Exposed Staging Server Reveals Data from Ababil of Minab Campaign, Including LA Metro Records

· Original article ↗

Summary

Hunt.io found an open staging server holding about 5 GB of data linked to the Ababil of Minab campaign, including LA Metro backups and sensitive records from other organizations. The investigation details the operator’s tools, infrastructure, and exfiltration methods.

Key points

  • Hunt.io observed the staging server at 5.255.127[.]55:8020 from April 28 through at least May 26, 2026. Its open directory contained 2,238 files across 545 subdirectories, totaling about 5 GB.
  • The LA Metro directory held more than 1 GB of data, including SQL Server backups, transit and SCADA configuration material, personnel documents, and Outlook PST archives.
  • Data linked to other organizations included academic and business records, personal information, database backups, browser passwords, VPN credentials, and network device configurations.
  • A custom Flask receiver supported encrypted, chunked uploads. Bash history also showed data retrieval using proxychains and Axel, and transfers from a second server via SCP.
  • FileFiend malware appeared under the decoy filename Exchangedb.exe in five LA Metro-related directories; the article provides sample hashes and additional indicators.
  • Gambit Security attributed the campaign with high confidence to Black Shadow, which it assesses operates for Iran’s MOIS; Hunt.io says it has not independently verified that attribution.
  • The article recommends searching for FileFiend, rotating potentially exposed credentials, preventing backup files from being web-accessible, and monitoring for the described archive-download activity.

Article Details

Attack Vectors
  • The operator compressed data into multi-part RAR archives on victim web servers, placed the archives in public web roots, and downloaded them to a staging server using proxychains and Axel.
  • A custom Flask receiver accepted AES-CBC-encrypted, chunked file uploads over HTTPS; the exposed directory contained active upload-session artifacts.
  • FileFiend, disguised as Exchangedb.exe, automatically enumerated local drives and SMB shares for collection.
  • Gambit Security reported SQL Server deletion, VM partition wipes, Veeam backup destruction, and file-system damage across four victim environments.
  • Historical records in the adabroker.com.tr data included SQL injection reports and probe payloads, but the article does not establish SQL injection as this campaign's entry point.
Defensive Notes
  • Hunt for Exchangedb.exe on endpoints and search EDR telemetry and retrospective logs for the three reported FileFiend SHA-256 hashes.
  • Rotate credentials potentially exposed in Web.config files, connection strings, and network-device running configurations.
  • Prevent web application service accounts from writing archives to public web roots, and monitor web logs for sequential multi-part archive downloads.
  • Block or alert on unexpected outbound port 443 connections from servers when the TLS certificate subject contains acmecloud.example.
  • Keep database backups out of publicly accessible web roots and avoid backup names that expose environment details.

Indicators of compromise

TypeIndicatorContext
DOMAINnefeshhope[.]comDomain of a fake IDF support portal previously used to target soldiers and deliver malware; previously linked to the secondary staging server.
EMAILadmin@acmecloud[.]exampleIdentity embedded in the self-signed TLS certificate generated for the operator's Flask receiver.
IPV431[.]172[.]87[.]20Secondary staging server from which the operator transferred files to the primary server via SCP.
IPV45[.]255[.]127[.]55Operator's primary staging server, exposing an open directory on port 8020 and an Apache service on port 8087.
SHA25633a6b4900c2fbfb3c2d816947871eade800d0c0e2a2680871700fd6e640e5f20Reported SHA-256 hash of a FileFiend sample disguised as Exchangedb.exe.
SHA25681a25357d027d0f04a43139377d5d58384b8e9b0770e699cdcc37e600641cf90Reported SHA-256 hash of a FileFiend sample disguised as Exchangedb.exe.
SHA256c8cc4225d1e21324ef419adbb1c10dd0578fb034b5f5d7b8000f0aae1871c061Reported SHA-256 hash of a FileFiend sample disguised as Exchangedb.exe.
URLhxxps[:]//ababilofminab[.]io/metro-net-is-hackedSpecific page on the threat actor's website claiming the LA Metro intrusion.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles