Full Report
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
Analysis Summary
# Incident Report: Exploitation of Recreation Management Platform
## Executive Summary
In September 2026, a threat actor, suspected to be operating from China, successfully compromised three municipal web servers by exploiting a file upload vulnerability in a popular recreation management software. The attacker utilized a combination of AI-generated scripts and manual techniques to deploy webshells, ultimately harvesting payment card data and injecting credential-stealing trojans. Despite initial defensive responses, the attacker demonstrated persistence by re-infecting a server that was returned to production without adequate remediation.
## Incident Details
- **Discovery Date:** September 10, 2026
- **Incident Date:** September 10, 2026
- **Affected Organization:** Multiple municipal tenants (Unnamed)
- **Sector:** Government / Local Municipalities (Parks & Recreation)
- **Geography:** Likely North America (based on software use); Attacker origin: China (suspected)
## Timeline of Events
### Initial Access
- **Date/Time:** September 10, 2026 (approx. 6-hour attempt window)
- **Vector:** Exploitation of file upload function via authenticated member account.
- **Details:** After 6 hours of failed unauthenticated probes (brute force, IIS 8.3 tilde enumeration, WebDAV manipulation), the attacker registered a legitimate member account and abused the "member files upload" function to bypass security controls.
### Lateral Movement
- The attacker moved between three distinct web servers belonging to the same platform provider, refining techniques with each compromise to avoid detection.
### Data Exfiltration/Impact
- **Payment Data Theft:** Attacker enumerated secure payment tenants and planted malicious scripts to harvest card information.
- **Credential Harvesting:** On the third server, the attacker injected a trojan into the authentication page to steal user credentials in real-time.
### Detection & Response
- **Discovery:** Detected by Huntress SOC monitoring through anomalous file uploads and webshell execution.
- **Response Actions:** Servers were taken offline for cleaning; however, one server was prematurely returned to production, leading to an immediate secondary compromise.
## Attack Methodology
- **Initial Access:** Valid account registration followed by File Upload vulnerability exploitation.
- **Persistence:** Malicious webshells and injected trojans in the authentication page.
- **Privilege Escalation:** Not explicitly detailed, but involved gaining enough access to modify core application scripts (`.aspx`).
- **Defense Evasion:** Renaming malicious files, manipulating metadata (timestomping), and switching tactics between servers.
- **Credential Access:** Real-time harvesting via a trojanized authentication page.
- **Discovery:** IIS 8.3 tilde enumeration and WebDAV `OPTIONS` probing.
- **Lateral Movement:** Repeated exploitation of the same vulnerability across shared infrastructure.
- **Collection:** Targeting of payment card data and sensitive tenant folders.
- **Exfiltration:** Likely via HTTP/S through the deployed webshells.
- **Impact:** Financial data theft and total compromise of user credentials.
## Impact Assessment
- **Financial:** High potential for loss due to stolen payment card data.
- **Data Breach:** Exposure of municipal member payment details and account credentials.
- **Operational:** Disruption of recreation services and emergency server shutdowns.
- **Reputational:** Loss of trust in municipal digital services and the management platform provider.
## Indicators of Compromise
- **Network:** Requests originating from IPs associated with China-based user-agents (Defanged: `User-Agent: [Specific Chinese Strings]`).
- **File:** Malicious `.aspx` and `.ashx` files; modified `Upload.ashx` and `FileUpload.ashx`.
- **Behavioral:** Unauthorized creation of member accounts followed immediately by file uploads to non-standard directories; Timestomping of file metadata.
## Response Actions
- **Containment:** Isolation of affected web servers.
- **Eradication:** Removal of webshells and reverting unauthorized code changes to the authentication page.
- **Recovery:** Full restoration of servers; Huntress advised against premature production release until root cause was addressed.
## Lessons Learned
- **AI-Assisted Attacks:** The volume and persistence of initial probes suggest attackers are effectively using AI to automate the "spray and pray" phase of attacks.
- **Premature Recovery Risks:** Returning a compromised system to production without fixing the underlying vulnerability (the file upload flaw) leads to immediate re-infection.
- **Defense Adaptability:** The attacker actively changed tactics (anti-forensics) once they realized they were being monitored.
## Recommendations
- **Input Validation:** Implement strict server-side validation for all file uploads, including file type, extension, and content headers.
- **Sanitize Upload Directories:** Ensure uploaded files are stored in a non-executable directory with restricted permissions.
- **Patch Management:** Address known IIS vulnerabilities (like 8.3 tilde enumeration) and update the management platform.
- **Multi-Factor Authentication (MFA):** Enforce MFA for both administrative and member accounts to hinder automated credential harvesting.
- **Continuous Monitoring:** Employ SOC services to detect behavioral anomalies that bypass traditional signature-based defenses.