ITSecurityGuru

Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data


Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular recreation management platform used by local municipalities and parks organisations, planting webshells and going after payment card data.

The activity, first observed on 10 September 2026, began noisily. Over roughly six hours the attacker threw a string of unauthenticated techniques at the first server, including brute-forcing the admin and member login pages, IIS 8.3 tilde enumeration, WebDAV method abuse and upload-handler parser bypasses. None of them worked.

What did work was far simpler. The attacker registered a new member account and abused the platform’s member file upload feature to drop .aspx webshells into a publicly reachable documents directory. From there they carried out reconnaissance, pulled the global IIS configuration file and searched web.config and C# source files for connection strings, passwords and API keys.

With database credentials in hand, the motive became clear. The attacker searched the environment for card-related strings and payment provider names, then dumped webhook logs from a payment integration to extract card numbers, expiry dates and CVVs.

Quieter, then stealthier

The same technique was used on a second server, this time with far less noise, before Huntress’s SOC removed the webshells. On the third server the attacker changed tactics again, copying their webshells into innocuous-looking locations under names such as css_bundle.aspx and webresource.aspx and timestomping the files so their metadata matched legitimate site components. An attempt to plant further copies inside the platform’s payment module directories failed.

The most serious phase came when the third server was put back into production before it had been fully secured. Using the account they had already registered, the attacker returned and ran PowerShell “planter” scripts that appended an obfuscated dropper to a legitimate jQuery file loaded by the platform’s authentication page. The trojanised script pulled a second-stage browser agent hosted on Cloudflare Workers and opened encrypted WebRTC and WebSocket channels, designed to harvest users’ credentials in real time.

AI fingerprints

Huntress says a zh-CN locale in the attacker’s PowerShell user-agent string suggests the actor is most likely based in China. The researchers also believe AI-generated scripts were used across the kill chain, from the high volume of early access attempts to the final PowerShell scripts, whose comments appear to include fragments of the instructions given to the AI.



Source link