AI Agents Used an Exposed Endpoint to Take Over a Server, ReliaQuest Finds

· Original article ↗

Summary

ReliaQuest details an incident in which an attacker used an unauthenticated job-submission feature to steal credentials and take full control of a server, with evidence suggesting LLM-driven agents carried out much of the attack.

Key points

  • The attacker exploited an internet-facing Apache Tomcat/Spring Batch job-submission feature that required no authentication; no zero-day or new malware was involved.
  • JavaScript executed inside the application, letting the attacker retrieve data through error messages and avoid creating child processes during early activity.
  • Credentials found in configuration files provided SQL Server sysadmin access; xp_cmdshell and staged PrintSpoofer and GodPotato tools enabled SYSTEM-level control.
  • The attacker accessed the SAM, SYSTEM, and SECURITY registry hives, created local administrator accounts, and attempted to remove artifacts.
  • ReliaQuest assesses with high confidence that LLM-driven agents handled substantial parts of the attack, citing a Cairn orchestration dashboard on the attack-origin host and adaptive command patterns.
  • ReliaQuest recommends authenticating and restricting exposed management endpoints, retaining application job history, monitoring script-engine activity, and securing stored credentials.

Article Details

Attack Vectors
  • An internet-facing job-submission feature accepted and executed task definitions without authentication. The attacker used it to invoke JavaScript inside the application's existing process.
  • Deliberately generated application errors returned command results through the same endpoint. The attacker retrieved files in sequential 1,800-byte chunks and uploaded tools as base64 fragments.
  • Plaintext credentials recovered from application configuration files granted database sysadmin rights. Enabling operating-system command execution then exposed a service account privilege that public escalation tools abused to obtain SYSTEM access.
  • The attacker created two local administrator accounts for continued access and left one in place after cleanup.
  • ReliaQuest assesses with high confidence that LLM-driven agents performed substantial portions of the attack, based on an orchestration dashboard on the attack-origin host and adaptive command sequences. The model, agent count, and extent of human approval were not determined.
Defensive Notes
  • Inventory internet-reachable job-submission, batch-configuration, and administrative endpoints; require authentication and appropriate authorization and restrict exposure.
  • Retain job definitions, execution and step history, exceptions, and exit descriptions alongside web, database, and endpoint logs. Application job history survived the attacker's deletion of disk artifacts.
  • Hunt for unusual job volume and sequencing, unexpected script-engine execution, and output returned through errors or exit descriptions. Command cadence alone does not establish AI involvement.
  • Move credentials out of application configuration files into a secrets store or managed identity, rotate exposed credentials, and restrict privileged database service accounts.
  • Automate host isolation when unauthorized script-engine execution is confirmed, while preserving job history for investigation.
  • Block all identified attacker infrastructure rather than only the submission source: separate addresses submitted jobs and collected their output.
  • Prioritize behavioral detection over orchestration-platform fingerprints or signatures for individual public escalation tools.

Indicators of compromise

TypeIndicatorContext
IPV4204[.]194[.]54[.]240Attacker staging host that scanned the environment before the incident and hosted escalation tools matching files delivered to the compromised server.
IPV4204[.]194[.]55[.]189Attack-origin host that submitted malicious application jobs and exposed a Cairn dashboard and exploit-staging material.
IPV494[.]177[.]131[.]113Retrieved job output in bulk and sent requests to the upload endpoint; a relay role was possible but unconfirmed.

MITRE ATT&CK

T1003.002 · Security Account ManagerWith SYSTEM access, the attacker saved the SAM and SYSTEM registry hives to enable offline extraction of local account password hashes.T1036.005 · Match Legitimate Resource Name or LocationThe staging directory contained rebuilt escalation tools renamed to resemble diagnostic utilities, including diagutil.exe and diag_fixed.exe.T1041 · Exfiltration Over C2 ChannelThe attacker retrieved file contents through error responses on the same application channel used to submit commands, with a separate address collecting job output in bulk.T1046 · Network Service DiscoveryAttacker infrastructure scanned the environment before the incident, and a binary dropped at /var/tmp/kvragent was used for scanning.T1059.001 · PowerShellThe attacker used PowerShell among the built-in utilities involved in the incident; payload comments referenced using -EncodedCommand.T1059.003 · Windows Command ShellThe attacker enabled xp_cmdshell to execute operating-system commands as the SQL Server service account.T1059.004 · Unix ShellRecorded jobs invoked /bin/sh to read file slices and write command output into job-specific temporary files.T1059.007 · JavaScriptSubmitted tasks invoked Nashorn to execute JavaScript inside the application process with the application account's privileges.T1070.004 · File DeletionThe attacker removed artifacts after completing the associated actions, but the application retained the malicious job history.T1105 · Ingress Tool TransferPrivilege-escalation tools were uploaded through the application command channel in sequential base64 fragments and reassembled on the compromised host.T1134.001 · Token Impersonation/TheftAfter checking for SeImpersonatePrivilege, the attacker staged PrintSpoofer and GodPotato to abuse impersonation privileges and obtained SYSTEM access.T1136.001 · Local AccountThe attacker created two local administrator accounts and left one in place after cleanup.T1140 · Deobfuscate/Decode Files or InformationThe attacker used certutil to reconstruct executable escalation tools from uploaded base64 fragments.T1190 · Exploit Public-Facing ApplicationThe attacker abused an unauthenticated, internet-facing application job-submission feature to execute task definitions; no zero-day or authentication bypass was required.T1552.001 · Credentials In FilesThe attacker recovered plaintext database credentials from application configuration files.

People

Vendors

Products

Tools

AcunetixAcunetixCairnfeature to steal credentials and gain control of a server. The attacker's infrastructure pointed to Cairn, a legitimate open-source orchestration platform for coordinating AI agents on multi-step tasks. Itscertutiltools, a public credential and protocol library, and built-in Windows utilities such as certutil, wmic, and PowerShell. What concealment they did attempt came late and covered little. Artifacts wereClaude CodeAgent execution console. Cairn dispatches agents through adapters named for Claude Code, Codex, and Pi — an adapter names an interface, not a model. This tier sits beneath an orchestrator.CodexAgent execution console. Cairn dispatches agents through adapters named for Claude Code, Codex, and Pi — an adapter names an interface, not a model. This tier sits beneath an orchestrator.CyberStrikeAITitle “CyberStrikeAI,” login pageGodPotatoGodPotato-NET4.exeGrok2APITitle “Grok2API”PiTitle “Pelican · Pi Console,” nginx and ExpressPi ConsoleTitle “Pelican · Pi Console,” nginx and ExpressPowerShella public credential and protocol library, and built-in Windows utilities such as certutil, wmic, and PowerShell. What concealment they did attempt came late and covered little. Artifacts were removed only after thePrintSpooferSource directories for both GodPotato and PrintSpoofer. The attacker compiled from source rather than using published releases.ResinTitle “Resin · Sticky Proxy Pool”wmictools, a public credential and protocol library, and built-in Windows utilities such as certutil, wmic, and PowerShell. What concealment they did attempt came late and covered little. Artifacts were removed

Related Articles