Back to Intelligence

Kimsuky XenoRAT, Longlegs Warlock Ransomware & Municipal Webshell Campaigns: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 2, 2026
12 min read

Three concurrent threat streams dominate this OTX pull, and together they sketch a familiar but accelerating pattern: state-nexus operators are pairing low-cost initial access vectors (spear-phishing LNKs, public-facing application exploits, legitimate feature abuse) with high-impact post-exploitation objectives ranging from espionage to ransomware-driven extortion.

Stream 1 — Kimsuky / XenoRAT (Espionage): The North Korea-nexus Kimsuky group ran at least six distinct attack variations against South Korean targets during August 2026, all initiated through spear-phishing emails carrying malicious LNK files. Execution chains branch into PowerShell scripts, AutoIt-compiled payloads, and DLL side-loading, with one variant (Type A) extracting HEX-encoded payloads and using PubNub as a C2 channel — a living-off-the-cloud technique designed to blend C2 traffic into legitimate messaging infrastructure. Type B abuses the signed curl.exe binary to retrieve HTA stages. The endgame is XenoRAT, an open-source remote access trojan repurposed for infostealing and surveillance.

Stream 2 — Longlegs / Warlock Ransomware (Extortion): The China-nexus group Longlegs continues to deploy Warlock ransomware against critical infrastructure — water utilities, telecom operators, government bodies, and universities across Portuguese- and Spanish-speaking regions in Europe, Africa, and Latin America. Initial access is almost exclusively the SharePoint ToolShell exploit chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), with CVE-2025-1055 also observed. This is deliberate critical-infrastructure targeting for maximum extortion leverage.

Stream 3 — Municipal Platform Webshell Intrusions (Data & Payment Theft): An unidentified, likely China-based actor compromised three web servers running recreation management software for municipalities and parks organizations. After repeated failed exploit attempts against CVE-2025-26399, the actor pivoted to registering legitimate user accounts and abusing the member file upload function to plant webshells. Post-compromise activity included timestomping, system enumeration, database credential extraction, payment card theft, and the use of AI-generated scripts to accelerate operations.

Collective read: Defenders should note the convergence — all three campaigns exploit the gap between perimeter trust (email attachments, unpatched edge applications, self-service upload features) and internal detection. Every one of these intrusions was detectable at the execution and post-exploitation layer.

Threat Actor / Malware Profile

Kimsuky + XenoRAT

  • Distribution: Spear-phishing emails with LNK file attachments masquerading as documents (invoices, event invitations, policy papers) targeting South Korean government, academic, and diplomatic entities.
  • Payload behavior: LNK shortcuts invoke powershell.exe or mshta.exe to decode embedded HEX or Base64 payloads. Type A writes decoded payloads to disk and executes via DLL side-loading against legitimate signed binaries. Type B uses curl.exe (LOLBin) to pull HTA second stages. Final payload is XenoRAT providing keylogging, credential theft, screen capture, and file exfiltration.
  • C2 communication: Type A leverages the PubNub publish/subscribe API as a dead-drop C2 channel — traffic appears as legitimate TLS to PubNub infrastructure. Type B stages from attacker-controlled domains (www.cwmodern.com, www.dolgicap.com).
  • Persistence: DLL side-loading into trusted processes; registry Run keys and scheduled tasks have been observed in historical Kimsuky tradecraft.
  • Anti-analysis: HEX-encoded payload extraction, AutoIt script compilation, staged delivery, and abuse of signed Microsoft binaries (curl.exe, mshta.exe, powershell.exe) to evade application control.

Longlegs + Warlock Ransomware

  • Distribution: Exploitation of internet-facing Microsoft SharePoint servers via the ToolShell chain — CVE-2025-49704 (deserialization), CVE-2025-49706 (spoofing/auth bypass), chained and re-weaponized as CVE-2025-53770 and CVE-2025-53771 after initial patches were bypassed. CVE-2025-1055 also observed in the exploit set.
  • Payload behavior: ToolShell drops an ASPX webshell (commonly spinstall0.aspx variants) used to steal SharePoint MachineKeys, enabling forged ViewState tokens and persistent unauthenticated RCE. Warlock ransomware is then staged for domain-wide encryption, typically preceded by data exfiltration for double extortion.
  • C2 / exfiltration: Rclone and similar sync tooling to attacker-controlled cloud storage; webshell-based tasking over HTTPS.
  • Persistence: Stolen cryptographic material (ValidationKey/DecryptionKey) survives patching — attackers retain access even after CVE remediation unless MachineKeys are rotated.
  • Anti-analysis: Exploitation occurs inside the IIS worker process (w3wp.exe), minimizing endpoint artifacts; timestomped webshells blend into legitimate SharePoint directories.

Municipal Webshell Actor (Unknown, China-based infrastructure)

  • Distribution: Attempted exploitation of CVE-2025-26399, followed by abuse of legitimate account registration and the member file upload function of the recreation management platform.
  • Payload behavior: Uploaded webshells provide remote command execution; actor enumerated systems, dumped database credentials from configuration files, and moved toward payment card data stores.
  • Anti-analysis: Timestomping of dropped files to defeat timeline forensics; use of AI-generated scripts for rapid, adaptive post-exploitation tooling that evades signature-based detection.
  • Objective: Credential harvesting and payment card theft from municipal systems — a soft-target sector with historically weak segmentation.

IOC Analysis

The indicator set across these pulses decomposes into four operational classes:

  1. File hashes (MD5/SHA1/SHA256): 20+ hashes covering XenoRAT payload stages, Kimsuky LNK droppers, webshells, and Warlock ToolShell artifacts. Hashes are the weakest per-indicator (trivially re-mutable) but valuable for retro-hunting in EDR telemetry, email gateways, and web server directories. Load into your EDR blocklist and run a 90-day lookback sweep — webshells and ToolShell ASPX files frequently sit dormant for weeks before tasking.
  2. Hostnames (www.cwmodern.com, www.dolgicap.com): Kimsuky staging infrastructure. Block at DNS and proxy layers; hunt for historical resolutions in DNS logs. These domains impersonate legitimate business sites — expect TLS with valid certificates, so certificate transparency and JA3/JA4 fingerprinting add detection value beyond simple domain blocking.
  3. CVEs (CVE-2025-26399, CVE-2025-49704/49706/53770/53771, CVE-2025-1055): These are your exposure map, not detections. Prioritize internet-facing SharePoint — the ToolShell chain allows pre-auth RCE. Critically: patching alone is insufficient for ToolShell; rotate SharePoint ASP.NET MachineKeys via the official Microsoft script, or assume retained access.
  4. Behavioral indicators: The strongest signals here are behaviors, not atoms — PubNub API abuse for C2, curl.exe pulling HTA from rare external domains, w3wp.exe spawning shells or dropping ASPX files, and file uploads from newly registered accounts followed by anomalous file timestamps.

Operationalization: Ingest hashes into MISP/your TIP and sync to EDR and email security. Domain IOCs go to DNS firewall/proxy. CVEs go to the vulnerability management queue with internet-facing assets flagged P1. Behavioral logic goes to the SIEM via the detection pack below.

Detection Engineering

YAML
---
title: Kimsuky XenoRAT - Suspicious LNK Spawn and LOLBin Staging
id: 7f3a9c1e-2b4d-4e8a-9f5c-1a2b3c4d5e6f
status: experimental
description: Detects execution chains consistent with Kimsuky XenoRAT campaigns - explorer-spawned LNK files launching PowerShell, mshta, or curl.exe retrieving HTA payloads from external infrastructure.
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\explorer.exe'
  selection_child_img:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\mshta.exe'
      - '\curl.exe'
  selection_child_cmd:
    CommandLine|contains:
      - '.lnk'
      - '.hta'
      - 'FromBase64String'
      - '-enc'
      - 'http://'
      - 'https://'
  condition: selection_parent and selection_child_img and selection_child_cmd
falsepositives:
  - Legitimate administrative scripting
  - Software deployment tooling using curl or HTA installers
level: high
tags:
  - attack.initial_access
  - attack.t1204.002
  - attack.t1105
  - attack.t1218.005
---
title: PubNub API Abuse for Malware Command and Control
id: 8a4b0d2f-3c5e-5f9b-0a6d-2b3c4d5e6f7a
status: experimental
description: Detects process network or command-line interaction with PubNub publish/subscribe infrastructure, abused by Kimsuky XenoRAT Type A variants as a covert C2 channel blended into legitimate messaging traffic.
author: Security Arsenal Threat Intel
logsource:
  category: network_connection
  product: windows
detection:
  selection_domain:
    DestinationHostname|contains:
      - 'pubnub.com'
      - 'pubnubapi.com'
      - 'ps.pndsn.com'
  selection_process:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  condition: selection_domain and selection_process
falsepositives:
  - Legitimate applications embedding PubNub SDKs executed via script engines (rare in enterprise)
level: high
tags:
  - attack.command_and_control
  - attack.t1102
  - attack.t1071.001
---
title: SharePoint ToolShell - IIS Worker Process Spawning Shell or Writing ASPX
id: 9b5c1e3a-4d6f-6a0c-1b7e-3c4d5e6f7a8b
status: experimental
description: Detects SharePoint ToolShell exploitation (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) via w3wp.exe spawning command shells, PowerShell, or encoding tools, consistent with webshell deployment and MachineKey theft.
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\w3wp.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\net.exe'
      - '\net1.exe'
      - '\whoami.exe'
      - '\certutil.exe'
      - '\rundll32.exe'
  filter_iis_worker:
    CommandLine|contains: 'w3wp.exe'
  condition: selection_parent and selection_child and not filter_iis_worker
falsepositives:
  - Rare - legitimate SharePoint solutions spawning child processes
  - SharePoint administrative tooling (verify against change windows)
level: critical
tags:
  - attack.execution
  - attack.t1190
  - attack.t1505.003
  - attack.t1059
KQL — Microsoft Sentinel / Defender
// Security Arsenal - Combined hunt: Kimsuky staging domains, ToolShell webshell behavior, XenoRAT LOLBin chains
// Lookback: 30 days | Tables: DeviceNetworkEvents, DeviceProcessEvents, DeviceFileEvents
let Lookback = 30d;
let KimsukyDomains = dynamic(["www.cwmodern.com", "www.dolgicap.com"]);
let NetworkHits = DeviceNetworkEvents
    | where TimeGenerated > ago(Lookback)
    | where RemoteUrl has_any (KimsukyDomains)
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType
    | extend HuntSignal = "Kimsuky C2/Staging Domain Contact";
let ToolShellHits = DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where InitiatingProcessFileName =~ "w3wp.exe"
    | where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","net.exe","whoami.exe","certutil.exe","rundll32.exe")
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256
    | extend HuntSignal = "SharePoint ToolShell - w3wp Child Process";
let XenoRATHits = DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where InitiatingProcessFileName =~ "explorer.exe"
    | where FileName in~ ("powershell.exe","mshta.exe","curl.exe")
    | where ProcessCommandLine has_any (".lnk", ".hta", "FromBase64String", "-enc", "http")
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256
    | extend HuntSignal = "XenoRAT LNK/LOLBin Execution Chain";
let WebshellHits = DeviceFileEvents
    | where TimeGenerated > ago(Lookback)
    | where FolderPath has_any ("\\inetpub\\", "\\wwwroot\\", "LAYOUTS", "TEMPLATE")
    | where FileName endswith ".aspx"
    | where ActionType == "FileCreated"
    | project TimeGenerated, DeviceName, FolderPath, FileName, InitiatingProcessFileName, SHA256
    | extend HuntSignal = "Webshell ASPX Drop in Web Root";
union NetworkHits, ToolShellHits, XenoRATHits, WebshellHits
| order by TimeGenerated desc
PowerShell
# Security Arsenal - XenoRAT / ToolShell / Webshell IOC Hunt Script
# Run elevated on endpoints and SharePoint/web servers. Outputs findings to CSV.

$Results = @()
$ReportPath = "$env:TEMP\SA_IOC_Hunt_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv"

# --- 1. Known-bad hash sweep (OTX pulse indicators) ---
$BadHashes = @(
    # Kimsuky XenoRAT LNK droppers (MD5)
    '0099bf67cfa72030c1c317240441f3b8','01e099f0947d0ef7bcb967063d761fa6',
    '02f87ffe09edad431746660b310956c5','03be987cd4c4e1e788f803ca6e464a29',
    '06b3b6fbf106d46534459d2189aac739',
    # Municipal webshells (SHA256)
    '0d8f7bf30aa1ac95d59fed24c433dd2b3d57767f38c088721699c841c6e861d3',
    '0d93c3a8ded46887f79ac4ca7f238c458de2231243176f6c05062e34f238d19a',
    '5f69ff7a2e024f94cc5f816fa16c90054b09d9ac430b1f8b0631dfdd4472905e',
    '7bb594a77f726bf21a49f717024f2915f82f47eb623d2ad305259301de1f1ab4',
    'b06b581d91f4108900d188c3ee1af18502a8cb65d4e101663b791bd670867485',
    'e9dee286069afb6b411febb96b91a963cd16baffbf8b6aa951e0ef1a7e0e3879',
    # Warlock / ToolShell artifacts
    '206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261',
    '80961850786d6531f075b8a6f9a756ad',
    'b0b912a3fd1c05d72080848ec4c92880004021a1'
)

$ScanPaths = @($env:TEMP, $env:APPDATA, "$env:USERPROFILE\Downloads", 'C:\Users\Public', 'C:\inetpub')
foreach ($Path in $ScanPaths) {
    if (Test-Path $Path) {
        Get-ChildItem -Path $Path -Recurse -File -ErrorAction SilentlyContinue |
            Where-Object { $_.Length -lt 50MB } |
            ForEach-Object {
                $h256 = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
                $hmd5 = (Get-FileHash $_.FullName -Algorithm MD5 -ErrorAction SilentlyContinue).Hash
                $hsha1 = (Get-FileHash $_.FullName -Algorithm SHA1 -ErrorAction SilentlyContinue).Hash
                if ($BadHashes -contains $h256 -or $BadHashes -contains $hmd5.ToLower() -or $BadHashes -contains $hsha1.ToLower()) {
                    $Results += [PSCustomObject]@{Check='HashMatch'; Path=$_.FullName; Detail="SHA256:$h256"; Host=$env:COMPUTERNAME}
                }
            }
    }
}

# --- 2. Recent LNK files spawning script interpreters (XenoRAT chain) ---
Get-ChildItem -Path "$env:USERPROFILE\Downloads", "$env:USERPROFILE\Desktop", $env:TEMP -Filter *.lnk -ErrorAction SilentlyContinue |
    Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-45) } |
    ForEach-Object {
        $shell = New-Object -ComObject WScript.Shell
        $sc = $shell.CreateShortcut($_.FullName)
        if ($sc.TargetPath -match 'powershell|mshta|curl|wscript' -or $sc.Arguments -match '-enc|FromBase64String|http') {
            $Results += [PSCustomObject]@{Check='SuspiciousLNK'; Path=$_.FullName; Detail="$($sc.TargetPath) $($sc.Arguments)"; Host=$env:COMPUTERNAME}
        }
    }

# --- 3. Active connections to Kimsuky staging domains ---
$KimsukyHosts = @('www.cwmodern.com','www.dolgicap.com')
foreach ($h in $KimsukyHosts) {
    try {
        $ips = (Resolve-DnsName $h -ErrorAction Stop).IPAddress
        foreach ($ip in $ips) {
            $conn = Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | Where-Object { $_.RemoteAddress -eq $ip }
            if ($conn) {
                $proc = (Get-Process -Id $conn[0].OwningProcess -ErrorAction SilentlyContinue).ProcessName
                $Results += [PSCustomObject]@{Check='C2Connection'; Path=$h; Detail="Connected to $ip via $proc"; Host=$env:COMPUTERNAME}
            }
        }
    } catch {}
}

# --- 4. ToolShell artifacts: ASPX webshells in SharePoint directories ---
$SPLayouts = @('C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS',
               'C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\TEMPLATE\LAYOUTS')
foreach ($dir in $SPLayouts) {
    if (Test-Path $dir) {
        Get-ChildItem $dir -Filter *.aspx -ErrorAction SilentlyContinue |
            Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-90) -and $_.Name -match 'spinstall|sp\w{4,}\.aspx' } |
            ForEach-Object {
                $Results += [PSCustomObject]@{Check='ToolShellWebshell'; Path=$_.FullName; Detail="Created:$($_.CreationTime) Modified:$($_.LastWriteTime)"; Host=$env:COMPUTERNAME}
            }
    }
}

# --- 5. Persistence audit: Run keys and suspicious scheduled tasks ---
$RunKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
             'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($rk in $RunKeys) {
    (Get-ItemProperty $rk -ErrorAction SilentlyContinue).PSObject.Properties |
        Where-Object { $_.Value -match 'powershell|mshta|curl|Temp|AppData' -and $_.Name -notmatch '^PS' } |
        ForEach-Object {
            $Results += [PSCustomObject]@{Check='PersistenceRunKey'; Path=$rk; Detail="$($_.Name) = $($_.Value)"; Host=$env:COMPUTERNAME}
        }
}
Get-ScheduledTask | Where-Object {
    $_.Actions.Execute -match 'powershell|mshta|wscript' -and $_.Actions.Arguments -match '-enc|http|FromBase64String'
} | ForEach-Object {
    $Results += [PSCustomObject]@{Check='SuspiciousScheduledTask'; Path=$_.TaskName; Detail="$($_.Actions.Execute) $($_.Actions.Arguments)"; Host=$env:COMPUTERNAME}
}

# --- Output ---
if ($Results.Count -gt 0) {
    $Results | Format-Table -AutoSize
    $Results | Export-Csv -Path $ReportPath -NoTypeInformation
    Write-Host "[ALERT] $($Results.Count) findings. Report: $ReportPath" -ForegroundColor Red
} else {
    Write-Host "[CLEAN] No IOC matches on $env:COMPUTERNAME" -ForegroundColor Green
}

Response Priorities

Immediate (0–4 hours)

  • Block www.cwmodern.com and www.dolgicap.com at DNS, proxy, and email gateway layers; retro-hunt 90 days of DNS resolution logs.
  • Push all pulse file hashes to EDR blocklists and run an enterprise-wide retro sweep, prioritizing web server directories, inetpub, SharePoint LAYOUTS folders, and user Download/Temp paths.
  • Inventory internet-facing SharePoint. If unpatched against CVE-2025-53770/53771, take offline or place behind WAF rules blocking ToolShell patterns — then patch and rotate ASP.NET MachineKeys immediately. Patching without key rotation leaves stolen-crypto persistence intact.
  • Hunt for w3wp.exe child processes and unexpected ASPX file creation on all web servers (KQL and PowerShell above).

24 Hours

  • All three campaigns involve credential theft (XenoRAT infostealing, database credential extraction, SharePoint MachineKey theft). Force credential resets for any account on a host with a confirmed hit, and invalidate active sessions/tokens.
  • Review new account registrations on public-facing platforms with upload functionality — the municipal actor registered legitimate accounts before weaponizing the upload feature. Flag accounts created shortly before anomalous uploads.
  • Audit PubNub (and similar pub/sub SaaS) traffic from endpoints — if your business doesn't use it, any endpoint TLS session to *.pubnub.com from script interpreters is anomalous.
  • Check SharePoint servers for MachineKey exfiltration indicators and validate ViewState integrity controls.

1 Week

  • SharePoint/edge architecture: Move SharePoint behind authenticated reverse proxy or VPN where feasible; deploy WAF virtual patching; implement EDR on all web tier servers — ToolShell executes almost entirely in-memory inside IIS and will evade AV-only defenses.
  • Email vector: Detonate all LNK attachments in sandboxing before delivery; consider blocking LNK file types at the gateway outright (negligible legitimate business use via email).
  • Upload hardening: For municipal/SaaS platforms, enforce file-type allowlisting with server-side MIME validation, store uploads outside the web root, disable script execution in upload directories, and add new-account velocity monitoring.
  • Timestomping resilience: Enable USN Journal monitoring and file creation time (MFT $STANDARD_INFORMATION vs $FILE_NAME) comparison in forensic tooling — the municipal actor's timestomping defeats naive timeline analysis.
  • Segmentation review: Water, telecom, and municipal networks hit by these campaigns shared flat topologies. Enforce segmentation between OT/utility systems and IT, and between web tiers and database/payment systems.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.