Exposed Staging Server Reveals Data from Ababil of Minab Campaign, Including LA Metro Records

Summary
Hunt.io found an open staging server holding about 5 GB of data linked to the Ababil of Minab campaign, including LA Metro backups and sensitive records from other organizations. The investigation details the operator’s tools, infrastructure, and exfiltration methods.
Key points
- Hunt.io observed the staging server at 5.255.127[.]55:8020 from April 28 through at least May 26, 2026. Its open directory contained 2,238 files across 545 subdirectories, totaling about 5 GB.
- The LA Metro directory held more than 1 GB of data, including SQL Server backups, transit and SCADA configuration material, personnel documents, and Outlook PST archives.
- Data linked to other organizations included academic and business records, personal information, database backups, browser passwords, VPN credentials, and network device configurations.
- A custom Flask receiver supported encrypted, chunked uploads. Bash history also showed data retrieval using proxychains and Axel, and transfers from a second server via SCP.
- FileFiend malware appeared under the decoy filename Exchangedb.exe in five LA Metro-related directories; the article provides sample hashes and additional indicators.
- Gambit Security attributed the campaign with high confidence to Black Shadow, which it assesses operates for Iran’s MOIS; Hunt.io says it has not independently verified that attribution.
- The article recommends searching for FileFiend, rotating potentially exposed credentials, preventing backup files from being web-accessible, and monitoring for the described archive-download activity.
Article Details
- Attack Vectors
- The operator compressed data into multi-part RAR archives on victim web servers, placed the archives in public web roots, and downloaded them to a staging server using proxychains and Axel.
- A custom Flask receiver accepted AES-CBC-encrypted, chunked file uploads over HTTPS; the exposed directory contained active upload-session artifacts.
- FileFiend, disguised as Exchangedb.exe, automatically enumerated local drives and SMB shares for collection.
- Gambit Security reported SQL Server deletion, VM partition wipes, Veeam backup destruction, and file-system damage across four victim environments.
- Historical records in the adabroker.com.tr data included SQL injection reports and probe payloads, but the article does not establish SQL injection as this campaign's entry point.
- Defensive Notes
- Hunt for Exchangedb.exe on endpoints and search EDR telemetry and retrospective logs for the three reported FileFiend SHA-256 hashes.
- Rotate credentials potentially exposed in Web.config files, connection strings, and network-device running configurations.
- Prevent web application service accounts from writing archives to public web roots, and monitor web logs for sequential multi-part archive downloads.
- Block or alert on unexpected outbound port 443 connections from servers when the TLS certificate subject contains acmecloud.example.
- Keep database backups out of publicly accessible web roots and avoid backup names that expose environment details.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | nefeshhope[.]com | Domain of a fake IDF support portal previously used to target soldiers and deliver malware; previously linked to the secondary staging server. |
admin@acmecloud[.]example | Identity embedded in the self-signed TLS certificate generated for the operator's Flask receiver. | |
| IPV4 | 31[.]172[.]87[.]20 | Secondary staging server from which the operator transferred files to the primary server via SCP. |
| IPV4 | 5[.]255[.]127[.]55 | Operator's primary staging server, exposing an open directory on port 8020 and an Apache service on port 8087. |
| SHA256 | 33a6b4900c2fbfb3c2d816947871eade800d0c0e2a2680871700fd6e640e5f20 | Reported SHA-256 hash of a FileFiend sample disguised as Exchangedb.exe. |
| SHA256 | 81a25357d027d0f04a43139377d5d58384b8e9b0770e699cdcc37e600641cf90 | Reported SHA-256 hash of a FileFiend sample disguised as Exchangedb.exe. |
| SHA256 | c8cc4225d1e21324ef419adbb1c10dd0578fb034b5f5d7b8000f0aae1871c061 | Reported SHA-256 hash of a FileFiend sample disguised as Exchangedb.exe. |
| URL | hxxps[:]//ababilofminab[.]io/metro-net-is-hacked | Specific page on the threat actor's website claiming the LA Metro intrusion. |
MITRE ATT&CK
T1005 · Data from Local SystemCollected victim-system data included database backups, PST files, configuration files, and exported credentials.T1036.005 · Match Legitimate Resource Name or LocationFileFiend binaries were placed in victim directories under the Exchange-related decoy filename Exchangedb.exe.T1048 · Exfiltration Over Alternative ProtocolThe custom Flask receiver accepted encrypted, chunked exfiltrated files over HTTPS on port 443.T1090.003 · Multi-hop ProxyThe article reports that the operator consistently used proxychains to route Axel downloads through multiple proxy hops.T1119 · Automated CollectionFileFiend automatically enumerated local drives and SMB network shares for data collection.T1485 · Data DestructionGambit Security reported SQL Server database deletion and file-system destruction in victim environments.T1552.001 · Credentials In FilesStaged files exposed plaintext VPN credentials, connection strings, and network-device passwords.T1555.003 · Credentials from Web BrowsersChrome password dumps were found among data staged on the operator's server.T1560.001 · Archive via UtilityThe operator created multi-part RAR archives on victim systems and used 7-Zip archives to aggregate staged data.T1561.002 · Disk Structure WipeGambit Security reported VM partition wipes performed through Disk Management.
People
Threat Actors
Ababil of MinabPro-Iranian group that claimed destructive intrusions, including the confirmed LA Metro breach. Gambit Security attributed the activity to Black Shadow with high confidence, but Hunt.io did not independently verify that attribution.Black ShadowGroup to which Gambit Security attributed the activity with high confidence; Hunt.io did not independently verify the attribution. A figure in the article calls Pink Sandworm an alias of Black Shadow.Pink SandwormIdentified as an alias of Black Shadow in a figure linking the group to nefeshhope[.]com.
Malware
Vendors
CheckPointto Ifat Media Group.A VPN batch script "connect_ifat_capsule.cmd" embeds plaintext credentials for a CheckPoint Endpoint Connect VPN gateway at sslvpn.ifat.com.CiscoIt contains complete Cisco and Juniper switch running configurations with encrypted and, in some cases, plaintext credentials.JuniperIt contains complete Cisco and Juniper switch running configurations with encrypted and, in some cases, plaintext credentials.MicrosoftLA Metro (LACMTA) confirmed exfiltrated data is present in the staging directory, over 1 GB of Microsoft SQL Server database backups covering transit operations, personnel records, SCADA configurations, yard managementThe Infrastructure Group B.V.a Python SimpleHTTP server that was left completely open on a Netherlands VPS hosted by The Infrastructure Group B.V. (AS60404), first seen April 28, 2026.Veeam2026, Gambit Security published a technical report documenting SQL Server deletion, VM partition wipes, Veeam backup destruction, and file system damage across four victim environments, but deliberately withheld theVMwareManagement / Train Control Display System, which was claimed to be hacked.Figure 3. The screenshot of VMware vCenter Server with administrative access to LACMTA's core virtualization management platform was claimed
Products
CheckPoint Endpoint Connect VPNMedia Group.A VPN batch script "connect_ifat_capsule.cmd" embeds plaintext credentials for a CheckPoint Endpoint Connect VPN gateway at sslvpn.ifat.com.Google ChromePlaintext Chrome password dumps, VPN credentials, network switch running configurations with passwords, and Outlook PST archives of named individuals were staged in the open directory, representing high-severityMicrosoft SQL ServerLA Metro (LACMTA) confirmed exfiltrated data is present in the staging directory, over 1 GB of Microsoft SQL Server database backups covering transit operations, personnel records, SCADA configurations, yard managementVeeam2026, Gambit Security published a technical report documenting SQL Server deletion, VM partition wipes, Veeam backup destruction, and file system damage across four victim environments, but deliberately withheld theVMware vCenter Server/ Train Control Display System, which was claimed to be hacked.Figure 3. The screenshot of VMware vCenter Server with administrative access to LACMTA's core virtualization management platform was claimed to have
Tools
AttackCaptureHunt.io's AttackCapture found the group's primary staging server sitting completely open at 5.255.127[.]55:8020. The directory contained 2,238 files across 545 subdirectories, approximately 5 GB of exfiltrated data, theAxeluploading to the victim's public web root, then downloading from the staging server using proxychains axel -n 8.http.flask.pyThe http.flask.py custom receiver and .bash_history recovered from the staging server confirm both exfiltration methods described in Gambit Security's report.proxychainsvictim host, uploading to the victim's public web root, then downloading from the staging server using proxychains axel -n 8.
Countries
Israelthat surfaced in late March 2026, claiming destructive intrusions against targets in the United States, Israel, Saudi Arabia, and Turkey, including a confirmed breach of the Los Angeles County MetropolitanNetherlandsstaging server at 5.255.127[.]55, a Python SimpleHTTP server that was left completely open on a Netherlands VPS hosted by The Infrastructure Group B.V. (AS60404), first seen April 28, 2026.Saudi Arabiain late March 2026, claiming destructive intrusions against targets in the United States, Israel, Saudi Arabia, and Turkey, including a confirmed breach of the Los Angeles County Metropolitan TransportationTurkey2026, claiming destructive intrusions against targets in the United States, Israel, Saudi Arabia, and Turkey, including a confirmed breach of the Los Angeles County Metropolitan Transportation Authority.United Statesthreat actor that surfaced in late March 2026, claiming destructive intrusions against targets in the United States, Israel, Saudi Arabia, and Turkey, including a confirmed breach of the Los Angeles County Metropolitan
Industries
Digital servicesThe orbital.co.il/ directory contains 81 MB across two multi-part RAR archives, confirming a distinct Israeli digital services organization as a target, though the archives were not extracted at capture time.EducationFood technology(89 MB) alongside four multi-part RAR archives, identifying Taam Tehara Titan as an Israeli food technology and kashrut management company whose full production database backup set was staged.Insuranceadabroker.com.tr - Turkish Insurance PIIMediaOrganizations with dedicated coverage in this report include Ruppin Academic Center, bac.org.il, adabroker.com.tr, courier.co.il, and Ifat Media Group, alongside LA Metro as the primary confirmed target.Public transportation