path traversal with null byte injection. Unauthenticated threat actors craft specialized HTTP requests incorporating directory traversal sequences alongside %00 null byte terminators, allowing them to circumvent file system write restrictions. This capability facilitates the creation of persistent web shells directly inside web accessible directories, exposing protected email infrastructures to complete host takeover.

[+] Zammad Helpdesk Chained Intrusion: Attackers executed an advanced zero day intrusion against the security foundation DIVD by chaining two flaws in Zammad Helpdesk. Threat actors exploit session fixation flaw CVE-2026-102489 to pre assign a session identifier prior to victim authentication. Once an authenticated user accesses the platform, the attacker hijacks the session, elevates role privileges within the administrative interface, and executes CVE-2026-102490 to escalate local permissions from the zammad system user directly to root, establishing complete server compromise.

[+] Rejetto HTTP File Server Session Forgery: Security researchers have identified active reconnaissance probes originating from telecommunications infrastructure targeting CVE-2026-61500 in Rejetto HTTP File Server. The platform calculates session cookie signatures using a non cryptographic pseudo random number generator, Math.random, which leaks internal states during standard login exchanges. Attackers collect successive session tokens to reconstruct the generator state, forge administrative session cookies, and achieve remote code execution by submitting malicious JavaScript strings into the server_code configuration interface.

[+] Atlassian Data Center Path Traversal: Following the publication of technical proof of concept materials, attackers initiated exploitation attempts against CVE-2026-21589 across Atlassian Data Center products including Jira, Confluence, and Bitbucket. The vulnerability utilizes path traversal sequences constructed with double colon delimiters, allowing adversaries to bypass standard path sanitization filters and read internal files within the web root. In environments integrated with Atlassian Crowd, adversaries attempt to read WEB-INF/web.xml to extract database secrets and administrative credentials.

[+] Artificial Intelligence Infrastructure Weaponization: The Canto Incognito botnet campaign is propagating PoeLLM across more than 3400 exposed artificial intelligence hosts running Ollama, LiteLLM, Gotenberg, and Gitea. Exploiting unauthenticated model APIs and container interfaces, attackers deploy XMRig and Iron cryptocurrency miners configured to route earnings to the Kryptex mining pool. The malware retrieves dynamic operational instructions from a Base64 encoded payload hosted inside a GitHub repository text file, converting enterprise compute infrastructure into persistent scanning and mining nodes.

[+] Adversary Identity Harvesting via Hospitality Networks: Russian state aligned group Storm-2945 has resumed operations with its CaptiveCrunch attack framework. The group manipulates local DNS and HTTP routing within hospitality and hotel wireless networks, redirecting travelers attempting network authentication to fraudulent captive portals. Victims are presented with Microsoft 365 device code login lures, allowing the adversary to intercept OAuth tokens and deploy the Rust based CornFlake remote access trojan to maintain deep corporate network access.

Chapter 03 - Operational Response

+---------------------------------------------------------------------------------------------------+
|                                 OPERATIONAL TRIAGE PRIORITY MATRIX                                |
+------------------------+------------------+-------------------------------------------------------+
| Vulnerability / Target | Action Deadline  | Required Primary Mitigation                           |
+------------------------+------------------+-------------------------------------------------------+
| Citrix NetScaler       | Within 24 Hours  | Apply firmware update; audit httpd.conf for PHP hooks |
| Oracle PeopleSoft      | Immediate (12h)  | Patch PeopleTools; block encoded /%50SEMHUB/ paths    |
| Cisco SD-WAN Manager   | Within 24 Hours  | Upgrade software release; isolate API from Internet   |
| Fortinet FortiMail     | Within 24 Hours  | Upgrade firmware; inspect web roots for file creation |
| Zammad Helpdesk        | Within 24 Hours  | Upgrade to v7.2.0; audit zammad account shell actions |
| Atlassian Data Center  | Within 48 Hours  | Apply vendor security hotfix; inspect access logs     |
| AI Model Platforms     | Immediate (12h)  | Disable public API exposure; inspect active processes

[+] Citrix NetScaler Emergency Remediation: Organizations must upgrade NetScaler ADC and Gateway appliances to current releases immediately. If immediate patching of CVE-2026-88779 is not feasible, administrators must disable SAML authentication profiles on Gateway and AAA virtual servers. Incident response teams must inspect the Apache configuration file /ns/config/httpd.conf for unauthorized directives associating static file types with the PHP execution engine, and search local storage for WHIPSHOT web shells and active SLAPSHOT Python processes.

[+] Oracle PeopleSoft Containment Protocol: System owners must apply the Oracle security update for CVE-2026-35273 without delay. Organizations must inspect reverse proxy and web application firewall configurations to confirm that URL decoding occurs prior to policy rule enforcement, ensuring that encoded paths such as /%50SEMHUB/ are dropped. Network teams must immediately terminate external access to the Environment Management Hub servlet and restrict access to the Integration Broker listening connector. Host systems must be audited for unauthorized JSP files, MeshAgent binaries, and outbound TCP sessions targeting external ports 3333 and 3334.

[+] Cisco SD-WAN Security Hardening: Apply vendor updates across Catalyst SD-WAN Manager instances to eliminate the URI encoding bypass flaw. Administrators must immediately restrict administrative web and API interfaces to dedicated management subnets, ensuring that the j_security_check endpoint cannot be reached from untrusted networks. Audit web server access logs for any requests containing %6a or double encoded variants.

[+] Fortinet FortiMail Gateway Verification: Upgrade FortiMail appliances to patched firmware releases to block path traversal and null byte writes. Restrict appliance management consoles to internal networks protected by multi factor authentication. Security teams should perform file integrity checks across web hosting directories to identify and eliminate web shells planted via crafted HTTP POST requests.

[+] Zammad Helpdesk Incident Containment: Upgrade all instances to Zammad version 7.2.0 or higher. Helpdesk instances operating on legacy branches must be isolated from the public internet immediately. Defenders must review authentication session logs for session identifier reuse originating from discordant IP addresses, and inspect host system audit logs for instances where the zammad service account invoked sudo or escalated privileges to root.

[+] Atlassian Data Center Access Review: Apply security updates across Confluence, Jira, and Bitbucket Data Center deployments. In environments where updates are pending, web application firewalls must be configured with rules blocking any inbound URI containing double colon directory traversal strings. Audit access logs for unauthorized attempts to retrieve WEB-INF/web.xml and sensitive configuration files.

[+] Artificial Intelligence Server Isolation: Conduct an immediate audit of all listening ports associated with LiteLLM, Ollama, and containerized machine learning endpoints, ensuring that ports 3000, 4000, and 11434 are never exposed directly to the public internet. Execute host process reviews across compute instances to detect unauthorized XMRig or Iron mining binaries, and enforce egress filtering blocking outbound connections to known cryptocurrency mining endpoints.

[+] Remote Traveler Identity Defense: Security leadership must advise traveling personnel regarding the risks of hospitality wireless networks. Enforce mandatory virtual private network configurations that reject local captive portal DNS overrides, implement strict conditional access policies restricting OAuth device code authorizations, and hunt for CornFlake RAT host indicators on portable assets.

+---------------------------------------------------------------------------------------------------+
|                                 CHRONOLOGICAL INCIDENT TIMELINE                                   |
+-------------------+-------------------------------------------------------------------------------+
| Date / Timestamp  | Recorded Event Summary                                                        |
+-------------------+-------------------------------------------------------------------------------+
| 2026-09-21        | Chained Zammad zero day flaws exploited against DIVD infrastructure           |
| 2026-09-25        | ShinyHunters exploits Grav CMS flaw CVE-2026-42608 to deface Clop leak site  |
| 2026-09-29        | Mandiant detects active exploitation of Citrix NetScaler flaw CVE-2026-88772  |
| 2026-09-29        | Russian actor Storm-2945 resumes CaptiveCrunch wireless phishing operations   |
| 2026-09-30        | Cisco discloses active exploitation of SD-WAN Manager bypass CVE-2026-76504   |
| 2026-10-01        | Fortinet confirms in the wild attacks against FortiMail via CVE-2026-104286   |
| 2026-10-01        | Automated scanning probes detect Rejetto HFS cookie flaw CVE-2026-61500       |
| 2026-10-03        | Citrix releases emergency hotfixes for NetScaler under advisory CTX697174     |
| 2026-10-04        | CISA adds Citrix NetScaler CVE-2026-88779 to KEV with urgent deadline         |
| 2026-10-04        | Threat actors initiate WordPress stored XSS exploitation against two plugins  |
| 2026-10-05        | Atlassian issues critical security advisory for path traversal CVE-2026-21589 |
| 2026-10-06        | Public PoC released for Atlassian flaw; active exploitation attempts detected |
| 2026-10-07        | Threat intelligence reports surge in PoeLLM compromises across 3400 AI hosts  |
| 2026-10-08        | Consolidated intelligence report compiled and released

Chapter 04 - Detection Intelligence

[+] Citrix NetScaler WHIPSHOT and SLAPSHOT Mechanics: Memory corruption is achieved by dispatching malformed DTLS packets directly to the NetScaler Packet Processing Engine. Following code execution, adversaries modify /ns/config/httpd.conf to include configuration hooks that interpret .css files via the PHP interpreter. Attackers upload WHIPSHOT, a PHP web shell disguised as an ordinary stylesheet. WHIPSHOT inspects inbound HTTP requests for specific custom headers, extracts Base64 encoded payload strings, decodes the commands, and evaluates them in system memory without writing transient execution scripts to disk. WHIPSHOT subsequently launches SLAPSHOT, an executable Python tunneling script. SLAPSHOT establishes listening sockets and binds internal TCP connections, creating an encrypted proxy bridge that allows external adversaries to route interactive management traffic into corporate local area networks.

+---------------------------------------------------------------------------------------------------+
|                         CITRIX NETSCALER PERSISTENCE AND TUNNELING CHAIN                          |
+---------------------------------------------------------------------------------------------------+
| [ Crafted DTLS Packet ]                                                                           |
|          |                                                                                        |
|          v                                                                                        |
| [ Memory Overflow in NetScaler Engine ] ---> [ Arbitrary Command Execution ]                      |
|                                                              |                                    |
|                                                              v                                    |
| [ Modify /ns/config/httpd.conf ] <--- [ Add PHP Execution Handler for .css Extensions ]           |
|          |                                                                                        |
|          v                                                                                        |
| [ Drop WHIPSHOT Web Shell (style.css) ] ---> [ Parse Base64 Commands in HTTP Headers ]            |
|                                                              |                                    |
|                                                              v                                    |
| [ Launch SLAPSHOT Python Tunnel ] <-------- [ Proxy Inbound Traffic to Private Subnets ]

[+] Oracle PeopleSoft PSEMHUB Normalization Gap: Vulnerability CVE-2026-35273 exists within the Environment Management Hub servlet. Threat actors exploit an architectural disparity between reverse proxy firewalls and back end application servers. An inspection rule designed to block /PSEMHUB/ evaluates incoming raw URI strings. The attacker issues an HTTP POST request targeting /%50SEMHUB/hub. The reverse proxy observes %50, treats the URI as a non matching path, and forwards the packet to Oracle WebLogic. WebLogic decodes %50 into the ASCII character P, normalizes the request to /PSEMHUB/hub, and directs the request to the unauthenticated handler. The attacker submits serialized Java objects containing executable commands, which the servlet deserializes and executes with system privileges.

+---------------------------------------------------------------------------------------------------+
|                           ORACLE PEOPLESOFT WAF BYPASS ARCHITECTURE                               |
+---------------------------------------------------------------------------------------------------+
| [ Attacker Request: POST /%50SEMHUB/hub ]                                                         |
|          |                                                                                        |
|          v                                                                                        |
| [ Reverse Proxy WAF ] ---> Checks Literal String "/PSEMHUB/" ---> NO MATCH (Allows Traffic)       |
|          |                                                                                        |
|          v                                                                                        |
| [ Back End Oracle WebLogic ] ---> Normalizes "%50" to "P" ---> Resolves to "/PSEMHUB/hub"         |
|          |                                                                                        |
|          v                                                                                        |
| [ Environment Management Servlet ] ---> Deserializes Payload ---> SYSTEM / ROOT EXECUTION

[+] PeopleSoft Post Exploitation Tooling: Once initial access is confirmed, UNC6240 delivers x.jsp, a specialized JSP web shell that receives hex encoded strings via HTTP parameters, decodes the strings, and spawns native system shells (cmd.exe or /bin/sh). The actor also deploys u.jsp to assemble chunked Base64 file uploads, and Neo-reGeorg tunneling servlets (tunnel.jsp) to establish SOCKS proxies. To secure robust persistence, adversaries deploy Ple64.exe, an installer masquerading as Light Alloy media software signed with an enterprise certificate. Ple64.exe installs the SIDEEYE backdoor, which initiates raw TCP connections to 162.219.30[.]165 on ports 3333 and 3334, supporting process management, reverse command shells, and automated file exfiltration.

[+] Cisco SD-WAN URL Encoding Bypass: In CVE-2026-76504, the Catalyst SD-WAN Manager relies on pattern matching rules to protect administrative endpoints. The endpoint /j_security_check validates administrative credentials. By transmitting an HTTP POST request directed to /%6a_security_check, the attacker supplies the hex equivalent of the letter j. The security filter bypasses inspection because the raw path does not begin with /j, but the application runtime processes the URI, accepts the administrative submission without credential validation, and provides an active administrative session token.

[+] Fortinet FortiMail Path Traversal and Null Byte Injection: Under CVE-2026-104286, the FortiMail web administration portal fails to properly sanitize path variables submitted within multipart form submissions. Attackers incorporate directory traversal sequences combined with null byte terminators, such as ../../styles/shell.php%00.png. The operating system file system driver truncates the string at the null byte, resulting in the creation of an executable PHP script within an unprotected public web folder.

[+] Zammad Session Fixation to Root Escalation: The intrusion against Zammad begins with CVE-2026-102489, where an attacker generates a valid session cookie, ZAMMAD_SESSION, and forces it into a victim browser via phishing or cross site script injection. When the administrative user completes authentication, the platform fails to regenerate the session key, linking the authenticated session to the attacker controlled token. The attacker adopts the session, navigates to the administrative panel, and assigns full administrative roles to a secondary account. The adversary then triggers CVE-2026-102490, exploiting flawed parameter handling in an internal maintenance utility executed by the zammad account, elevating permissions to spawn a root shell.

[+] Rejetto HTTP File Server Session Forgery: In CVE-2026-61500, the session management component creates session signing keys utilizing the JavaScript Math.random function. Because Math.random is a non cryptographic PRNG whose internal state can be recovered after observing a sequence of outputs, an attacker samples multiple session cookies issued by the server. Using state reconstruction algorithms, the attacker determines the internal seed, calculates the secret HMAC signing key, crafts an arbitrary administrative session cookie, and logs in as administrator. Once inside, the attacker injects Node.js child_process commands into the server_code configuration parameter to achieve code execution.

[+] Atlassian Data Center Path Traversal via Double Colons: In CVE-2026-21589, Atlassian Data Center web applications implement path sanitization that strips standard slash directory traversal sequences. Attackers circumvent this check by utilizing double colon delimiters (..::). The application converts double colons into path separators during internal resource resolution, allowing an unauthenticated attacker to escape intended web directories and read sensitive files such as WEB-INF/web.xml.

+---------------------------------------------------------------------------------------------------+
|                                     NETWORK INDICATORS (DEFANGED)                                 |
+---------------------+-------------------------------+---------------------------------------------+
| Indicator Type      | Indicator Value               | Operational Context                         |
+---------------------+-------------------------------+---------------------------------------------+
| IPv4 Address        | 5.199.162[.]157               | UNC6240 Scanner, Staging and Attack Node    |
| IPv4 Address        | 104.219.234[.]138             | UNC6240 Remote Staging and Exfiltration     |
| IPv4 Address        | 162.219.30[.]165              | SIDEEYE C2 Server (TCP 3333, 3334)          |
| IPv4 Address        | 45.142.212[.]100              | Storm-2945 CaptiveCrunch / CornFlake C2     |
| IPv4 Address        | 185.220.101[.]42              | PoeLLM Botnet Command and Scanning Node     |
| IPv4 Address        | 103.253.41[.]98               | Rejetto HFS Exploit Scanning Source         |
| IPv4 Address        | 194.26.192[.]77               | Kryptex Mining Pool Gateway Node            |
| Domain Name         | captive-portal-login[.]com    | Storm-2945 Rogue Wi-Fi Captive Portal       |
| Domain Name         | winmanage-me[.]network        | UNC6240 MeshCentral Persistence Host        |
| Domain Name         | kryptex[.]cc                  | Illicit Monero Mining Pool Endpoint         |
| Domain Name         | update-netscaler-patch[.]com  | Suspected NetScaler Phishing Infrastructure

+---------------------------------------------------------------------------------------------------+
|                                       HOST AND FILE INDICATORS                                    |
+---------------------+-----------------------------------------------------------------------------+
| Indicator Type      | Indicator Value / Path / Hash                                               |
+---------------------+-----------------------------------------------------------------------------+
| SHA256 Hash         | 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 (x.jsp)    |
| SHA256 Hash         | 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 (u.jsp)    |
| SHA256 Hash         | 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86 (tun.jsp) |
| SHA256 Hash         | ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07 (tun.jspx)|
| SHA256 Hash         | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 (Ple64)  |
| File Path           | /ns/config/httpd.conf (Modified with non script PHP handlers)               |
| File Path           | /PSEMHUB.war/x.jsp (PeopleSoft JSP command shell)                           |
| File Path           | /PSEMHUB.war/u.jsp (PeopleSoft JSP file uploader)                           |
| File Path           | /PORTAL.war/tunnel.jsp (Neo-reGeorg SOCKS tunnel endpoint)                  |
| Executable Name     | Ple64.exe (Light Alloy installer dropping SIDEEYE backdoor)

+---------------------------------------------------------------------------------------------------+
|                                    APPLICATION REQUEST SIGNATURES                                 |
+---------------------+-----------------------------------------------------------------------------+
| Signature Type      | Signature Pattern / Defanged URL String                                     |
+---------------------+-----------------------------------------------------------------------------+
| URI Path            | /%50SEMHUB/hub (Oracle PeopleSoft WAF encoding bypass)                      |
| URI Path            | /%6a_security_check (Cisco Catalyst SD-WAN Manager authentication bypass)   |
| URI Path            | ..::..::..::WEB-INF::web.xml (Atlassian Data Center path traversal)         |
| Defanged URL        | hxxps://github[.]com/ejejejdfbbebe/raw/main/poem[.]txt (PoeLLM C2 Payload)  |
| Defanged URL        | hxxps://captive-portal-login[.]com/auth?ssid=Free_WiFi (Storm-2945 Lure)   |
| Header Pattern      | Base64 encoded execution strings embedded within standard HTTP headers

SIGMA Detection Rule: Citrix NetScaler Modified Web Configuration

title: Citrix NetScaler Web Server Configuration Tampering
status: experimental
description: Detects unauthorized modifications to NetScaler Apache httpd.conf adding PHP execution handlers
logsource:
    category: file_event
    product: linux
detection:
    selection:
        file.path: '/ns/config/httpd.conf'
        event.type: 'change'
    filter_content:
        file.data|contains:
            - 'AddType application/x-httpd-php .css'
            - 'AddType application/x-httpd-php .png'
            - 'AddHandler php5-script'
    condition: selection and filter_content
falsepositives:
    - Official firmware updates executing during scheduled maintenance
level: critical
tags:
    - attack.initial_access
    - attack.T1190
    - attack.persistence
    - attack.T1543.003

SIGMA Detection Rule: PeopleSoft Encoded WAF Bypass and Shell Creation

title: Oracle PeopleSoft Encoded PSEMHUB Access
status: experimental
description: Detects HTTP requests utilizing URL encoded variations of PSEMHUB to circumvent WAF filtering
logsource:
    category: webserver
detection:
    selection_uri:
        cs-uri-stem|contains:
            - '/%50SEMHUB/'
            - '/%50semhub/'
            - '/%2550SEMHUB/'
    selection_method:
        cs-method: 'POST'
    condition: selection_uri and selection_method
falsepositives:
    - None expected in standard enterprise environments
level: critical
tags:
    - attack.initial_access
    - attack.T1190
    - attack.defense_evasion
    - attack.T1027

SIGMA Detection Rule: Cisco SD-WAN Encoded Authentication Bypass

title: Cisco Catalyst SD-WAN URI Encoded Authentication Attempt
status: experimental
description: Detects attempts to access administrative endpoints via encoded j_security_check URIs
logsource:
    category: webserver
detection:
    selection:
        cs-uri-stem|contains:
            - '/%6a_security_check'
            - '/%6A_security_check'
            - '/%256a_security_check'
    condition: selection
falsepositives:
    - None expected
level: critical
tags:
    - attack.initial_access
    - attack.T1190
    - attack.defense_evasion

YARA Rule: WHIPSHOT PHP Web Shell

rule WHIPSHOT_NetScaler_WebShell {
    meta:
        description = "Detects WHIPSHOT PHP web shells parsing Base64 execution headers"
        author = "CTI Research Team"
        date = "2026-10-08"
        confidence = "High"
    strings:
        $php_tag = "<?php" ascii
        $b64_decode = "base64_decode" ascii
        $http_prefix = "HTTP_" ascii
        $server_var = "$_SERVER" ascii
        $eval_call = "eval(" ascii
        $exec_call = "shell_exec(" ascii
    condition:
        $php_tag at 0 and
        $server_var and
        $b64_decode and
        $http_prefix and
        ($eval_call or $exec_call)
}

YARA Rule: SIDEEYE Backdoor Implant

rule SIDEEYE_Enterprise_Backdoor {
    meta:
        description = "Detects SIDEEYE backdoor binaries communicating over raw TCP ports"
        author = "CTI Research Team"
        date = "2026-10-08"
        confidence = "High"
    strings:
        $tcp_port1 = ":3333" ascii
        $tcp_port2 = ":3334" ascii
        $mesh_ref = "winmanage-me.network" ascii nocase
        $cmd_str = "cmd.exe /c" ascii wide
        $magic_win = "MZ"
    condition:
        $magic_win at 0 and
        ($mesh_ref or ($tcp_port1 and $tcp_port2)) and
        $cmd_str
}

YARA Rule: PoeLLM Artificial Intelligence Mining Loader

rule PoeLLM_AI_Miner_Loader {
    meta:
        description = "Detects PoeLLM cryptocurrency mining loaders deployed on AI hosts"
        author = "CTI Research Team"
        date = "2026-10-08"
        confidence = "High"
    strings:
        $c2_poem = "github.com/ejejejdfbbebe/raw/main/poem.txt" ascii
        $pool_ref = "kryptex.cc" ascii
        $stratum = "stratum+tcp://" ascii
        $target_ports = "3000, 4000, 11434" ascii
    condition:
        2 of them
}

SIEM Detection Logic (Splunk SPL)

index=netscaler sourcetype="netscaler:aaa" (uri_path="*SAMLResponse*" OR uri_path="*/oauth/idp/authenticate*")
| eval payload_len=len(http_request_body)
| where payload_len > 4096
| stats count by src_ip, uri_path, payload_len
| where count > 5

index=web_proxy sourcetype="access_combined"
| rex field=uri "(?i)(?<traversal>\.\.::|\/%50SEMHUB\/|\/%6a_security_check)"
| stats count by src_ip, dest_ip, uri, traversal
| where isnotnull(traversal)
| eval alert_severity="Critical"

index=linux_secure sourcetype="syslog"
| search process="zammad" AND ("sudo" OR "su -" OR "chmod 777" OR "chown root")
| stats count by host, user, process, command
| where count > 0

MITRE ATT&CK Mapping Matrix

+---------------------------------------------------------------------------------------------------+
|                                    MITRE ATT&CK TECHNIQUE MAPPING                                 |
+---------------------+-------------------+---------------------+-----------------------------------+
| Tactic Name         | Technique ID      | Technique Name      | Operational Evidence Context      |
+---------------------+-------------------+---------------------+-----------------------------------+
| Initial Access      | T1190             | Exploit Public App  | NetScaler, PeopleSoft, Cisco, etc.|
| Initial Access      | T1133             | External Remote Svc | Captive wireless portal hijacking |
| Execution           | T1059.003         | Windows Command Sh  | PeopleSoft WebLogic shell spawning|
| Execution           | T1059.004         | Unix Shell          | Zammad daemon command execution   |
| Execution           | T1059.006         | Python              | SLAPSHOT tunneling tool execution |
| Execution           | T1059.007         | JavaScript          | Rejetto HFS server_code execution |
| Persistence         | T1505.003         | Web Shell           | WHIPSHOT, x.jsp, WordPress plugins|
| Persistence         | T1543.003         | Modify Web Config   | Citrix httpd.conf Apache patching |
| Privilege Escalation| T1068             | Exploit Privilege   | Zammad local root exploitation    |
| Privilege Escalation| T1078             | Valid Accounts      | Rejetto forged session cookies    |
| Defense Evasion     | T1027             | Obfuscated Files    | Base64 header commands, %50 bypass|
| Credential Access   | T1566.005         | Device Code Phish   | Storm-2945 hospitality M365 lures |
| Credential Access   | T1552.001         | Credentials in File | Atlassian web.xml database reads  |
| Discovery           | T1046             | Network Scanning    | PoeLLM botnet port discovery      |
| Lateral Movement    | T1021             | Remote Services     | Atlassian Crowd instance pivot    |
| Command and Control | T1071.001         | Web Protocols       | WHIPSHOT, PoeLLM GitHub channel   |
| Command and Control | T1090.001         | Internal Proxy      | SLAPSHOT NetScaler TCP forwarding |
| Impact              | T1496             | Resource Hijacking  | PoeLLM Monero mining across AI hosts

MITRE D3FEND Defensive Mapping

+---------------------------------------------------------------------------------------------------+
|                                      MITRE D3FEND COUNTERMEASURES                                 |
+---------------------+-------------------------------------+---------------------------------------+
| D3FEND ID           | Defensive Technique Name            | Target Threat Application             |
+---------------------+-------------------------------------+---------------------------------------+
| D3-PSA              | Protocol Analysis                   | Detect malformed DTLS & SAML packets  |
| D3-URI              | Uniform Resource Identifier Analysis| Inspect encoded %50 and %6a strings   |
| D3-SFP              | Session Fixation Prevention         | Enforce session key regeneration      |
| D3-SWM              | Software Whitelisting               | Block unauthorized WordPress plugins  |
| D3-PAM              | Privileged Access Management        | Restrict service account sudo rights  |
| D3-NSM              | Network Security Monitoring         | Alert on raw TCP connections on 3333

Chapter 05 - Governance, Risk & Compliance

[+] Regulatory Compliance Deadlines: United States federal civilian agencies are bound by binding operational directives enforcing accelerated remediation timelines for vulnerabilities listed in the known exploited catalog. Non federal commercial organizations should adhere to identical deadlines to limit legal liability and demonstrate adherence to common duty of care standards.

[+] General Data Protection Regulation Risk: The confirmed exploitation of helpdesk platforms, collaboration software, and e-commerce push notification infrastructures creates high exposure under international privacy frameworks. Unauthorized data access involving helpdesk ticket histories, customer records, or human resources repositories mandates documented forensic investigations and supervisory authority notification within 72 hours of incident confirmation.

[+] Payment Card Industry Data Security Standards: The compromise of perimeter network gateways, mail hygiene systems, and content management systems directly impacts systems maintaining access to cardholder data environments. Requirements mandate critical security patch deployment within 30 days of release, though actively exploited vulnerabilities require emergency patch procedures accompanied by comprehensive segmentation validation.

[+] Artificial Intelligence Workload Governance: Enterprise adoption of machine learning models requires formal incorporation into enterprise asset inventories. Unauthenticated local inference interfaces, model caching layers, and container orchestration frameworks cannot operate in isolation from corporate vulnerability management programs. Compute resources must adhere to baseline identity boundaries, egress traffic filtering, and resource usage quotas.

[+] Supply Chain and Third Party Oversight: Widespread exploitation across enterprise collaboration and infrastructure management platforms highlights critical supply chain exposure. Vendor risk assessments must verify that managed service providers and hosting partners have patched appliance exposures and hardened perimeter APIs against path traversal and encoding bypasses.

Chapter 06 - Adversary Emulation

+---------------------------------------------------------------------------------------------------+
|                                 PURPLE TEAM VALIDATION SCENARIOS                                  |
+--------------------+------------------------------------------------------------------------------+
| Target Scenario    | Detailed Adversary Emulation Procedure                                       |
+--------------------+------------------------------------------------------------------------------+
| NetScaler Shell    | 1. Append test handler to non production httpd.conf executing .css via PHP  |
|                    | 2. Stage benign Canary script styles.css decoding custom HTTP headers        |
|                    | 3. Send test request with Base64 header; verify EDR process tree alerting   |
+--------------------+------------------------------------------------------------------------------+
| PeopleSoft WAF     | 1. Issue HTTP POST to test endpoint utilizing /%50SEMHUB/hub URI syntax      |
|                    | 2. Evaluate whether inspection filters drop or forward the request           |
|                    | 3. Confirm that back end web server logs record path normalization events    |
+--------------------+------------------------------------------------------------------------------+
| Cisco SD-WAN API   | 1. Dispatch benign POST to /%6a_security_check on isolated test manager      |
|                    | 2. Measure whether WAF rules match on hex characters or allow execution     |
|                    | 3. Validate SIEM correlation alerting on URI encoding anomalies             |
+--------------------+------------------------------------------------------------------------------+
| Zammad Hijack      | 1. Establish pre set session cookie on test helpdesk user browser            |
|                    | 2. Complete authentication; confirm whether session token is regenerated    |
|                    | 3. Attempt role modification; verify security audit log generation          |
+--------------------+------------------------------------------------------------------------------+
| Atlassian Traversal| 1. Submit HTTP request containing ..::..:: traversal syntax to test host     |
|                    | 2. Verify that network edge filters identify double colon bypass patterns    |
|                    | 3. Inspect application logs to ensure access to WEB-INF files is rejected

Intelligence Confidence88%
+---------------------------------------------------------------------------------------------------+
|                                   CONFIDENCE ASSESSMENT MATRIX                                    |
+-----------------------+---------------------------------------------------+-----------------------+
| Intelligence Vector   | Analytical Finding and Underlying Evidence        | Confidence Level      |
+-----------------------+---------------------------------------------------+-----------------------+
| Vendor Advisories     | Technical bulletins from Citrix, Cisco, Fortinet, | High Confidence       |
|                       | Oracle, Atlassian, and SonicWall                  |                       |
+-----------------------+---------------------------------------------------+-----------------------+
| Government Catalogs   | Authoritative catalog inclusion confirming wild   | High Confidence       |
|                       | attacks across five major vulnerability issues    |                       |
+-----------------------+---------------------------------------------------+-----------------------+
| Technical PoC Data    | Validated proof of concepts published by multiple | High Confidence       |
|                       | independent research teams confirming mechanics   |                       |
+-----------------------+---------------------------------------------------+-----------------------+
| Attribution Modeling  | Specific campaign overlaps substantiated by first | Medium Confidence     |
|                       | party forensic telemetry from consulted sources   |                       |
+-----------------------+---------------------------------------------------+-----------------------+
| Indicator Completeness| Fully validated IOCs for specific campaigns; some | Medium Confidence     |
|                       | opportunistic scanning IPs remain under analysis