Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries
|
Short version of some research worth a read: an open directory on a Singapore server that was staging live exploits instead of just serving files. On the box were NGINX Rift and a Ghost CMS SQL injection, sitting next to older tooling for Splunk, PaperCut, Samba, WebLogic, and D-Link devices, plus a red-team framework (AdaptixC2) and a web shell manager. The operator used a neat trick to tell whether their blind attacks worked: the payloads triggered a DNS request back to a server they controlled, so an incoming request meant the exploit had run, even when the target itself gave nothing back. The targeting spanned eleven countries and leaned heavily on government, universities, healthcare, and finance. Nothing in the capture confirms a successful break-in, so it's better read as a snapshot of an operation being built than proof of a breach. Full detail and indicators in the post. submitted by /u/Straight-Practice-99 |