Since late 2021, Seashell Blizzard has used this initial access subgroup to conduct targeted operations by exploiting vulnerable Internet-facing infrastructure following discovery through direct scanning and, more uniquely, use of third-party internet scanning services and knowledge repositories. These exploitation efforts are followed by an operational lifecycle using a consistent set of TTPs to support persistence and lateral movement, which have incrementally evolved to become more evasive over time. Microsoft Threat Intelligence has identified at least three distinct exploitation patterns and operational behaviors linked to this subgroup
Deployment of remote management and monitoring (RMM) suites for persistence and command and control (February 24, 2024 – present)
In early 2024, the initial access subgroup began using RMM suites, which was a novel technique used by Seashell Blizzard to achieve persistence and command and control (C2). This was first observed when the subgroup exploited vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788). The subgroup then deployed RMM software such as Atera Agent and Splashtop Remote Services. The use of RMM software allowed the threat actor to retain critical C2 functions while masquerading as a legitimate utility, which made it less likely to be detected than a remote access trojan (RAT). While these TTPs have been used by other nation-state threat actors since at least 2022, including by Iranian state actor Mango Sandstorm, the Seashell Blizzard initial access subgroup’s specific techniques are considered distinct.
In early 2024, the initial access subgroup began using RMM suites, which was a novel technique used by Seashell Blizzard to achieve persistence and command and control (C2). This was first observed when the subgroup exploited vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788). The subgroup then deployed RMM software such as Atera Agent and Splashtop Remote Services. The use of RMM software allowed the threat actor to retain critical C2 functions while masquerading as a legitimate utility, which made it less likely to be detected than a remote access trojan (RAT). While these TTPs have been used by other nation-state threat actors since at least 2022, including by Iranian state actor Mango Sandstorm, the Seashell Blizzard initial access subgroup’s specific techniques are considered distinct.
Microsoft Threat Intelligence has identified a web shell that we assess as exclusive to the initial access subgroup and is associated with the previously mentioned web shell retrieval patterns. Detected as LocalOlive, this web shell is identified on compromised perimeter infrastructure and serves as the subgroup’s primary means of achieving C2 and deploying additional utilities to compromised infrastructure
BadPilot campaign - Seashell Blizzard subgroup conducts multiyear global access operation (IOCs):
Indicators of Compromise
Indicator Type
def.aspx LocalOlive web shell
akfcjweiopgjebvh@proton[.]me Actor-controlled email address
ohipfdpoih@proton[.]me Actor-controlled email address
miccraftsor@outlook[.]com Actor-controlled email address
amymackenzie147@protonmail[.]ch Actor-controlled email address
ehklsjkhvhbjl@proton[.]me Actor-controlled email address
MirrowSimps@outlook[.]com Actor-controlled email address
MsChSoft.exe Chisel tunneling utility
MsNan.exe Chisel tunneling utility
Msoft.exe Chisel tunneling utility
Chisel.exe Chisel tunneling utility
Win.exe Chisel tunneling utility
MsChs.exe Chisel tunneling utility
MicrosoftExchange32.exe Chisel tunneling utility
Sc.exe Rocstun tunneling utility
103.201.129[.]130 Seashell Blizzard infrastructure
104.160.6[.]2 Seashell Blizzard infrastructure
195.26.87[.]209 Seashell Blizzard infrastructure
hwupdates[.]com Seashell Blizzard infrastructure
cloud-sync[.]org Seashell Blizzard infrastructure
c7379b2472b71ea0a2ba63cb7178769d27b27e1d00785bfadac0ae311cc88d8b LocalOlive
b38f1906680c80e1606181b3ccb8539dab5af2a7222165c53cdd68d09ec8abb0 LocalOlive
9f3d8252e8f3169751a705151bdf675ac194bfd8457cbe08e1f3c17d7e9e9be2 LocalOlive
68c7aab670ee9d7461a4a8f06333994f251dc79813934166421091e2f1fa145c LocalOlive
b9ef2e948a9b49a6930fc190b22cbdb3571579d37a4de56564e41a2ef736767b Chisel
148.251.53[.]222 Seashell Blizzard infrastructure
89.149.200[.]91
17738a27bb307b3cb7bd571934a398223e170842005f1725c46c7075f14e90fe Seashell Blizzard infrastructure
cab97e837a3fc095bf59703574cbfa7e60fb10991101ba9bfc9bbf294c18fd97 LocalOlive
Indicators of Compromise
Indicator Type
def.aspx LocalOlive web shell
akfcjweiopgjebvh@proton[.]me Actor-controlled email address
ohipfdpoih@proton[.]me Actor-controlled email address
miccraftsor@outlook[.]com Actor-controlled email address
amymackenzie147@protonmail[.]ch Actor-controlled email address
ehklsjkhvhbjl@proton[.]me Actor-controlled email address
MirrowSimps@outlook[.]com Actor-controlled email address
MsChSoft.exe Chisel tunneling utility
MsNan.exe Chisel tunneling utility
Msoft.exe Chisel tunneling utility
Chisel.exe Chisel tunneling utility
Win.exe Chisel tunneling utility
MsChs.exe Chisel tunneling utility
MicrosoftExchange32.exe Chisel tunneling utility
Sc.exe Rocstun tunneling utility
103.201.129[.]130 Seashell Blizzard infrastructure
104.160.6[.]2 Seashell Blizzard infrastructure
195.26.87[.]209 Seashell Blizzard infrastructure
hwupdates[.]com Seashell Blizzard infrastructure
cloud-sync[.]org Seashell Blizzard infrastructure
c7379b2472b71ea0a2ba63cb7178769d27b27e1d00785bfadac0ae311cc88d8b LocalOlive
b38f1906680c80e1606181b3ccb8539dab5af2a7222165c53cdd68d09ec8abb0 LocalOlive
9f3d8252e8f3169751a705151bdf675ac194bfd8457cbe08e1f3c17d7e9e9be2 LocalOlive
68c7aab670ee9d7461a4a8f06333994f251dc79813934166421091e2f1fa145c LocalOlive
b9ef2e948a9b49a6930fc190b22cbdb3571579d37a4de56564e41a2ef736767b Chisel
148.251.53[.]222 Seashell Blizzard infrastructure
89.149.200[.]91
17738a27bb307b3cb7bd571934a398223e170842005f1725c46c7075f14e90fe Seashell Blizzard infrastructure
cab97e837a3fc095bf59703574cbfa7e60fb10991101ba9bfc9bbf294c18fd97 LocalOlive
سرویس اطلاع رسانی نقض داده Have I Been Pwned (HIBP) تعداد ۲۸۴,۱۳۲,۹۶۹ حساب کاربری که توسط بدافزارهای Infostealer دزدیده و در کانال تلگرامی ALIEN TXTBASE پیدا شدن رو به دیتابیس خودش اضافه کرده.
حجم این داده ها، 1.5 ترابایت و شامل ۲۳ میلیارد ردیف است که ۴۹۳ میلیون جفت سایت و آدرس ایمیل منحصربهفرد رو در بر میگیره و ۲۸۴ میلیون آدرس ایمیل منحصربهفرد رو تحت تأثیر قرار داده.
با توجه به تعداد زیاد اکانتها در این مجموعه، احتمالاً این دادهها شامل اعتبارنامههای قدیمی و جدید است که از طریق حملات Credential Stuffing و نقضهای دادهای، دزدیده شدن.
قبل از اضافه کردن این اکانتها به HIBP، با بررسی اینکه آیا تلاش برای بازنشانی رمز عبور با استفاده از آدرسهای ایمیل دزدیده شده باعث میشه سرویس ایمیل بازنشانی رمز عبور رو ارسال کنه یا نه، صحت اونارو تأیید کردن.
همچنین این سرویس یسری API هم به سایتش اضافه کرده که امکان جستجو رو برای صاحبان سایتها فراهم میکنه.
برای اینکه بدونید، آیا تحت تاثیر این نقض بودید، فقط کافیه وارد سایت HIBP بشید و ایمیلتون رو برای جستجو وارد کنید.
اگه بخوایید بدونید که اطلاعات اکانتتون در کدوم سایتها تحت تاثیر بوده، باید اشتراک تهیه کنید. این کار برای جلوگیری از افشای اطلاعات حساس انجام دادن.
حجم این داده ها، 1.5 ترابایت و شامل ۲۳ میلیارد ردیف است که ۴۹۳ میلیون جفت سایت و آدرس ایمیل منحصربهفرد رو در بر میگیره و ۲۸۴ میلیون آدرس ایمیل منحصربهفرد رو تحت تأثیر قرار داده.
با توجه به تعداد زیاد اکانتها در این مجموعه، احتمالاً این دادهها شامل اعتبارنامههای قدیمی و جدید است که از طریق حملات Credential Stuffing و نقضهای دادهای، دزدیده شدن.
قبل از اضافه کردن این اکانتها به HIBP، با بررسی اینکه آیا تلاش برای بازنشانی رمز عبور با استفاده از آدرسهای ایمیل دزدیده شده باعث میشه سرویس ایمیل بازنشانی رمز عبور رو ارسال کنه یا نه، صحت اونارو تأیید کردن.
همچنین این سرویس یسری API هم به سایتش اضافه کرده که امکان جستجو رو برای صاحبان سایتها فراهم میکنه.
برای اینکه بدونید، آیا تحت تاثیر این نقض بودید، فقط کافیه وارد سایت HIBP بشید و ایمیلتون رو برای جستجو وارد کنید.
اگه بخوایید بدونید که اطلاعات اکانتتون در کدوم سایتها تحت تاثیر بوده، باید اشتراک تهیه کنید. این کار برای جلوگیری از افشای اطلاعات حساس انجام دادن.
Have I Been Pwned
Have I Been Pwned: Check if your email address has been exposed in a data breach
Search tens of billions of breached records, monitor corporate domains via API, and get alerted when credentials are exposed. Trusted by security teams, MSSPs, and government agencies worldwide.
👍1
ClickFix Phishing Campaign Deploying Havoc C2 via Microsoft SharePoint
ClickFix phishing attack is tricking users into executing malicious PowerShell commands, leading to the deployment of Havoc C2, a post-exploitation framework similar to Cobalt Strike. Attackers distribute phishing emails containing HTML attachments with fake OneDrive error messages, prompting users to run PowerShell scripts. These scripts retrieve payloads from compromised Microsoft SharePoint sites, conduct sandbox checks, modify Windows Registry, install Python if missing, and ultimately inject Havoc C2 as a DLL. The malware leverages Microsoft Graph API to disguise C2 communications, making detection difficult. Mitigation: Avoid executing unsolicited scripts, verify email sources, block unauthorized PowerShell execution.
ClickFix phishing attack is tricking users into executing malicious PowerShell commands, leading to the deployment of Havoc C2, a post-exploitation framework similar to Cobalt Strike. Attackers distribute phishing emails containing HTML attachments with fake OneDrive error messages, prompting users to run PowerShell scripts. These scripts retrieve payloads from compromised Microsoft SharePoint sites, conduct sandbox checks, modify Windows Registry, install Python if missing, and ultimately inject Havoc C2 as a DLL. The malware leverages Microsoft Graph API to disguise C2 communications, making detection difficult. Mitigation: Avoid executing unsolicited scripts, verify email sources, block unauthorized PowerShell execution.
امنیت سایبری SOC
ClickFix Phishing Campaign Deploying Havoc C2 via Microsoft SharePoint ClickFix phishing attack is tricking users into executing malicious PowerShell commands, leading to the deployment of Havoc C2, a post-exploitation framework similar to Cobalt Strike.…
حمله فیشینگ ClickFix کاربران را فریب میدهد تا دستورات مخرب PowerShell را اجرا کنند که در نهایت منجر به استقرار Havoc C2 میشود، یک فریمورک پس از بهرهبرداری مشابه Cobalt Strike. مهاجمان ایمیلهای فیشینگ حاوی فایلهای HTML ارسال میکنند که شامل پیامهای خطای جعلی OneDrive هستند و کاربران را ترغیب میکنند تا اسکریپتهای PowerShell را اجرا کنند.
این اسکریپتها، محمولههای مخرب را از سایتهای آلوده Microsoft SharePoint دریافت کرده، محیطهای آزمایشی (sandbox) را بررسی میکنند، رجیستری ویندوز را تغییر میدهند، در صورت نبود Python آن را نصب میکنند و در نهایت Havoc C2 را بهصورت DLL تزریق میکنند.
بدافزار از Microsoft Graph API برای پنهان کردن ارتباطات C2 استفاده میکند که شناسایی آن را دشوار میسازد.
راهکارهای مقابله:
از اجرای اسکریپتهای ناشناس خودداری کنید.
منابع ایمیلها را تأیید کنید.
اجرای PowerShell غیرمجاز را مسدود کنید.
این اسکریپتها، محمولههای مخرب را از سایتهای آلوده Microsoft SharePoint دریافت کرده، محیطهای آزمایشی (sandbox) را بررسی میکنند، رجیستری ویندوز را تغییر میدهند، در صورت نبود Python آن را نصب میکنند و در نهایت Havoc C2 را بهصورت DLL تزریق میکنند.
بدافزار از Microsoft Graph API برای پنهان کردن ارتباطات C2 استفاده میکند که شناسایی آن را دشوار میسازد.
راهکارهای مقابله:
از اجرای اسکریپتهای ناشناس خودداری کنید.
منابع ایمیلها را تأیید کنید.
اجرای PowerShell غیرمجاز را مسدود کنید.
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs
A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted on Webflow CDN, GoDaddy, and Wix, these PDFs execute PowerShell scripts when victims interact with the CAPTCHA, leading to credential theft and remote access via GhostSocks proxy malware. Mitigation: Avoid downloading untrusted PDFs, do not interact with unsolicited CAPTCHA
A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted on Webflow CDN, GoDaddy, and Wix, these PDFs execute PowerShell scripts when victims interact with the CAPTCHA, leading to credential theft and remote access via GhostSocks proxy malware. Mitigation: Avoid downloading untrusted PDFs, do not interact with unsolicited CAPTCHA
امنیت سایبری SOC
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted…
یک کمپین فیشینگ گسترده با استفاده از تصاویر جعلی CAPTCHA در فایلهای PDF مخرب، بدافزار Lumma Stealer را توزیع میکند و بیش از 1,150 سازمان در آمریکای شمالی، جنوب اروپا و آسیا را هدف قرار داده است.
این PDFها که در Webflow CDN، GoDaddy و Wix میزبانی شدهاند، هنگام تعامل قربانیان با CAPTCHA، اسکریپتهای PowerShell را اجرا میکنند که منجر به سرقت اطلاعات کاربری و دسترسی از راه دور از طریق بدافزار پروکسی GhostSocks میشود.
راهکارهای مقابله:
از دانلود فایلهای PDF ناشناس خودداری کنید.
با CAPTCHAهای مشکوک و ناخواسته تعامل نداشته باشید.
این PDFها که در Webflow CDN، GoDaddy و Wix میزبانی شدهاند، هنگام تعامل قربانیان با CAPTCHA، اسکریپتهای PowerShell را اجرا میکنند که منجر به سرقت اطلاعات کاربری و دسترسی از راه دور از طریق بدافزار پروکسی GhostSocks میشود.
راهکارهای مقابله:
از دانلود فایلهای PDF ناشناس خودداری کنید.
با CAPTCHAهای مشکوک و ناخواسته تعامل نداشته باشید.
امنیت سایبری SOC
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted…
Public indicators:
https[://]booking[.]procedeed-verific[.]com/goo_pdf
https[://]payment-confirmation[.]82736[.]store/pgg46
0419A1942AF24E21F988249DB2C1748509471CCA6B5B7FE9305EAC817C5C4D41
64C9723E61808E95716485B020F24CE3DADFD982E2BF3E94E7EE5E8CED388DC2
71FE618A360C3D077AF47DDB17B35DE5300C94D3F46FB173A039C01D8CA6B86C
7B3BD767FF532B3593E28085940646F145B9F32F2AE97DFA7CDD652A6494257D
8C408B29CBD76F60ECDF703F737408C5C0AE4D87BFA9C43F3307A36DF408122B
AAF43AAB8C08B41682F2B682B05D612651A2B43E235ABC06BB5C4FDE01BF50BE
https[://]booking[.]procedeed-verific[.]com/goo_pdf
https[://]payment-confirmation[.]82736[.]store/pgg46
0419A1942AF24E21F988249DB2C1748509471CCA6B5B7FE9305EAC817C5C4D41
64C9723E61808E95716485B020F24CE3DADFD982E2BF3E94E7EE5E8CED388DC2
71FE618A360C3D077AF47DDB17B35DE5300C94D3F46FB173A039C01D8CA6B86C
7B3BD767FF532B3593E28085940646F145B9F32F2AE97DFA7CDD652A6494257D
8C408B29CBD76F60ECDF703F737408C5C0AE4D87BFA9C43F3307A36DF408122B
AAF43AAB8C08B41682F2B682B05D612651A2B43E235ABC06BB5C4FDE01BF50BE
Security Updates
Account Takeover Vulnerability in ADSelfService Plus (CVE-2025-1723)
The UAE Cyber Security Council has identified a high-severity vulnerability in ManageEngine ADSelfService Plus, a widely used self-service password management and single sign-on (SSO) solution. Organizations utilizing affected versions are advised to apply security updates immediately to mitigate potential risks.
Details
Vulnerability Details • CVE Identifier: CVE-2025-1723
• Severity: High
• Vulnerability Type: Improper Session Handling
• Description:
• The vulnerability arises due to improper session handling in ADSelfService Plus, potentially allowing unauthorized access to user enrollment data.
• If Multi-Factor Authentication (MFA) is not enabled for ADSelfService Plus login, attackers could exploit this flaw to access sensitive user information and potentially compromise accounts.
Affected Products and Services • ADSelfService Plus builds 6510 and earlier
Fixed Versions • ADSelfService Plus build 6511
Mitigation/Workaround • Immediate Upgrade: Update ADSelfService Plus to build 6511 or later to patch the vulnerability.
• Enforce Multi-Factor Authentication (MFA): Enable MFA for ADSelfService Plus logins to reduce the risk of unauthorized access.
• Monitor User Activity: Regularly audit access logs for signs of unauthorized login attempts or unusual user behavior.
References
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
Account Takeover Vulnerability in ADSelfService Plus (CVE-2025-1723)
The UAE Cyber Security Council has identified a high-severity vulnerability in ManageEngine ADSelfService Plus, a widely used self-service password management and single sign-on (SSO) solution. Organizations utilizing affected versions are advised to apply security updates immediately to mitigate potential risks.
Details
Vulnerability Details • CVE Identifier: CVE-2025-1723
• Severity: High
• Vulnerability Type: Improper Session Handling
• Description:
• The vulnerability arises due to improper session handling in ADSelfService Plus, potentially allowing unauthorized access to user enrollment data.
• If Multi-Factor Authentication (MFA) is not enabled for ADSelfService Plus login, attackers could exploit this flaw to access sensitive user information and potentially compromise accounts.
Affected Products and Services • ADSelfService Plus builds 6510 and earlier
Fixed Versions • ADSelfService Plus build 6511
Mitigation/Workaround • Immediate Upgrade: Update ADSelfService Plus to build 6511 or later to patch the vulnerability.
• Enforce Multi-Factor Authentication (MFA): Enable MFA for ADSelfService Plus logins to reduce the risk of unauthorized access.
• Monitor User Activity: Regularly audit access logs for signs of unauthorized login attempts or unusual user behavior.
References
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
Manageengine
CVE-2025-1723 – Account takeover vulnerability in ADSelfService Plus