Exposed Server Staged NGINX and Ghost CMS Exploits for Targets in 11 Countries

Summary
Researchers found an exposed server hosting exploits and target lists spanning 11 countries. Scripts used DNS callbacks to check execution, but recovered evidence did not confirm successful compromises.
Key points
- The Singapore-hosted server exposed 572 files, including exploit tooling for NGINX, Ghost CMS, Splunk, Samba, WebLogic, PaperCut, and D-Link NAS.
- Recovered shell history showed the operator running exploits against external systems; NGINX attempts recorded in the history were unsuccessful.
- Ghost CMS SQL injection scripts checked targets and attempted to extract email addresses and password hashes, but the output files were not recovered, so success is unconfirmed.
- Scripts used unique per-target DNS callbacks to verify execution; the investigation found no evidence that a callback succeeded.
- Target lists covered 11 countries and focused on government, academic, healthcare, and financial organizations.
- AdaptixC2 and SuperShell files were present, but neither framework was tied to a specific intrusion in the recovered data.
- The report says the affected vulnerabilities have been patched, except for the D-Link NAS flaw affecting end-of-life devices, which require retirement rather than a patch.
Article Details
- Attack Vectors
- The operator staged exploits for seven vulnerabilities and ran some against external hosts. Recorded NGINX Rift attempts did not succeed, and the recovered data does not establish a compromise.
- The Ghost CMS script checked hosts for CVE-2026-26980, then attempted to extract email and password-hash columns from the users table. The output CSV files were not recovered, so success is unconfirmed.
- NGINX Rift and PaperCut scripts used per-target DNS subdomains for out-of-band verification of command execution. The recovered data does not confirm that any callback arrived.
- The exposed server hosted exploit files and served as a reverse-shell listener. AdaptixC2 and SuperShell files were present, but neither framework was tied to a specific intrusion.
- Defensive Notes
- Check logs for the reported out-of-band callback domains and activity involving the staged exploits; the reported indicators do not establish successful exploitation.
- Apply available fixes for the affected NGINX, Ghost CMS, Samba, Oracle WebLogic, PaperCut, and Splunk products.
- Retire affected end-of-life D-Link NAS devices, which the article says will not receive a fix for CVE-2024-3273.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 2397103e30d34d0c[.]gobygo[.]net | Per-target out-of-band DNS callback domain hardcoded in exploit scripts. |
| DOMAIN | 9eac1cf2cb[.]ddns[.]1433[.]eu[.]org | Per-target out-of-band DNS callback domain hardcoded in exploit scripts. |
| DOMAIN | b69415f328[.]ddns[.]1433[.]eu[.]org | Per-target out-of-band DNS callback domain hardcoded in exploit scripts. |
| IPV4 | 165[.]154[.]236[.]93 | Singapore-hosted server exposing the operator's exploit directory and used as a reverse-shell listener. |
| SHA256 | e0e1ffc5429bb074d5cb7ae3bbfe6f5df6033931a12d24a0d377568150dfa11a | Hash of the NGINX Rift poc.py exploit file staged in the operator's directory. |
MITRE ATT&CK
T1190 · Exploit Public-Facing ApplicationThe operator ran exploits against externally reachable hosts, including NGINX Rift attempts and Ghost CMS Content API vulnerability checks and credential-extraction attempts; compromise was not confirmed.T1595.002 · Vulnerability ScanningThe operator's Ghost CMS script checked a range of IP- and domain-based hosts for CVE-2026-26980 before attempting extraction against a smaller set.
CVE
CVE-2017-10271an open-source tool covering several WebLogic vulnerabilities, but the operator focused on CVE-2017-10271. This CVE is an XMLDecoder deserialization flaw, which is still widely exploited.CVE-2023-27350CVE-2024-3273NGINX, Ghost, Samba, WebLogic, PaperCut, and Splunk have since been patched. The D-Link NAS flaw (CVE-2024-3273) affects end-of-life devices that will not receive a fix, so exposure there depends on retirementCVE-2026-20253CVE-2026-26980heap overflow in the rewrite module, and a blind SQL injection in the Ghost Content API (CVE-2026-26980). Exploit code for both became public quickly. What we found was a single host staging them alongsideCVE-2026-42945months of each other earlier this year, critical vulnerabilities were found in both: NGINX Rift (CVE-2026-42945), a long-standing heap overflow in the rewrite module, and a blind SQL injection in the Ghost ContentCVE-2026-4480
Vendors
Products
D-Link NASNGINX Rift (CVE-2026-42945) and Ghost CMS SQLi (CVE-2026-26980) are hosted alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling.Ghost CMSNGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both:NGINXNGINX sits in front of a large share of the internet's web traffic and Ghost CMS powers well over 100,000 publishing sites. Within months of each other earlier this year, critical vulnerabilities were found in both:Oracle WebLogicscanned) bugs to vulnerabilities just a few weeks old. Some of the earlier exploits target PaperCut, Oracle WebLogic, and D-Link NAS devices; the most recent include a Samba print-spooler flaw from late May and aPaperCut MF/NGSambaNGINX Rift (CVE-2026-42945) and Ghost CMS SQLi (CVE-2026-26980) are hosted alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling.Splunk Enterprise
Tools
AdaptixC2reverse shells. Alongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavilyAttackCaptureFigure 02: Open directory on 165.154.236[.]93:8000 as captured by Hunt.io's AttackCapture File Manager, showing 572 files across 126 directories, totaling 31 MB.Inside the Exploit KitGobygobygo[.]net is the DNSLog backend for Goby, a Chinese attack-surface-mapping and vulnerability scanning tool. The scripts queried the subdomain in its scans to confirm blind vulnerabilities through DNS. Goby's accountsSuperShellAlongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavily toward high-valueweblogicScannerexception, given what the operator kept alongside the exploit code. The activity is centered around weblogicScanner, an open-source tool covering several WebLogic vulnerabilities, but the operator focused on
Countries
AustraliaAustralia - state health departments, universities, and financial servicesBrazilTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightFranceTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightIndonesiaIndonesia - regency government hostIrelandTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightItalyTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightNew ZealandVietnam, New Zealand - individual private-sector targetsSingaporeIn June 2026, we identified an exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, built to target these same flaws. The recovered shell history from the directory recorded the attacker running the exploitsSouth KoreaTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightUnited KingdomTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightUnited StatesUnited States - global insurance firmVietnamVietnam, New Zealand - individual private-sector targets
Industries
EducationFinancial Servicesheavily toward high-value sectors: federal and state government, universities, healthcare and financial services. Command-line artifacts, exploit diagrams, and code comments suggest the operator is comfortableGovernmenteleven countries across five continents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services. Command-line artifacts, exploit diagrams, and codeHealthcarecontinents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services. Command-line artifacts, exploit diagrams, and code comments suggest the