The Flask app uses sandboxed Jinja2. The operator intentionally leaked JWT_SECRET through template rendering but blocked direct #RCE methods, protecting their own infrastructure from other attackers while still exposing sensitive config values.
An open directory on 124.223.221[.]83:9999 (Tencent Cloud, Shanghai) exposes a full #offensive toolkit. #CobaltStrike 4.7, Chrome XXE #exploit, internal network scan results, a web shell, and a custom #C2. Let's break it down. 🧵👇
Found via @Huntio
PHISHING INFRASTRUCTURE ALIVE 🚨
A # leads to multiple nodes hosting the same site
IOCS:
fbi-investingationunit[.]com
digitalassetsreclaim[.]com
www.fbi-sec.globalfundrecoveryunit[.]com
auracyber-investigation[.]com
198.251.84[.]200
172.67.162[.]245
66.85.46[.]67
51.195.95[.]80
wiki.txt is the full documentation for #Ladon 9.1.7.
160 usage examples covering #MS17010 scanning, #SMBGhost detection, password spraying, privilege escalation, credential dumping, and lateral movement. The operator left their entire post-exploitation playbook on the server.
A #CobaltStrike teamserver operation is exposed on 101.42.136[.]73 (Tencent Cloud, Beijing). The #opendirectory contains #beacon keys, #teamserver config, subdomain wordlists, and post-exploitation tooling.
Credits @Huntio
SubDomain.dic is a #wordlist for subdomain #bruteforcing. Entries target common subdomains like www, blog, admin, portal, mail, vpn, secure, dashboard, api, cdn, and more.
Broad target discovery across internet-facing infrastructure.
Day 1/30 of posting #CTI findings every day.
kjjt.pages[.]dev is distributing a #trojanized executable disguised as a screenshot uploader tool. The site hosts a functional landing page with a Windows download option
@Huntio This infrastructure is currently active. Organizations should block 159.223.5[.]148. The login page is live and accessible. The panel is operational.