An attacker who spent six hours failing to break into a recreation management platform finally got in the simplest way possible: by signing up for an account. According to a new report from Huntress, the intruder registered as a member, uploaded malicious files through the platform's own document feature, and turned them into web shells (small scripts that let an attacker run commands on a server through a browser) on three web servers belonging to tenants of the shared platform.
The target was money: payment card data, and later the credentials of anyone using the platform's login page. Huntress, which credits Olly Maxwell for contributions to the investigation, did not name the vendor or the affected organizations.
Six hours of failure, then the front door
Huntress first saw the activity on September 10, 2026. On the first server the attacker was loud, brute-forcing login pages, probing for IIS short-filename (tilde) enumeration, trying WebDAV methods and attacking the upload handlers. Huntress says the volume suggests AI-generated automation may have been involved. All of it failed.
What worked was registering a member account and uploading 14 files, including .aspx web shells, to the /documents/MemberFiles/ directory. The attacker then pulled IIS configuration files, searched web.config and C# source files for database connection strings, and used the SQL credentials it found to query the database for cardholder data.
It also dumped log files written by a Fortis payment webhook integration to pull out card numbers, expiry dates and CVVs, and Huntress's summary of the incident says payment data was stolen.
The attacker got quieter each time
On a second server the Huntress SOC removed the shells after a handful of commands. On the third, the approach was deliberately stealthy: five web shells were copied and renamed to look like ordinary site files such as css_bundle.aspx, jquery.validate.min.aspx and webresource.aspx, with timestamps altered to match legitimate files (timestomping). An attempt to drop more shells inside the platform's payment folders failed.
Back in through a server restored too early
The most serious act came after the third server was put back into production before it was fully locked down. Using the account it had already registered, the attacker returned with PowerShell "planter" scripts that appended an obfuscated dropper to a jQuery file loaded by the platform's /auth/default.aspx login page. Huntress says the goal was to make every visiting browser fetch a second-stage agent and open encrypted WebRTC and WebSocket channels to attacker servers on Cloudflare Workers to harvest credentials in real time.
Huntress says the planter scripts appear AI-generated, since their comments echo instructions such as "append only - do not rewrite head/structure". The PowerShell user agent carried a Simplified Chinese (zh-CN) locale, which Huntress takes as a sign the attacker is most likely based in China. A locale string is a weak signal, and no known group has been named.
Lock down member uploads before restoring a server
Huntress did not name a patched version or vendor fix, so there is no update to apply yet. The report's details point to where to look: member upload folders that can execute .aspx files, unexpected .aspx files beside static assets, and changes to jquery.mousewheel-3.0.6.pack.js. Most of all, a cleaned server should not go back into service until the original way in is closed, because this attacker simply logged back in. The same quiet, payment-focused persistence shows up in IIS web shell intrusions and checkout skimming campaigns.
Indicators of compromise
- Second-stage payload: hxxps://chat[.]ririmochii[.]workers[.]dev/core[.]js
- C2: hxxps://fk[.]bubuneeko[.]workers[.]dev/_cf/rel and wss://fk[.]bubuneeko[.]workers[.]dev/_cf/soc
- plant_ccrtc_mousewheel.ps1 SHA256: 0d8f7bf30aa1ac95d59fed24c433dd2b3d57767f38c088721699c841c6e861d3
- ccrtc_sdk_init.js SHA256: b06b581d91f4108900d188c3ee1af18502a8cb65d4e101663b791bd670867485
- Web shell keys: wf9x and m7Qx2pL9
The lesson is persistence, not clever malware: an attacker who failed at everything sophisticated succeeded with a sign-up form, and came back the moment defenders relaxed.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.