Three concurrent threat streams dominate this OTX pull, and together they sketch a familiar but accelerating pattern: state-nexus operators are pairing low-cost initial access vectors (spear-phishing LNKs, public-facing application exploits, legitimate feature abuse) with high-impact post-exploitation objectives ranging from espionage to ransomware-driven extortion.
Stream 1 — Kimsuky / XenoRAT (Espionage): The North Korea-nexus Kimsuky group ran at least six distinct attack variations against South Korean targets during August 2026, all initiated through spear-phishing emails carrying malicious LNK files. Execution chains branch into PowerShell scripts, AutoIt-compiled payloads, and DLL side-loading, with one variant (Type A) extracting HEX-encoded payloads and using PubNub as a C2 channel — a living-off-the-cloud technique designed to blend C2 traffic into legitimate messaging infrastructure. Type B abuses the signed curl.exe binary to retrieve HTA stages. The endgame is XenoRAT, an open-source remote access trojan repurposed for infostealing and surveillance.
Stream 2 — Longlegs / Warlock Ransomware (Extortion): The China-nexus group Longlegs continues to deploy Warlock ransomware against critical infrastructure — water utilities, telecom operators, government bodies, and universities across Portuguese- and Spanish-speaking regions in Europe, Africa, and Latin America. Initial access is almost exclusively the SharePoint ToolShell exploit chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), with CVE-2025-1055 also observed. This is deliberate critical-infrastructure targeting for maximum extortion leverage.
Stream 3 — Municipal Platform Webshell Intrusions (Data & Payment Theft): An unidentified, likely China-based actor compromised three web servers running recreation management software for municipalities and parks organizations. After repeated failed exploit attempts against CVE-2025-26399, the actor pivoted to registering legitimate user accounts and abusing the member file upload function to plant webshells. Post-compromise activity included timestomping, system enumeration, database credential extraction, payment card theft, and the use of AI-generated scripts to accelerate operations.
Collective read: Defenders should note the convergence — all three campaigns exploit the gap between perimeter trust (email attachments, unpatched edge applications, self-service upload features) and internal detection. Every one of these intrusions was detectable at the execution and post-exploitation layer.
Threat Actor / Malware Profile
Kimsuky + XenoRAT
- Distribution: Spear-phishing emails with LNK file attachments masquerading as documents (invoices, event invitations, policy papers) targeting South Korean government, academic, and diplomatic entities.
- Payload behavior: LNK shortcuts invoke
powershell.exeormshta.exeto decode embedded HEX or Base64 payloads. Type A writes decoded payloads to disk and executes via DLL side-loading against legitimate signed binaries. Type B usescurl.exe(LOLBin) to pull HTA second stages. Final payload is XenoRAT providing keylogging, credential theft, screen capture, and file exfiltration. - C2 communication: Type A leverages the PubNub publish/subscribe API as a dead-drop C2 channel — traffic appears as legitimate TLS to PubNub infrastructure. Type B stages from attacker-controlled domains (
www.cwmodern.com,www.dolgicap.com). - Persistence: DLL side-loading into trusted processes; registry Run keys and scheduled tasks have been observed in historical Kimsuky tradecraft.
- Anti-analysis: HEX-encoded payload extraction, AutoIt script compilation, staged delivery, and abuse of signed Microsoft binaries (
curl.exe,mshta.exe,powershell.exe) to evade application control.
Longlegs + Warlock Ransomware
- Distribution: Exploitation of internet-facing Microsoft SharePoint servers via the ToolShell chain — CVE-2025-49704 (deserialization), CVE-2025-49706 (spoofing/auth bypass), chained and re-weaponized as CVE-2025-53770 and CVE-2025-53771 after initial patches were bypassed. CVE-2025-1055 also observed in the exploit set.
- Payload behavior: ToolShell drops an ASPX webshell (commonly
spinstall0.aspxvariants) used to steal SharePoint MachineKeys, enabling forged ViewState tokens and persistent unauthenticated RCE. Warlock ransomware is then staged for domain-wide encryption, typically preceded by data exfiltration for double extortion. - C2 / exfiltration: Rclone and similar sync tooling to attacker-controlled cloud storage; webshell-based tasking over HTTPS.
- Persistence: Stolen cryptographic material (ValidationKey/DecryptionKey) survives patching — attackers retain access even after CVE remediation unless MachineKeys are rotated.
- Anti-analysis: Exploitation occurs inside the IIS worker process (
w3wp.exe), minimizing endpoint artifacts; timestomped webshells blend into legitimate SharePoint directories.
Municipal Webshell Actor (Unknown, China-based infrastructure)
- Distribution: Attempted exploitation of CVE-2025-26399, followed by abuse of legitimate account registration and the member file upload function of the recreation management platform.
- Payload behavior: Uploaded webshells provide remote command execution; actor enumerated systems, dumped database credentials from configuration files, and moved toward payment card data stores.
- Anti-analysis: Timestomping of dropped files to defeat timeline forensics; use of AI-generated scripts for rapid, adaptive post-exploitation tooling that evades signature-based detection.
- Objective: Credential harvesting and payment card theft from municipal systems — a soft-target sector with historically weak segmentation.
IOC Analysis
The indicator set across these pulses decomposes into four operational classes:
- File hashes (MD5/SHA1/SHA256): 20+ hashes covering XenoRAT payload stages, Kimsuky LNK droppers, webshells, and Warlock ToolShell artifacts. Hashes are the weakest per-indicator (trivially re-mutable) but valuable for retro-hunting in EDR telemetry, email gateways, and web server directories. Load into your EDR blocklist and run a 90-day lookback sweep — webshells and ToolShell ASPX files frequently sit dormant for weeks before tasking.
- Hostnames (
www.cwmodern.com,www.dolgicap.com): Kimsuky staging infrastructure. Block at DNS and proxy layers; hunt for historical resolutions in DNS logs. These domains impersonate legitimate business sites — expect TLS with valid certificates, so certificate transparency and JA3/JA4 fingerprinting add detection value beyond simple domain blocking. - CVEs (CVE-2025-26399, CVE-2025-49704/49706/53770/53771, CVE-2025-1055): These are your exposure map, not detections. Prioritize internet-facing SharePoint — the ToolShell chain allows pre-auth RCE. Critically: patching alone is insufficient for ToolShell; rotate SharePoint ASP.NET MachineKeys via the official Microsoft script, or assume retained access.
- Behavioral indicators: The strongest signals here are behaviors, not atoms — PubNub API abuse for C2,
curl.exepulling HTA from rare external domains,w3wp.exespawning shells or dropping ASPX files, and file uploads from newly registered accounts followed by anomalous file timestamps.
Operationalization: Ingest hashes into MISP/your TIP and sync to EDR and email security. Domain IOCs go to DNS firewall/proxy. CVEs go to the vulnerability management queue with internet-facing assets flagged P1. Behavioral logic goes to the SIEM via the detection pack below.
Detection Engineering
---
title: Kimsuky XenoRAT - Suspicious LNK Spawn and LOLBin Staging
id: 7f3a9c1e-2b4d-4e8a-9f5c-1a2b3c4d5e6f
status: experimental
description: Detects execution chains consistent with Kimsuky XenoRAT campaigns - explorer-spawned LNK files launching PowerShell, mshta, or curl.exe retrieving HTA payloads from external infrastructure.
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_child_img:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\curl.exe'
selection_child_cmd:
CommandLine|contains:
- '.lnk'
- '.hta'
- 'FromBase64String'
- '-enc'
- 'http://'
- 'https://'
condition: selection_parent and selection_child_img and selection_child_cmd
falsepositives:
- Legitimate administrative scripting
- Software deployment tooling using curl or HTA installers
level: high
tags:
- attack.initial_access
- attack.t1204.002
- attack.t1105
- attack.t1218.005
---
title: PubNub API Abuse for Malware Command and Control
id: 8a4b0d2f-3c5e-5f9b-0a6d-2b3c4d5e6f7a
status: experimental
description: Detects process network or command-line interaction with PubNub publish/subscribe infrastructure, abused by Kimsuky XenoRAT Type A variants as a covert C2 channel blended into legitimate messaging traffic.
author: Security Arsenal Threat Intel
logsource:
category: network_connection
product: windows
detection:
selection_domain:
DestinationHostname|contains:
- 'pubnub.com'
- 'pubnubapi.com'
- 'ps.pndsn.com'
selection_process:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\wscript.exe'
- '\cscript.exe'
condition: selection_domain and selection_process
falsepositives:
- Legitimate applications embedding PubNub SDKs executed via script engines (rare in enterprise)
level: high
tags:
- attack.command_and_control
- attack.t1102
- attack.t1071.001
---
title: SharePoint ToolShell - IIS Worker Process Spawning Shell or Writing ASPX
id: 9b5c1e3a-4d6f-6a0c-1b7e-3c4d5e6f7a8b
status: experimental
description: Detects SharePoint ToolShell exploitation (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) via w3wp.exe spawning command shells, PowerShell, or encoding tools, consistent with webshell deployment and MachineKey theft.
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\w3wp.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\net.exe'
- '\net1.exe'
- '\whoami.exe'
- '\certutil.exe'
- '\rundll32.exe'
filter_iis_worker:
CommandLine|contains: 'w3wp.exe'
condition: selection_parent and selection_child and not filter_iis_worker
falsepositives:
- Rare - legitimate SharePoint solutions spawning child processes
- SharePoint administrative tooling (verify against change windows)
level: critical
tags:
- attack.execution
- attack.t1190
- attack.t1505.003
- attack.t1059
// Security Arsenal - Combined hunt: Kimsuky staging domains, ToolShell webshell behavior, XenoRAT LOLBin chains
// Lookback: 30 days | Tables: DeviceNetworkEvents, DeviceProcessEvents, DeviceFileEvents
let Lookback = 30d;
let KimsukyDomains = dynamic(["www.cwmodern.com", "www.dolgicap.com"]);
let NetworkHits = DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteUrl has_any (KimsukyDomains)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType
| extend HuntSignal = "Kimsuky C2/Staging Domain Contact";
let ToolShellHits = DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","net.exe","whoami.exe","certutil.exe","rundll32.exe")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256
| extend HuntSignal = "SharePoint ToolShell - w3wp Child Process";
let XenoRATHits = DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe","mshta.exe","curl.exe")
| where ProcessCommandLine has_any (".lnk", ".hta", "FromBase64String", "-enc", "http")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256
| extend HuntSignal = "XenoRAT LNK/LOLBin Execution Chain";
let WebshellHits = DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where FolderPath has_any ("\\inetpub\\", "\\wwwroot\\", "LAYOUTS", "TEMPLATE")
| where FileName endswith ".aspx"
| where ActionType == "FileCreated"
| project TimeGenerated, DeviceName, FolderPath, FileName, InitiatingProcessFileName, SHA256
| extend HuntSignal = "Webshell ASPX Drop in Web Root";
union NetworkHits, ToolShellHits, XenoRATHits, WebshellHits
| order by TimeGenerated desc
# Security Arsenal - XenoRAT / ToolShell / Webshell IOC Hunt Script
# Run elevated on endpoints and SharePoint/web servers. Outputs findings to CSV.
$Results = @()
$ReportPath = "$env:TEMP\SA_IOC_Hunt_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv"
# --- 1. Known-bad hash sweep (OTX pulse indicators) ---
$BadHashes = @(
# Kimsuky XenoRAT LNK droppers (MD5)
'0099bf67cfa72030c1c317240441f3b8','01e099f0947d0ef7bcb967063d761fa6',
'02f87ffe09edad431746660b310956c5','03be987cd4c4e1e788f803ca6e464a29',
'06b3b6fbf106d46534459d2189aac739',
# Municipal webshells (SHA256)
'0d8f7bf30aa1ac95d59fed24c433dd2b3d57767f38c088721699c841c6e861d3',
'0d93c3a8ded46887f79ac4ca7f238c458de2231243176f6c05062e34f238d19a',
'5f69ff7a2e024f94cc5f816fa16c90054b09d9ac430b1f8b0631dfdd4472905e',
'7bb594a77f726bf21a49f717024f2915f82f47eb623d2ad305259301de1f1ab4',
'b06b581d91f4108900d188c3ee1af18502a8cb65d4e101663b791bd670867485',
'e9dee286069afb6b411febb96b91a963cd16baffbf8b6aa951e0ef1a7e0e3879',
# Warlock / ToolShell artifacts
'206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261',
'80961850786d6531f075b8a6f9a756ad',
'b0b912a3fd1c05d72080848ec4c92880004021a1'
)
$ScanPaths = @($env:TEMP, $env:APPDATA, "$env:USERPROFILE\Downloads", 'C:\Users\Public', 'C:\inetpub')
foreach ($Path in $ScanPaths) {
if (Test-Path $Path) {
Get-ChildItem -Path $Path -Recurse -File -ErrorAction SilentlyContinue |
Where-Object { $_.Length -lt 50MB } |
ForEach-Object {
$h256 = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
$hmd5 = (Get-FileHash $_.FullName -Algorithm MD5 -ErrorAction SilentlyContinue).Hash
$hsha1 = (Get-FileHash $_.FullName -Algorithm SHA1 -ErrorAction SilentlyContinue).Hash
if ($BadHashes -contains $h256 -or $BadHashes -contains $hmd5.ToLower() -or $BadHashes -contains $hsha1.ToLower()) {
$Results += [PSCustomObject]@{Check='HashMatch'; Path=$_.FullName; Detail="SHA256:$h256"; Host=$env:COMPUTERNAME}
}
}
}
}
# --- 2. Recent LNK files spawning script interpreters (XenoRAT chain) ---
Get-ChildItem -Path "$env:USERPROFILE\Downloads", "$env:USERPROFILE\Desktop", $env:TEMP -Filter *.lnk -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-45) } |
ForEach-Object {
$shell = New-Object -ComObject WScript.Shell
$sc = $shell.CreateShortcut($_.FullName)
if ($sc.TargetPath -match 'powershell|mshta|curl|wscript' -or $sc.Arguments -match '-enc|FromBase64String|http') {
$Results += [PSCustomObject]@{Check='SuspiciousLNK'; Path=$_.FullName; Detail="$($sc.TargetPath) $($sc.Arguments)"; Host=$env:COMPUTERNAME}
}
}
# --- 3. Active connections to Kimsuky staging domains ---
$KimsukyHosts = @('www.cwmodern.com','www.dolgicap.com')
foreach ($h in $KimsukyHosts) {
try {
$ips = (Resolve-DnsName $h -ErrorAction Stop).IPAddress
foreach ($ip in $ips) {
$conn = Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | Where-Object { $_.RemoteAddress -eq $ip }
if ($conn) {
$proc = (Get-Process -Id $conn[0].OwningProcess -ErrorAction SilentlyContinue).ProcessName
$Results += [PSCustomObject]@{Check='C2Connection'; Path=$h; Detail="Connected to $ip via $proc"; Host=$env:COMPUTERNAME}
}
}
} catch {}
}
# --- 4. ToolShell artifacts: ASPX webshells in SharePoint directories ---
$SPLayouts = @('C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS',
'C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\15\TEMPLATE\LAYOUTS')
foreach ($dir in $SPLayouts) {
if (Test-Path $dir) {
Get-ChildItem $dir -Filter *.aspx -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-90) -and $_.Name -match 'spinstall|sp\w{4,}\.aspx' } |
ForEach-Object {
$Results += [PSCustomObject]@{Check='ToolShellWebshell'; Path=$_.FullName; Detail="Created:$($_.CreationTime) Modified:$($_.LastWriteTime)"; Host=$env:COMPUTERNAME}
}
}
}
# --- 5. Persistence audit: Run keys and suspicious scheduled tasks ---
$RunKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($rk in $RunKeys) {
(Get-ItemProperty $rk -ErrorAction SilentlyContinue).PSObject.Properties |
Where-Object { $_.Value -match 'powershell|mshta|curl|Temp|AppData' -and $_.Name -notmatch '^PS' } |
ForEach-Object {
$Results += [PSCustomObject]@{Check='PersistenceRunKey'; Path=$rk; Detail="$($_.Name) = $($_.Value)"; Host=$env:COMPUTERNAME}
}
}
Get-ScheduledTask | Where-Object {
$_.Actions.Execute -match 'powershell|mshta|wscript' -and $_.Actions.Arguments -match '-enc|http|FromBase64String'
} | ForEach-Object {
$Results += [PSCustomObject]@{Check='SuspiciousScheduledTask'; Path=$_.TaskName; Detail="$($_.Actions.Execute) $($_.Actions.Arguments)"; Host=$env:COMPUTERNAME}
}
# --- Output ---
if ($Results.Count -gt 0) {
$Results | Format-Table -AutoSize
$Results | Export-Csv -Path $ReportPath -NoTypeInformation
Write-Host "[ALERT] $($Results.Count) findings. Report: $ReportPath" -ForegroundColor Red
} else {
Write-Host "[CLEAN] No IOC matches on $env:COMPUTERNAME" -ForegroundColor Green
}
Response Priorities
Immediate (0–4 hours)
- Block
www.cwmodern.comandwww.dolgicap.comat DNS, proxy, and email gateway layers; retro-hunt 90 days of DNS resolution logs. - Push all pulse file hashes to EDR blocklists and run an enterprise-wide retro sweep, prioritizing web server directories,
inetpub, SharePointLAYOUTSfolders, and user Download/Temp paths. - Inventory internet-facing SharePoint. If unpatched against CVE-2025-53770/53771, take offline or place behind WAF rules blocking ToolShell patterns — then patch and rotate ASP.NET MachineKeys immediately. Patching without key rotation leaves stolen-crypto persistence intact.
- Hunt for
w3wp.exechild processes and unexpected ASPX file creation on all web servers (KQL and PowerShell above).
24 Hours
- All three campaigns involve credential theft (XenoRAT infostealing, database credential extraction, SharePoint MachineKey theft). Force credential resets for any account on a host with a confirmed hit, and invalidate active sessions/tokens.
- Review new account registrations on public-facing platforms with upload functionality — the municipal actor registered legitimate accounts before weaponizing the upload feature. Flag accounts created shortly before anomalous uploads.
- Audit PubNub (and similar pub/sub SaaS) traffic from endpoints — if your business doesn't use it, any endpoint TLS session to
*.pubnub.comfrom script interpreters is anomalous. - Check SharePoint servers for MachineKey exfiltration indicators and validate ViewState integrity controls.
1 Week
- SharePoint/edge architecture: Move SharePoint behind authenticated reverse proxy or VPN where feasible; deploy WAF virtual patching; implement EDR on all web tier servers — ToolShell executes almost entirely in-memory inside IIS and will evade AV-only defenses.
- Email vector: Detonate all LNK attachments in sandboxing before delivery; consider blocking LNK file types at the gateway outright (negligible legitimate business use via email).
- Upload hardening: For municipal/SaaS platforms, enforce file-type allowlisting with server-side MIME validation, store uploads outside the web root, disable script execution in upload directories, and add new-account velocity monitoring.
- Timestomping resilience: Enable USN Journal monitoring and file creation time (MFT
$STANDARD_INFORMATIONvs$FILE_NAME) comparison in forensic tooling — the municipal actor's timestomping defeats naive timeline analysis. - Segmentation review: Water, telecom, and municipal networks hit by these campaigns shared flat topologies. Enforce segmentation between OT/utility systems and IT, and between web tiers and database/payment systems.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.