Back to Intelligence

Webshell Intrusion on Municipal Platforms + TA419 AiTM Credential Phishing: OTX Pulse Analysis — Detection & Hunt Pack

SA
Security Arsenal Team
October 2, 2026
9 min read

Threat Summary

Two live OTX pulses published 2026-10-02 reveal parallel credential-theft campaigns converging on government and policy-sector targets — a pattern consistent with China-aligned collection priorities.

Pulse 1 — Municipal webshell intrusion. An unknown actor compromised three web servers hosting recreation management software used by municipalities and parks organizations. The operator initially failed to exploit the application, then pivoted to registering legitimate accounts and abusing the member file-upload function to deploy webshells. Post-compromise activity included system enumeration, extraction of database credentials, timestomping to blend webshell timestamps with legitimate files, and — critically — payment card theft. The activity is tagged as China-based, uses AI-generated scripts, and references CVE-2025-26399. This is a classic espionage-plus-financial dual-motive intrusion: harvest credentials and PII from a low-maturity municipal target, then monetize payment data on criminal markets.

Pulse 2 — TA419 credential phishing (AiTM/BitB). China-aligned threat actor TA419 conducted July 2026 credential-phishing campaigns impersonating prominent economists and AI policymakers. Targets: AI experts at US think tanks, universities, legal organizations, and defense-adjacent institutions (US and Japan). The social engineering is patient: benign conversation-starter emails themed around AI policy (e.g., invitations to an "AI Policy Advisory Committee"), escalating after the target replies to a malicious file-sharing lure. TA419 uses a frameless Browser-in-the-Browser (BitB) technique — a convincingly rendered fake authentication window without the visual seams of traditional BitB — combined with Adversary-in-the-Middle (AiTM) relay infrastructure to capture session tokens and bypass MFA. Lure domains masquerade as file-sharing platforms (sharehub.space, driftshare.co, globalfileshareplatform.com, etc.).

Collectively these pulses show credential harvesting at two layers: direct database credential extraction from compromised servers, and session-token theft from high-value policy individuals. Defenders in government, education, and policy research should treat both as active campaigns.

Threat Actor / Malware Profile

TA419 (China-Aligned Espionage Actor)

  • Distribution: Multi-stage social engineering. Benign policy-themed opener emails establish rapport; malicious links only deployed after the target responds — defeating link-scanning sandboxes that analyze on arrival.
  • Payload behavior: Frameless BitB phishing pages that render a fake SSO/OAuth login window in-page, proxying to an AiTM relay. The relay passes authentication through to the legitimate IdP while capturing credentials and session cookies, enabling MFA bypass and mailbox/cloud access.
  • C2 / Infrastructure: Rotating low-reputation "file sharing" themed domains (sharehub.space, driftshare.co, quickfly.online, smartsyncbox.com, cirrushare.co, mypublicshare.com, goshshare.online, globalfileshareplatform.com) with TLD skew toward cheap registrations (.space, .co, .online).
  • Persistence: Captured session tokens are replayed from actor infrastructure; expect new inbox rules and OAuth consent grants as persistence once a mailbox is compromised.
  • Anti-analysis: Delayed payload delivery (only post-reply), rotating domains, and frameless BitB rendering that resists screenshot-based phishing detection.

Municipal Webshell Operator (Unknown, China-Based Tag)

  • Distribution: File-upload vulnerability (CVE-2025-26399) in a recreation management platform, abused via legitimately registered member accounts after direct exploitation attempts failed.
  • Payload behavior: Webshells providing command execution, system enumeration, database credential extraction, and payment-card data access.
  • Persistence: Webshell files planted in web-accessible directories; timestomping used to match webshell $STANDARD_INFO timestamps to surrounding legitimate application files, evading timeline analysis.
  • Anti-analysis: Timestomping, AI-generated script artifacts, and use of legitimate application functionality (member upload) as the delivery vector, which generates no exploit-crash telemetry.

IOC Analysis

The pulses contain two distinct indicator classes requiring different operationalization:

File hashes (6x SHA256, Pulse 1): Webshell payloads. These should be ingested directly into your EDR blocklist and retro-hunted across IIS/Apache/Tomcat webroots. Hashes are high-confidence but brittle — pair them with behavioral detections below since re-compiled webshells change hashes trivially.

Domains (8x, Pulse 2): TA419 AiTM phishing infrastructure. Feed these to DNS sinkhole/proxy block and hunt retrospectively in DNS query logs, proxy logs, and browser network events. Also use the domains' lexical pattern (*share*, *sync*, *fly* on .space/.co/.online TLDs) as a proactive regex rule in your secure web gateway.

CVE-2025-26399: If you operate any parks/recreation management SaaS or on-prem deployment (Vermont Systems, RecTrac-class platforms), escalate patching immediately and assume breach until file-integrity checks are complete.

Tooling: Hash retro-hunts — your EDR console or Velociraptor. Domain pivoting — PassiveTotal/OTX DirectConnect, VirusTotal Graph. AiTM session theft detection — Microsoft Entra sign-in logs with token theft/anomaly detections. Webshell triage — hx-webshell-scanner, YARA with webshell rulesets, IIS log review for POSTs to upload directories.

Detection Engineering

YAML
---
title: Webshell Dropped into Web Application Upload Directory
id: 9f2c1a7e-3b44-4d8a-9c1f-muniwebshell01
status: experimental
description: Detects web server worker processes writing script/executable files into upload or web-accessible directories, consistent with the parks & rec platform webshell deployment via abused member file-upload functionality.
author: Security Arsenal Threat Intelligence
references:
  - https://www.huntress.com/blog/parks-recreation-platform-webshell-attack
date: 2026/10/02
logsource:
  category: file_event
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\w3wp.exe'
      - '\httpd.exe'
      - '\tomcat9.exe'
      - '\java.exe'
  selection_target:
    TargetFilename|contains:
      - '\uploads\'
      - '\upload\'
      - '\members\'
      - '\files\'
      - '\inetpub\wwwroot\'
  selection_ext:
    TargetFilename|endswith:
      - '.aspx'
      - '.asp'
      - '.php'
      - '.jsp'
      - '.ashx'
      - '.cshtml'
  condition: selection_parent and selection_target and selection_ext
falsepositives:
  - Legitimate CMS/plugin updates writing templates into content directories
level: high
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.t1105
---
title: Timestomping of File in Web Server Directory
id: 7a3d5b2c-8e11-4f6a-b2d9-timestomp002
status: experimental
description: Detects timestamp manipulation tooling or API abuse altering file creation/modification times inside web-accessible directories, matching the timestomping behavior used to hide webshells among legitimate recreation platform files.
author: Security Arsenal Threat Intelligence
references:
  - https://www.huntress.com/blog/parks-recreation-platform-webshell-attack
date: 2026/10/02
logsource:
  category: process_creation
  product: windows
detection:
  selection_tools:
    Image|endswith:
      - '\timestomp.exe'
      - '\setmace.exe'
      - '\nircmd.exe'
  selection_cmdline:
    CommandLine|contains:
      - 'SetFileTime'
      - '-CreationTimeUtc'
      - 'LastWriteTime'
  selection_path:
    CommandLine|contains:
      - 'inetpub'
      - 'wwwroot'
      - 'uploads'
  condition: 1 of selection_tools or (selection_cmdline and selection_path)
falsepositives:
  - Rare; backup/restore utilities may legitimately restore timestamps
level: high
tags:
  - attack.defense_evasion
  - attack.t1070.006
---
title: TA419 AiTM Phishing Infrastructure DNS Resolution
id: 4c8e1f9a-62d3-4b7c-a1e5-ta419aitm003
status: experimental
description: Detects DNS resolution or outbound connection to TA419 frameless BitB / AiTM credential phishing domains impersonating file-sharing services, targeting AI policy staff at think tanks and universities.
author: Security Arsenal Threat Intelligence
references:
  - https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
date: 2026/10/02
logsource:
  category: dns
detection:
  selection_iocs:
    query|contains:
      - 'sharehub.space'
      - 'driftshare.co'
      - 'globalfileshareplatform.com'
      - 'quickfly.online'
      - 'smartsyncbox.com'
      - 'cirrushare.co'
      - 'mypublicshare.com'
      - 'goshshare.online'
  condition: selection_iocs
falsepositives:
  - Threat research or sandbox detonation of the lure
level: critical
tags:
  - attack.credential_access
  - attack.t1566.002
  - attack.t1557
KQL — Microsoft Sentinel / Defender
// Hunt: TA419 AiTM phishing connections + webshell process lineage
// Microsoft Sentinel / MDE — run over last 30 days
let ta419_domains = dynamic(["sharehub.space","driftshare.co","globalfileshareplatform.com","quickfly.online","smartsyncbox.com","cirrushare.co","mypublicshare.com","goshshare.online"]);
let network_hits = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteUrl has_any (ta419_domains)
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, RemoteUrl, RemoteIP, ActionType
| extend HuntType = "TA419_AiTM_Domain";
let webshell_lineage = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("w3wp.exe","httpd.exe","tomcat9.exe","nginx.exe")
| where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","whoami.exe","net.exe","nltest.exe")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, AccountName
| extend HuntType = "Webshell_Child_Process";
let webshell_hash_hits = DeviceFileEvents
| where TimeGenerated > ago(30d)
| where SHA256 in ("0d8f7bf30aa1ac95d59fed24c433dd2b3d57767f38c088721699c841c6e861d3","0d93c3a8ded46887f79ac4ca7f238c458de2231243176f6c05062e34f238d19a","5f69ff7a2e024f94cc5f816fa16c90054b09d9ac430b1f8b0631dfdd4472905e","7bb594a77f726bf21a49f717024f2915f82f47eb623d2ad305259301de1f1ab4","b06b581d91f4108900d188c3ee1af18502a8cb65d4e101663b791bd670867485","e9dee286069afb6b411febb96b91a963cd16baffbf8b6aa951e0ef1a7e0e3879")
| project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, ActionType
| extend HuntType = "Webshell_Hash_Match";
union network_hits, webshell_lineage, webshell_hash_hits
| sort by TimeGenerated desc
PowerShell
# Security Arsenal — Webshell & TA419 AiTM IOC Hunt Script
# Run elevated on suspected web servers and user endpoints.

$ErrorActionPreference = 'SilentlyContinue'
$report = @()

# --- 1. Webshell hash sweep of common webroots ---
$webshellHashes = @(
  "0d8f7bf30aa1ac95d59fed24c433dd2b3d57767f38c088721699c841c6e861d3",
  "0d93c3a8ded46887f79ac4ca7f238c458de2231243176f6c05062e34f238d19a",
  "5f69ff7a2e024f94cc5f816fa16c90054b09d9ac430b1f8b0631dfdd4472905e",
  "7bb594a77f726bf21a49f717024f2915f82f47eb623d2ad305259301de1f1ab4",
  "b06b581d91f4108900d188c3ee1af18502a8cb65d4e101663b791bd670867485",
  "e9dee286069afb6b411febb96b91a963cd16baffbf8b6aa951e0ef1a7e0e3879"
)
$webRoots = @("C:\inetpub\wwwroot","C:\inetpub","D:\www","C:\xampp\htdocs") | Where-Object { Test-Path $_ }
foreach ($root in $webRoots) {
  Get-ChildItem -Path $root -Recurse -Include *.aspx,*.asp,*.php,*.ashx,*.jsp,*.cshtml -File | ForEach-Object {
    $h = (Get-FileHash -Path $_.FullName -Algorithm SHA256).Hash.ToLower()
    if ($webshellHashes -contains $h) {
      $report += [PSCustomObject]@{Type="WEBSHELL_HASH_HIT"; Path=$_.FullName; Hash=$h}
    }
  }
}

# --- 2. Timestomping heuristic: script files with creation time older than neighbours ---
foreach ($root in $webRoots) {
  Get-ChildItem -Path $root -Recurse -Directory | ForEach-Object {
    $dir = $_.FullName
    $files = Get-ChildItem -Path $dir -File
    $scripts = $files | Where-Object { $_.Extension -in '.aspx','.asp','.php','.ashx','.jsp' }
    if ($files.Count -gt 3 -and $scripts) {
      $medianWrite = ($files | Sort-Object LastWriteTime)[[int]($files.Count/2)].LastWriteTime
      foreach ($s in $scripts) {
        if ([math]::Abs(($s.CreationTime - $medianWrite).TotalDays) -gt 30) {
          $report += [PSCustomObject]@{Type="TIMESTOMP_SUSPECT"; Path=$s.FullName; Hash="Created=$($s.CreationTime) Modified=$($s.LastWriteTime)"}
        }
      }
    }
  }
}

# --- 3. TA419 AiTM domain connections (DNS cache + netstat) ---
$ta419 = @("sharehub.space","driftshare.co","globalfileshareplatform.com","quickfly.online","smartsyncbox.com","cirrushare.co","mypublicshare.com","goshshare.online")
$dnsCache = Get-DnsClientCache | Where-Object { $d = $_.Entry; $ta419 | Where-Object { $d -like "*$_*" } }
foreach ($e in $dnsCache) { $report += [PSCustomObject]@{Type="TA419_DNS_CACHE"; Path=$e.Entry; Hash=$e.Data} }
Get-NetTCPConnection -State Established | ForEach-Object {
  $proc = Get-Process -Id $_.OwningProcess
  try { $r = (Resolve-DnsName $_.RemoteAddress -ErrorAction Stop).NameHost } catch { $r = "" }
  if ($ta419 | Where-Object { $r -like "*$_*" }) {
    $report += [PSCustomObject]@{Type="TA419_ACTIVE_CONN"; Path="$($proc.ProcessName) -> $($_.RemoteAddress):$($_.RemotePort)"; Hash=$r}
  }
}

if ($report) { $report | Format-Table -AutoSize; $report | Export-Csv ".\otx_hunt_$(Get-Date -Format yyyyMMdd_HHmm).csv" -NoTypeInformation }
else { Write-Host "[+] No OTX IOC hits found on $env:COMPUTERNAME" -ForegroundColor Green }

Response Priorities

Immediate (0–4h):

  • Block all 8 TA419 domains at DNS sinkhole, secure web gateway, and EDR network protection; block the 6 webshell SHA256 hashes in EDR.
  • If you operate any recreation/parks management platform, isolate the application servers and run the hash sweep + timestomp heuristic immediately; assume the database credential store is compromised.
  • Alert on any mailbox sign-in from unfamiliar ASN within 24h of a user visiting a TA419 lure domain.

24 hours:

  • Both campaigns are credential-theft operations — force password resets for any account whose credentials resided in the compromised recreation platform database, and revoke all active sessions/refresh tokens for any user with a TA419 domain hit.
  • Review Entra ID / Okta sign-in logs for AiTM indicators: impossible travel, token replay from non-corp IP, new inbox forwarding rules, and suspicious OAuth consent grants.
  • Rotate database connection strings and service account passwords referenced by the recreation platform.

1 week:

  • Restrict file-upload functionality: allowlist extensions, store uploads outside webroot, scan uploads with AV + YARA webshell rules, and disable script execution in upload directories via web server config.
  • Deploy FIDO2/phishing-resistant MFA for policy, research, and executive staff — AiTM relays defeat TOTP and push-based MFA but not hardware-bound passkeys.
  • Add pre-delivery and post-delivery detection for the two-stage lure pattern (benign opener → link on reply) to your email security stack; brief think tank and policy staff on TA419's impersonation tradecraft.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.

Webshell Intrusion on Municipal Platforms + TA419 AiTM Credential Phishing: OTX Pulse Analysis — Detection & Hunt Pack | Security Arsenal | Security Arsenal