Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-011
Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
Status
Active
Distinct actor
HIGH 87%
Named actor
INSUFFICIENT
First observed
17 May 2026
Last updated
17 May 2026
Motivation
Financial, credential theft and traffic monetisation (HIGH)
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-011 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

A 45-file credential-harvesting toolkit, a live Flask dashboard and a traffic-distribution monetisation layer across more than seventeen domains, deployed about two weeks after the vulnerability's disclosure. Registrar-level account locks and synchronised DNS changes across otherwise separate domain clusters are what tie the estate to one operator.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Sectors
Enterprise (Office 365)Web hostingCryptocurrencyAviationGovernment tax authorities

Multi-sector credential phishing behind a traffic-distribution monetisation layer.

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

infrastructure mx.plingest.com operator MX backend across otherwise-separate domain clusters
string 6e3644a97f844763a34565b865d35310 operator Linux machine-id
account-id pkAId=2143526812 operator traffic-monetisation customer account ID
domain adorarama.com operator-controlled TDS landing domain
brand Beast possible operator self-brand in toolkit filenames (unverified)

Infrastructure and tooling

Primary host
216.126.227.49 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
Custom Python and Bash harvesterFlask C2 dashboardParklogic TDS

MITRE ATT&CK

32 techniques across 11 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.