Exposed Server Staged NGINX and Ghost CMS Exploits for Targets in 11 Countries

· Original article ↗

Summary

Researchers found an exposed server hosting exploits and target lists spanning 11 countries. Scripts used DNS callbacks to check execution, but recovered evidence did not confirm successful compromises.

Key points

  • The Singapore-hosted server exposed 572 files, including exploit tooling for NGINX, Ghost CMS, Splunk, Samba, WebLogic, PaperCut, and D-Link NAS.
  • Recovered shell history showed the operator running exploits against external systems; NGINX attempts recorded in the history were unsuccessful.
  • Ghost CMS SQL injection scripts checked targets and attempted to extract email addresses and password hashes, but the output files were not recovered, so success is unconfirmed.
  • Scripts used unique per-target DNS callbacks to verify execution; the investigation found no evidence that a callback succeeded.
  • Target lists covered 11 countries and focused on government, academic, healthcare, and financial organizations.
  • AdaptixC2 and SuperShell files were present, but neither framework was tied to a specific intrusion in the recovered data.
  • The report says the affected vulnerabilities have been patched, except for the D-Link NAS flaw affecting end-of-life devices, which require retirement rather than a patch.

Article Details

Attack Vectors
  • The operator staged exploits for seven vulnerabilities and ran some against external hosts. Recorded NGINX Rift attempts did not succeed, and the recovered data does not establish a compromise.
  • The Ghost CMS script checked hosts for CVE-2026-26980, then attempted to extract email and password-hash columns from the users table. The output CSV files were not recovered, so success is unconfirmed.
  • NGINX Rift and PaperCut scripts used per-target DNS subdomains for out-of-band verification of command execution. The recovered data does not confirm that any callback arrived.
  • The exposed server hosted exploit files and served as a reverse-shell listener. AdaptixC2 and SuperShell files were present, but neither framework was tied to a specific intrusion.
Defensive Notes
  • Check logs for the reported out-of-band callback domains and activity involving the staged exploits; the reported indicators do not establish successful exploitation.
  • Apply available fixes for the affected NGINX, Ghost CMS, Samba, Oracle WebLogic, PaperCut, and Splunk products.
  • Retire affected end-of-life D-Link NAS devices, which the article says will not receive a fix for CVE-2024-3273.

Indicators of compromise

TypeIndicatorContext
DOMAIN2397103e30d34d0c[.]gobygo[.]netPer-target out-of-band DNS callback domain hardcoded in exploit scripts.
DOMAIN9eac1cf2cb[.]ddns[.]1433[.]eu[.]orgPer-target out-of-band DNS callback domain hardcoded in exploit scripts.
DOMAINb69415f328[.]ddns[.]1433[.]eu[.]orgPer-target out-of-band DNS callback domain hardcoded in exploit scripts.
IPV4165[.]154[.]236[.]93Singapore-hosted server exposing the operator's exploit directory and used as a reverse-shell listener.
SHA256e0e1ffc5429bb074d5cb7ae3bbfe6f5df6033931a12d24a0d377568150dfa11aHash of the NGINX Rift poc.py exploit file staged in the operator's directory.

MITRE ATT&CK

CVE

Vendors

Products

Tools

Countries

AustraliaAustralia - state health departments, universities, and financial servicesBrazilTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightFranceTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightIndonesiaIndonesia - regency government hostIrelandTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightItalyTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightNew ZealandVietnam, New Zealand - individual private-sector targetsSingaporeIn June 2026, we identified an exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, built to target these same flaws. The recovered shell history from the directory recorded the attacker running the exploitsSouth KoreaTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightUnited KingdomTarget lists were organized by country: Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. Paired with these text files were logs recording which hosts were vulnerable. This sub-directory gave insightUnited StatesUnited States - global insurance firmVietnamVietnam, New Zealand - individual private-sector targets

Industries

Related Articles